
Hack my (hard-coded) heart
mnemonic security podcast
03/09/20
•29m
About
Comments
Featured In
In this episode, we chat with the former Head of the SOC at the Norwegian National CERT, and current member of mnemonic’s Threat Intelligence team. She also happens to have a personal interest in the "Internet of Things" and medical devices.
In 2011, Marie Moe received a pacemaker to help her heart maintain a consistent beat. As a security researcher, she felt the need to do her homework and figure out everything she could about the device that had newly been introduced to her body. What she found prompted her to join the "I Am The Cavalry" group, an organisation focusing on the impact computer security has on public safety and human life, which since then has lead a revolution in the medical device industry.
Technical level: 1/5
Host: Robby Peralta
Producer: Paul Jæger
Show notes:
Hippocratic Oath for Connected Medical Devices: https://www.iamthecavalry.org/domains/medical/oath/
Software Transparency and the SBOM multistakeholder process at the US NTIA: https://www.ntia.doc.gov/SoftwareTransparency
New EU regulations for medical devices: https://ec.europa.eu/growth/sectors/medical-devices/new-regulations_en
Previous Episode

Super CISO! With 300 brands to secure
February 24, 2020
•34m
In this episode, we chat with the CISO of consumer goods conglomerate Orkla - Antonio Martiradonna.
In 2017, he accepted the task of building up a security organisation to secure 300 brands, helping us to keep food in our fridges and beauty products in our bathrooms. In our conversation, we discuss the following:
· How it has been to build a security organization from the ground up
· How to work with the governance of so many brands
· Security around the physical production of products
Technical level: 1/5
Host: Robby Peralta
Producer: Paul Jæger
Next Episode

Bug Bounties and Unicorns
March 23, 2020
•35m
In this episode, we speak with a security expert that is actually willing to pay money to "hackers" - the Product Security Director in Visma, Espen Johansen.
As you can imagine, eliminating software vulnerabilities in a company with 5,000 developers is no easy task. Mr. Johansen and his developers always aim to improve the security of their software, among other things through organising both private and public bug bounty programs. If you are interested in bug bounty programs, this interview is a great place to start! As he shares his advise for when and what it takes for an organisation to be ready for bug bounty.
Technical difficulty: 2/5
Host: Robby Peralta
Producer: Paul Jæger
Related reading:
https://hackerone.com/visma
https://www.visma.com/trust-centre/smb/security-and-privacy/operational/responsible-disclosure/
https://www.visma.com/trust-centre/smb/security-and-privacy/operational/responsible-disclosure/hall-of-fame/
If you like this episode you’ll love
Promoted




