Skip to content
Artwork for SecurityCafé
TechnologyNewsTech News

SecurityCafé

Quint Ketting Menno van der Horst

“Pull up a chair at the Security Café – your monthly deep dive into the hottest cybersecurity news and trends. Each episode brings you an inspiring guest and a story that will spark your imagination. Produced by Quint & Menno (Atos), this is where insights meet conversation. Don’t just stay informed—join the discussion!”

Play
  • 20 episodes
  • monthly
  • Avg 32 min
  • English
  • S3 · E9
    Yesterday · 50 min

    SecurityCafe — Andreas Wuchner: AI, the boardroom, and the bill nobody budgeted for

    Andreas Wuchner ran large-scale security organisations for some 30 years and now invests in and advises startups, family offices, VC and PE firms. On geopolitical risk, AI governance, and what AI actually costs. Chapters 00:00 — Welcome 01:00 — In the news: 900+ agents coordinating over a shared channel 05:07 — Geopolitical risk is real, and NIST/ISO don't map it 07:39 — The CybersecNL keynote: is what we built still good enough? 11:40 — "What brings you in jail is non-compliance" 13:00 — The AI governance tooling wave 14:44 — Punish vs enable: pocket money for Big Tech kills a startup 16:53 — The minimum viable control set 17:43 — Fines: where does that money actually go? 22:50 — What AI means for the business, from a board seat 26:30 — Three types of adopters, and AI-native hiring in seven days 32:04 — "Meat proxies": what the AI-native crowd calls the rest of us 34:47 — AI is not cheap: what a €200 subscription really costs 37:10 — $20 per run vs $2.84, same job 39:22 — Outsourcing efficiency promises vs rising AI costs 41:44 — Augmentation vs a greenfield agentic machine room 43:43 — Cooling, solar, subsea, space: the infrastructure race 47:19 — What to read, what to watch Key takeaways A policy keeps you out of jail — and that's all it does. Regulators ask for governance; many tick that box with a document. Anyone declaring AI governance "done" is at the beginning. Define the non-negotiables, then get out of the way. The organisations doing this well name 10 to 50 controls that are not up for discussion and let the rest develop over time — a minimum viable control set. The alternative is the department of no. Token economics is a skill, not a budget line. The same investment-document analysis ran at roughly $20 per company; converting inputs to markdown first brought it to $2.84. A week-long AI strategy course for managers does nothing for the layer that spends the money. Mentioned Log Force — a project in Spain predicting indicators of compromise before they become threats, and spotting when agentic systems start hallucinating. Not a commercial product yet. Tehran — the espionage series from What to Watch Uber's €824,990,000 fine from the Dutch DPA for fully automated driver deactivation, under GDPR Article 22: https://www.autoriteitpersoonsgegevens.nl/en/current/uber-fined-nearly-825-million-euros-for-automated-driver-blocking The Odido breach (February 2026): some 6.4 million people and 600,000 companies, including over 5 million ID document numbers. https://nos.nl/artikel/2604461-odido-hackers-publiceren-resterende-klantdata-ook-miljoenen-id-nummers Meta's settlement over harm to minors: up to $17.1 billion, with 52 US attorneys general — not an EU case. https://www.npr.org/2026/08/26/nx-s1-5944781/meta-settlement-child-safety-lawsuit Powered by Atos

    • Transcript
  • S3 · E9
    July 23 · 41 min

    "Sovereignty Is the Wrong Word": Digital Autonomy with Mika Lauhde

    SecurityCafe — "Sovereignty Is the Wrong Word": Digital Autonomy with Mika Lauhde Hosts: Menno van der Horst & Quint Ketting Guest: Mika Lauhde, Luxembourg House of Cybersecurity (linkedin.com/in/mika-lauhde-4270711) About this episode Mika Lauhde spent 30 years across Nokia, Huawei, and ENISA before landing at Luxembourg House of Cybersecurity, the national hub keeping Luxembourg's municipalities, SMEs, and economy cyber-resilient. His argument: Europe has the wrong word. Not "sovereignty" — hard borders around who owns what — but autonomy: acting independently while still sharing tools and trust. From GPS glitches during US foreign policy disputes, to Europe always getting the second-best tech (fighter jets included), to a national CERT running entirely on open source — this one covers a lot of ground. In this episode 00:11 — Welcome & Mika's background (Nokia, Huawei, ENISA, Luxembourg House of Cybersecurity) 02:08 — News: an integrator data-leak claim ("888") and what makes integrator breaches different 06:06 — Android's new developer certificate as a "kill switch," African nations building their own internet, UK VPN/age-verification rollout, an EU "tech sovereignty" proposal that leans on non-European hardware 09:11 — A US court ruling that may have quietly broken a GDPR assumption on data transfers 10:34 — NIS2 finally live in NL (15 Aug) — are our laws fast enough for machine-speed attacks? 19:20 — The "SplinterNet," and why Mika argues for shared autonomy over walled-garden sovereignty 23:46 — The Cyber Resilience Act's unprecedented recognition of open source (79 mentions) 24:19 — AI models as the new trade weapon — allies get the previous generation, like fighter jets 26:50 — The GPS/Galileo story, and SES's Iris² as Europe's answer to Starlink 30:15 — EU tax rules that quietly disadvantage open source; the Nokia N900 as Europe's "Sputnik moment" 33:00 — Luxembourg's national CERT runs entirely on open-source tools 34:40 — The call to action: a free open-source toolkit so any EU SME can stand up a cyber ops center 36:41 — What to read: Quint's, Mika's, and Menno's picks 41:04 — Wrap-up Key takeaways Autonomy, not sovereignty — sharing open standards beats walling off borders Dependency is invisible until it breaks — GPS glitches led to Galileo, now to Iris² New tech follows old patterns — AI models, like military hardware, come second-best to allies Open source is operational, not aspirational — Luxembourg's CERT proves it at national scale Mentioned Accenture leak claims (unconfirmed) · NIS2 (NL) · Cyber Resilience Act · European OSPO network · SES Iris² · Trump v. Slaughter ruling Reads: The Subtle Art of Not Giving a Fck* by Mark Manson (markmanson.net/books/subtle-art) · Max Schrems / noyb (noyb.eu/en/us-supreme-court-just-blew-eu-us-data-transfers) · Bert Hubert's blog (berthub.eu) SecurityCafe is hosted by Menno van der Horst and Quint Ketting. Powered by Atos.

    • Transcript
  • S3 · E8
    June 25 · 28 min

    AI Where It Matters, Not AI Everywhere — with Zeina Zakhour, Global Cyber CTO Atos/Eviden

    AI Where It Matters, Not AI Everywhere — with Zeina Zakhour, Global CTO Cybersecurity at Eviden (Atos) Recorded live at CISO Day, this episode brings Menno van der Horst and co-host Quint Ketting together with Zeina Zakhour, Global CTO for Cybersecurity at Eviden (Atos), for a fast-moving conversation on where cyber is heading and what it really takes to keep up. We open with a sobering reality: many of today's threats are exposing weaknesses that have existed for decades. The panic isn't warranted — but action is. Zeina makes the case that the issue is rarely a lack of technology depth, but a lack of security depth: the basic hygiene and foundational controls that too many organisations still treat as something for "next year." Spoiler — next year is no longer an option. From there we get into the heart of it: — Adaptive, systemic resilience. Security can't be an afterthought bolted on once innovation ships. It has to sit at the core. We dig into why maturity built once and then left alone decays faster than most leaders expect. — Risk first, always. You don't secure a water utility the way you secure a hospital, a retailer or a bank. Every organisation has its own ecosystem and purpose — and that's where Eviden's Prepare, Respond, Adapt approach starts: understanding who you are, then keeping your risk picture live rather than buried in a spreadsheet updated once a year. — AI, agents and the new attack surface. Not "AI everywhere" — AI where the risk, the data and the friction justify it. We talk identity as the number one attack vector, the danger of human-led processes throttling machine-speed tooling, prompt and meta-prompt injection, agent goal drift, kill switches, and what "identity" even means for an autonomous agent that has intent, makes decisions and calls tools. — Chained vulnerabilities. Why "we'll only fix the high-severity CVEs" is the wrong instinct — low-severity issues can be chained into something genuinely exploitable, fast. — Sovereignty vs autonomy. A crucial distinction too many conflate. We get into data residency, technological sovereignty, the model/middleware/GPU reality of "sovereign AI" today, post-quantum, and why Europe can only answer these questions together rather than country by country. We close where good security conversations always seem to land: sharing more, building a bubble of trust, backing European innovation and startups, and staying agile enough to adapt as the ground keeps shifting. Zeina's recommendations: 📑 Atos Cyber Shield blog and Threat Research Center — regular, genuinely interesting analysis on new campaigns and malware variants. 📖 The Five People You Meet in Heaven by Mitch Albom — nothing to do with cyber, everything to do with being worth your time. 🎧 Listen now, and let us know your take in the comments. #SecurityCafe #Cybersecurity #CISO #AISecurity #Resilience #DigitalSovereignty

    • Transcript
  • S3 · E7
    May 28 · 28 min

    Data is the New Uranium: Critical Infrastructure, CISOCommunity & AI with Dimitri van Zantvliet (NS)

    A SecurityCafe special, recorded live at CISOday 2026 with Dimitri van Zantvliet — CISO & Cybersecurity Director at Nederlandse Spoorwegen (NS), Chairman of the CISO Community NL and co-founder of CISOday. Host Menno van der Horst is joined by co-host Quint Ketting for a wide-ranging conversation on what it actually takes to defend critical infrastructure in a world where the geopolitical, technological and threat landscape is shifting faster than ever. In this episode: - Why CISOday and the CISO Community NL exist, and how community accelerates maturity across the sector - Becoming a NIS1 critical entity in 2021 and how the war in Ukraine reshaped NS's threat model overnight - Belarusian railway wiperware, Iranian-aligned activity, and the recent railway incident in Florida - Working with NCSC, NCTV, AIVD, the Rail-ISAC and Dutch ISAC to exchange threat intel - Building an in-house CTI team of five — strategic, tactical, operational and technical - The NS Cyber Academy: training people from train drivers to office staff into cyber roles, plus SANS, CISSP and CISA tracks - Why stamina and curiosity beat a classic IT background when hiring — including the case for ex-Olympians, HYROX athletes and journalists - The cultural shift from "my threat intel is my IP" to active two-way sharing across the ecosystem - Supplier risk as a knock-out criterion: no ISO 27001 / SOC 2 Type 2, no business - AI and Gen.AI as the new frontier — from "data is the new gold" to "data is the new uranium" - Quantum on the horizon, and why the impact reaches far beyond encryption - The basics still decide everything: MFA, passwords, segmentation — and the move toward real-time patching - Autonomous agents as the next attack vector we don't yet fully understand - Historical parallels, from the AIDS Trojan on floppy disk to ILOVEYOU and SQL Slammer - Nassim Taleb's Antifragile — and why "prepare, respond, adapt" is the cycle every organisation needs - Cybersecurity is no longer an IT conversation; it's geopolitics, brand, and business continuity Book of the episode: - Antifragile — Nassim Nicholas Taleb About the guest: Dimitri van Zantvliet is CISO & Cybersecurity Director at NS, Chairman of the CISO Community NL and co-founder of CISOday. He joined NS five years ago and has led the organisation's response to the post-2021 shift in geopolitical and cyber risk affecting European critical infrastructure. Working at NS: Dimitri's team is hiring. If cybersecurity at one of the Netherlands' most critical infrastructure providers sounds like your kind of challenge, check the openings at werkenbijns.nl. About SecurityCafe: SecurityCafe is hosted by Menno van der Horst with co-host Quint Ketting — an open conversation about the strategic, technical and human sides of cybersecurity. Produced by Quint Ketting. Subscribe wherever you get your podcasts. This CISOday special was made possible in partnership with Atos.

    • Transcript
  • S3 · E6
    May 12 · 29 min

    SecurityCafe Special | Mythos – Facts, Fiction and What You Need to Do Now

    About this episode In this special edition of SecurityCafe, Quint Ketting and Koen Maris join host Menno van der Horst for an open, no-nonsense conversation about Mythos — Anthropic's frontier AI model expected to become more widely available around mid-August. No panic, no hype — just an honest look at what will actually change, and what your organization should already have been doing. What we cover Mythos: revolution or evolution? Koen opens with a sharp reality check: if it takes five days to build an exploit today and Mythos brings that down to twenty hours — how much really changes? The hype around Mythos risks drawing attention away from what's already happening. Claude Opus 4.7 is already live, carrying many of the same capabilities, with barely anyone noticing. The real shift: accessibility The barrier to sophisticated attacks is dropping fast. It's not that experts are becoming more dangerous — it's the new wave of attackers without deep technical skills that warrants concern. Quint illustrates the point with his own experience using Claude: from building custom tools to recovering audio from a faulty recording. What this means for your organization Cyber hygiene first. If your foundations aren't in order, you already have a problem — Mythos just makes it more visible and more urgent. Third-party contracts. Patch response clauses of 90 days or more are no longer viable. Time to renegotiate. Asset management. If you don't know what you have, you don't know what to protect. A scan often reveals 40% more assets than organizations think they manage. Exposure management. Unmanaged assets are exactly where attackers will strike first. Patch cycles. Microsoft recently released 250 patches in a single Patch Tuesday — normally 10 to 20. That pattern is not a coincidence. Prepare, Respond, Adapt Koen introduces the PRA framework: we are currently in a fragile peace. Use this window well. Organizations that prepare thoroughly will weather the storm quickly. Those that don't may find themselves in a prolonged and costly recovery. Frontier AI: the next buzzword — and what it actually means Mythos is part of a broader phenomenon. Vendors like Palo Alto are already embedding the same AI engines into their defensive toolsets. The question isn't whether this will affect you — it's whether you'll be ready. Project Glasswing & responsible disclosure Anthropic has given early access to a select group of major technology companies, resulting in both an explosion of patches and new AI-powered defenses. Responsible management of this capability is exactly the right approach — and a model the industry should follow. Key takeaways Start an internal working group now. Structure it with proper governance, board-level reporting, and weekly progress reviews. Review your third-party agreements: do your SLAs still hold in a world of 24/7 patching? Don't wait for Mythos to get your basics right. A low security maturity level cannot be fixed in two months. Frontier AI is the bigger frame. Follow developments across Anthropic, Google, and others — not just the Mythos headlines. Guests linkedin.com/in/menno-van-der-horst-74710794 linkedin.com/in/koen-maris linkedin.com/in/quintketting

    • Transcript
  • S3 · E5
    May 7 · 47 min

    Navigating the Future of Cybersecurity, Frontier-AI, and Society: Insights from the Security Café

    SecurityCafe – Liesbeth Holterman, Cyberveilig Nederland Hosts: Quint Ketting & Menno Recorded: Eindhoven Studio (our first ever in-person guest!) We always say: Prepare. Respond. Adapt. — Quint's microphone broke mid-recording. We practiced what we preached. 🎙️💀 About Our Guest Liesbeth Holterman is Managing Director of Cyberveilig Nederland — the Dutch trade association for the cybersecurity industry, focused on improving quality, transparency, and the digital resilience of the Netherlands. What We Discussed Data leaks — daily news, preventable problems Breaches are no longer weekly — they're daily. Social engineering, not sophisticated hacking, is the attacker's weapon of choice. The Odido case is a perfect example. Basic cyber hygiene remains the answer. Check your credentials: 👉 HaveIBeenPwned.com AI & Mythos — marketing or menace? Agentic AI can scan environments and find zero-days at scale. Bad actors have been using LLMs for a while already — what's new is that low-skill attackers now have access too. Bruce Schneier calls some of the fear "marketing hype" — but the underlying shift is real. The good news: in 4–5 years, defence will benefit just as much. 👉 Schneier on Security NIS2 & EU legislation Don't know where to start with cyber hygiene? Read NIS2 Article 21 — it's a solid baseline checklist. Legislation is finally getting boards to ask the right questions. 👉 NIS2 Directive | Article 21 Dutch critical infrastructure The Netherlands' legendary efficiency — remote dikes, interconnected logistics, everything online — is also its biggest attack surface. The cybersecurity workforce of tomorrow AI will reshape roles like pen testing and SOC analysis. But the need for cyber professionals is still enormous. The sector isn't thinking strategically enough about what this means. Liesbeth's call: reach out, collaborate, have the conversation. 👉 cyberveilignederland.nl 🎬 Recommendations Quint → Hanna (Amazon Prime) A girl targeted by a CIA program for what an algorithm predicts she'll do — not what she's done. A thought-provoking lens on AI, surveillance, and pre-emptive power. 👉 IMDb Liesbeth → The Boys (Amazon Prime) Superheroes in the hands of a private corporation guided by profit, not public interest. Sound familiar? 👉 IMDb SecurityCafe — because good security conversations deserve good coffee.

    • Transcript
  • S3 · E4
    March 30 · 37 min

    The Rise of the Agents & Modern Geopolitics

    Host: Menno van der Horst Regular Guest & Chief Storyteller: Quint Ketting Special Guest: Jan Paul Oosterom (EMEA Regional Business Lead for Security, Microsoft) Episode Summary In this episode, the trio dives into the rapidly shifting threat landscape. While geopolitical tensions remain the "elephant in the room," the real tactical shift is happening within the realm of AI Agents. Jan Paul explains why identity management is no longer just about people—it’s about governing the thousands of non-human entities now operating within corporate environments. The team discusses the "Assume Breach" mindset, the death of "badly written" phishing emails, and why protecting your Intellectual Property (IP) requires a deep understanding of who exactly is targeting you. Key Takeaways The Identity of Agents: We are moving beyond managing human access. Organizations now face the challenge of managing non-human identities (AI Agents) that have their own permissions, access levels, and potential for "rogue" behavior. Assume Breach as a Culture: Security isn't just a set of tools; it’s a mindset. "Assume Breach" means every employee and executive must operate with the default action of verifying before acting, especially regarding financial transactions or data access. The Intellectual Property Target: Threat intelligence isn't one-size-fits-all. A camera manufacturer faces different risks (IP theft) than a national tax office (financial disruption). Knowing your "Why" helps you build the right "How." Timestamped Highlights [01:10] – Jan Paul Oosterom’s role at Microsoft and his remit across EMEA. [03:45] – The "Elephant in the Room": Geopolitical risks and the pace of AI evolution. [05:50] – The 10,000 Agent Problem: How one customer already has a massive fleet of autonomous agents running. [07:20] – Deep dive into Identity Management: Protecting non-human identities. [12:15] – The evolution of phishing: Why attackers are now "spot on" with their messaging. [15:30] – The "Assume Breach" mindset: Moving from "Can we stop it?" to "How do we respond when it fails?" [18:45] – Threat Intel: Identifying your specific enemies based on your business IP. [24:10] – Closing thoughts: Why the Board needs to be challenged on security. Memorable Quotes "The days that we were able to easily recognize something bad are over." — Jan Paul Oosterom "What you need to protect is probably not what you have budget for. You need to get those things in line." — Quint Ketting "If you cannot truly verify that what you see is real or good—stop it and start asking questions." — Jan Paul Oosterom The Recommendation Corner Movie: Minority Report (Recommended by Jan Paul Oosterom) Why: It explores the philosophical and ethical boundaries of "Predictive Systems"—how far can we go in flagging "criminal behavior" before a crime is even committed? Quint was referring to a movie which was actually a Serie called: Hannah

    • Transcript
  • S3 · E3
    March 3 · 23 min

    Bonus Episode: The AI Shift: From Script Kiddies to Agentic Warfare

    SecurityCafe Podcast: Bonus Episode The AI Shift: From Script Kiddies to Agentic Warfare In this unplanned, deep-dive "after-talk," Menno Van Der Horst, Quint Ketting, and Max Heinemeyer peel back the curtain on the rapid evolution of AI in cybersecurity. Recorded just weeks after a massive shift in the landscape, the trio discusses why the "old ways" of hacking are being supercharged by AI agents and what this means for national resilience. Key Takeaways The Scaling of Social Engineering: Data leaks (passports, IBANs, addresses) are no longer just static dumps; AI can now process these at scale to create hyper-personalized phishing campaigns for thousands of victims simultaneously. The "Agentic" Shift: We are moving from static scripts to AI Agents. Unlike traditional malware, agents can make autonomous decisions, potentially making them more effective but also far more unpredictable and dangerous (the "Stuxnet with a brain" scenario). The Defender’s Dilemma: While attackers don't care about "breaking" systems as long as they get in, defenders and penetration testers must remain deterministic and safe—a gap that AI is currently making harder to bridge. Systemic Resilience: Cybersecurity is no longer just about protecting a single company; it’s about the "ecosystem." National security now depends on how well the entire supply chain—from big telcos to small vendors—is defended. Timestamped Highlights [00:41] The Four-Week Shift: Max explains how AI has hit the mainstream for both attackers and personal assistance (OpenCloud, NotebookLM). [01:15] Weaponizing Data Dumps: How AI turns old-school data leaks into targeted, automated social engineering machines. [02:45] From SQLi to Prompt Injection: Quint draws a parallel between the early days of SQL injection and the modern "hobby" of breaking LLM guardrails. [04:48] Nation-State Guardrails: A look at how China and other actors use Western AI infrastructure and the risks of "spillover" (WannaCry style) in AI-led operations. [08:27] The "Autonomous Stuxnet": What happens when an attack isn't run by a human, but by an agent with its own prompts? [09:38] The Car Wash Paradox: Menno shares a hilarious (yet scary) anecdote about an AI losing the plot, illustrating why "hallucinations" in autonomous pen-testing are a major liability. [12:39] The End of the Human Bottleneck: Max discusses how AI is removing the "human hands" requirement for vulnerability research and exploit development. [16:40] The "Football Team" Analogy: Quint argues that cybersecurity needs to move past silos—even the best "players" (companies) lose if they don't play as a coordinated unit. [21:17] Reason for Optimism: Why Max believes NIS2 and the rise of ML-driven SOC operations give defenders a fighting chance to regain the upper hand. Links & Resources Mentioned Backtrack / Kali Linux: The "old school" penetration testing roots. DARPA Grand Challenge (2016): The early race for autonomous cyber defense (Shellphish & Mayhem). NIS2 Directive: The evolving European legislation for cybersecurity. Sven Herpig: Mentioned as a leading researcher on nation-state cyber policy.

  • S3 · E2
    February 25 · 38 min

    The Year of the Data Leak: Why SaaS is the New Frontier (with Max Heinemeyer & Quint Ketting)

    Show Notes | Episode: The Year of the Data Leak Welcome back to the Security Cafe, the podcast where we discuss cybersecurity with good coffee, questionable humor, and guests who—for their own good—know far too much about the cyber world. In this episode, your host Menno Van Der Horst sits down with regular guest Quint Ketting (our human equivalent of a SIEM) and special guest Max Heinemeyer, a heavyweight in cyber threat intelligence and AI-driven defense. As we kick off 2026, one thing is clear: the battlefield has shifted. We are no longer just fighting off ransomware; we are living in the "Year of the Data Leak." From massive telco breaches to compromised SaaS environments, the tactics are getting louder, faster, and more automated. In this episode, we break down: The Pivot in Tactics: Why attackers are moving away from complex network encryption and towards "low-hanging fruit" like CRM databases and SaaS solutions. The Identity Crisis: How AI-driven social engineering is becoming a machine, making phishing attempts nearly indistinguishable from reality. The "Least Privilege" Paradox: Why do we still struggle with basic principles 20 years later? We discuss how a single helpdesk account can lead to 6 million compromised records. Boardroom Liability & NIS2: Moving from "security as a risk" to personal accountability for the C-suite. The Watchlist: Why Mr. Robot is being outpaced by reality and which "hacker" shows you should avoid at all costs. Special Guest Highlight: Stick around for a meta-moment where Max’s own security team accidentally proves that real-world controls actually work during our recording. Grab your coffee, log your accounts, and join us in the chaos.

  • S3 · E1
    January 26 · 31 min

    Navigating Cybersecurity in a Geopolitical Landscape

    Summary: In this episode of the Cybersecurity Cafe, Menno Van Der Horst, Koen, and Quint Ketting delve into the complexities of cybersecurity in the context of geopolitical tensions and digital autonomy. They discuss the importance of preparation, adaptation, and response in maintaining business resilience and sovereignty. The conversation also touches on the role of cybersecurity frameworks like ISO 27001 and NIST in enhancing organizational resilience. Keywords: cybersecurity, digital autonomy, geopolitical tensions, business resilience, ISO 27001, NIST, sovereignty, cyber resilience, cybersecurity frameworks, digital sovereignty Takeaways: Sovereignty is becoming a crucial topic in cybersecurity. Preparation, adaptation, and response are key to resilience. Geopolitical tensions impact digital autonomy. ISO 27001 and NIST frameworks aid in resilience. Understanding your organization's purpose is vital. Cyber resilience protects brand and organization. Frameworks focus on preventing incidents. Resilience ensures business continuity. Digital sovereignty is linked to data control. Effective cybersecurity requires both planning and execution.

  • Dec 23, 2025 · 27 min

    What to Expect in 2026?

    🎄 Security Café Christmas Special! 🎄 What does the future of cybersecurity look like in 2026? In this episode of the Security Cafe Podcast, host Menno van der Horst and guests Quint Ketting and Fred Streefland discuss the future of cybersecurity, focusing on predictions for 2026. They explore current trends, the impact of AI, the importance of government involvement, and the need for digital education. The conversation highlights the increasing threat of cybercrime and the necessity for organizations to adapt to new challenges in the digital landscape. ✔ AI-driven security & prompt injection challenges ✔ Why government involvement is critical ✔ The role of digital education for future generations ✔ How collaboration can fight cybercrime – now the third-largest economy in the world Grab a coffee (or a mulled wine 🍷) and tune in to this insightful conversation! 🎧 Listen now! #Cybersecurity #ChristmasSpecial #AI #DigitalEducation #Cybercrime #SecurityTrends #Technology

  • Dec 5, 2025 · 33 min

    AI and Cybersecurity: A New Frontier

    In this episode of the Security Cafe Podcast, host Menno Van Der Horst and guests Ahmed Achchak and Quint Ketting discuss the intersection of AI and cybersecurity. They explore how AI can be both a tool for attackers and a defense mechanism for businesses. The conversation delves into the importance of trust in AI systems, the role of data in enhancing security operations, and the challenges posed by generative AI. The episode emphasizes the need for basic cybersecurity hygiene and the potential of AI to transform security operations while maintaining human oversight. Video Link: SecurityCafe ep29

  • Oct 31, 2025 · 31 min

    Cyber Shadows and Quantum Fears — Halloween Special with Lars Klinghammer

    In this Halloween edition of the Security Café Podcast, host Menno van der Horst and co-host Quint Ketting welcome special guest Lars Klinghammer for a spine-chilling deep dive into the darker corners of cybersecurity. Together, they explore: Recent Cyber Incidents: From data leaks and ransomware to the F5 source code breach — how these events ripple across organizations and supply chains. Incident Response & Recovery: Why many organizations still struggle when the lights go out — dependencies, communication breakdowns, and planning gaps. Resilience & Crown Jewels: Aligning technical and business priorities to protect what truly matters — and understanding the real-world impact of cyberattacks. AI & Quantum Computing: How emerging technologies are reshaping both attack and defense strategies — and why now is the time to prepare for the quantum era. Practical Tips & Resources: Lars’s top reads, blogs, and newsletters to help cybersecurity professionals stay ahead of the curve. 🎃 Tune in for stories that are both frighteningly real and eerily insightful — a perfect Halloween brew of knowledge and caution for anyone navigating today’s cyber landscape.

  • Oct 9, 2025 · 19 min

    CyberSec NL Special #3 with Josephine van luik

    🚨 Final episode of the CyberSec Café Live Edition – now streaming! Host Menno van der Horst, storyteller Quint Ketting, and guest Josephine van Luik (HSD Community Manager) wrap up the 3-part CyberSec NL series with a dive into OT security: 🏭 Building OT resilience 🧼 Why basic hygiene is still step one 🗺️ Understand: know what you have and who can be after it 🤝 Inside the OT HSD community – connecting people, sharing insights A great close to the CyberSec NL live trilogy – A must-listen for anyone navigating the intersection of OT and cybersecurity. 🎧

  • Sep 25, 2025 · 25 min

    CyberSec NL Special #2 with Fleur van Leusden

    CyberSecurity Café Podcast – CyberSec NL Special In this special live edition of the SecurityCafé Podcast, recorded at Cybersec Netherlands, host Menno van der Horst is joined by Fleur van Leusden (CISO by day, podcaster by night) and regular guest & storyteller Quint Ketting. 🔥 Together, they dive into two urgent themes shaping the cybersecurity community: Sovereignty labelling – what does it mean for organizations, vendors, and Europe’s digital future? Less Hype Culture, More Fundamental Collaboration – why our industry needs to move beyond buzzwords and towards real, sustainable partnerships. This is not just another panel talk. It’s a candid conversation from inside the community where we reflect on how we can break silos, challenge commercial noise, and strengthen collaboration as our strongest firewall. 👉 Whether you’re a CISO, practitioner, or part of the wider security ecosystem, this episode is packed with insights you won’t want to miss. 🔗 Listen now and join the discussion on building a more resilient cyber future.

  • Sep 17, 2025 · 19 min

    CyberSec NL Special #1 with Max Heinemeyer

    In this CyberSec NL special episode of Security Café, we sit down with Max Heinemeyer; Global field CISO and Analyst at Darktrace to discuss the evolving cybersecurity landscape and the challenges facing today’s security professionals. From the growing sophistication of threat actors to the need for stronger collaboration between teams, Max shares practical insights on how organizations can stay resilient in an environment where cybercrime is outpacing defenses.

  • Jun 20, 2025 · 42 min

    NATO Summit & Cyber Threat Landscape

    The NATO Summit is just around the corner, and the cyber threat landscape — already dynamic in the Netherlands — is poised to intensify. In this episode of the Security Café Podcast, your regular host Menno is joined by storyteller Quint and special guest Jeroen Herlaar from Mandiant. Together, they unpack the latest shifts in cyber threats and explore whether — and how — organizations can prepare for a high-stakes event like the NATO Summit. Stay tuned until the end for practical tips you can start applying today to strengthen your security posture.

  • May 22, 2025 · 29 min

    Boardroom leadership: the accountability factor

    In collaboration with Hans Koolen (CEO Atos Netherlands) our very own Quint Ketting discussed board room responsibility and accountability in relation to cyber resilience and compliance. Quint emphasized that this responsibility goes beyond just following rules and regulations like NIS2, DORA, and the Cyber Resilience Act. While compliance with these laws is essential, he pointed out that true accountability means actively working to make sure the company is prepared to handle cyber threats. It’s not just about ticking boxes—it’s about building a strong, resilient organization that can withstand digital risks.

  • S2 · E1
    May 16, 2025 · 29 min

    TU/E en Take me Scooting

    In deze aflevering reeds opgenomen eind Januari nemen Quint en Menno ons mee in de cyberaanval op de Technische Universiteit Eindhoven die toen net in het nieuws was. Maak kennis met ons fictieve bedrijf, Take Me Scooting, en leer van diverse echte resilience vraagstukken die wij daar tegen kwamen, Abonneer je nu en blijf veilig in de digitale wereld!

  • Dec 19, 2024 · 33 min

    🎄 Het Security Café viert Kerst! 🎄

    Wat hebben kerst, contant geld en cyberincidenten met elkaar te maken? Dat ontdek je in onze nieuwste podcastaflevering! Doomsday prepper Quint en Wouter duiken samen met Stijn Rommens van Vectra het nieuws over banken die adviseren om cash achter de hand te houden in onrustige tijden. Maar dat is nog maar het begin! Ze delen spannende verhalen over cyberincidenten die rond de feestdagen plaatsvonden en leggen uit waarom juist deze periode zo interessant is voor kwaadwillenden. 🔒 Hoe komen cybercriminelen tegenwoordig binnen? 🎅 Wat maakt de feestdagen een kwetsbare tijd voor organisaties? 🛡️ En vooral: wat kun jij doen om dit te voorkomen? Luister mee en ontdek hoe je jouw organisatie cyberproof houdt, zelfs tijdens de feestdagen. 📻✨ #CyberSecurity #Podcast #Feestdagen #SecurityCafe #Kerstveiligheid Kijk/luister tips: - Red One (Quint) - Say Nothing (Stijn) - Home Alone (Wouter) Regie: Willem Bekenkamp Productie: Ketting productions

Showing 1–20 of 20 episodes