mnemonic security podcast

mnemonic security podcast

Download on the App Store

mnemonic security podcast episodes

  • Security Engineering - IAM

    The importance of identity within our field has been established. According to analysis from CrowdStrike, 8/10 attacks are identity-based. But what does that actually mean? How do we even define identity these days, and how has it changed?

    To look into this, Robby has invited an expert within the field, Peter Barta. Peter works as a Senior Cloud Security Engineer at Rothesay, the UK's largest specialist pensions insurer, securing pensions for over 810 000 people, and has previously worked in Norges Bank Investment Management (NBIM) which manages the Norwegian Government Pension Fund Global.

    During their conversation, Peter takes us both to the far side of Security Engineering, as well as goes though some of the more standard best practice most organisations should have on their radar.

    They talk about how you can design and create something that is user-friendly enough for everyone in an organisation, also the users not interested in identity or security. As well as the developer side of secret management, dynamic sessions, zero trust, and what he thinks security engineers should focus more on.

    Send us Fan Mail

    40 min
  • Bots

    Bots; they can be both helpful assistants and harmful pests, and you’ll find them all over the internet targeting most public facing applications in some way or another. But what actually are they?

    To explore the bad bots on the Internet, Robby is joined by someone that has spent the last seven years studying them, Dan Woods, Global Head of Intelligence, F5.

    They talk about why Dan became fascinated by bots, real-life examples of how bots are being used, and what separates the sophisticated bots from the rest.

    They also discuss if we are underestimating the sophistication and the motivation of the organisations behind these automations, how botnets and human click farms work, and whether Elon Musk will be able to solve his bot problem on Twitter.

    Send us Fan Mail

    39 min
  • We are Defending (ISACA series)

    This episode is for anyone working within cybersecurity that has ever had to explain what they actually do, or defend why they are investing in security.

    We’re happy to welcome Jeff Barto back to the podcast, to go through his presentation “We are Defending” that he presented at mnemonic’s C2 summit this summer. Jeff is the CISO of a large hedge found in the US, and has worked in security for over 20 years. He will share some of the key lessons from his presentation that aims to explain what it is we, the defenders out there, actually do. 

    During his presentation, Jeff goes through the importance of continuous improvement in security, testing, and how to identify what your major gaps are and what you need to take care of in 2023.

    To follow Jeff’s PowerPoint presentation, Feel free to check out the video version of the podcast on ISACA Norway's channel - https://www.youtube.com/@isacanorwaychapter

    Send us Fan Mail

    41 min
  • House of Pain (ISACA series)

    House of Pain: new EU cyber regulations

    NIS2, DORA, the Cyber Resilience and Artificial Intelligence acts; have you started to familiarise yourself with the new EU cyber regulations that are coming into force?

    In this episode, Robby welcomes Rolf von Roessing, former Vice Chair of ISACA Global, and CEO of FORFA Consulting, a German company specialising in senior level consultancy and advisory work.

    During their conversation, Rolf provides an introduction to a few new and upcoming EU regulations many are now starting the familiarise themselves with; the Network and Information Security Directive, version 2 (NIS2), the EU Cyber Resilience Act, the Artificial Intelligence Act and the Digital Operational Resilience Act (DORA).

    Rolf walks us through these upcoming regulations, and provides an overview of the main differences between them, who the regulations are for and who they will affect.

    Feel free to check out the video version of the podcast on ISACA Norway's channel - https://www.youtube.com/@isacanorwaychapter

    Send us Fan Mail

    43 min
  • Insider threats to ransomware groups

    What happens when cyber criminals don’t get what they believe they're owed?

    For this episode, Robby is joined by John Fokker, Head of Trellix Threat Intelligence. John shares from his long experience fighting cybercrime, where he among other places has worked for the Dutch National High-Tech Crime Unit (NHTCU), the Dutch National Police unit dedicated to investigate advanced forms of cybercrime. John was also one of the co-founders of the NoMoreRansom Project.

    They discuss John’s encounter with an insider in a ransomware group, the valuable information these situations provide the security community, and what we have learned from them.

    John also talks about how cybercrime has changed during his career, and how the war in the Ukraine has affected organised cybercrime.

    Send us Fan Mail

    31 min
  • Network detection and response (NDR): the value of evidence

    Network detection and response (NDR): the value of evidence

    What exactly is NDR, how have these technologies changed over the years, and are they more relevant now than ever?

    To help answer these questions, Robby is joined by Jean Schaffer. She’s had, to say the least, an interesting career with more than 33 years of experience from the US Department of Defense. Including managing the network of the NSA, and holding the position of CISO of the Defense Intelligence Agency. Currently she’s the Federal CTO at Corelight, an open-source network detection and response company.

    During their conversation, they talk about the differences, limitations and benefits of EDR and NDR, what evidence based detection really is, and President Biden’s Executive Order on Improving the Nation's Cybersecurity.

    She also shares some of the most common pain points she’s observed that organisations are looking to solve, as well as go into how the adaption of cloud affects the value of NDR, and her take on the future of NDR.

    Send us Fan Mail

    34 min
  • ICS in the Cloud

    Industrial Control Systems (ICS) in the cloud

    Can the cloud fundamentally revolutionise Operational Technology (OT) security?

    To help Robby understand some of the nuances of OT security and help connect the dots between IT and OT, we’re joined by Vivek Ponnada from the OT, ICS & IoT security company Nozomi Networks.

    Vivek shares from his 24 years of experience working with ICS, and explains how much cloud is and is going to be utilised within OT in the years to come.

    He also shares what threats he is seeing in the OT space, as well as some examples of what’s up-and-coming in OT security

    Send us Fan Mail

    36 min
  • Enterprise Security Architecture

    Enterprise Security Architecture

    Most organisations find it challenging to protect themselves against the ever-evolving list of risks and threats. The fact that most of us do this with a limited set of resources makes this even more complicated.

    Knowing what you should spend your time and efforts on is far from straight forward. But hopefully this episode on enterprise security architecture can give some guidance on where to start mapping out the best path for your organisation.

    We’re joined by both Nick Murison, CISO at Ardoq, a tool for enterprise architecture that helps companies understand the interdependencies between their technology and people, and Angel Alonso, a CISO for hire and team lead for the Governance, Risk and Compliance (GRC) department in mnemonic.

    During their conversation with Robby, they discuss mapping and identifying an organisation’s security gaps, IT cost management, and the importance of traceability in security.

    Related reading:

    https://www.ardoq.com/blog/mnemonic-enterprise-security-architecture

    https://www.mnemonic.io/solutions/enterprise-security-architecture/

    Send us Fan Mail

    29 min
  • Azure / Office365: monitoring & hardening

    Azure monitoring & hardening

    What is the best way to build and automate security in the world of Azure?

    For this episode, Robby has invited someone that spends all their time doing exactly that, or more specifically, identifying all the things that can go wrong within the Microsoft ecosystem; Rik van Duijn, Hacker & Co-Founder of the Dutch cybersecurity company Zolder B.V.

    They discuss what’s beneficial for organisations to manage themselves – and what the realistic expected workload is. They also discuss hardening of Azure tenants, deployment and tuning of Azure Sentinel, importance of logging for incident responders and other Azure central components that are noteworthy. 

    During their conversation, Rik also shares what he would recommend automating, and what he would not automate. As well as what the biggest challenges his clients most often experience are.

    Send us Fan Mail

    38 min
  • Keeping the lights on

    Who are the people helping us to keep the lights on? And what are our adversaries doing to get in the way of this? 

    This episode of the mnemonic security podcast is directing some love and attention toward the people working with Operational Technology (OT) / Industrial Control Systems (ICS). 

    To help him navigate this field, Robby is joined by Michael Weng, Senior Security Consultant OT/ICS at the security company WithSecure (formerly known as F-Secure for Business).

    They talk about cyber warfare directed at critical infrastructure in the Ukraine, what trends Michael  are seeing in the OT security space, and what the main concerns of the experts in the field are these days. Michael also shares his views on venturing into cloud, and what common challenges he’s observed when it comes to testing/assessments, resilience, and incident response.

    Send us Fan Mail

    26 min

About mnemonic security podcast

From the publisher's feed

Hosted by Robby Peralta from mnemonic, one of Europe’s leading cybersecurity companies, the show features conversations with researchers, founders, operators, and security leaders working across…

More shows like mnemonic security podcast

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast) by Johannes B. Ullrich

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

651 Listeners

CyberWire Daily by N2K Networks

CyberWire Daily

1,028 Listeners

Misjonen med Antonsen og Golden by P4-gruppen

Misjonen med Antonsen og Golden

84 Listeners

#pengepodden by Nordnet

#pengepodden

22 Listeners

Smashing Security by Graham Cluley

Smashing Security

317 Listeners

The Daily by The New York Times

The Daily

111,874 Listeners

Darknet Diaries by Jack Rhysider

Darknet Diaries

8,055 Listeners

Cybersecurity Today by David Shipley

Cybersecurity Today

179 Listeners

Nasjonal sikkerhetsmyndighet (NSM) by Nasjonal sikkerhetsmyndighet (NSM)

Nasjonal sikkerhetsmyndighet (NSM)

1 Listeners

Nerdelandslaget by Nerdelandslaget // Acast

Nerdelandslaget

7 Listeners

MEDVIND by Alexis Barnekow

MEDVIND

0 Listeners

Cybersecurity Headlines by CISO Series

Cybersecurity Headlines

138 Listeners

Prompt by DR

Prompt

3 Listeners

Only in America by RADIO IIII

Only in America

25 Listeners

Plattformpodden by Hans Kristian Flaatten og Audun Fauchald Strand

Plattformpodden

0 Listeners