re:invent security

re:invent security

By Jeroen Prinse / Irfaan SantoeBusinessTechnologyEducationSelf-Improvement
Download on the App Store

re:invent security episodes

  • Bibi van den Berg (LEI): “Why traditional risk management falls short in cyber security"

    Join hosts Jeroen Prinse and Irfaan Santoe in this thought-provoking episode of Reinvent Security as they sit down with Prof. Dr. Bibi van den Berg, a renowned expert in cybersecurity governance. Bibi shares her unique perspective on the limitations of traditional risk management approaches in the rapidly evolving cyber landscape. She introduces the concept of value-driven decision-making, emphasizing the need to align security practices with organizational values, not just numbers. Discover how human behavior, technology, and regulations intertwine in cybersecurity, why data limitations pose significant challenges, and how organizations can rethink their approach to managing cyber risk. Whether you’re a seasoned security professional or new to the field, this episode offers fresh insights and practical advice to help you navigate the complexities of today’s cybersecurity challenges.


    Chapters:

    00:00 - 03:04 Introduction of the episode and Prof.dr. Bibi van den Berg

    03:44 - 06:03 How is Bibi contributing to reinventing security?

    06:04 - 08:05 Safety Science vs. Cyber Risk Management

    08:06 - 09:47 What inspired Bib to focus on Value Driven Decision Making?

    09:48 - 21:19 What would be the main limitations of traditional risk management?

    21:20 - 25:47 How does value driven decision making for risk differ?

    25:48 - 28:52 Asset prioritization and value driven decision making

    28:53 - 32:42 The challenge with board and the need to quantify

    32:43 - 43:32 How can organizations define their core values?

    43:33 - 48:49 Common challenges for organizations in transition to a more value based decision making approach

    48:50 - 55:04 Key takeaways Jeroen & Irfaan


    Connect with Bibi: https://www.linkedin.com/in/bibivandenberg/


    Subscribe to this channel to find all new episodes:

    https://youtube.com/@reinventsecurity?feature=shared


    Listen on:

    Spotify: https://ap.lc/SzTrY

    Apple Podcasts: https://ap.lc/HmXhf


    FOLLOW ►

    Jeroen Prinse

    LinkedIn: https://www.linkedin.com/in/jprinse/


    Irfaan Santoe:

    LinkedIn: https://www.linkedin.com/in/irfaansantoe/

    Hosted on Acast. See acast.com/privacy for more information.

    56 min
  • Sander Zwiebel (NN Group) on DORA: "The Final Countdown"

    Join hosts Jeroen Prinse and Irfaan Santoe as they dive in the world of DORA, together with Sander Zwiebel (NN). During this episode we discuss what DORA is, why it came to existence, the scope of DORA and challenges and solutions directions for getting DORA implemented. It is the FINAL COUNT DOWN because organizations in scope for DORA have to comply by January 2025.


    Chapters:

    0:00 Introduction to DORA

    01:02 Introduction of the episode and Sander Zwiebel

    09:01 Introduction of DORA

    13:06 DORA's Impact on Security

    17:39 DORA's Impact on Financial Industry and Third-Party Management

    28:59 Implementation Challenges Ahead

    35:55 Tips for Successful DORA Implementation

    40:55 Future of Regulatory Landscape

    45:47 Closing Thoughts on Compliance and Security

    52:50 Conclusion and Next Steps


    Resources:

    DORA formal law Digital Operational Resilience Act: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32022R2554&qid=1727030708806


    DORA regulatory technical standards or RTS: https://www.eiopa.europa.eu/publications/second-batch-policy-products-under-dora_en


    DORA Questions and answers, joinedly done by the ESA’s (Eiopa, EBA, ESMA): https://www.eiopa.europa.eu/about/governance-structure/joint-committee/joint-qas_en


    ESA link to a dry run exercise on the information register, in order to learn as supervisor and supervisee how the information register is going to work on both sides: https://www.eiopa.europa.eu/esas-publish-templates-and-tools-voluntary-dry-run-exercise-support-dora-implementation-2024-05-30_en


    Dutch National Bank (DNB) link to DORA: https://www.google.com/url?q=https://www.dnb.nl/en/sector-information/open-book-supervision/laws-and-eu-regulations/dora/&source=gmail&ust=1727370130061000&usg=AOvVaw3GieR7OhPwfIElBvDRye_m


    Connect with Sander: linkedin.com/in/sander-zwiebel-241a16


    Subscribe to this channel to find all new episodes:

    https://youtube.com/@reinventsecurity?feature=shared


    Listen on:

    Spotify: https://ap.lc/SzTrY

    Apple Podcasts: https://ap.lc/HmXhf


    FOLLOW ►

    Jeroen Prinse

    LinkedIn: https://www.linkedin.com/in/jprinse/


    Irfaan Santoe:

    LinkedIn: https://www.linkedin.com/in/irfaansantoe/

    Hosted on Acast. See acast.com/privacy for more information.

    59 min
  • Steve Hollands (BQCM): "The future of security is quantum-proof: Start preparing today!"

    Join hosts Jeroen Prinse and Irfaan Santoe in this thought-provoking episode of Reinvent Security as they welcome quantum computing and security expert Steve Hollands, Chair of the Board at Blackhills Quantum Computing. Steve dives deep into the fascinating and complex world of quantum computing, discussing its far-reaching implications for the future of cybersecurity. From the looming threat of quantum computers breaking traditional encryption to the opportunities quantum key distribution offers, this episode covers the cutting-edge advancements that could revolutionize security as we know it. Discover how AI and quantum computing could drastically shorten the timeline for encryption vulnerabilities, why businesses need to start preparing today, and the importance of crypto agility in a post-quantum world. Whether you're an IT professional, a cybersecurity enthusiast, or just curious about the future of technology, this episode delivers expert insights and actionable advice to help you stay ahead of the curve in the quantum era.


    Chapters:

    00:00 Welcome to the podcast

    00:35 Introduction of the episode and Steve Hollands

    02:53 How is Steve contributing to Quantum proof security?

    04:49 How does quantum computing differ from traditional silicon based computing?

    08:53 How does quantum computing impact the field of information security?

    12:16 What is the timeframe of quantum computing threats and opportunities?

    15:26 What is quantum safe cryptography and what are researchers doing?

    16:37 Crypto agility is a key security principle in any security strategy

    18:27 Are actors using quantum capabilities everybody's problem?

    20:54 How a Quantum Readiness Framework can help organizations towards a post quantum security strategy?

    24:06 What steps should organizations be taking now to prepare for the future impact of quantum computing on their security infrastructure?

    29:46 How to create a Quantum Secure Defense in Depth Strategy?

    34:57 What other steps should organizations take to prepare for the future impact of quantum computing on their security infrastructure?

    36:24 What are the regulatory and ethical considerations that come with the rise of quantum computing in information security?

    37:09 Resources for your journey into quantum and security

    38:26 Which board member is driving the change towards a post quantum organization?

    41:38 Can we make quantum secure cryptography a service for the organization?

    44:03 Wrap Up


    Resources:

    Forbes: https://www.forbes.com/sites/adrianbridgwater/2018/01/03/neuromorphic-computing-will-build-human-like-machine-brains/

    Nature: https://www.nature.com/articles/s41928-021-00646-1

    McKinsey, timeline for Q-Day: https://www.linkedin.com/posts/activity-7229084010952478720-9nku

    Blackhills new website: https://www.blackhillsquantum.com

    Hosted on Acast. See acast.com/privacy for more information.

    51 min
  • Ashish Rajan (Kaizenteq): "Data Sovereignty Will Define the Future of Cloud Security and Compliance"

    Join hosts Jeroen Prinse and Irfaan Santoe in this enlightening episode of Reinvent Security as they sit down with cloud security expert Ashish Rajan, founder of Kaizenteq and host of the Cloud Security Podcast. With 250+ cloud security podcasts to his name Ashish shares invaluable insights into the evolving landscape of cloud security, discussing key challenges, best practices, and future trends. Discover the importance of identity and access management, strategies to prevent misconfigurations, and how to balance data sovereignty with cloud service capabilities. Learn why incident response in the cloud needs more focus and how to strategically select the right tools for your cloud security needs. Whether you're a seasoned professional or new to cloud security, this episode offers actionable advice and deep expertise to help you navigate the complexities of securing your cloud environments.


    Chapters:

    0:35 introduction

    4:11 How is Ashish contributing to Cloud Security and AI?

    08:30 Primary Cloud Security Challenge

    13:22 Cloud Security Best Practices

    23:10 The latest exciting trends in Cloud Security

    29:18 How is data sovereignty impacting Cloud Security strategies?

    34:30 Emerging threats and opportunities

    37:20 Top 3 things to focus on starting tomorrow

    40:11 Resources for your Cloud Security journey

    44:05 Wrap up


    Resources:

    - Cloud Security Podcast - www.cloudsecuritypodcast.tv

    - Cloud Security Bootcamp - www.cloudsecuritybootcamp.com

    - Cloud Security Newsletter - www.cloudsecuritynewsletter.com

    Hosted on Acast. See acast.com/privacy for more information.

    51 min
  • Paul Watts (ISF): “Here is what it takes to be a NextGen CISO!”

    This episode of re:invent security shares what it takes to be the next generation (NextGen) CISO. Our guest Paul Watts, a multiple times CISOs at companies like Kantar, Domino’s Pizza UK & Ireland, Network Rail, clarifies what it takes to be the NextGen CISO. Key questions discussed are: “What are the expectations from Business/IT leaders hiring these NextGen CISOs?”, “What transformation should CISOs explicitly consider staying relevant as CISO?”, “What is most important AND challenging for the NextGen CISOs to fulfill these expectations and how can they go about it?”. Dive into the conversation with Paul, someone that has been there, done that, now sharing this!


    Resources:

    Paper 1 - Unlocking the business value of security - Leadership Insights: Unlocking the business value of security - Information Security Forum


    Paper 2 - Exploring the role of the BISO - Leadership Insights: Exploring the role of the Business Information Security Officer (BISO) - Information Security Forum


    Paper 3 - Looking to the future - is yet to be published publicly (link will be added later).


    Paper 4 - Modelling the security leader - to be published to ISF Members on July 1st. Synopsis ...

    The definition of a security leader continues to suffer from ambiguity, with misaligned expectations between business and incumbent a principal cause of stress and – somewhat inevitably – short tenures and disappointment for both employee and employer. We describe how the role could be better modelled, qualifying its fundamental criteria and providing some guidance on what qualities to look for, and what to not over-rely upon.


    Paper 5 - Nominet CISO Stress Report: businesses get £23k ($30k) ‘free’ CISO time while impact of stress on mental health doubles in 2020 - Nominet


    Other interview with Paul: The New Security Leader: Less Techie, More Business Savvy (inforisktoday.com)

    Hosted on Acast. See acast.com/privacy for more information.

    1 hr 2 min
  • Toon Segers (Roseman Labs): "Multi-Party Computation for Secure, Private Data Collaboration"

    Join hosts Jeroen Prinse and Irfaan Santoe as they dive into the world of multi-party computation with expert Toon Segers. In this episode, they explore how multi-party computation keeps data secure when collaborating, sharing and analyzing the data with partners, without exposing sensitive information. Toon Segers, co-founder of Roseman Labs and PhD candidate in mathematics and cryptography, explains the revolutionary changes this technology brings to data security and privacy of individuals, offering a promising solution to prevent data breaches and maintain confidentiality and privacy. Discover the future of data security and privacy and learn how multi-party computation is re:inventing the landscape of information security.


    Resources

    Multi Party Computation Wikipedia page: https://en.wikipedia.org/wiki/Secure_multi-party_computation

    MPyC framework from TU Eindhoven: https://github.com/lschoe/mpyc

    The Whitehouse on advancing Privacy-Enhancing Technologies: https://www.whitehouse.gov/ostp/news-updates/2022/06/28/advancing-a-vision-for-privacy-enhancing-technologies/

    Roseman Labs website: https://rosemanlabs.com/en/

    Collaborative Computing Slack community : https://collabcomputing.slack.com/


    A correction: at 31:55 Toon states that the large Intel server has 192 CPUs, which should instead be 192 cores.

    Hosted on Acast. See acast.com/privacy for more information.

    54 min
  • Sunette Runhaar (Uber): "Why managing Insider Threat is so challenging, and how to start"

    Insider Threat deals with the fact that every employee in the organization is a potential threat. How does one identify the actual threats and how to act and respond to them? What are the good practices to scale mitigation of the Insider Threat? What are the differences in Insider Threat Programs across different regions like the US and EU? All these questions are addressed by Sunette Runhaar from Uber.


    Resources:


    • 'Never split the difference: Negotiating as if your life depended on it' - Chriss Voss and Tahl Raz. This is essential reading to help manage tricky stakeholder relationships, but really helps understand the mindset of what motivates people in daily life. 
    • 'The Culture Map: Breaking the Through the Invisible Boundaries of Global Business' - Erin Meyer. Great reading to understand how different business cultures affect perceptions in the workplace and interpersonal relationships. 

    Hosted on Acast. See acast.com/privacy for more information.

    54 min
  • Rob van der Veer: "Treat Artificial Intelligence as Software Initiatives"

    What is the relationship between AI and Security? Learn from world industry expert Rob van der Veer what to consider when securing AI. This episode goes into detail about the security risks of developing AI and sheds light on how to start tomorrow with securing AI. We also discuss the upward risk of AI, what benefits will AI have and is having on doing security better!


    Resources:

    • OpenCRE
    • OpenCRE chat
    • OWASP AI Exchange
    • 5338 blog
    • IEC on 5338
    • SAMM Agile guidance
    • AI software quality gap research
    • Diary of CEO podcast met Mo Gawdat
    • Mo Gawdat - Scary Smart

    Hosted on Acast. See acast.com/privacy for more information.

    52 min
  • Welcome to re:invent security
    Welcome to re:invent security, the podcast where we look at ways to reinvent information security together with industry leaders.

    Hosted on Acast. See acast.com/privacy for more information.

    2 min

About re:invent security

From the publisher's feed

re:invent security is a podcast where we, on a monthly basis, learn from industry leaders how they reinvented security and how you can turn their experiences into action. Join us…