Log in

mnemonic security podcast - Experience Sharing - Bug Bounty Programs
share icon

Experience Sharing - Bug Bounty Programs

mnemonic security podcast

08/28/23

30m

About

Comments

Featured In

How to succeed with bug bounties

Responsible disclosure and vulnerability reporting have come a long way in recent years, and have gone from being feared and even something you took legal action against, to something that is appreciated for its value.

Ioana Piroska, Bug Bounty Program Manager at Visma, joins Robby to share how Visma has succeeded with their bug bounty program. She talks about Vismas’ approach to these kind of programs, and the actual value they receive from them.

Ioana and Robby discuss the difference between penetration testing and a bug bounty program, and how they complement each other. And how Visma also uses their live hacking competitions and public responsible disclosure program to improve their vulnerability detection capabilities.
Video version (with presentation) available on our YouTube channel!

Send us Fan Mail

Previous Episode

undefined - Influencing the board
Influencing the board

August 14, 2023

38m

Influencing the board

What are some of the most effective methods of gaining a board’s support, and how do you maintain this trust and improve it over time?

Our guest today has worked with a lot of boards, and joins us to share his experiences providing boards with the tools to ask the right questions when it comes to cybersecurity, and conveying to them why cybersecurity is important for their organisation.

Roger Ison-Haug has worked in IT for close to 30 years and is now working as the CISO & DPO at the data science and weather intelligence provider StormGeo. He is also currently working on his PhD in cybersecurity and leadership.

Roger and Robby discuss the most common challenges that boards experience, and what kind of questions they usually ask. They also talk about what it’s actually like being a board member, Roger’s best advice to security people wanting to influence a board, and what kind of questions security people usually aren’t very good at answering – but should be.

Send us Fan Mail

Next Episode

undefined - Supply Chain Attacks
Supply Chain Attacks

September 11, 2023

37m

What do you really know about your vendors? And about your vendors' vendors?To talk about supply chain attacks, and how to best mitigate and meet these risks, Robby is joined by a pair with a lot of experience on this topic: Roger Ison-Haug, CISO of StormGeo, and Martin Kofoed, CEO of Improsec.
Martin and Roger discuss what a supply chain attack looks like these days, how to prepare for when a compromise happens, and how to get an overview of your organization's exposure. They also highlight the importance of knowing what happens if someone accesses your infrastructure, and fixing your basics.

Send us Fan Mail

Promoted