Find partners
mnemonic security podcast

mnemonic security podcast

Hosted by mnemonic

Episodes

165

Latest episode

Aug 2026

Language

EN-US

About the show

Hosted by Robby Peralta from mnemonic, one of Europe’s leading cybersecurity companies, the show features conversations with researchers, founders, operators, and security leaders working across the cybersecurity landscape. Each episode explores a specific topic within cybersecurity: from incident response, threat intelligence, AI, and geopolitics, to leadership, resilience, and the changing role of security leaders. The podcast is tailored to cybersecurity practitioners and decision-makers who want grounded conversations about where cybersecurity is going, what organisations should prepare for, and what experienced people are seeing.

Listen to episodes

60 recent
August 10, 202626 min

The Asymmetric Future

With or without agents, the cost of failure is asymmetric for attackers and defenders. An attacking agent that fails risks getting caught. A defending agent that fails risks taking down its own business. In this episode of the mnemonic security podcast, Robby is joined by Matteo Strada, a cybersecurity engineer and researcher specialising in AI security. Drawing on his blog post, The Asymmetric Future of AI and Cybersecurity , they explore the guardrail paradox exposed by the recent OpenAI–Hugging Face incident, the growing case for local and open-source models in the enterprise, and how much control companies are giving up when they build critical workflows on top of frontier AI models. https://mstrada.me/posts/aicybersec Send us Fan Mail

July 20, 202643 min

OSINT

In a world where images can be manipulated, eyewitnesses dismissed, and official accounts contradicted by what happened on the ground, proving what is real has never been more important. In this episode, Robby speaks with Vladimir Zaha, a threat intelligence researcher and volunteer contributor to the Bellingcat community, about the growing role of open-source intelligence in journalism, cybersecurity, conflict monitoring, and democratic accountability. Vladimir explains how OSINT investigators verify images and videos, geolocate events using seemingly insignificant details, monitor activity in active conflicts, and challenge false or misleading official narratives. He also discusses his work documenting civilian harm in Ukraine, investigating the actions of enforcement agencies in the United States, and helping analyse information that may eventually support legal proceedings. The conversation explores how OSINT can help cybersecurity professionals understand their threat environment, how artificial intelligence is changing the investigative process, and why human verification remains essential even as collection and analysis become increasingly automated. Send us Fan Mail

June 29, 202627 min

Canaries and Deception Technology

Why did the security industry stop talking about deception technology? And why should we start paying attention again? In this episode, Robby is joined by Andy Smith, CEO and Co-Founder of Tracebit, to discuss the evolution of deception technology and its role in modern security. Andy explains how organisations can deploy canaries, honey tokens and other deceptive resources in their environments to generate high-fidelity alerts when attackers move laterally, escalate privileges or attempt to access credentials and sensitive data. These alerts are designed to be both simple and highly reliable: if someone touches a fake resource, something suspicious is happening. The conversation explores modern deception techniques, what these look like when customers deploy them in their SOCs, how realistic decoys can be customised for different environments and the next generation of deception technology. Send us Fan Mail

June 8, 202638 min

Everything Is Being Recorded

In this episode of the mnemonic security podcast, we're joined by Joe Sullivan - former Chief Security Officer at Uber, Facebook, and Cloudflare, federal cybercrime prosecutor, and one of the most consequential figures in the history of the CISO role. The conversation explores the security implications of AI becoming part of everyday life, from AI note-takers to wearables and humanoid robots. Joe discusses the privacy, legal, and security challenges these technologies introduce, why organisations need clear policies and stronger governance to manage them, and how the role of the CISO is expanding as AI risk moves higher up the boardroom agenda. Send us Fan Mail

May 25, 202640 min

Lay of the Land: How Attackers Move in '26

The security world is a noisy place lately. What's actually going on in the trenches? Candid Wüest, Principal Security Advocate at xorlab, joins Robby to cut through the hype and take a look at how attackers are actually operating in 2026. They open with a reference to their last discussion about LLM-infused malware, and touch upon using deception techniques such as honey tokens, fake password files and prompt injections to derail automated attackers. From there, they walk through the actual lay of the land: edge device exploits, credential abuse via infostealers, supply chain attacks targeting GitHub repositories, and why ClickFix social engineering is still working just as well as ever. They also dig into the growing connection between AI-assisted development and supply chain risk and what organisations should actually be doing about it. The episode closes on the bug bounty market, where AI is quietly disrupting the economics of responsible disclosure, and what that might mean for how vulnerabilities get reported, priced, and exploited going forward. Send us Fan Mail

May 4, 202634 min

Auditing AI

How do you audit machine learning models, and where do you start on your AI governance journey? In this episode, Robby is joined by Gaute Brynildsen, Chief Audit Executive at Gjensidige, one of the leading Nordic insurance groups. Gjensidige has built a mature and tested approach to AI governance, and Gaute shares what they’ve learned along the way. Gaute explains how they went about auditing their in-house machine learning model trained solely on their own data, before expanding into broader governance across security, policies, roles, training, and risk. He also covers where he recommends starting when building AI governance, highlighting the risks of shadow AI and how to monitor it, the importance of cloud competence and the value of an AI risk officer role. They also discuss the level of automation among organisations in the Nordics, exploring agentic agents, and whether it’s overhyped or the next real shift. Send us Fan Mail

April 20, 202632 min

OpenClaw

The AI agent everyone is talking about. In this episode of the mnemonic security podcast, Robby is joined by Marius Sandbu, fellow podcaster (CloudFirst Podcast and KI til Kaffen/AI with Coffee) and Cloud Evangelist at Sopra Steria. Together, they dive into the potential of agentic technologies, as of now. In particular, they cover OpenClaw, the open-source autonomous AI agent that is one of the most popular repositories on GitHub right now. The conversation covers key risks, including remote control access, overly broad permissions and supply-chain concerns. As well as enterprise governance challenges, the need for policies and observability across different agent platforms. They both share what conversations they're having with customers and security teams these days, both with the "gatekeepers" and the "believers". Send us Fan Mail

April 8, 202633 min

INTERPOL

Ever wondered how INTERPOL tackles organised crime and cyber threats? In this episode of the mnemonic Security Podcast, we’re joined by Bjørn Watne, Global Chief Information Security Officer at INTERPOL, for a conversation on how cybercrime is evolving, and what it takes to combat it. Bjørn draws on more than 25 years of experience across industries including law enforcement, financial services and telecoms. In his role at INTERPOL, he explains how the organisation connects and supports law enforcement across 196 countries, tackling terrorism, organised crime, financial crime, and cybercrime. He also explains how and why INTERPOL distinguishes between cybercrime and cyber-enabled crime, highlighting how traditional crimes are increasingly amplified by digital tools, AI, and cloud technologies. During Bjørn and Robby's conversation, Bjørn outlines INTERPOL’s coordination model with local jurisdictional leads, partnerships with private expertise, and the need for neutrality, including avoiding state-on-state cyber war issues. As well as discusses the “cybercrime supply chain”, attribution challenges, and where they've observed AI do the most harm. Send us Fan Mail

March 23, 202636 min

Social Engineering TTPs

“Human behavior is not going to change significantly year after year.” In our latest podcast episode, Robby is joined by Rob Shapland, ethical hacker and Director at Cyonic Cyber, to explore how social engineering works in practice today. Despite advances in technology, social engineering remains an effective attack method. Whether it is a convincing email, a friendly conversation, or a well-timed request to the support desk, attackers continue to exploit human trust. In this episode, we discuss how social engineering tactics have evolved and what still stays the same, how new tools are making attackers more effective, and real-world stories, including how many buildings Rob has gained access to during his career so far. Rob will also be speaking at mnemonic’s annual conference, C2 Summit, this May. Check out the program and see if you should join us as well: mnemonic.io/c2-summit-2026 Send us Fan Mail

March 9, 202633 min

Initial Access Trends

In this episode of the mnemonic security podcast, we’re joined by Will Thomas, Senior Threat Intelligence Advisor at the CTI company Team Cymru, to discuss the latest trends in initial access. Will shares what he is currently observing, including the growing exploitation of edge devices, the targeting of SaaS environments using infostealers and stolen credentials, and the rise of ClickFix-style social engineering techniques. He also explains how these trends differ between threat actors depending on their motivations, and what organisations should prioritise to stay ahead. Will outlines practical steps defenders can take and the key questions security teams should be asking to stay ahead of attackers. The conversation also covers Will’s main concerns around threat actors’ use of LLMs, and how CTI and threat hunting should ideally be carried out to support security operations. Want more Will Thomas? Here you can find his Ransomware-Tool-Matrix: https://github.com/BushidoUK/Ransomware-Tool-Matrix/tree/main/Tools And his own podcast Future of Threat Intelligence (FoTI) Podcast: https://www.team-cymru.com/future-of-threat-intelligence-podcast Send us Fan Mail

Is this your show?

Claim this listing to keep it up to date, reach guests who want to pitch you, and manage bookings with Guestify.

Claim this listing

More Technology podcasts