
Bug Bounties and Unicorns
mnemonic security podcast
03/23/20
•35m
About
Comments
Featured In
In this episode, we speak with a security expert that is actually willing to pay money to "hackers" - the Product Security Director in Visma, Espen Johansen.
As you can imagine, eliminating software vulnerabilities in a company with 5,000 developers is no easy task. Mr. Johansen and his developers always aim to improve the security of their software, among other things through organising both private and public bug bounty programs. If you are interested in bug bounty programs, this interview is a great place to start! As he shares his advise for when and what it takes for an organisation to be ready for bug bounty.
Technical difficulty: 2/5
Host: Robby Peralta
Producer: Paul Jæger
Related reading:
https://hackerone.com/visma
https://www.visma.com/trust-centre/smb/security-and-privacy/operational/responsible-disclosure/
https://www.visma.com/trust-centre/smb/security-and-privacy/operational/responsible-disclosure/hall-of-fame/
Previous Episode

Hack my (hard-coded) heart
March 9, 2020
•29m
In this episode, we chat with the former Head of the SOC at the Norwegian National CERT, and current member of mnemonic’s Threat Intelligence team. She also happens to have a personal interest in the "Internet of Things" and medical devices.
In 2011, Marie Moe received a pacemaker to help her heart maintain a consistent beat. As a security researcher, she felt the need to do her homework and figure out everything she could about the device that had newly been introduced to her body. What she found prompted her to join the "I Am The Cavalry" group, an organisation focusing on the impact computer security has on public safety and human life, which since then has lead a revolution in the medical device industry.
Technical level: 1/5
Host: Robby Peralta
Producer: Paul Jæger
Show notes:
Hippocratic Oath for Connected Medical Devices: https://www.iamthecavalry.org/domains/medical/oath/
Software Transparency and the SBOM multistakeholder process at the US NTIA: https://www.ntia.doc.gov/SoftwareTransparency
New EU regulations for medical devices: https://ec.europa.eu/growth/sectors/medical-devices/new-regulations_en
Next Episode

IAM these days
April 6, 2020
•39m
Who should own Identity and Access Management in an organisation?
In this episode, Robby speaks to Espen Skjøld from Sailpoint about the evolution of Identity and Access Management - and he also found some interesting people to discuss this with from Equinor and UCPH on the floor of the Nordic Cyber Series in Copenhagen.
Technical Difficulty: 1/5
SailPoint: Espen Skjøld
Equinor: Deric Stroud
UCPH: Poul Halkjær Nielsen
Host: Robby Peralta
Producer: Paul Jæger
https://mnemonic.no/podcast
If you like this episode you’ll love
Promoted




