DiscoverSecurityCafé
SecurityCafé
Claim Ownership

SecurityCafé

Author: Quint Ketting Menno van der Horst

Subscribed: 2Played: 1
Share

Description

“Pull up a chair at the Security Café – your monthly deep dive into the hottest cybersecurity news and trends. Each episode brings you an inspiring guest and a story that will spark your imagination. Produced by Quint & Menno (Atos), this is where insights meet conversation. Don’t just stay informed—join the discussion!”

31 Episodes
Reverse
Recorded at the Atos booth, CybersecNL 2026. Kelvin Rorive is CISO at ICT Group and runs the Cyber Chain Resilience Consortium(CCRC), which prepares organisations and their suppliers to handlea crisis together. Hosted by Menno van der Horst with QuintKetting.## Timestamps00:00 Day one, and nobody is quite awake yet01:12 Kelvin: CISO at ICT Group, and what CCRC does02:05 Why this conference feels like a family reunion03:09 The message at the booth: practice for the worst03:34 Survivability — a word picked up from a Ukrainian speaker04:03 Weerbaarheid, veerkracht, and a telco under drone attack05:25 Fine for the top 10. What about everyone below?06:09 "My IT manager will handle it" — and why he won't07:00 Quint: I talk about business risk, not about cyber08:31 Crisis in the chain: rehearse it with your supplier present10:08 Exercises spill over into day-to-day cooperation10:28 The factory that has to stop because the trucks don't come12:02 One organisation escalates 1-2-3. The other runs it in reverse.13:23 CEOs walking out of the room with a list13:44 Putting the CEO in the hot seat, and not letting them delegate15:11 What not to do: questionnaire bombardment, and AI filling them in15:47 Know the CISOs of your critical suppliers personally16:21 The security family, and why you don't abuse it18:14 FI-ISAC: competitors around one table, one shared goal19:41 Compliance is not security20:11 An APT campaign where every control was green20:42 NIS2, and whether Europe adapts fast enough22:11 The balance is shifting from prevention to resilience22:40 The most important word is not cyber. It is resilience.## Key takeaways- Survivability sits one level beyond resilience. It starts fromthe assumption that everything can be broken: people, buildings,data, networks.- A cyber crisis gets handed to the IT manager and then escalatesinto a chain crisis long before anyone at board level notices.- A crisis exercise only tests the chain if your critical supplieris in the room. Mismatched escalation ladders, unclearresponsibilities and missing contacts surface in minutes.- Supplier questionnaires are close to worthless now. They areanswered by AI, approved unread, and can be manipulated withinstructions hidden in the document.- What works instead is a real relationship with the CISOs ofyour critical suppliers, used sparingly enough that a callmeans something.- Compliance is the floor, not the ceiling. Green controls and along-running intrusion coexist comfortably.- Preventive measures still matter, but the centre of gravity hasmoved to resilience. Assume something gets through and trainthe goalkeeper.## MentionedCyber Chain Resilience Consortium — https://ccrc.nlICT Group — https://ict.euFI-ISAC, the financial sector information sharing communityCybersecNL 2026 — https://www.cybersecnl.nl## Also in this seriesRamsés Gallego on speed and governance — out now.Martin de Vries on sector differences — publishing 24 September.---SecurityCafe. Powered by Atos.
# Speed, governance and a changing landscape — Ramsés GallegoSpecial: Live from CybersecNL — Episode 1 of 7Recorded live at the Atos booth, CybersecNL 2026. Ramsés Gallegois Chief Technologist at DXC, ISACA Hall of Fame, and president ofthe ISACA Barcelona chapter. Hosted by Menno van der Horst withQuint Ketting.## Timestamps00:00 Welcome and introductions00:42 Why DXC came to CybersecNL: detect more, respond faster01:28 Rivals, never enemies — why competitors share a stage02:24 The other side collaborates better than we do04:28 What integrators owe their customers: service over technology06:34 A second risk equation: means, motives, opportunities07:32 Are our frameworks still fit for purpose?08:29 COBIT 2019 is ageing, and ISACA's AI certification track09:53 "The human in the loop is dead" — as a reflex, not as a role10:35 Quantum: RSA, Diffie-Hellman and elliptic curve on the clock11:55 The part nobody talks about: code signing and certificates12:38 ISACA Quantum Pulse Poll — the skills gap in numbers13:21 It is not IT you are protecting. It is the business.14:01 Trucks that stop delivering, invoices quietly altered15:02 Why risk has to come from the business, not only the CISO16:26 Enterprise risk management: risk is always plural17:22 Should we still be calling it cybersecurity at all?18:17 Business continuity is not resilience18:54 The positive side of risk19:34 Why a car has brakes20:22 Three pillars: identity, data, applications21:51 Non-human identities and the 100-to-1 future23:18 Governance is not management, and we need AI-natives## Key takeaways- The classic risk equation still holds, but means, motives and opportunities now sits next to it. AI has collapsed the cost of all three.- Business first. Customers do not speak Kubernetes, they speak euros. The database was not hacked — the business was.- Identity remains the cornerstone. Two of the three major incidents discussed on the CybersecNL main stage were identity related.- Non-human identity is the governance problem of the next few years. Almost nobody can say how many agents they run, let alone which accounts sit behind them.- Quantum is not only an encryption story. Code signing, certificates and anything that depends on keeping a secret are in scope.- Brakes let you go fast. Security exists so the business can move, not so it can stop.- Ramsés states that ISACA is already building COBIT 7, returning to a numbered release. Not independently confirmed at the time of publishing.- The 10-to-1 non-human to human identity ratio, and the projected 100-to-1, are cited from industry statistics and not sourced on air.- The 5-to-12-year window for cryptographically relevant quantum computing is Ramsés' own estimate.- ISACA Quantum Pulse Poll figures (2,586 respondents, 67 percent expecting new skill requirements) are quoted from memory.## MentionedISACA — https://www.isaca.orgDXC Technology — https://dxc.comQuantum World AssociationThe brakes analogy is credited to Art Wong.## Also in this seriesMartin de Vries on sector differences and why we may need aNIST 3 — referenced in this episode, publishing 24 September.Aernout Reijmer on collaboration after ASML — publishing29 September.---SecurityCafe. Powered by Atos.
Andreas Wuchner ran large-scale security organisations for some 30 years and now invests in and advises startups, family offices, VC and PE firms. On geopolitical risk, AI governance, and what AI actually costs.Chapters00:00 — Welcome01:00 — In the news: 900+ agents coordinating over a shared channel05:07 — Geopolitical risk is real, and NIST/ISO don't map it07:39 — The CybersecNL keynote: is what we built still good enough?11:40 — "What brings you in jail is non-compliance"13:00 — The AI governance tooling wave14:44 — Punish vs enable: pocket money for Big Tech kills a startup16:53 — The minimum viable control set17:43 — Fines: where does that money actually go?22:50 — What AI means for the business, from a board seat26:30 — Three types of adopters, and AI-native hiring in seven days32:04 — "Meat proxies": what the AI-native crowd calls the rest of us34:47 — AI is not cheap: what a €200 subscription really costs37:10 — $20 per run vs $2.84, same job39:22 — Outsourcing efficiency promises vs rising AI costs41:44 — Augmentation vs a greenfield agentic machine room43:43 — Cooling, solar, subsea, space: the infrastructure race47:19 — What to read, what to watchKey takeawaysA policy keeps you out of jail — and that's all it does. Regulators ask for governance; many tick that box with a document. Anyone declaring AI governance "done" is at the beginning.Define the non-negotiables, then get out of the way. The organisations doing this well name 10 to 50 controls that are not up for discussion and let the rest develop over time — a minimum viable control set. The alternative is the department of no.Token economics is a skill, not a budget line. The same investment-document analysis ran at roughly $20 per company; converting inputs to markdown first brought it to $2.84. A week-long AI strategy course for managers does nothing for the layer that spends the money.MentionedLog Force — a project in Spain predicting indicators of compromise before they become threats, and spotting when agentic systems start hallucinating. Not a commercial product yet.Tehran — the espionage series from What to WatchUber's €824,990,000 fine from the Dutch DPA for fully automated driver deactivation, under GDPR Article 22: https://www.autoriteitpersoonsgegevens.nl/en/current/uber-fined-nearly-825-million-euros-for-automated-driver-blockingThe Odido breach (February 2026): some 6.4 million people and 600,000 companies, including over 5 million ID document numbers. https://nos.nl/artikel/2604461-odido-hackers-publiceren-resterende-klantdata-ook-miljoenen-id-nummersMeta's settlement over harm to minors: up to $17.1 billion, with 52 US attorneys general — not an EU case. https://www.npr.org/2026/08/26/nx-s1-5944781/meta-settlement-child-safety-lawsuitPowered by Atos
SecurityCafe — "Sovereignty Is the Wrong Word": Digital Autonomy with Mika LauhdeHosts: Menno van der Horst & Quint Ketting Guest: Mika Lauhde, Luxembourg House of Cybersecurity (linkedin.com/in/mika-lauhde-4270711)About this episodeMika Lauhde spent 30 years across Nokia, Huawei, and ENISA before landing at Luxembourg House of Cybersecurity, the national hub keeping Luxembourg's municipalities, SMEs, and economy cyber-resilient. His argument: Europe has the wrong word. Not "sovereignty" — hard borders around who owns what — but autonomy: acting independently while still sharing tools and trust. From GPS glitches during US foreign policy disputes, to Europe always getting the second-best tech (fighter jets included), to a national CERT running entirely on open source — this one covers a lot of ground.In this episode00:11 — Welcome & Mika's background (Nokia, Huawei, ENISA, Luxembourg House of Cybersecurity)02:08 — News: an integrator data-leak claim ("888") and what makes integrator breaches different06:06 — Android's new developer certificate as a "kill switch," African nations building their own internet, UK VPN/age-verification rollout, an EU "tech sovereignty" proposal that leans on non-European hardware09:11 — A US court ruling that may have quietly broken a GDPR assumption on data transfers10:34 — NIS2 finally live in NL (15 Aug) — are our laws fast enough for machine-speed attacks?19:20 — The "SplinterNet," and why Mika argues for shared autonomy over walled-garden sovereignty23:46 — The Cyber Resilience Act's unprecedented recognition of open source (79 mentions)24:19 — AI models as the new trade weapon — allies get the previous generation, like fighter jets26:50 — The GPS/Galileo story, and SES's Iris² as Europe's answer to Starlink30:15 — EU tax rules that quietly disadvantage open source; the Nokia N900 as Europe's "Sputnik moment"33:00 — Luxembourg's national CERT runs entirely on open-source tools34:40 — The call to action: a free open-source toolkit so any EU SME can stand up a cyber ops center36:41 — What to read: Quint's, Mika's, and Menno's picks41:04 — Wrap-upKey takeawaysAutonomy, not sovereignty — sharing open standards beats walling off bordersDependency is invisible until it breaks — GPS glitches led to Galileo, now to Iris²New tech follows old patterns — AI models, like military hardware, come second-best to alliesOpen source is operational, not aspirational — Luxembourg's CERT proves it at national scaleMentionedAccenture leak claims (unconfirmed) · NIS2 (NL) · Cyber Resilience Act · European OSPO network · SES Iris² · Trump v. Slaughter ruling Reads: The Subtle Art of Not Giving a Fck* by Mark Manson (markmanson.net/books/subtle-art) · Max Schrems / noyb (noyb.eu/en/us-supreme-court-just-blew-eu-us-data-transfers) · Bert Hubert's blog (berthub.eu)SecurityCafe is hosted by Menno van der Horst and Quint Ketting. Powered by Atos.
AI Where It Matters, Not AI Everywhere — with Zeina Zakhour, Global CTO Cybersecurity at Eviden (Atos)Recorded live at CISO Day, this episode brings Menno van der Horst and co-host Quint Ketting together with Zeina Zakhour, Global CTO for Cybersecurity at Eviden (Atos), for a fast-moving conversation on where cyber is heading and what it really takes to keep up.We open with a sobering reality: many of today's threats are exposing weaknesses that have existed for decades. The panic isn't warranted — but action is. Zeina makes the case that the issue is rarely a lack of technology depth, but a lack of security depth: the basic hygiene and foundational controls that too many organisations still treat as something for "next year." Spoiler — next year is no longer an option.From there we get into the heart of it:— Adaptive, systemic resilience. Security can't be an afterthought bolted on once innovation ships. It has to sit at the core. We dig into why maturity built once and then left alone decays faster than most leaders expect.— Risk first, always. You don't secure a water utility the way you secure a hospital, a retailer or a bank. Every organisation has its own ecosystem and purpose — and that's where Eviden's Prepare, Respond, Adapt approach starts: understanding who you are, then keeping your risk picture live rather than buried in a spreadsheet updated once a year.— AI, agents and the new attack surface. Not "AI everywhere" — AI where the risk, the data and the friction justify it. We talk identity as the number one attack vector, the danger of human-led processes throttling machine-speed tooling, prompt and meta-prompt injection, agent goal drift, kill switches, and what "identity" even means for an autonomous agent that has intent, makes decisions and calls tools.— Chained vulnerabilities. Why "we'll only fix the high-severity CVEs" is the wrong instinct — low-severity issues can be chained into something genuinely exploitable, fast.— Sovereignty vs autonomy. A crucial distinction too many conflate. We get into data residency, technological sovereignty, the model/middleware/GPU reality of "sovereign AI" today, post-quantum, and why Europe can only answer these questions together rather than country by country.We close where good security conversations always seem to land: sharing more, building a bubble of trust, backing European innovation and startups, and staying agile enough to adapt as the ground keeps shifting.Zeina's recommendations: 📑 Atos Cyber Shield blog and Threat Research Center — regular, genuinely interesting analysis on new campaigns and malware variants. 📖 The Five People You Meet in Heaven by Mitch Albom — nothing to do with cyber, everything to do with being worth your time.🎧 Listen now, and let us know your take in the comments.#SecurityCafe #Cybersecurity #CISO #AISecurity #Resilience #DigitalSovereignty
loading
Comments