
Sign up to save your podcasts
Or


How to succeed with bug bounties
Responsible disclosure and vulnerability reporting have come a long way in recent years, and have gone from being feared and even something you took legal action against, to something that is appreciated for its value.
Ioana Piroska, Bug Bounty Program Manager at Visma, joins Robby to share how Visma has succeeded with their bug bounty program. She talks about Vismas’ approach to these kind of programs, and the actual value they receive from them.
Ioana and Robby discuss the difference between penetration testing and a bug bounty program, and how they complement each other. And how Visma also uses their live hacking competitions and public responsible disclosure program to improve their vulnerability detection capabilities.
Video version (with presentation) available on our YouTube channel!
Send us Fan Mail
Influencing the board
What are some of the most effective methods of gaining a board’s support, and how do you maintain this trust and improve it over time?
Our guest today has worked with a lot of boards, and joins us to share his experiences providing boards with the tools to ask the right questions when it comes to cybersecurity, and conveying to them why cybersecurity is important for their organisation.
Roger Ison-Haug has worked in IT for close to 30 years and is now working as the CISO & DPO at the data science and weather intelligence provider StormGeo. He is also currently working on his PhD in cybersecurity and leadership.
Roger and Robby discuss the most common challenges that boards experience, and what kind of questions they usually ask. They also talk about what it’s actually like being a board member, Roger’s best advice to security people wanting to influence a board, and what kind of questions security people usually aren’t very good at answering – but should be.
Send us Fan Mail
KraftCERT trusselvurdering 2023 | In Norwegian only
Our podcast guest this week is Espen Endal, previous mnemonic colleague and currently OT Security Analyst at the Norwegian energy sector CERT: KraftCERT/InfraCERT.
InfraCERT is an ISAC (Information Sharing and Analysis Center) and an IRT (Incident Response Team). Mainly working to update their members about relevant vulnerabilities and threats to make them able to better detect and respond to digital attacks. They are also part of the Norwegian national response organisation.
During their conversation, Robby and Espen discuss KraftCERT/InfraCERT's annual threat report, what they consider the most serious threats for their member organisations, both long term and short term, and what techniques they often see being used against their members.
Espen also talks about the push to the cloud, the trade-off this entails particularly in these sectors, as well as the impact NIS and eventually NIS2 will have on their members.
Send us Fan Mail
Avoiding overload and managing stress in cybersecurity
For today’s episode, Robby’s joined by Lisa Ventura, Cybersecurity Specialist, Author, and qualified Mental Health First Aider. After many years of experience from the industry, she’s become particularly interested in the human aspects of cybersecurity, especially when it comes to mental health issues, stress, and burnouts.
During their conversation, Lisa explains how common stress and burnouts are in InfoSec and cybersecurity, and discuss how the pandemic impacted these numbers. As well as what the main factors contributing to stress and burnout in our industry is, and how these symptoms manifest themselves.
She also shares some advice on how to combat overload and stress both on an individual and organisational level.
If you’d like to also see Lisa’s presentation, feel free to visit our YouTube channel to watch the full recording of the episode.
Send us Fan Mail
Asset Intelligence
Imagine a scenario where your organisation discovers that a threat actor currently possesses more knowledge about your environments than you do. Let’s find a way to make sure we don’t end up there - but how?
For this episode, Robby is joined by a serial entrepreneur and serial guest at the mnemonic security podcast. For the fourth time, we’re welcoming Brian Contos. Today, to discuss his latest role as Chief Strategy Officer at Sevco, a company specialising in asset intelligence.
Brian talks about the importance of having an accurate and comprehensive understanding of your assets' security and compliance status, especially in the governance, risk, and compliance (GRC) landscape. As well as how asset intelligence is gaining renewed attention in the industry.
Send us Fan Mail
Operationalising Threat Intelligence
What can you do to get the most out of your threat intelligence initiatives?
A good place to start, is picking Kyle Wilhoit’s brain. Kyle’s the Director of Threat Research at Palo Alto Network's Unit 42, and author of the book Operationalizing Threat Intelligence: A guide to developing and operationalizing cyber threat intelligence programs.
During his chat with Robby, he provides some advice on how organisations should be handling their threat intelligence, what you can leverage from your vendors and partners, and what you need to do yourself to achieve full value from your threat intelligence.
He also shares the major trends that Unit 42 are seeing when it comes to hacking tools, attack frameworks, campaigns, malware, and ransomware.
Send us Fan Mail
Crypto Finance
How does a crypto finance agency work with security?
To answer this question, and provide insight into security in the world of crypto, we’re joined by Dr. Dominik Raub. He has more than 10 years of experience from the financial industry, a Doctor of Sciences in Cryptography, and works as CISO at Crypto Finance AG, an organisation providing crypto and blockchain services to institutional clients.
Dominik talks about the threat landscape they are in, the adversaries in the space, and what he’s learned about their TTPs. As well as the mechanisms his organisation uses to help them distinguish bad transactions and stop large-scale issues.
Robby and Dominik also discuss the recent developments in the crypto finance market, and Dominik shares what he predicts will happen in the market in the years to come.
Send us Fan Mail
Office IoT
Can you say for certain that you have a full overview of the IoT devices that are set up in your office environment? Smart Lighting, thermostats, locks, appliances, security cameras, sensors... perhaps even a fish tank?
To talk about the importance of securing our office IoT, and specifically our printers, Robby is joined by Quentyn Taylor, Senior Director – Information Security and Global Response at Canon.
During their conversation, Quentyn shares from his vast experience working with both IT and information security, and the security evolution he’s observed in office IoT throughout his career.
He also shares his expert advice on how to secure these products, the main security challenges associated with them, and how zero trust affects this conversation.
Send us Fan Mail
Passwords and their managers
How do you create your passwords? Do you get help from a password manager, or is your personal “system” bulletproof?
Robby has invited two guests passionate about passwords, and how we manage them. Not surprisingly, they can with confidence say that our own “systems” are highly guessable, and not as unique as you might think.
Our experts this episode, Cecilie Wian from the Norwegian consultancy Bouvet, and Per Thorsheim CISO and password & digital authentication researcher, share why are they so fascinated with passwords. They also discuss under what circumstances password managers work best, and how to convince your staff to actually use them. As well as what they see for the future of passwords.
Interested in this topic? Feel free to check out this conference! https://passwordscon.org/
Send us Fan Mail
Darkwebs
Most of us have our ideas and perceptions of what the Dark Web is. But could it be more than just the dark side of the World Wide Web?
To talk about the Dark Web, Robby is joined by Keven Hendricks, Dark Web Subject Matter Expert at The Ubivis Project. Keven has worked in law enforcement in the US since 2007, in areas such as computer and mobile device forensics, and Dark Web investigations. In 2021, Hendricks founded The Ubivis Project – StopDarkwebDrugs.com as a medium for both law enforcement and civilians to report Dark Web vendors and overdoses.
Holding more experience than most within this area, he now works to break the stigmas out there about what the Dark Web is, what you can find on the Dark Web, and particularity what you can do as an investigator or researcher involving the Dark Web. He also teaches this to law enforcement and other public sector entities including the Department of Defense.
Keven and Robby dive into the misconceptions around the Dark Web, what Keven’s learned about Dark Web investigations, how accessible the different Darknets have become, as well as why the Dark Web has become important for privacy and free speech in some countries.
Send us Fan Mail
From the publisher's feed
Hosted by Robby Peralta from mnemonic, one of Europe’s leading cybersecurity companies, the show features conversations with researchers, founders, operators, and security leaders working across…
Each episode explores a specific topic within cybersecurity: from incident response, threat intelligence, AI, and geopolitics, to leadership, resilience, and the changing role of security leaders.
The podcast is tailored to cybersecurity practitioners and decision-makers who want grounded conversations about where cybersecurity is going, what organisations should prepare for, and what experienced people are seeing.

651 Listeners

1,028 Listeners

84 Listeners

22 Listeners

317 Listeners

111,874 Listeners

8,055 Listeners

179 Listeners

1 Listeners

7 Listeners

0 Listeners

138 Listeners

3 Listeners

25 Listeners

0 Listeners