Log in

mnemonic security podcast - OODA Loops with Open Source
share icon

OODA Loops with Open Source

mnemonic security podcast

09/21/20

36m

About

Comments

Featured In

This time, Robby has invited his most recent online friendship and the uncrowned king of open source, Simon Simonsen, to the podcast. Simon also happens to have a lot of experience developing and utilising security architecture defense strategies, or as he calls it; utilising your home court advantage.

Simon has over a decade of experience in security and is working as a Senior Information Security Officer at the Danish energy trading house Danske Commodities (DC).

In his discussion with Robby, he explains his mostly open source approach to protecting his home court by using OODA Loops (Observe, Orient, Decide and Act) and by knowing that as long as you know your network better than any adversary, you should come out winning. He also shares his approach to making sure you do know your network better, as well as his journey with OODA Loops.
Hunting ELK: https://github.com/Cyb3rWard0g/HELK

The Open Source Security Events Metadata (OSSEM): https://github.com/OTRF/OSSEM

Security Onion: https://securityonion.net/

Sentinel ATT&CK: https://github.com/BlueTeamLabs/sentinel-attack

Technical level: 4/5

Host: Robby Peralta

Send us Fan Mail

Previous Episode

undefined - Security Validation
Security Validation

September 7, 2020

38m

How can we prove cybersecurity effectiveness?

With USD 124 billion being spent worldwide on IT security last year alone, it's no wonder this is a question many would like the answer to. However, finding a quantitative metric to evaluate security investments, outside of positive effects like diminishing risks and reducing the amount of bad things happening, is not straight forward.
To help us navigate this question, Robby is joined by someone with a lot of experience making security investments effective. Brian Contos has a long list of merits after his more than two decades of experience working in the cybersecurity field. He has also written several security books and is an award-winning podcaster. Brian is now CISO & VP Technology Innovation in Mandiant Security Validation, also known as Verodin, a business platform for measuring and managing cybersecurity effectiveness.

Technical level: 1/5

Host: Robby Peralta
Producer: Paul Jæger

https://mnemonic.no/podcast

Send us Fan Mail

Next Episode

How do we go from data to information, and from information to intelligence in the cyber world?

Who better to try to explain this than the former Director of the national communications and security agency in the Netherlands, Job Kuijpers, and his colleague and trusted advisor for Threat Intelligence, Piet Kerkhofs. After more than 15 years in the Dutch government's cyber program the two of them founded the cyber security company EYE, and in their conversation with Robby they share from their vast and hands-on experience working with threat intelligence.

In this episode, you’ll hear about the most common misconceptions about threat intelligence that they’ve come across, and how much and what should be automated in threat intelligence – and what shouldn’t.

They also discuss what’s required by an organisation buying/receiving threat intelligence, and how to evaluate if your organisation actually needs threat intelligence tools for its security work.

Technical level: 2/5

Host: Robby Peralta

Send us Fan Mail

Promoted