mnemonic security podcast
Hosted by Robby Peralta from mnemonic, one of Europe’s leading cybersecurity companies, the show features conversations with researchers, founders, operators, and security leaders working across the cybersecurity landscape.
Each episode explores a specific topic within cybersecurity: from incident response, threat intelligence, AI, and geopolitics, to leadership, resilience, and the changing role of security leaders.
The podcast is tailored to cybersecurity practitioners and decision-makers who want grounded conversations about where cybersecurity is going, what organisations should prepare for, and what experienced people are seeing.
Contributors
Guests
Amine Besson
Amine Besson is a threat detection and response specialist focused on helping security operations teams build more mature, scalable and automated technical systems. He works across detection engineering, threat hunting, threat intelligence, SIEM/SOAR/EDR/CDR/XDR engineering and SOC automation.
He is the creator and maintainer of OpenTIDE, an open-source detection engineering ecosystem designed to turn threat intelligence and operational lessons from SOC environments into structured, reusable detection and response workflows. His work has been presented at security conferences including hack.lu and BSides Luxembourg, where he has spoken on the future of detection and response operations. He has also written on detection engineering and the evolution of MDR, including work co-authored with mnemonic.
Guest appearance on:
Andy Smith
Andy Smith is the Co-Founder and CEO of Tracebit, a cloud security company bringing canary-based intrusion detection to modern security teams. With a background in building engineering teams at high-growth cybersecurity companies, Andy is focused on making deception technology practical, scalable, and useful for detecting real attacker behaviour.
Guest appearance on:
Armin Buescher
Armin Buescher is Senior Technical Director at RSAC, where he focuses on practical applications of large language models in cybersecurity. His work includes designing evaluations, stress-testing AI limitations, advising organizations on AI security programs, and building prototypes that explore how emerging technologies can be used responsibly in security operations.
He has more than 15 years of experience across the cybersecurity stack, from malware analysis and software engineering to cloud security and machine learning-based detection. Before joining RSAC, he held senior research and technical roles at Crosspoint Labs, NortonLifeLock, Symantec, FireEye, Blue Coat Systems and Websense. His current research centers on AI for security, LLM evaluation, and the real-world strengths and weaknesses of generative AI in cyber defense.
Guest appearance on:
Bernard Montel
Bernard Montel is EMEA Technical Director and Security Strategist at Tenable, where he advises organisations across Europe, the Middle East and Africa on cyber risk, exposure management and security strategy. With more than 20 years in cybersecurity, he brings deep expertise in cryptography, identity and access management, security operations and threat detection.
A respected industry voice, Bernard has published widely and is regularly invited to speak on emerging threats, cyber resilience and the evolving risk landscape. Before joining Tenable, he served as EMEA Field CTO at RSA, where he played a leading role in Threat Detection & Response. His career combines technical depth, executive advisory experience and a clear view of how organisations can reduce real-world cyber exposure.
Guest appearance on:
Bjørn R. Watne
Bjørn Richard Watne is the Global Chief Information Security Officer at INTERPOL, where he helps protect the systems and information that support international police cooperation across 196 member countries.
He has more than two decades of experience in information security and cyber risk, with senior roles at Storebrand and Telenor Group, advisory work with Europol, and now global responsibility at INTERPOL. His work sits at the intersection of cybersecurity, law enforcement, critical infrastructure and global trust.
He holds a BSc in Computer Science from the University of Agder and an Executive MBA from ESCP Business School. He has also been recognised among the Global Top 100 Leaders in Information Security and is a regular speaker on cyber risk, resilience and the evolving role of security leadership.
Guest appearance on:
Bjørn Tore Hellesøy
Bjørn Tore Hellesøy is a security analyst at KraftCERT, Norway’s sector-specific cyber response organization for the energy, petroleum and other critical infrastructure sectors. His work focuses on understanding cyber threats, strengthening incident response and communicating complex security challenges to both technical specialists and decision-makers.
He is also co-chair of FIRST’s Human Factors in Security Special Interest Group, where he works to promote a more human-centred approach to cybersecurity and challenge the tendency to treat “human error” as the root cause of security incidents. Bjørn Tore regularly contributes to KraftCERT’s threat assessments and is an active commentator on cyber risk, preparedness and the security of society’s most critical services.
Guest appearance on:
Brian Contos
Brian Contos is Field CISO at Mitiga and a veteran cybersecurity executive with more than 30 years of experience building and scaling security companies. His career includes senior roles at ArcSight, Imperva, McAfee, Verodin, Mandiant, Phosphorus and Sevco Security, with involvement in multiple IPOs and acquisitions.
He began his security career with DISA and Bell Labs, and has worked across six continents and more than 60 countries. Brian is also an author, advisor, speaker and Forbes Technology Council contributor, known for his perspectives on cloud security, cyber risk, AI, and the evolution of security operations.
Guest appearance on:
Brian Harris
Brian Harris is an internationally experienced cybersecurity and physical security specialist with more than two decades of experience across the public and private sectors. He is the founder of Covert Access Team, a Copenhagen-based company specialising in covert entry, physical penetration testing, social engineering and black-team operations.
Brian has participated in hundreds of security engagements for major companies, government organisations and critical infrastructure operators around the world. His work examines how determined attackers can combine reconnaissance, deception, technical bypass methods and human manipulation to defeat physical and digital security controls.
He is also an internationally recognised trainer, speaker and podcast host, teaching security professionals practical skills in covert access, physical security auditing, operational planning and adversarial tradecraft.
Guest appearance on:
Brian Singer
Brian Singer is a Ph.D. candidate in Electrical and Computer Engineering at Carnegie Mellon University, where his research focuses on computer security, network security, power-grid cybersecurity, cyber deception and the security implications of large language models.
His work includes research on inconsistencies in grid cybersecurity and Incalmo, an autonomous LLM-assisted system for red teaming multi-host networks. Through his research, he examines how emerging technologies can both strengthen security operations and introduce new risks, especially as AI systems become more capable of planning and executing complex cyber tasks.
Guest appearance on:
Candid Wüest
Candid Wüest is Principal Security Advocate at xorlab, a Swiss cybersecurity company focused on advanced email and messaging security. He has more than 25 years of experience in cybersecurity, threat research and product strategy.
Before joining xorlab, Candid held senior roles at Acronis, including VP of Cyber Protection Research, where he helped build the company’s security research function and contributed to the development of its EDR capabilities. Earlier in his career, he spent more than 16 years at Symantec, working on global security response and malware research, covering threats from early mass-mailing worms to advanced attacks such as Stuxnet.
Candid is a frequent speaker at international security conferences, including RSA Conference and Black Hat, and is known for translating complex threat research into practical insights. His areas of focus include malware, threat trends, email security, AI security and the future of cyber defence.
Guest appearance on:
Dan Cleary
Dan Cleary works at Anthropic and is an AI builder, entrepreneur and writer focused on practical applications of large language models. He previously co-founded PromptHub, a platform for managing, testing and deploying prompts across teams, helping developers and organisations build more reliable AI workflows.
His work spans prompt engineering, AI coding, model evaluation and LLM product development, with a focus on turning generative AI from experimentation into dependable production systems.
Guest appearance on:
Darius Belejevas
Darius Belejevas is the CEO of Incogni, a privacy company that helps individuals remove their personal information from data brokers, people-search websites and other online databases. He leads the company’s efforts to give people greater control over their digital footprint and reduce the risks created by the widespread collection, sale and misuse of personal data.
Through his work at Incogni, Darius is a prominent voice on online privacy, data-broker practices and the practical limitations of existing data-protection regulation. He regularly contributes to discussions about how personal information is collected and traded, the risks this creates for individuals, and the steps people and organisations can take to limit unnecessary exposure.
Guest appearance on:
Duncan Ogilvie
Duncan Ogilvie is a renowned reverse engineer, open-source developer, and creator of x64dbg, one of the most widely used open-source x64/x32 debuggers for Windows. Built specifically for reverse engineering and malware analysis, x64dbg has become an essential tool for security researchers, malware analysts, and low-level Windows specialists worldwide.
Duncan is also the mind behind more than 100 other projects, with deep expertise in binary analysis, Windows internals, debugging, C++, and software tooling. Through his work, writing, and contributions to the security community, he has helped make advanced reverse engineering more accessible, practical, and collaborative for professionals across the industry.
Guest appearance on:
Dustin Childs
Dustin Childs is Head of Threat Awareness at Trend Micro’s Zero Day Initiative, the world’s largest vendor-agnostic bug bounty program. A long-standing voice in vulnerability research and disclosure, he helps translate complex zero-day, exploit, and patching issues into practical insight for security teams, vendors, and the wider public.
Dustin began his information security career in the late 1990s at the U.S. Air Force Information Warfare Center before moving into defence contracting and later Microsoft’s Trustworthy Computing group. Today, he is a prominent ZDI spokesperson, frequent conference speaker, and author of regular security update analysis covering Microsoft, Adobe, Apple, Pwn2Own, and major vulnerability trends.
Guest appearance on:
Einar Oftedal
Einar Oftedal is the Founder and CEO of NorForge, where he helps technology companies transform R&D, engineering and product organizations for an AI-native era. He is a cybersecurity executive, founder, investor and operator with more than two decades of experience across public and private sector security.
Before NorForge, he led and scaled global engineering, research and security teams at Symantec, NortonLifeLock and Blue Coat, and was Head of Crosspoint Labs. Earlier in his career, he helped establish and grow Norway’s national cybersecurity capabilities, including work connected to NSM and NorCERT. His expertise spans engineering leadership, M&A, cyber strategy, emerging technology and building high-performing security communities.
Guest appearance on:
Eirik Nordbø
Eirik Nordbø is a cybersecurity professional in Equinor’s Cyber Defense Center and one of the driving forces behind the Equinor CTF. He has worked at Equinor since completing his master’s degree in 2011 and moved into security around 2015, building deep experience across penetration testing and incident response.
As part of the Equinor pwn team, Eirik has helped grow the Equinor CTF from a small initiative into one of Norway’s most impressive hands-on security events, attracting around 500 participants in Oslo. His perspective combines real-world cyber defence, advanced technical testing, critical infrastructure security and a strong commitment to building the Norwegian security community.
Guest appearance on:
Emil Vaagland
At the time of recording, Emil Vaagland was Head of Product Security at FINN.no, one of Norway’s most important and widely used digital marketplaces. In this role, he worked at the intersection of engineering, security, and large-scale product development, helping shape security practices across a complex organisation with hundreds of developers and product teams.
His background spans hands-on software engineering, security engineering, vulnerability management, secure development, and bug bounty programs, giving him a rare ability to translate deep technical security work into practical, organisation-wide impact. Emil is a recognised voice in modern product security and DevSecOps, with a particular focus on building security programs that work in real development environments rather than only on paper.
Guest appearance on:
Eoin Wickens
Eoin Wickens is Director of Threat Intelligence at HiddenLayer and a leading voice in the rapidly evolving field of AI security. He leads research into the threats facing artificial intelligence and machine-learning systems, examining how adversaries can target models, training data, development pipelines and the wider infrastructure supporting AI applications. His work helps organisations move beyond abstract discussions of AI risk by showing how these systems can be manipulated, compromised and exploited in real-world attacks.
Eoin regularly shares his research with the wider security community through industry reports, conference presentations, podcasts and technical discussions. He is particularly recognised for his analysis of the emerging AI threat landscape and his ability to translate complex attack techniques into practical guidance for security teams, developers and business leaders.
Guest appearance on:
Erica Burgess
Erica Burgess is an cybersecurity architect, offensive security researcher and consultant with a background in software engineering, application security and red teaming. She moved into AppSec red teaming in 2018 after years as a developer and cybersecurity hobbyist, and has since worked on bug bounties, CVEs, exploit techniques, penetration tester training and security R&D.
Erica has spoken at major security conferences and events, including Black Hat Europe, DEF CON, SkyTalks, CactusCon and Live360!, with a particular focus on hacking, AI security, offensive techniques and practical security research.
Guest appearance on:
Erin West
Erin West is the founder and president of Operation Shamrock, a nonprofit focused on disrupting transnational digital scams through education, advocacy and law enforcement collaboration. A former Deputy District Attorney in Santa Clara County, California, she spent 26 years as a prosecutor, including extensive work on cryptocurrency-enabled crime, SIM swapping and online financial fraud.
West is widely recognised for her work helping trace and recover funds stolen through “pig butchering” and other crypto scam operations. She is a global speaker and educator on cybercrime, organised scam networks, victim protection and the growing industrialisation of online fraud.
Guest appearance on:
Erlend Leiknes
Erlend Leiknes is a cybersecurity researcher and security consultant at mnemonic, where he has spent more than a decade working with penetration testing, red teaming and hands-on security research. He holds a master’s degree in technical societal safety from the University of Stavanger, and has a background that combines engineering, IT and practical offensive security.
Erlend was one of the mnemonic researchers behind the Magic Cat investigation into Darcula, a global phishing-as-a-service operation linked to hundreds of thousands of victims and large-scale credit card theft. His work has been presented through mnemonic’s research, the mnemonic security podcast, BSides Oslo and NDC Security.
Guest appearance on:
Espen Endal
Espen Endal is an OT Security Analyst at KraftCERT/InfraCERT, where he helps protect Norway’s energy sector and other critical infrastructure from cyber threats. His work includes analysing emerging threats and vulnerabilities, sharing actionable intelligence with member organisations, and supporting the detection and response to attacks targeting industrial control systems and operational technology.
Before joining KraftCERT, Espen worked at mnemonic and, prior to that, at Hafslund. This background has given him experience from both the energy sector and cybersecurity operations, as well as insight into the specialised challenges involved in securing critical infrastructure.
At KraftCERT/InfraCERT, Espen contributes to strengthening collaboration, preparedness and information sharing among organisations responsible for some of Norway’s most essential services.
Guest appearance on:
Ford Merrill
Ford Merrill is Senior Director of Research and Innovation at SecAlliance, a CSIS Security Group company. He has spent years tracking the evolution of Chinese-language phishing-as-a-service operations — from the early "Smishing Triad" campaigns impersonating postal services and toll operators, through the pivot to mobile wallet fraud, and most recently to phishing kits targeting brokerage accounts in "ramp-and-dump" stock manipulation schemes.
His research has been cited repeatedly by Krebs on Security and CyberScoop, and he presented a deep dive into a 4,000-member Chinese smishing syndicate at M3AAWG's 63rd General Meeting. Merrill's work sits at the intersection of technical kit analysis and tracking how these criminal ecosystems adapt in real time to law enforcement and platform defenses.
Guest appearance on:
Gaute Brynildsen
Gaute Brynildsen is Chief Audit Executive at Gjensidige, one of the leading insurance groups in the Nordics. He has more than 17 years of experience in internal audit, with a background spanning IT, cyber risk, governance, and assurance.
Gaute has played an active role in developing Gjensidige’s approach to auditing technology and AI, including work on machine learning model assurance, AI governance, security controls, policies, roles, training, and risk management. He is also a certified and experienced audit professional, with credentials including CIA, CISA, CRISC, CCSP, GIAC GSNA, CCSK, Azure Fundamentals, and AAIA, and has previously served as president of the ISACA Norway Chapter and as a board member of the Cloud Security Alliance.
His work sits at the intersection of internal audit, cybersecurity, operational resilience, and responsible AI governance.
Guest appearance on:
Haakon Staff
Haakon Staff is a penetration tester at mnemonic, where he helps organisations understand and reduce real-world security risk by thinking like an attacker before actual attackers get the chance. As part of one of Europe’s leading cybersecurity environments, Haakon works in the discipline where technical depth, curiosity, and practical exploitation skills meet business-critical risk reduction.
He has also appeared on the mnemonic Security Podcast to discuss Capture the Flag competitions, highlighting his interest in hands-on security learning, offensive security techniques, and the hacker mindset. With experience from mnemonic’s offensive security environment, Haakon represents the practical, deeply technical side of cybersecurity: finding weaknesses, explaining their impact, and helping organisations become harder to compromise.
Guest appearance on:
Håkon Sørum
Håkon Sørum is Principal Security Architect and Partner at O3C, a specialist cybersecurity consultancy focused on cloud, platform and AI security. He has extensive expertise in designing secure cloud architectures, implementing modern software security practices and helping organisations operate complex cloud environments securely.
Håkon works at the intersection of application security, cloud infrastructure and secure software development, translating technical risk into practical security improvements for modern engineering teams. He is also an experienced speaker and podcast host, regularly sharing insights on topics including threat modelling, cloud detection and response, and building security into the development lifecycle.
Guest appearance on:
Harrison Sand
Harrison Sand is a security researcher at mnemonic, specialising in application security, penetration testing, reverse engineering, embedded devices, IoT and hardware security. His work spans technical security testing, vulnerability management and hands-on research into how real-world systems fail in practice. He has analysed devices such as EV chargers and smartwatches, and publishes research through his personal blog, Harrison’s Sandbox.
In 2026, he uncovered a serious Telia Norway signaling issue that exposed location-related data for mobile users, a case later investigated and reported by NRK. His research has also been featured by outlets including TechCrunch, PC Magazine, The Register, Ars Technica, Hackaday, Aftenposten and NRK.
Guest appearance on:
Harry Wetherald
Harry Wetherald is Co-Founder and CEO of Maze, a London-based cybersecurity startup using AI agents to help security teams investigate, triage and resolve cloud vulnerabilities. Maze launched in 2024 and has raised millions to build agentic AI tools for vulnerability management.
Before Maze, Wetherald was a product leader at Tessian and worked in venture capital at Winton, focusing on cybersecurity and AI startups. He also writes Security Tales, a Substack covering security, AI and startup themes. His work focuses on moving vulnerability management beyond noisy backlogs and generic remediation advice toward context-aware workflows that help developers and security teams fix what matters.
Guest appearance on:
Helen Kearney
Helen Kearney is a humanitarian technology and innovation specialist focused on helping non-profit and humanitarian organisations use digital tools responsibly, strategically and with real-world impact. She has worked with the H2H Network, where she has been listed as Head of Network Development, and has contributed to sector discussions on innovation, transformation and new ways of working in humanitarian response.
Helen writes about the use of generative and agentic AI in humanitarian settings, including practical questions around private LLMs, responsible adoption, safeguarding sensitive data and the future of AI-enabled humanitarian work. She joined the mnemonic security podcast to discuss agentic browsers, the risks and opportunities they create, and what humanitarian organisations need to consider as AI tools become mainstream.
Guest appearance on:
Jambul Tologonov
Jambul Tologonov is a Security Researcher at Trellix, focused on APT tracking, malware analysis, threat intelligence and automation. His work examines how cybercriminal and state-linked actors operate, including ransomware groups, dark web activity and adversary infrastructure.
Before joining Trellix, he worked on forensic analysis and threat research in financial-sector environments, giving him strong practical experience in investigating real-world incidents. Jambul has contributed to Trellix research on ransomware ecosystems such as Yanluowang and LockBit-related activity, helping defenders understand attacker tactics, relationships and emerging criminal trends.
Guest appearance on:
Jeff Schiemann
Jeff Schiemann is an experienced cybersecurity executive and board adviser with more than two decades of experience in information security, risk management and technology leadership. He previously served as Chief Information Security Officer at AMINA Bank, formerly SEBA Bank, where he was responsible for protecting a regulated financial institution operating at the intersection of traditional banking, digital assets and blockchain technology.
Before joining AMINA, Jeff held security and risk roles at Blockchain Propulsion and spent nearly two decades in senior leadership positions at Orange Business Services. He now advises organizations on cyber resilience, threat-informed security strategies and the evolving responsibilities of the modern CISO.
Guest appearance on:
Jens Christian Vedersø
Jens Christian Vedersø is an experienced cyber risk and operational technology security leader with a background spanning the military, intelligence, government and the renewable energy sector. As Head of Cyber Risk Management at Vestas, he works to identify, quantify and manage cyber risks affecting one of the world’s largest wind turbine manufacturers.
A former Danish naval and intelligence officer, Jens later helped shape energy-sector cybersecurity legislation and preparedness at the Danish Energy Agency. He has also served as a subject-matter expert at the Danish Centre for Cyber Security, specialising in SCADA, operational technology, industrial control systems and IoT security.
Throughout his career, Jens has advocated for a practical, risk-based approach to cybersecurity—one that moves beyond compliance and treats security as an organisation-wide business and change-management challenge.
Guest appearance on:
Joe Slowik
Joe Slowik is Director of Cybersecurity Alerting Strategy at Dataminr, where he focuses on identifying and contextualising cyber events, threat activity and emerging risks in real time. He has more than 15 years of experience across government, critical infrastructure and private-sector cybersecurity, with previous roles at organisations including MITRE, Los Alamos National Laboratory, the U.S. Navy, Dragos, DomainTools and Huntress.
Joe is widely known for his work on threat intelligence, industrial control system security, adversary tradecraft and critical infrastructure defence. He has shared his research and perspective at leading cybersecurity forums including RSA Conference, CYBERWARCON, SANS, FIRST Conference and The Hague Threat Intelligence Exchange, bringing a practical, intelligence-led view of how defenders understand and respond to hostile activity.
Guest appearance on:
Joe Sullivan
Joe Sullivan is one of the most experienced and widely recognised security leaders in the technology industry. A former federal cybercrime prosecutor, he has held senior security leadership roles at some of the world’s most influential technology companies, including Facebook, Uber, Cloudflare and eBay.
At Uber, Joe served as the company’s first Chief Security Officer, where he was responsible for building and leading security during one of the most intense periods in the company’s history. His career has placed him at the centre of major conversations around breach response, executive accountability, cyber policy, trust and safety, and the evolving role of the modern CISO.
Today, Joe advises companies and security leaders on how to build stronger, more accountable security programs. He remains an important voice in discussions about what security leadership should look like in an era of escalating digital risk.
Guest appearance on:
John Fokker
John Fokker is the Vice President of Threat Intelligence Strategy at Trellix, where he leads work to detect, understand and disrupt cyber adversaries. He has spent years investigating cybercrime, ransomware and underground threat activity, and is known for translating complex attacker behaviour into practical intelligence for defenders, customers and partners.
John is also a co-founder of the NoMoreRansom project and has contributed to international cybercrime cooperation through his work with Europol’s EC3 advisory community. With a background spanning military service, digital investigations and threat research, he brings a rare mix of operational, investigative and strategic experience to the cybersecurity field.
Guest appearance on:
Jon DiMaggio
Jon DiMaggio is a cybersecurity researcher, author, and former US intelligence analyst renowned for infiltrating and investigating some of the world’s most dangerous ransomware groups. He is the co-founder of Arkem Cyber, where he focuses on cybercrime intelligence and threat-actor research.
Over a career spanning more than 16 years, Jon has investigated nation-state operations, organized cybercrime, and major ransomware syndicates. His work has included going undercover inside the LockBit ransomware operation, building relationships with its members and gathering intelligence on the people and structures behind the group.
Jon is also the author of The Art of Cyberwarfare: An Investigator’s Guide to Espionage, Ransomware, and Organized Cybercrime. His research and writing have earned industry recognition, including a SANS Difference Makers Award, and established him as one of the leading voices on the human side of cybercrime.
Guest appearance on:
Keven Hendricks
Keven Hendricks is a veteran law enforcement officer and specialist in dark web, cryptocurrency and cybercrime investigations. He began his law enforcement career in 2007 and has served on both FBI and DEA cybercrime task forces, investigating offences ranging from online child exploitation to narcotics trafficking through dark web marketplaces.
Keven is the founder of the Ubivis Project, an initiative dedicated to combating the sale and distribution of illegal narcotics through the dark web. He is also an instructor, published author and recognised subject-matter expert in dark web investigations, contributing his expertise to law enforcement publications, analytical journals and technical reports.
Guest appearance on:
Knut Elde Johansen
Knut Elde Johansen works with cyber defence at Storebrand, where he has played a central role in the company’s cloud security journey. He has led Storebrand’s Cyber Defence Center and is described as an active blue teamer with a focus on threat intelligence, incident response and risk.
His work includes detection as code, creative use of threat intelligence, CTEM and modern vulnerability management across a multi-cloud environment. Knut has spoken publicly about Storebrand’s shift from early cloud challenges to a more mature, engineering-driven and cloud-native security model.
Guest appearance on:
Kyle Gallatin
Kyle Gallatin is a machine learning engineer, author and educator specializing in the development of scalable machine learning systems and infrastructure. Currently an ML Engineer at Handshake, he has previously worked on machine learning infrastructure at Etsy and developed operationalized machine learning solutions within the biomedical sector at Pfizer.
Kyle is the co-author of the second edition of Machine Learning with Python Cookbook, a practical guide to solving real-world machine learning challenges using Python. Alongside his engineering work, he has served as a professional data science mentor, volunteered as a computer science teacher and written extensively about the intersection of software engineering, machine learning and MLOps. He holds both bachelor’s and master’s degrees in molecular and cellular biology from Quinnipiac University.
Guest appearance on:
Leonid Rozenberg
Leonid Rozenberg is a cybercrime and threat intelligence researcher at Hudson Rock, specialising in infostealer malware, dark-web intelligence and the criminal ecosystems that enable modern cyberattacks. With nearly a decade of hands-on experience, he has previously held threat intelligence roles at leading cybersecurity companies including Check Point and IntSights, now part of Rapid7.
Today, he is a recognised authority on how credentials, session cookies and other information stolen from compromised devices are used to facilitate account takeovers, data breaches and ransomware attacks. Through his research and public speaking, Leonid helps organisations understand emerging cybercrime tactics and turn underground intelligence into practical defensive action.
Guest appearance on:
Levi Gundert
Levi Gundert is Chief Security & Intelligence Officer at Recorded Future, where he leads the company’s security and intelligence strategy. His work focuses on translating cyber threats, geopolitical developments and criminal activity into actionable intelligence that helps security teams and business leaders make better-informed decisions.
Before joining Recorded Future, Levi held senior cyber threat-intelligence roles at Fidelity Investments and Cisco Talos, giving him extensive experience across both enterprise security and large-scale threat research. He is also an Adjunct Professor at Embry-Riddle Aeronautical University’s College of Business, Security and Intelligence, where he teaches subjects related to intelligence analysis, security and criminal investigations.
Guest appearance on:
Marius Kotlarz
Marius Kotlarz is a penetration tester at Equinor and one of the key creators behind the Equinor CTF. Originally joining Equinor as an incident responder before moving full-time into the security testing team, Marius brings practical offensive security experience and a strong CTF background to one of Norway’s most important critical infrastructure environments.
His work on the Equinor CTF spans both challenge design and the demanding technical infrastructure behind the event, including cloud, Kubernetes, Terraform, stress testing and backup planning. He represents the kind of security professional who turns hands-on hacking, creativity and resilience engineering into real value for both Equinor and the wider cyber community.
Guest appearance on:
Marius Sandbu
Marius Sandbu is a Norwegian cloud architect, technology evangelist and specialist in artificial intelligence, cloud technology and cybersecurity at Sopra Steria. With more than 15 years of experience in IT, he has worked extensively with cloud architecture, implementation, security, DevOps and infrastructure-as-code across technologies such as Microsoft Azure, Microsoft 365, AWS, Google Cloud, VMware and Citrix.
He is also a long-standing Microsoft MVP and a widely read technical writer, known for publishing practical insights on cloud, AI, security and enterprise technology through his own blog and public knowledge base.
Guest appearance on:
Martin Gundersen
Martin Gundersen is a journalist and writing news editor at NRKbeta, where he covers the intersection of technology, society, security and digital culture. He has a background in civil engineering studies at NTNU and previously served as editor of Under Dusken.
At NRK, he has worked on investigative reporting into cybercrime, telecom security and digital fraud, including the Magic Cat/Darcula investigation and reporting on spoofing and mobile-network vulnerabilities affecting Norwegian users. His work combines technical understanding with clear public-interest journalism, helping make complex digital threats understandable for a broad audience.
Guest appearance on:
Matt Cooke
Matt Cooke is Director of Cybersecurity Strategy for EMEA at Proofpoint, where he helps organisations understand and respond to an increasingly people-centric threat landscape. With more than 20 years of experience across technical, product and strategic roles, Matt specialises in areas including email security, human risk, security awareness, insider threats and the protection of sensitive data. Before joining Proofpoint, he held senior roles at Sophos, Symantec and Mimecast. He is passionate about making cybersecurity accessible, relevant and actionable for both security leaders and the wider workforce.
Guest appearance on:
Max Heinemeyer
Maximilian “Max” Heinemeyer is a globally recognised cybersecurity leader and the Global Field CISO at Darktrace. With more than a decade of experience spanning penetration testing, red teaming, threat hunting, SIEM, SOC consulting and advanced persistent threat investigations, Max has built a career at the intersection of offensive security, incident response and AI-driven defence.
At Darktrace, he works closely with some of the organisation’s most strategic customers, helping security leaders understand emerging threats and strengthen their ability to detect and respond to sophisticated attacks. Having previously led global threat-hunting initiatives and held senior product and cyber-innovation roles, Max has played an influential part in shaping how Darktrace’s technology is applied to real-world security challenges.
Guest appearance on:
Øystein Stadskleiv
Øystein Stadskleiv is a technical sales specialist at Leteng AS, one of Norway’s established value-added distributors within professional AV and IT. With deep practical expertise in networking, cabling, signal distribution and AV infrastructure, he helps installers and resellers design reliable, future-ready technical solutions for demanding environments.
Øystein also serves as an instructor for Leteng’s networking courses, where he translates complex technical concepts into clear, actionable guidance for professionals across the industry. Through his combination of product insight, hands-on technical competence and customer-facing advisory experience, he plays an important role in strengthening competence across Norway’s professional AV and installation market.
Guest appearance on:
Øyvind Bergerud
Øyvind Bergerud is Head of Security Operations at Storebrand, where he works with operational security, cloud security and cyber resilience in one of the Nordic region’s major financial services groups. He has been part of Storebrand’s security journey as the company moved from outsourced IT toward a more modern, in-house cloud and security capability, including the development of stronger cloud maturity, policy-as-code practices and operational security processes.
Bergerud has also represented Storebrand publicly in discussions about cybersecurity, openness around incidents and how financial institutions can prepare for evolving digital threats.
Guest appearance on:
Patric J.M. Versteeg
Patric J.M. Versteeg is an experienced cybersecurity executive and CISO with more than 25 years of experience building and leading information security programs across global organizations. He has held senior security roles in the food industry and is also a researcher in Cyber Security at HU University of Applied Sciences Utrecht.
Named European CISO of the Year 2024 by The Millennium Alliance, Patric is known for challenging traditional security thinking and focusing on the human side of cybersecurity. His work combines strategic security leadership, organizational behavior, cybersecurity culture and practical risk management, helping organizations stay secure while supporting business growth in a changing threat landscape.
Guest appearance on:
Ragnhild Sageng
Ragnhild “Bridget” Sageng is a specialist in social engineering and open-source intelligence, with a professional background spanning IT support, project management and human psychology. In 2020, she won the Temple University Collegiate Cybersecurity Competition as its only non-US, non-native-English contestant, producing an overnight OSINT assessment as part of the challenge. She became a Certified Social Engineering Pentest Professional in 2021.
Ragnhild has presented at conferences including DEF CON, Black Hat Europe, Sikkerhetsfestivalen, KiNS-Tech and NDC Security Oslo. Her work focuses particularly on deepfake-enabled fraud, the psychology of trust and the human impact of social-engineering assessments.
Guest appearance on:
Ricardo Ferreira
Ricardo Ferreira is Field CISO for EMEA at Fortinet, where he advises CxOs and global organisations on security strategy, risk management and secure digital transformation. He has more than 20 years of experience across cybersecurity, cloud, automation, DevOps and emerging technologies, with previous roles spanning EY London, Rackspace and HSBC.
Ricardo is a published author and contributor to Cloud Security Alliance research, including work on cloud security, microservices, serverless security, GenAI and LLM threat taxonomies. He has also developed AI-powered cloud compliance accelerators and is active in senior cybersecurity policy and leadership communities, including the ACM CyberSecurity Policy Working Group and Aphinia. His work focuses on helping organisations adopt new technologies securely while managing business and operational risk.
Guest appearance on:
Rob Shapland
Rob Shapland is an ethical hacker, physical penetration tester and cyber security speaker known for showing organisations how attackers exploit both technology and human behaviour.
With more than 16 years of experience in penetration testing, Rob has worked with hundreds of organisations, from smaller businesses to major international companies. His work often combines technical security testing with social engineering, including authorised attempts to enter corporate buildings, bypass physical controls and demonstrate how real-world attackers think and operate.
Rob is Director of Cyonic Cyber and has previously held senior cyber roles at Falanx Cyber. A regular speaker and media commentator, he has appeared on major UK outlets including BBC, Sky News, ITV and Channel 4, helping make complex cyber security risks understandable and memorable.
Guest appearance on:
Runa Sandvik
Runa Sandvik is a Norwegian-American security researcher and the founder of Granitt, where she works to protect journalists, human rights defenders and other people facing sophisticated digital threats. She began her career as an early developer at the Tor Project, contributing to technology that enables anonymous and censorship-resistant communication online.
Runa later served as Senior Director of Information Security at The New York Times, where she helped protect journalists, sources and newsroom operations, and led work including the launch of the newspaper’s Tor onion service. She has also advised the Freedom of the Press Foundation and conducted widely recognised security research, including demonstrating how an internet-connected smart rifle could be remotely compromised.
Her career has focused on cybersecurity, privacy, press freedom and defending people targeted by nation-state and other advanced adversaries.
Guest appearance on:
Scott Piper
Scott Piper is one of the cloud security community’s most respected researchers and an internationally recognised authority on AWS security. As a Principal Cloud Security Researcher at Wiz, he focuses on identifying, explaining and helping organisations address complex risks across modern cloud environments.
Scott is the creator of several widely used open-source security projects, including CloudMapper, Parliament, CloudTracker and the influential flAWS and flAWS2 cloud security challenges. These resources have helped security professionals around the world develop a practical understanding of common AWS vulnerabilities, misconfigurations and attack paths.
Scott is a co-founder and organiser of fwd, one of the industry’s leading community-driven cloud security conferences, and an administrator of the Cloud Security Forum. Through his research, tools, writing and community leadership, he has played a significant role in shaping how cloud security is practised today.
Guest appearance on:
Sergej Epp
Sergej Epp is Chief Information Security Officer at Sysdig, where he leads cybersecurity strategy, operations and risk management for the company’s cloud-native security platform.
He joined Sysdig after serving as CISO at Palo Alto Networks and brings nearly two decades of experience across cyber defense, threat intelligence, incident response and security leadership.
Earlier in his career, he spent more than a decade at Deutsche Bank, including roles focused on cyber forensics and cyber hygiene operations. Alongside his executive work, Sergej is a regular speaker, lecturer and advisor to technology startups and venture funds, with a strong focus on cloud security, real-time threat detection and the evolving role of the CISO.
Guest appearance on:
Tine Anneberg
Tine Anneberg is the Founder and CEO of CREOSUM Create Impact, where she advises and trains organisations in commercial negotiation. With more than ten years of negotiation experience, including work on million-dollar contracts, she helps businesses build stronger negotiation strategies, improve outcomes and create value through a more collaborative approach.
Tine is a Certified SMARTnership Partner and CREOSUM is part of the SMARTnership Negotiation Organization. Her work focuses on trust, curiosity, relationship-building and practical negotiation skills, particularly for technology companies and commercial teams. She is also a speaker and trainer, sharing insights on how diverse teams and better preparation can improve negotiation performance.
Guest appearance on:
Tony Fergusson
Tony Fergusson is CISO in Residence for EMEA at Zscaler and a respected cybersecurity strategist with more than 25 years of experience across security, networking and IT leadership. An early Zero Trust pioneer, he began applying its principles in enterprise environments in 2015, before the model became mainstream. He was the first Zscaler customer to deploy Zscaler Private Access and among the earliest leaders to extend Zero Trust into cloud and operational technology environments.
Before joining Zscaler, Tony led an award-winning secure-cloud transformation. Today, he advises executives and security leaders on cyber resilience, digital transformation, attack-surface reduction and AI-native security. A prolific writer and international speaker, he is known for challenging conventional thinking and turning complex technological shifts into practical strategies.
Guest appearance on:
Ulf Larsson
Ulf Larsson is Security CTO at SEB Group, where he works to strengthen security across one of the Nordic region’s leading financial services institutions. His role spans information security, IT and infrastructure security, physical security and the protection of customer identity and data.
With a background in enterprise architecture and many years at SEB, Ulf focuses on embedding security into large-scale technology environments, balancing innovation, resilience and business-critical risk management. He has also contributed to SEB’s work on Zero Trust and quantum-safe security, helping the bank prepare for future threats while protecting customers today.
Vladimir Zaha
Vladimir Zaha is an open-source researcher with experience in digital verification, geolocation and the analysis of publicly available information. As a volunteer researcher with Bellingcat’s Global Authentication Project, he has contributed research to investigations examining immigration enforcement and the use of force against protesters in the United States.
His work supports the verification of user-generated content, the reconstruction of events and the documentation of issues of significant public interest. He is particularly interested in applying open-source intelligence techniques to investigative journalism, accountability and human-rights reporting.
Guest appearance on:
Will Thomas
Will Thomas is a Senior Threat Intelligence Advisor at Team Cymru, where he focuses on cyber threat intelligence, threat hunting and the infrastructure behind cybercriminal activity. He is also a SANS instructor and co-author of the FOR589 Cybercrime Intelligence course.
Beyond his role at Team Cymru, Will is the co-founder of Curated Intelligence, a threat intelligence community, and has spoken at events including DEF CON, Sleuthcon, Underground Economy and BSides London. He has also been involved in research supporting investigations into cybercrime groups and online criminal infrastructure.
With a background spanning threat intelligence vendors, security research and community-led intelligence sharing, Will is a strong voice on how defenders can better understand adversaries, map malicious infrastructure and turn intelligence into operational action.