Skip to content
Artwork for mnemonic security podcast
TechnologyBusinessNewsTech News

mnemonic security podcast

mnemonic

Hosted by Robby Peralta from mnemonic, one of Europe’s leading cybersecurity companies, the show features conversations with researchers, founders, operators, and security leaders working across the cybersecurity landscape.


Each episode explores a specific topic within cybersecurity: from incident response, threat intelligence, AI, and geopolitics, to leadership, resilience, and the changing role of security leaders.


The podcast is tailored to cybersecurity practitioners and decision-makers who want grounded conversations about where cybersecurity is going, what organisations should prepare for, and what experienced people are seeing.

Play
  • 20 episodes
  • fortnightly
  • Avg 37 min
  • English
  • September 7 · 40 min

    The Speed of Threat

    The speed of threat: Threat intelligence and detection engineering in the age of AI How can security teams shorten the time from identifying a cyber threat to having detection code live in production? In this episode of the mnemonic security podcast, Robby is joined by Nick Maeckelberghe, Co-Founder and Managing Director at Crimson7, which empowers organizations to find and fix their security weaknesses before attackers do, combining purpose-built platforms with expert-led managed services. Robby also welcomes Jeff Schiemann back to the podcast, now a Board Advisor at Crimson7. Nick and Jeff discuss how security teams can shorten the OODA loop, the time it takes to observe, orient, decide and act on a threat, with the ambition of going from understanding what an attacker is doing to having detection code live in production in a matter of hours. They explore what it takes to keep pace with attackers as new tools and techniques emerge, and how cyber threat intelligence (CTI) and detection engineering can work together to identify and stop threats at different stages of an attack campaign. They also discuss how LLMs and other forms of AI are changing cybersecurity on both sides of the equation, as attackers move faster and defenders look for ways to analyse threats and turn what they learn into detections at the same speed. The conversation also turns to some future-gazing: the rise of neoclouds, the concept of "headless security services" increasingly delivered by AI, and a potential shift from identity as the attack surface to trust as the attack surface. They discuss what these developments could mean for the security industry, and how customers will distinguish between good and average security vendors as AI takes on more of the work. Send us Fan Mail

    • Transcript
  • August 31 · 46 min

    Norway's Ace: Space (live from Arendalsuka)

    Live episode: Why is Norway investing in space? (In Norwegian) This week, we’re bringing you a live recording of the mnemonic security podcast from Arendalsuka, Norway’s largest political gathering held every year in the town of Arendal. Here, Robby was joined by Ole Morten Olsen from the Norwegian Space Agency to discuss why Norway is investing in space from a strategic, security and economic perspective. What do we actually "sell from space", and which companies are involved? How dependent are we on satellites in our daily lives, and how will technologies like Starlink influence Norway's national preparedness in the years ahead? Check out this episode if you want to understand what Norway is actually doing in space, and why it matters. And perhaps we'll even get an answer to whether data centres in space are a realistic prospect! Send us Fan Mail

    • Transcript
  • August 10 · 26 min

    The Asymmetric Future

    With or without agents, the cost of failure is asymmetric for attackers and defenders. An attacking agent that fails risks getting caught. A defending agent that fails risks taking down its own business. In this episode of the mnemonic security podcast, Robby is joined by Matteo Strada, a cybersecurity engineer and researcher specialising in AI security. Drawing on his blog post, The Asymmetric Future of AI and Cybersecurity, they explore the guardrail paradox exposed by the recent OpenAI–Hugging Face incident, the growing case for local and open-source models in the enterprise, and how much control companies are giving up when they build critical workflows on top of frontier AI models. https://mstrada.me/posts/aicybersec Send us Fan Mail

    • Transcript
  • July 20 · 43 min

    OSINT

    In a world where images can be manipulated, eyewitnesses dismissed, and official accounts contradicted by what happened on the ground, proving what is real has never been more important. In this episode, Robby speaks with Vladimir Zaha, a threat intelligence researcher and volunteer contributor to the Bellingcat community, about the growing role of open-source intelligence in journalism, cybersecurity, conflict monitoring, and democratic accountability. Vladimir explains how OSINT investigators verify images and videos, geolocate events using seemingly insignificant details, monitor activity in active conflicts, and challenge false or misleading official narratives. He also discusses his work documenting civilian harm in Ukraine, investigating the actions of enforcement agencies in the United States, and helping analyse information that may eventually support legal proceedings. The conversation explores how OSINT can help cybersecurity professionals understand their threat environment, how artificial intelligence is changing the investigative process, and why human verification remains essential even as collection and analysis become increasingly automated. Send us Fan Mail

    • Transcript
  • June 29 · 27 min

    Canaries and Deception Technology

    Why did the security industry stop talking about deception technology? And why should we start paying attention again? In this episode, Robby is joined by Andy Smith, CEO and Co-Founder of Tracebit, to discuss the evolution of deception technology and its role in modern security. Andy explains how organisations can deploy canaries, honey tokens and other deceptive resources in their environments to generate high-fidelity alerts when attackers move laterally, escalate privileges or attempt to access credentials and sensitive data. These alerts are designed to be both simple and highly reliable: if someone touches a fake resource, something suspicious is happening. The conversation explores modern deception techniques, what these look like when customers deploy them in their SOCs, how realistic decoys can be customised for different environments and the next generation of deception technology. Send us Fan Mail

    • Transcript
  • June 8 · 38 min

    Everything Is Being Recorded

    In this episode of the mnemonic security podcast, we're joined by Joe Sullivan - former Chief Security Officer at Uber, Facebook, and Cloudflare, federal cybercrime prosecutor, and one of the most consequential figures in the history of the CISO role. The conversation explores the security implications of AI becoming part of everyday life, from AI note-takers to wearables and humanoid robots. Joe discusses the privacy, legal, and security challenges these technologies introduce, why organisations need clear policies and stronger governance to manage them, and how the role of the CISO is expanding as AI risk moves higher up the boardroom agenda. Send us Fan Mail

    • Transcript
  • May 25 · 40 min

    Lay of the Land: How Attackers Move in '26

    The security world is a noisy place lately. What's actually going on in the trenches? Candid Wüest, Principal Security Advocate at xorlab, joins Robby to cut through the hype and take a look at how attackers are actually operating in 2026. They open with a reference to their last discussion about LLM-infused malware, and touch upon using deception techniques such as honey tokens, fake password files and prompt injections to derail automated attackers. From there, they walk through the actual lay of the land: edge device exploits, credential abuse via infostealers, supply chain attacks targeting GitHub repositories, and why ClickFix social engineering is still working just as well as ever. They also dig into the growing connection between AI-assisted development and supply chain risk and what organisations should actually be doing about it. The episode closes on the bug bounty market, where AI is quietly disrupting the economics of responsible disclosure, and what that might mean for how vulnerabilities get reported, priced, and exploited going forward. Send us Fan Mail

    • Transcript
  • May 4 · 34 min

    Auditing AI

    How do you audit machine learning models, and where do you start on your AI governance journey? In this episode, Robby is joined by Gaute Brynildsen, Chief Audit Executive at Gjensidige, one of the leading Nordic insurance groups. Gjensidige has built a mature and tested approach to AI governance, and Gaute shares what they’ve learned along the way. Gaute explains how they went about auditing their in-house machine learning model trained solely on their own data, before expanding into broader governance across security, policies, roles, training, and risk. He also covers where he recommends starting when building AI governance, highlighting the risks of shadow AI and how to monitor it, the importance of cloud competence and the value of an AI risk officer role. They also discuss the level of automation among organisations in the Nordics, exploring agentic agents, and whether it’s overhyped or the next real shift. Send us Fan Mail

    • Transcript
  • April 20 · 32 min

    OpenClaw

    The AI agent everyone is talking about. In this episode of the mnemonic security podcast, Robby is joined by Marius Sandbu, fellow podcaster (CloudFirst Podcast and KI til Kaffen/AI with Coffee) and Cloud Evangelist at Sopra Steria. Together, they dive into the potential of agentic technologies, as of now. In particular, they cover OpenClaw, the open-source autonomous AI agent that is one of the most popular repositories on GitHub right now. The conversation covers key risks, including remote control access, overly broad permissions and supply-chain concerns. As well as enterprise governance challenges, the need for policies and observability across different agent platforms. They both share what conversations they're having with customers and security teams these days, both with the "gatekeepers" and the "believers". Send us Fan Mail

    • Transcript
  • April 8 · 33 min

    INTERPOL

    Ever wondered how INTERPOL tackles organised crime and cyber threats? In this episode of the mnemonic Security Podcast, we’re joined by Bjørn Watne, Global Chief Information Security Officer at INTERPOL, for a conversation on how cybercrime is evolving, and what it takes to combat it. Bjørn draws on more than 25 years of experience across industries including law enforcement, financial services and telecoms. In his role at INTERPOL, he explains how the organisation connects and supports law enforcement across 196 countries, tackling terrorism, organised crime, financial crime, and cybercrime. He also explains how and why INTERPOL distinguishes between cybercrime and cyber-enabled crime, highlighting how traditional crimes are increasingly amplified by digital tools, AI, and cloud technologies. During Bjørn and Robby's conversation, Bjørn outlines INTERPOL’s coordination model with local jurisdictional leads, partnerships with private expertise, and the need for neutrality, including avoiding state-on-state cyber war issues. As well as discusses the “cybercrime supply chain”, attribution challenges, and where they've observed AI do the most harm. Send us Fan Mail

    • Transcript
  • March 23 · 36 min

    Social Engineering TTPs

    “Human behavior is not going to change significantly year after year.” In our latest podcast episode, Robby is joined by Rob Shapland, ethical hacker and Director at Cyonic Cyber, to explore how social engineering works in practice today. Despite advances in technology, social engineering remains an effective attack method. Whether it is a convincing email, a friendly conversation, or a well-timed request to the support desk, attackers continue to exploit human trust. In this episode, we discuss how social engineering tactics have evolved and what still stays the same, how new tools are making attackers more effective, and real-world stories, including how many buildings Rob has gained access to during his career so far. Rob will also be speaking at mnemonic’s annual conference, C2 Summit, this May. Check out the program and see if you should join us as well: mnemonic.io/c2-summit-2026 Send us Fan Mail

    • Transcript
  • March 9 · 33 min

    Initial Access Trends

    In this episode of the mnemonic security podcast, we’re joined by Will Thomas, Senior Threat Intelligence Advisor at the CTI company Team Cymru, to discuss the latest trends in initial access. Will shares what he is currently observing, including the growing exploitation of edge devices, the targeting of SaaS environments using infostealers and stolen credentials, and the rise of ClickFix-style social engineering techniques. He also explains how these trends differ between threat actors depending on their motivations, and what organisations should prioritise to stay ahead. Will outlines practical steps defenders can take and the key questions security teams should be asking to stay ahead of attackers. The conversation also covers Will’s main concerns around threat actors’ use of LLMs, and how CTI and threat hunting should ideally be carried out to support security operations. Want more Will Thomas? Here you can find his Ransomware-Tool-Matrix: https://github.com/BushidoUK/Ransomware-Tool-Matrix/tree/main/Tools And his own podcast Future of Threat Intelligence (FoTI) Podcast: https://www.team-cymru.com/future-of-threat-intelligence-podcast Send us Fan Mail

    • Transcript
  • February 23 · 37 min

    Runtime

    "It's prime time for runtime!" In this episode of the mnemonic security podcast, we're joined by Sergej Epp, Global CISO & Member of the Executive Team of Sysdig, to discuss threats at machine speed and runtime security. Sergej explains how runtime security enables organisations to understand what is really happening inside containers and serverless workloads, and why, without it, they are effectively blind to critical activity within their cloud-native environments. He shares recent examples of supply chain incidents that highlight these risks, including the GitHub Actions compromise, NPM attacks, and the two waves of Shai-Hulud. Robby and Sergej also discuss the most common ways that attackers get access to clusters and containers, and how organisations can stay ahead of attacks using real-time telemetry. Send us Fan Mail

    • Transcript
  • February 9 · 32 min

    Cloud Detection and Response

    "We are not really seeing as many attacks in the cloud where people hack in. It's more likely that they simply log in." In this episode of the mnemonic security podcast, we're exploring Cloud Detection & Response (CDR) together with Brian Contos; returning guest, fellow podcast host, author, and serial security entrepreneur. In his conversation with Robby, he shares from his new role as Field CISO for the Cloud Detection & Response platform Mitiga. They discuss the Salesforce supply chain attack and the challenges of protecting interconnected cloud ecosystems, the evolution of Cloud Detection & Response so far, and what we should expect in the near future. Send us Fan Mail

    • Transcript
  • January 26 · 32 min

    Pentesting anno 2026

    Pentesting anno 2026 Erica Burgess, an experienced penetration tester and security consultant, joins us for this episode of the mnemonic security podcast to deliver a state of the union on penetration testing in 2026. Drawing on her Black Hat Europe AI Security Summit keynote, “Never Break the Chain: Attack Chaining for 0-Days,” Erica breaks down how seemingly low-severity or “informational” findings can be chained together into full system compromises. Erica details her practical approach to using customized AI agents for subtasking, from validating dynamic scanner results to finding obscure commands that bypass blacklists. Tasks that once required three days of manual research can now be completed in minutes, dramatically increasing the volume and sophistication of findings during time-constrained engagements. They also explore the broader implications of AI-assisted hacking: the risk of new blind spots when everyone leans on similar models, and the uncomfortable questions this raises about creativity, labor, and the future of junior talent in cybersecurity. Erica emphasizes the importance of maintaining human intuition and critical thinking, warning that over-reliance on AI can literally reduce brain activity, while acknowledging that pen testers who don't adapt to these tools risk being left behind. Send us Fan Mail

    • Transcript
  • January 5 · 51 min

    LLMalware

    We’re kicking off the new year by taking a closer look at some of the threats that will shape 2026, and how they impact defenders. In this episode of the mnemonic security podcast, Robby welcomes Candid Wüest, Principal Security Advocate at xorlab, drawing on more than 25 years of experience in the field. After seeing Candid's talk “The Rise of AI-Driven Malware: Threats, Myths, and Defenses” at BlackHat Europe, Robby invited him to share his research and perspectives on the current state of AI-driven malware. They talk about the most common misunderstandings around AI-powered, AI-generated and AI-supported threats, as well as which types of LLM-related attacks Candid expects to make the news, and actually be effective, in 2026. Candid also shares his thoughts on how defenders’ roles are evolving, where he has seen organisations successfully implement AI in defense, and why going back to basics still matters. They also explore some of the biggest topics from Black Hat Europe in December, including AI-enabled SOCs. Send us Fan Mail

    • Transcript
  • Dec 1, 2025 · 54 min

    Present and Future of MDR

    What is the future of MDR? In this episode of the mnemonic security podcast, Robby is joined by Migjen Hakaj from mnemonic's Innovation & Emerging Technologies Department and Amine Besson, Director at Behemoth Security. They've joined forces by collecting their shared extensive experience with security monitoring, and published a popular three-part blog series on what Managed Detection and Response (MDR) really is on a deep level, where they examine the past, present, and future challenges within the field. In their conversation they talk about the evolution of the SOC space, what main forms of security operations they are seeing today, and why they believe the SOC needs to change. They also explain why it's hard to define what MDR really is today, the main value proposition of MDR providers, and what the next big differentiators for MDR providers will be. As well as in what ways they've seen that the industry has matured over the last few years, where the industry needs radical change, and where AI SOC has a place and where its main challenges lie. Interested in more? Visit their blog series: The Present and Future of Managed Detection and Response: https://detect.fyi/the-present-and-future-of-managed-detection-and-response-01a72088e6f6 The missing link in MDR. Spoiler, it starts with a Detection Engineering framework: https://detect.fyi/the-missing-link-in-mdr-spoiler-it-starts-with-a-detection-engineering-framework-5f836347c92f Beyond Detections : Scaling Analysis & Response to keep MDR relevant: https://detect.fyi/beyond-detections-scaling-analysis-response-to-keep-mdr-relevant-592285d0fd25 Send us Fan Mail

    • Transcript
  • Nov 24, 2025 · 19 min

    Agentic Browsers

    In this short and sweet episode on agentic browsers, we’re joined by Helen Kearney, a leader in helping humanitarian and non-profit organisations use technology strategically, responsibly, and with real impact. Robby and Helen discuss the challenges and opportunities posed by these new browsers, where their "agentic" abilities create new risks, raise questions about ethical AI use, and heighten concerns around safeguarding sensitive data. Helen also shares the conversations she’s having across the humanitarian sector as AI tools go mainstream - what’s inspiring, what’s misunderstood, and the developments she believes deserve far more attention. Send us Fan Mail

    • Transcript
  • Nov 10, 2025 · 44 min

    Dark Web Roast

    Start your week with a laugh. And yes, it’s work-relevant. Today’s guests, John Fokker, Head of Threat Intelligence, and Jambul Tologonov, Security Researcher at Trellix, have spent years monitoring the dark web and have quite a few stories to tell. They are joining Robby to talk about their concept "Dark Web Roast", a satirical look at cyber criminals and their world of crime, aiming to show that at the end of the day, these threat actors are just human beings, messing up just like anyone else. In the episode, they take us behind the scenes of the dark web: exposing failures among cybercriminals, uncovering ransomware-group drama, and revealing the vanity and rivalries fueling it all. Send us Fan Mail

    • Transcript
  • Oct 27, 2025 · 40 min

    The Quiet Conflict

    In this episode of the mnemonic security podcast, we take a closer look at a tension that remains invisible to most of us, yet is very real: the quiet conflict unfolding within our critical infrastructure. This topic gave us the perfect excuse to once again invite one of our favorite guests, for the fourth time, Joe Slowik. Joe brings over 15 years of experience in cyber threat intelligence (CTI), detection engineering, and incident response, with expertise in industrial control systems (ICS), operational technology (OT), and critical infrastructure environments. He currently serves as Director of Cybersecurity Alerting Strategy at Dataminr. In his conversation with Robby, Joe explores the threats posed by Volt Typhoon, a state-sponsored Chinese cyber operation known for targeting critical infrastructure, primarily in the United States. They discuss the origins and activities of the group, recent operations, and Joe also shares his research into what this group has the potential to achieve based on their current operations and proven capabilities. The discussion also covers Joe’s broader research into China’s cyber eco-system and how it has evolved, including the country’s extensive network of research institutions, companies, and lesser known contractors. Joe also shares his observations about current trends in the OT industry, insights into his upcoming areas of research within OT, and his perspective on where the field is heading. Send us Fan Mail

    • Transcript
Showing 1–20 of 20 episodes