
Security Validation
mnemonic security podcast
09/07/20
•38m
About
Comments
Transcript
Featured In
How can we prove cybersecurity effectiveness?
With USD 124 billion being spent worldwide on IT security last year alone, it's no wonder this is a question many would like the answer to. However, finding a quantitative metric to evaluate security investments, outside of positive effects like diminishing risks and reducing the amount of bad things happening, is not straight forward.
To help us navigate this question, Robby is joined by someone with a lot of experience making security investments effective. Brian Contos has a long list of merits after his more than two decades of experience working in the cybersecurity field. He has also written several security books and is an award-winning podcaster. Brian is now CISO & VP Technology Innovation in Mandiant Security Validation, also known as Verodin, a business platform for measuring and managing cybersecurity effectiveness.
Technical level: 1/5
Host: Robby Peralta
Producer: Paul Jæger
Previous Episode

A shared responsibility
August 31, 2020
•36m
For this Norwegian episode of the mnemonic security podcast, Robby and co-host for the day Manager of Governance, Risk & Compliance at mnemonic, Gjermund Vidhammer, are joined by two major actors in the Norwegian cyber landscape: Robin Bakke, Specialist Director for Cyber Security at the Ministry of Justice & Public Security, and Bente Hoff, Director National Cyber Security Center (NCSC) at the Norwegian National Security Authority (NSM).
They discuss the importance, and the many different arenas, of private-public cooperation both in Norway and internationally, and share the Ministry and NSM’s thoughts on what’s important for digital security these days – and where they see most risk.
Related reading:
Nasjonal strategi for digital sikkerhet: https://www.regjeringen.no/no/dokumenter/nasjonal-strategi-for-digital-sikkerhet/id2627177/
Nasjonal Sikkerhetsmåned: https://norsis.no/nsm/
Technical level: 1/5
Next Episode

OODA Loops with Open Source
September 21, 2020
•36m
This time, Robby has invited his most recent online friendship and the uncrowned king of open source, Simon Simonsen, to the podcast. Simon also happens to have a lot of experience developing and utilising security architecture defense strategies, or as he calls it; utilising your home court advantage.
Simon has over a decade of experience in security and is working as a Senior Information Security Officer at the Danish energy trading house Danske Commodities (DC).
In his discussion with Robby, he explains his mostly open source approach to protecting his home court by using OODA Loops (Observe, Orient, Decide and Act) and by knowing that as long as you know your network better than any adversary, you should come out winning. He also shares his approach to making sure you do know your network better, as well as his journey with OODA Loops.
Hunting ELK: https://github.com/Cyb3rWard0g/HELK
The Open Source Security Events Metadata (OSSEM): https://github.com/OTRF/OSSEM
Security Onion: https://securityonion.net/
Sentinel ATT&CK: https://github.com/BlueTeamLabs/sentinel-attack
Technical level: 4/5
Host: Robby Peralta
If you like this episode you’ll love
Promoted




