
TIBER
mnemonic security podcast
08/08/22
•37m
About
Comments
Featured In
Threat Intelligence-Based Ethical Red-teaming
In most organisations, there’s more to security than preventive measures. This means that testing your capabilities within detection, investigation and containment can be just as relevant as looking at preventive capabilities. One way of doing so, is by following the Threat Intelligence Based Ethical Red-teaming (TIBER) framework, and simulating a real adversary and how you organisation would do against such a threat.
To explain how a TIBER test is performed and it’s most common use-cases, Robby is joined by Stan Hegt, Etical hacker, Red teamer and Co-founder of the Dutch security company Outflank. Stan also shares his observations of the evolution of red teaming, the main differences between pentesting and red teaming, and what challenges they often meet when preforming these tests.
A special thanks to Dennis Nuijens at Cqure for helping us to find our guest for this episode!
Sound engineering by Paul Jæger
Previous Episode

Security Leadership Essentials for Managers
July 11, 2022
•39m
Security leadership essentials for managers
What knowledge base should a CISO have? And what is the best approach to shaping the next generation of security leaders?
Our guest today is better equipped than most to answer these questions. Frank Kim, former CISO of and currently a Fellow and Curriculum Director at SANS Institute, joins Robby to discuss leadership essentials for security managers.
Frank shares how SANS and their classes approach teaching strategic leadership in security, and how this can help CISOs both navigate the politics in the boardroom and craft a business plan that makes sense for their entire organisation.
They also discuss to whom security ultimately report to, and how to lead, motivate and inspire security teams to get their work done.
Sound engineering by Paul Jæger
Next Episode

Nordic Choice
August 22, 2022
•29m
Lessons learned from a real incident: Nordic Choice Hotels
What can we learn from the Nordic Choice Hotels supply chain attack of December 2021, and how it was handled?
For this episode, we’re happy to welcome Kari Anna Fiskvik, Vice President Technology at Nordic Choice Hotels, that will share some of her lessons learned from being at the centre of attention as Nordic Choice had to shut their systems down at one of their most busy times of the year.
Kari Anna has 20 years of experience with Tech, Digital Transformation, and Business Process and Strategy, and has been named one of the Top 50 Women in Tech 2022 in Norway. She shares with us how Nordic Choice reacted to the attack, what they were able to see of the threat actor from their side of things, and their considerations around balancing security and being service-minded and a customer-friendly organisation.
Robby and Kari Anne also talk about the importance of a security partner, and communicating cybersecurity in a language that people understand.
Sound engineering by Paul Jæger
If you like this episode you’ll love
Promoted




