Cyber Security Sauna brings you expert guests with sizzling insight into the latest information security trends and topics. WithSecure’s Janne Kauhanen hosts the show to make sure you know all you need to about the hotter-than-ever infosec game. Join us as we sweat out the hot topics in security.
Cyber Security Sauna Cyber Security Sauna brings you expert guests with sizzling insight into the latest information security trends and topics. WithSecure’s Janne Kauhanen hosts the show to make sure you know all you need to about the hotter-than-ever infosec game. Join us as we sweat out the hot topics in security.
- 086| Why showing value is more important for CISOs than everby WithSecure™ on January 3, 2024 at 9:02 am
CISOs find themselves at the forefront of safeguarding sensitive information, ensuring regulatory compliance, and protecting their organizations from constantly evolving cyber risks. Today, we are joined by Cybersecurity Strategist and Eclipz.io Inc. CISO Matthew Rosenquist and WithSecure CISO Christine Bejerasco to discuss why making senior leadership and the board clear on the value that CISOs bring to the table.
- 085| NIST Cyber Security Framework V.2 – Help or Hindrance?by WithSecure™ on November 22, 2023 at 9:37 am
The NIST Cyber Security Framework has helped secure organizations for nearly a decade and while it’s proven to be an invaluable tool, it’s gotten a bit long in the tooth for a cyber security landscape that never stays static. Enter V.2 which goes a long way in identifying the increasing cyber risk in organizations and implementing more governance, oversight and senior leadership accountability. For this episode we were joined by very special guest Cybersecurity Strategist and Eclipz.io Inc. CISO, Matthew Rosenquist, and WithSecure CISO Christine Bejerasco to discuss if the new framework will be enough and whether it will help or hinder CISOs. Read more: https://www.withsecure.com/en/expertise/resources/navigating-nist-csf-2 Check out the recent webinar with Matthew Rosenquist and Christine Bejerasco for further discussions on the NIST Cyber Security Framework V.2.
- 084| Let’s Talk About Threats Babyby WithSecure™ on November 1, 2023 at 11:21 am
A successful cyber defense should protect an organization’s critical assets from today’s threats, not yesterday’s. For this episode, we sat down with threat intelligence analysts Stephen Robinson and Ziggy Davies, two such people responsible for keeping tabs on threats and recent developments, to discuss updates on the threats currently affecting organizations. Check out the latest insights from the WithSecure Countercept Threat Intelligence team. Read the report on the professionialization of cybercrime
- 083| Security by design for CISOsby WithSecure™ on October 9, 2023 at 8:00 am
The term Shifting Left has not been traditionally associated with cyber security. In this episode, WithSecure CISO Christine Bejerasco lays out the case for how shifting left can evolve beyond its origins in software development to be a powerful tool for successful security and business outcomes. Recorded on-site at #SPHERE23.
- 082| Hyped and Hacked – AI in Cyber Securityby WithSecure™ on September 20, 2023 at 9:57 am
As Mikko Hyppönen said recently, we are indeed in the midst of the hottest AI summer ever, and the hype level is off the charts. Yes, AI presents amazing opportunities, but unfortunately, also threats. Nowadays, practically anyone with a passing interest in using it has a lot of power at their fingertips – no PhD is necessary. Naturally, we must view all of this through the lens of the cyber security industry. We sat down with Ian Beacraft, Founder and Chief Futurist of Signal and Cipher, and Tom Van de Wiele, Principal Technology and Threat Researcher at WithSecure, to discuss if we are getting too worked up about AI and what it means for cyber defenders either way. Recorded on-site at #SPHERE23.
- 081| Mudge – the man, the myth, the mythbustingby WithSecure™ on August 28, 2023 at 8:55 am
We have the pleasure of being joined by the one and only Peiter “Mudge” Zatko, network security expert, open-source programmer, writer, and hacker, with a rapid-fire discussion on some myths in the cyber security industry that could do with busting, sprinkled with some truths that could do with trusting. This episode was recorded on-site at #SPHERE23.
- 080| The Power Of Putting Security Outcomes Firstby WithSecure™ on August 7, 2023 at 7:33 am
As security is primarily about stopping bad things from happening, victories are often silent. At the same time, failures are often very public, so how can organizations tell when their security is paying off? In this episode, we are joined by guest speaker Laura Koetzle, Vice President and Group Director at Forrester and Robin Oldham, CEO of consulting firm Cydea, to discuss assessing the value of a result that produces nothing. Recorded on-site at #SPHERE23.
- 079|(Mind the) Detection and Response Gapby WithSecure™ on July 17, 2023 at 10:53 am
The time that an attacker spends on a network before attempting to achieve their objective is decreasing rapidly, making many organizations’ typical detection and response solutions ineffective. Speed is the key, but unfortunately the gap between detection and response is growing. In this episode, we are joined by WithSecure’s Threat Hunter Jojo O’Gorman and Principle Incident Response Consultant Mehmet Surmeli to discuss what we can do to solve these challenges. Read more >> https://www.withsecure.com/en/expertise/resources/how-to-identify-your-response-gaps?utm_source=libsyn&utm_medium=podcast&utm_campaign=gl-pr-response-gap-tool Check out our Response Gap Assessment tool >> https://www.withsecure.com/en/solutions/incident-readiness-and-response/identify-your-response-gap?utm_source=libsyn&utm_medium=podcast&utm_campaign=gl-pr-response-gap-tool
- 078| John Grant on the relationship between sustainability and cyber securityby WithSecure™ on June 26, 2023 at 8:21 am
The development of new sustainable technologies undoubtedly benefits society, but it also opens the door to new cyber security challenges. For this episode, we were on-site at SPHERE23 with author John Grant to discuss the challenges for organizations to be sustainable and secure.
- 077| Jessica Berlin and Stephen Robinson on the cyber frontby WithSecure™ on June 6, 2023 at 1:55 pm
Russia’s invasion of Ukraine changed the entire geopolitical landscape. For this episode, we were on-site at SPHERE23 with security and foreign policy analyst Jessica Berlin, and threat intelligence analyst Stephen Robinson, to discuss the use of cyber attacks and disinformation as policy instruments in the wake of the invasion.
- 076| What we get wrong (and right) about APTsby WithSecure™ on May 8, 2023 at 8:17 am
Advanced persistent threats, or APTs, are generally seen as a sort of apex predator in the cyber threat landscape. And while they’re certainly noteworthy, their reputation can distort what makes them unique, and what they may have in common with other adversaries. In this episode, we’re joined by Senior Threat Intelligence Analyst Stephen Robinson, and Security Consultant Richard Suls, to shed some light on APTs and how we can protect ourselves against them. Read more:https://labs.withsecure.com/publications/no-pineapple-dprk-targeting-of-medical-research-and-technology-sector
- 075| Winning with outcome-based securityby WithSecure™ on April 4, 2023 at 10:54 am
Security protects organizations from cyber attacks. However, studies show that limiting your understanding of security to this basic premise can hinder protection efforts or even other business goals. Instead of spending more and more on security to simply keep things running, maybe it’s time for a different approach. In this episode, we are joined by WithSecure Chief Information Security Officer Christine Bejerasco, and guest speaker Laura Koetzle, Vice President and Group Director at Forrester to discuss a strategy called outcome-based security.
- 074| Do you even patch bro?by WithSecure™ on March 7, 2023 at 10:54 am
Vulnerabilities and security gaps are increasingly being identified in software and applications daily. Attackers are often quick to act when any vulnerabilities are made known – even within minutes. You may have heard of the term patching in cyber security, but what is it exactly, and how does it figure into an organization’s security posture? WithSecure security consultants Katie Inns and Antti Laatikainen join us to discuss all things patching.
- 073| 2023 – Looking Forwardby WithSecure™ on February 1, 2023 at 9:18 am
In our last episode, we were joined by cyber security advisor Paul Brucciani and WithSecure Intelligence Researcher Andy Patel to discuss some notable 2022 infosec developments. Now that 2022 is in the rear-view mirror, all eyes are turning to the year ahead. What should we expect? Is there some disaster on the horizon for which we need to prepare? Conversely, are there any positive devlopments that we can look forward to? We’re once again joined by Paul and Andy to discuss some of the trends we should look out for in 2023.
- 072| 2022 Wrap-Upby WithSecure™ on January 1, 2023 at 11:00 am
As the year draws to a close, it’s time for us to review and reflect on notable infosec events and trends from 2022, and also what might happen in 2023. In this episode we’re joined by cyber security advisor Paul Brucciani and WithSecure Intelligence Researcher Andy Patel to hear their thoughts on the impact of Russia’s invasion of Ukraine on cyber security, what they think about the changes at Twitter, and other significant developments from the last 12 months.
- 071| Deepfakin it: AI content in cyber attacksby WithSecure™ on December 5, 2022 at 1:14 pm
Until recently, AI-generated synthetic content has been more commonly used for gaming and art creation, where the tech is still relatively new, and pixel perfection is unnecessary. However, with the tech rapidly advancing in complexity and speed, it’s probably only a matter of time before it’s genuinely challenging to determine if something is fake or not. Unfortunately, this increase in technology will also provide many avenues for disinformation and other assorted nefariousness. Digital artist and YouTuber Nerdy Rodent and WithSecure Researcher Andy Patel join is to discuss how the technology is developing and its possible implications, good and bad.
- Cyber Security Sauna: Breaking Views – The Vastaamo caseby WithSecure™ on November 9, 2022 at 11:14 am
In this Cyber Security Sauna special edition podcast, we cover new developments in the data breach of Finnish Psychotherapy provider Vastaamo in 2020. This case has recently hit the news again, with the Finnish authorities arresting a suspect in absentia. The suspect in the breach and subsequent leaking of patient data is a 25-year-old Finnish citizen. Officials believe he is at large somewhere in Europe. Neglect by Vastaamo system administrators prior to the incident has also been called out by officials and cyber security experts. Cyber Security Sauna host Janne Kauhanen is joined by WithSecure™ CRO Mikko Hypponen and CISO Erka Koivunen to discuss the history of the attack, what possibly drove the subject to the dark side, and the ethics of securing data within a fast-growing company.
- 070| Crowdsourcing Security with Bug Bountiesby WithSecure™ on November 2, 2022 at 7:49 am
Bug bounties (also known as vulnerability reward programs) crowdsource security expertise to address vulnerabilities in products or services before attackers exploit them. Many companies have adopted reward programs and sometimes offer hefty rewards for finding vulnerabilities. It’s a great way for white hat hackers to make some money and showcase their talents for a possible job, and for companies to improve their security. In this episode, we’re joined by Intigriti’s Head of Hackers, Inti De Ceukelaire, a bug bounty expert that connects organizations with the ethical hacking community, and WithSecure’s Chief Information Security Officer Erka Koivunen. https://www.intigriti.com/
- 069| Cyber conflicts, Corporations and Collateral damageby WithSecure™ on October 3, 2022 at 10:30 am
Geo-political conflicts are increasingly being played out in cyberspace, and organizations, whether they are aware or not, are often caught in the crossfire. Janne Taalas and Johannes Laaksonen from CMI – Martti Ahtisaari Peace Foundation and WithSecure™ Chief Technology Officer Christine Bejerasco joined us to discuss how we can resolve these conflicts and try to make cyberspace a safer place for everyone. CMI – Martti Ahtisaari Peace Foundation
- SPHERE SESSION | Johanna Småros on winning the algorithmic retailby WithSecure™ on September 26, 2022 at 8:07 am
Co-founder & CMO at RELEX Solutions, Johanna Småros, joined us in our cyber sauna recording booth at SPHERE22, the world’s first co-security unconference, for a discussion on supply chain management, both in retail and in a broader aspect.
- SPHERE SESSION | Matthew Rosenquist on why value is the cybersecurity blindspotby WithSecure™ on September 13, 2022 at 6:44 am
CISO and cybersecurity Strategist, Matthew Rosenquist, joined us in our cyber sauna recording booth at SPHERE22, the world’s first co-security unconference, for a discussion on why we should aim to maximise value in cybersecurity.
- 068|The other TTPs: Tools, technologies, and peopleby WithSecure™ on September 7, 2022 at 7:20 am
In this episode, we’re joined by Frank Fransen, Senior Scientist in Cyber Security at TNO, and Technical Coordinator of the EU’s SOCCRATES project, which is developing a new cybersecurity-oriented decision-making platform, and John Rogers, Global Head of Incident Response for WithSecure™, to discuss the role automation can and should play in cyber defenses. SOCCRATES website https://www.soccrates.eu/ SOCCRATES final event: ‘Innovation for Next Generation SOCs’ is on 19 October 2022ools, technologies, and people SOCCRATES final event: ‘Innovation for Next Generation SOCs’ – Soccrates SOCCRATES Vision Paper https://www.soccrates.eu/wp-content/uploads/2022/05/SOCCRATES-Vision-Paper.pdf
- SPHERE SESSION | Sari Stenfors on AI, humanness and positive futuresby WithSecure™ on August 19, 2022 at 8:33 am
Serial entrepreneur, scientist and futurist, Sari Stenfors, joined us in our cyber sauna recording booth at SPHERE22, the world’s first co-security unconference, for a discussion on the importance of looking to the future with a positive mindset.
- SPHERE SESSION | Risto Siilasmaa on trust as the building block for businessesby WithSecure™ on August 9, 2022 at 8:09 am
Chairman and Founder of F-Secure & WithSecure, Risto Siilasmaa, joined us in our cyber sauna recording booth at SPHERE22, the world’s first co-security unconference, for a discussion on why trust is the foundation upon which successful and meaningful business partnerships are formed.
- SPHERE SESSION | Christine Bejerasco on the development of ransomwareby WithSecure™ on July 29, 2022 at 8:42 am
WithSecure CTO, Christine Bejerasco, joined us in our cyber sauna recording booth at SPHERE22, the world’s first co-security unconference, for a discussion on how she has seen the development of ransomware families throughout her career.
- 067| How Mikko Hypponen learned to stop worrying and love the internetby WithSecure™ on July 14, 2022 at 6:10 pm
Mikko Hyppönen is one of the world’s most renowned cyber security experts and has investigated cybercrime for over 25 years. From the days of naughty, nuisance, but ultimately harmless viruses to the very serious cyber threats society faces today, he’s seen it all. In addition to his many accomplishments, he is also an author, and he dropped in to discuss the English-language release of his book “If It’s Smart, It’s Vulnerable”.
- SPHERE SESSION | Simone Giertz on building useless thingsby WithSecure™ on July 11, 2022 at 8:24 am
Swedish inventor and world-famous YouTuber, Simone Giertz joined us in our cyber sauna recording booth at SPHERE22, the world’s first co-security unconference, for a discussion about building useless things, and if they are actually useless…
- SPHERE SESSION | Carole Cadwalladr on threats to democracyby WithSecure™ on June 30, 2022 at 10:56 am
TED speaker and Pulitzer-nominated journalist Carole Cadwalladr joined us in our cyber sauna recording booth at SPHERE22, the world’s first co-security unconference, for a discussion about threats to democracy.
- SPHERE SESSION | Philip Ingram on nation-state threatsby WithSecure™ on June 13, 2022 at 6:24 pm
Spymaster-turned-journalist Philip Ingram joined us in our cyber sauna recording booth at SPHERE22, the world’s first co-security unconference, for a quick chat about nation-state threats.
- 066| Co-security: collaboration, cooperation and cyber securityby WithSecure™ on April 5, 2022 at 10:41 am
There’s many different ways to collaborate on infosec problems. There’s no shortage of associations, conferences, and other frameworks that organizations can use to find others to work with. And there’s a healthy supply of security companies to choose from. But do any of these offer concrete benefits to organizations? Will organizations somehow achieve better outcomes by working with others? Or is it more complicated than that? Today, we’re joined by UK-based Julia Ward, WithSecure’s Principal Client & Markets Liaison, and Tom Van de Wiele from Denmark, a former red teamer and current Principal Threats and Technology Researcher for WithSecure™, to hear more about cooperative approaches to security.
- 065| Security for non-profit organizationsby WithSecure™ on February 28, 2022 at 1:12 pm
Non-profit organizations play a crucial role in our well-being. In many parts of the world, they’re a major source of education, health care, social services, and more. And while they’re not in it for the money, they remain a target for cyber attacks, just like other organizations. Why is this case? What can and should be done about this? In this episode, Adrien Ogee, Chief Operating Officer for the CyberPeace Institute, a non-governmental organization that helps defend the security, dignity, and equity of people in cyber space; and Heikki Stark, a security consultant with F-Secure who recently won an award for his work with the KyberVPK Community Cyber Response Force, which helps providers of critical services fight and recover from cyber attacks, gave us their thoughts on how NPOs can and should tackle the challenges they face in cyber security.
- 064| 2021, 2022 and beyond – Part 2by F-Secure on January 24, 2022 at 1:28 pm
With 2021 now behind us, it’s time to revisit the highs and lows of the past 12 months, and look ahead to what we can expect in the months ahead. To mark the year’s end, we recorded a special two-part episode of Cyber Security Sauna. F-Secure’s Chief Research Officer Mikko Hypponen, Security Consultant Adriana Verhagen, and AI researcher Andy Patel join episode 64 to share their key takeaways from 2021, and thoughts on important issues we’ll face in 2022 and beyond. In this episode: regulating social media networks, cloudification, AI-powered attacks, security in an age of unlimited computing power, NFTs, and more. Links: Episode 64 transcript
- 063| 2021, 2022 and beyond – Part 1by F-Secure on December 29, 2021 at 12:40 pm
2021 is drawing to a close, and it’s time to look back on the events of the past year. At the same time we look ahead to the brand new year to come. Welcome to part one of a special two-part episode of Cyber Security Sauna. In this episode we’re joined by F-Secure’s Chief Research Officer Mikko Hypponen, Security Consultant Adriana Verhagen, and AI researcher Andy Patel, to hear their key takeaways from 2021, and thoughts on important issues we’ll face in 2022 and beyond. In this episode: cyber security and the board, how companies are doing at integrating security into the business, what a Metaverse could mean, cyber crime unicorns, machine learning in attacks, the future of programming, and more. Links: Episode 63 transcript
- 062| Log4j Zero Day: What It Means for Your Orgby F-Secure on December 14, 2021 at 4:41 pm
The remotely exploitable Log4j zero day vulnerability disclosed just a few days ago has been called one of the most serious vulnerabilities to date. So what is it all about, and what does it mean for organizations? How is it being exploited? What are the risks, and what can you do if you’re waiting for a patch? F-Secure CISO Erka Koivunen joins Janne to break down the issue, and explains why this vulnerability should be a wakeup call for security practitioners and developers. Links: Episode 62 transcript How attackers are trying to exploit Log4Shell
- 061| AppSec, According to Two Guys Named Anttiby F-Secure on November 24, 2021 at 6:35 pm
The topic of application security has never been more important. So how are companies approaching appsec? What should companies do to ensure appsec gets the attention it needs? Antti Tuomi, who works in Japan, and Antti Vaha-Sipila (known as AVS), from Finland, join the show to share their thoughts on changes in application security, shifting left, supporting developers, “level boss testing,” and much more. Links: Episode 61 transcript
- 060| Biometrics: Privacy, Problems and Possibilitiesby F-Secure on November 2, 2021 at 7:55 pm
Biometrics have gotten a lot of attention in recent years. Biometric authentication systems have the potential to take the place of passwords, streamlining the user login experience. But there are a lot of considerations before taking these systems into use. When should they be used, and how? What are the risks, and when should biometrics be approached with skepticism? Security expert Vic Harkness and red teamer Tom Van de Wiele join Janne to talk about the advantages and disadvantages of biometric authentication systems, some of the wackiest ways our bodies can be measured, and why layered security still works best. Links: Episode 60 transcript Top 10 Bogus Biometrics – Vic Harkness – DEFCON 29 Rogues Village
- 059| Keeping Your Latest Tech from Becoming the Latest Threatby F-Secure on October 11, 2021 at 7:15 pm
Cyber crime is a constantly evolving game. As soon as new technology is introduced, attackers start figuring out how to exploit it for malicious purposes. No one understands this better than F-Secure Chief Technology Officer Christine Bejerasco. Christine joins Janne to discuss the changing world of cyber crime, and how companies can avoid having their new technologies exploited by taking a secure-by-design approach. Links: Episode 59 transcript
- 058| Paths to Infosec: From ER to IRby F-Secure on September 20, 2021 at 7:38 pm
Data breaches and other security incidents have become a frequent, severe problem for organizations. But with incident responders in short supply, there are fewer professionals available to help organizations in their hour of need. We’re joined this episode by F-Secure incident response consultant Eliza Bolton, who successfully transitioned to cybersecurity from the nursing profession, and F-Secure’s head of incident response, Matt Lawrence. Matt and Eliza share their views on tackling the cyber skills shortage, why diverse teams are more adaptable, and why Eliza’s background as a nursing assistant is an asset in the world of incident response. Links: Episode 58 transcript F-Secure Consulting UK Associate Scheme