mnemonic security podcast

mnemonic security podcast

Download on the App Store

mnemonic security podcast episodes

  • Innsiderisiko

    Insider threats | In Norwegian only

    Where should organisations start to protect themselves from insider threats?

    For this episode on insider risks, Robby is joined by Frode Skaarnes, COO at Lørn, a startup creating digital learning programs, with long experience from The Norwegian National Security Authority (NSM), as well as Kristian Haga from mnemonic’s Governance Risk and Compliance department.

    They share from their experience working to help organisations minimise their risks of insider threats towards both the public and private sector, discuss how insiders often operate and why it’s especially important to separate between intentional and unintentional insiders.

    Frode and Kristian also go into what organisations can do to pre-emptively minimise their own risks, and how working from home during the pandemic has impacted how we approach this risk. 

    Related reading:
    https://nsm.no/regelverk-og-hjelp/rad-og-anbefalinger/grunnprinsipper-for-personellsikkerhet/introduksjon/
    https://www.mnemonic.no/globalassets/security-report/we-need-to-talk-about-insider-threats.pdf 

    Producer: Paul Jæger

    Send us Fan Mail

    30 min
  • Does your managed SOC suck?

    Does your managed SOC suck?

    Are you fighting today’s war with yesterday’s weaponry?

    Morten Munck, Engagement Manager at the cybersecurity advisory company Improsec, joins Robby to discuss his much-shared article “Does your managed SOC suck?” with the top ten red flags suggesting that your managed SOC provider should step up their game.

    Morten has a background from finance and telecommunication and holds a strong profile within Blue Teaming - particularly SIEM, SOC and detection engineering, and has long experience helping customers build and operate their SOCs.

    During this episode, they discuss gathering the right telemetry, stale use-case catalogues, and how you know if it’s time to start looking elsewhere.

    Related reading: https://improsec.com/cyber-blog/does-your-managed-soc-suck

    Produced by Paul Jæger

    Send us Fan Mail

    39 min
  • Project 2030

    Project 2030: Future trends in security

    To share the findings from his new report and webseries called Project 2030, Rik Ferguson, the Vice President of Security Research at Trend Micro, chats with Robby about what role cybersecurity will play in year 2030.

    Rik has used his over twenty-five years of experience in information security looking forward, sharing what he’s found when trying to anticipate the next ten years of technology, and what opportunities that will mean for cybercriminals. As well as their impact on security, both for the enterprise and for society as a whole.

    In their discussions they go into what will change in the sensors and wearables space, and topics like 4D printing, neuralink and cyber-implants. As well as the ethical considerations to the worth of our data and technical tools helping us telling facts from fiction. Rik also shares what he considers the biggest collective risks going forward from a security perspective.

    Related reading: https://2030.trendmicro.com/

    Produced by Paul Jæger

    Send us Fan Mail

    37 min
  • CMMC

    CMMC: Cybersecurity Maturity Model Certification

    Your security reflects your maturity.

    For this episode, Robby is joined by two of mnemonic’s security experts from our Governance, Risk and Compliance department to talk about CMMC and the alphabet soup that comes with it.

    Both of them have experience preparing organisations for what CMMC actually means for them. Anders Hval Olsen as an Information Security Management Implementation subject-matter expert, and Kenneth Crawford, using his long experience with US Defense and defense contracting, among other things as a Cybersecurity Manager at Lockheed Martin.

    They discuss how the new cybersecurity requirements to work with the US Defense industry will influence both US organisations and international subcontractors performing everything from software development to human resource services. As well as what CMMC actually means for securing your supply chain and investing in your security posture, why they believe every security professional should have knowledge of CMMC and how CMMC 2 differs from the original certification model.

    Related reading: https://www.mnemonic.no/blog/cmmc/

    Producer: Paul Jæger

    Send us Fan Mail

    38 min
  • Mergers & Acquisitions

    The business of cyber security: Mergers & Acquisitions

    What separates the acquisitions that go well from those that don’t?

    To discuss the business side of security, Robby is joined by Brian Contos; returning guest, fellow podcast host, serial security entrepreneur and CISO & Vice President of Mandiant Security Validation. 

    Mandiant Security Validation, previously known as Verodin, was acquired by Mandiant little over two years ago. In this episode, Brian shares from his experience going through that process, as well as other similar transitions he’s been a part of throughout his 25 year long career in security.

    In their discussions, they go into everything that leads up to an acquisition decision, picking the right company with the right DNA and how to get the two companies to fit together.

    Brian also shares what he’s learned about how to start your own security company, and why he believes there’ll be more mergers and acquisitions happening in the security space in the next years than we’ve seen in the last two decades.

    Producer: Paul Jæger

    Send us Fan Mail

    46 min
  • Initial Access Brokers

    Initial Access Brokers (IABs)

    The growth and professionalisation of the Initial Access Market has fascinated many in recent years. Few know as much about who the threat actors operating in these markets are, and how the market of providing others with remote access to corporate networks work as   Dmitry Shestakov, Head of Cybercrime Research at the cyber intelligence company Group-IB. 

    In his conversation with Robby, Dmitry shares some of his findings after researching these underground communities over several years. He also goes into how his team of researchers work with Initial Access Brokers, and shares some light onto some of their on-going investigations.

    They also discuss where these groups operate from, how many of them manage to remain uncovered, and who they actually sell their information to.

    Producer: Paul Jæger

    Send us Fan Mail

    38 min
  • Communicating threat intelligence to management

    Communicating threat intelligence to management

    For this episode, Robby has invited someone with a unique expertise of the threat landscape in the finance industry. Freddy works as a Senior Threat Intelligence Analyst at the Nordic Financial CERT, a nonprofit organisation owned by the financial institutions in Norway, Sweden, Demark, Finland and Iceland.

    By receiving data from and supporting their 220 member financial institutions on tasks like incident response, anti-fraud and threat intelligence, the Nordic Financial CERT has a one of a kind overview of the threat these organisations are facing.

    Freddy shares with Robby how they work to make sure their members are defending themselves against their most relevant threat actors, how they approach intelligence, and translating technical analyses to a language understood by the entire business.

    They also discuss what the data the Nordic Financial CERT has access to can tell us about changes in the ecosystem of organised crime groups targeting financial institutions.

    Producer: Paul Jæger

    Send us Fan Mail

    47 min
  • Buying security products

    Buying security products

    Purchasing cybersecurity solutions and services can be challenging. Not only is the industry rapidly evolving, but there is rarely a case where solutions can be compared "apples to apples."  

    In this episode, we explore the procurement of cybersecurity solutions. Robby is joined by Thor Milde, SVP - Head of IT Access Management at DNB, sharing his experiences from one of the largest banks in the Nordics, and Øyvind Nordvik, BID Manager in mnemonic, with more than 10 years of experience from procurement.

    They discuss where the seller and customer side have mutual interests, and the role of procurement departments. And they try to answer the question; how can we make sure we buy the right services? For the right price?

     Producer: Paul Jæger 

    Send us Fan Mail

    33 min
  • The state of cyber insurance in 2021

    How is it possible for the insurance industry to adapt to a cyber threat landscape that is continuously changing?

    To try to answer that, and explain the evolution the cyber insurance field has gone through the last few years, Robby is joined by Jens Zakarias and Paul Jæger from Riskpoint, a global insurance underwriter agency.

    They dive into how cyber insurance differs from more traditional insurance, and the five things every organisation needs to have in place for an insurance company to even consider them as a client.

     Producer: Paul Jæger 


    Send us Fan Mail

    31 min
  • Can threat intelligence be automated?

    Can threat intelligence be automated?

    If so, what can be automated, and what should still be left in the hands of human analysts?

    With us today, we have PhD. Martin Eian, Head of R&D in mnemonic. He sits down with Robby to speak about his team’s part in building a security platform to prevent cyber-threats together with nine other European organisations. The research project bringing these organisations together is called SOCCRATES, and is part of the European Union's Horizon 2020 Research and Innovation program (https://www.soccrates.eu/).

    Martin describes how the research project aims to semi-automate threat intelligence in a platform for security operations centres (SOCs) and incident response teams, to help them better detect attacks and make the correct decisions on how to handle them.

    He also shares some of his experience with how companies are actually working with threat intelligence today.

    Technical level: 3/5

    Producer: Paul Jæger

    Send us Fan Mail

    36 min

About mnemonic security podcast

From the publisher's feed

Hosted by Robby Peralta from mnemonic, one of Europe’s leading cybersecurity companies, the show features conversations with researchers, founders, operators, and security leaders working across…

More shows like mnemonic security podcast

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast) by Johannes B. Ullrich

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

651 Listeners

CyberWire Daily by N2K Networks

CyberWire Daily

1,028 Listeners

Misjonen med Antonsen og Golden by P4-gruppen

Misjonen med Antonsen og Golden

84 Listeners

#pengepodden by Nordnet

#pengepodden

22 Listeners

Smashing Security by Graham Cluley

Smashing Security

317 Listeners

The Daily by The New York Times

The Daily

111,874 Listeners

Darknet Diaries by Jack Rhysider

Darknet Diaries

8,055 Listeners

Cybersecurity Today by David Shipley

Cybersecurity Today

179 Listeners

Nasjonal sikkerhetsmyndighet (NSM) by Nasjonal sikkerhetsmyndighet (NSM)

Nasjonal sikkerhetsmyndighet (NSM)

1 Listeners

Nerdelandslaget by Nerdelandslaget // Acast

Nerdelandslaget

7 Listeners

MEDVIND by Alexis Barnekow

MEDVIND

0 Listeners

Cybersecurity Headlines by CISO Series

Cybersecurity Headlines

138 Listeners

Prompt by DR

Prompt

3 Listeners

Only in America by RADIO IIII

Only in America

25 Listeners

Plattformpodden by Hans Kristian Flaatten og Audun Fauchald Strand

Plattformpodden

0 Listeners