
Sign up to save your podcasts
Or


In this episode, Robby chats with Erlend Gjære, Co-founder and CEO of Secure Practice, on how to turn an organisation’s users into its last line of defense against email threats.
Erlend has spent most of his career studying people and their email habits. At Secure Practice he combines scientific research and employee behavior to find out how to best reach through with security awareness messaging in organisations, by identifying why people do what they do, how they do it, and most importantly, how to make them do it securely.
Robby and Erlend discuss email as an attack vector, and what companies are doing to protect themselves. They also talk about what is actually working nowadays in terms of security awareness, and what the most successful companies are doing.
Technical level: 1/5
Host: Robby Peralta
Producer: Paul Jæger
Suggested reading:
https://www.mnemonic.no/security-report-2020/the-missing-link-in-email-security
https://mnemonic.no/podcast
Send us Fan Mail
The CISO role in Operational Technology (OT) means securing environments where digital and physical worlds meet, and where a service disruption in the digital space can have a direct and immediate impact on our physical world.
In this episode, Robby wants to know how a CISO handles the challenge of securing both IT and OT environments.
To kick off our miniseries on OT, Robby welcomes Karsten Duus Wetteland, CISO at BKK. BKK is a leading organisation within renewable energy, working to replace fossil fuels by electrifying everything from fishfarms, cars and cruise ships, to the oil and gas industry's offshore power supplies.
Karsten shares how they are finding new methods to identify risks when the risk spectrum spans from trees falling over power lines to hacked fish tanks. And how to avoid IT risks becoming OT risks.
Stay tuned for more OT specific episodes in the coming weeks.
Technical level: 1/5
Host: Robby Peralta
Producer: Paul Jæger
https://mnemonic.no/podcast
Send us Fan Mail
In this episode, Robby chats with two experts from mnemonic that are highly passionate about microservices; security researcher Andreas Claesson and Head of Development of our Argus security platform, Joakim von Brandis.
Andreas explains how he works with microservices with customers, and what the dark side of microservices are regarding security. Joakim returns to the podcast to show how mnemonic's Argus security platform made the transition over to microservices. If you haven't heard Joakim's first episode, we recommend you check it out (episode 4 - Under the hood of Argus).
Have a listen to learn how microservices are useful, and what companies that use microservices should be monitoring for.
Technical level: 3/5
Host: Robby Peralta
Producer: Peter Harket
Show notes:
https://www.mnemonic.no/security-report-2019/
https://www.mnemonic.no/globalassets/security-report/serverless-security.pdf
https://www.mnemonic.no/mnemonic-security-podcast/episode-4/
https://aws.amazon.com/whitepapers/
https://mnemonic.no/podcast
Send us Fan Mail
How to best avoid being stuck in Groundhog Day?
In the second part of our mini series about SOAR, Robby chats with a gentleman that was referred to as The Godfather of SOAR in the first episode of the series.
Rob Gresham, SANS Instructor specialising in automation for Security Operation Centers and a Security Solutions Architect at Splunk, takes us through how to be successful with automation, the evolution of Phantom and what he thinks he will be spending his time on going forward.
Technical level: 2/5
Host: Robby Peralta
Producer: Paul Jæger
Show notes:
"Hacking your SOEL. SOC Automation and Orchestration – SANS Security Operations Summit": https://www.youtube.com/watch?v=_mnxZ1iSUGg
https://mnemonic.no/podcast
Send us Fan Mail
Do it smart, so you won't have to do it again.
In this episode, we chat with Tibor Földesi, Security Automation Analyst in Norlys, one of the largest Telco & Energy companies in Denmark. At Norlys, his main motivation is to get more time to enjoy his coffee, which directly correlates with his ability to automate what can be automated.
Tibor and Robby discuss what we can and cannot automate within security, as of now. And Tibor shares his recommendations for SOAR vendors.
Technical level: 2/5
Host: Robby Peralta
Producer: Paul Jæger
Send us Fan Mail
In this episode, we chat with the people in charge of the healthcare and sensitive data collected in what is amongst the world's largest COVID-19 studies to date.
The study known as the Corona Study, is lead by the Oslo University Hospital and aims to examine how the coronavirus spreads in Norway. At the time this episode was recorded the study had been available for 19 days and more than 122 000 people had already answered the questionnaire.
Dr. Gard Thomassen and Leon Charl du Toit work in an organisation called TSD at the University of Oslo. TSD (in Norwegian) is an abbreviation for "Service for sensitive data" and is a big data/ security platform that researchers use to carry out their studies.
We talk about how the sensitive data collected is handled in terms of security, and how they were able to set up the infrastructure for the study in less than 24 hours.
Technical level: 2/5
Show Notes:
https://tv.nrk.no/serie/nyheter/202004/NNFA41017520/avspiller (from minute 12:20)
https://www.uio.no/english/services/it/research/sensitive-data/
https://www.usit.uio.no/om/aktuelt/2020/koronastudien.html
Host: Robby Peralta
Producer: Peter Harket
Send us Fan Mail
Who should own Identity and Access Management in an organisation?
In this episode, Robby speaks to Espen Skjøld from Sailpoint about the evolution of Identity and Access Management - and he also found some interesting people to discuss this with from Equinor and UCPH on the floor of the Nordic Cyber Series in Copenhagen.
Technical Difficulty: 1/5
SailPoint: Espen Skjøld
Equinor: Deric Stroud
UCPH: Poul Halkjær Nielsen
Host: Robby Peralta
Producer: Paul Jæger
https://mnemonic.no/podcast
Send us Fan Mail
In this episode, we speak with a security expert that is actually willing to pay money to "hackers" - the Product Security Director in Visma, Espen Johansen.
As you can imagine, eliminating software vulnerabilities in a company with 5,000 developers is no easy task. Mr. Johansen and his developers always aim to improve the security of their software, among other things through organising both private and public bug bounty programs. If you are interested in bug bounty programs, this interview is a great place to start! As he shares his advise for when and what it takes for an organisation to be ready for bug bounty.
Technical difficulty: 2/5
Host: Robby Peralta
Producer: Paul Jæger
Related reading:
https://hackerone.com/visma
https://www.visma.com/trust-centre/smb/security-and-privacy/operational/responsible-disclosure/
https://www.visma.com/trust-centre/smb/security-and-privacy/operational/responsible-disclosure/hall-of-fame/
Send us Fan Mail
In this episode, we chat with the former Head of the SOC at the Norwegian National CERT, and current member of mnemonic’s Threat Intelligence team. She also happens to have a personal interest in the "Internet of Things" and medical devices.
In 2011, Marie Moe received a pacemaker to help her heart maintain a consistent beat. As a security researcher, she felt the need to do her homework and figure out everything she could about the device that had newly been introduced to her body. What she found prompted her to join the "I Am The Cavalry" group, an organisation focusing on the impact computer security has on public safety and human life, which since then has lead a revolution in the medical device industry.
Technical level: 1/5
Host: Robby Peralta
Producer: Paul Jæger
Show notes:
Hippocratic Oath for Connected Medical Devices: https://www.iamthecavalry.org/domains/medical/oath/
Software Transparency and the SBOM multistakeholder process at the US NTIA: https://www.ntia.doc.gov/SoftwareTransparency
New EU regulations for medical devices: https://ec.europa.eu/growth/sectors/medical-devices/new-regulations_en
Send us Fan Mail
In this episode, we chat with the CISO of consumer goods conglomerate Orkla - Antonio Martiradonna.
In 2017, he accepted the task of building up a security organisation to secure 300 brands, helping us to keep food in our fridges and beauty products in our bathrooms. In our conversation, we discuss the following:
· How it has been to build a security organization from the ground up
· How to work with the governance of so many brands
· Security around the physical production of products
Technical level: 1/5
Host: Robby Peralta
Producer: Paul Jæger
Send us Fan Mail
From the publisher's feed
Hosted by Robby Peralta from mnemonic, one of Europe’s leading cybersecurity companies, the show features conversations with researchers, founders, operators, and security leaders working across…
Each episode explores a specific topic within cybersecurity: from incident response, threat intelligence, AI, and geopolitics, to leadership, resilience, and the changing role of security leaders.
The podcast is tailored to cybersecurity practitioners and decision-makers who want grounded conversations about where cybersecurity is going, what organisations should prepare for, and what experienced people are seeing.

650 Listeners

1,027 Listeners

85 Listeners

21 Listeners

317 Listeners

111,852 Listeners

8,061 Listeners

179 Listeners

1 Listeners

7 Listeners

0 Listeners

137 Listeners

2 Listeners

24 Listeners

0 Listeners