Podcast charts
Published by Threat Talks
Threat Talks is your cybersecurity knowledge hub. Unpack the latest threats and explore industry trends with top experts as they break down the complexities of cyber threats. We make complex cybersecurity topics accessible and engaging for everyone, from IT professionals to every day internet users by providing in-depth and first-hand experiences from leading cybersecurity professionals. Join us for monthly deep dives into the dynamic world of cybersecurity, so you can stay informed, and stay secure!
On the charts
Every published chart this podcast appears in, in the snapshot behind this page. Each one links to the chart it came off.
From the feed
The latest episodes published to this podcast’s own RSS feed. Titles and descriptions are the publisher’s.
Your Outlook account recovery will accept an authenticator code on its own. No password, no inbox, no phone number. Anyone holding that TOTP secret owns the account, and the second factor you bought to survive credential theft becomes the only thing in the way. Koen Kandelaars found one sitting in a PDF on a public help page at the NOS, the largest news organization in the Netherlands. He scanned a QR code out of an onboarding manual and had a real employee's second factor on his phone. Rob Maas, Field CTO at ON2IT, walks the full chain with the attacker himself: eleven vulnerabilities in the first responsible disclosure, a twelfth Koen estimates at 1 to 5 million euros, and the recovery flow nobody tested. Timestamps (00:00) - MFA was on. He got in anyway. (02:04) - Why the biggest news organization became the target (03:24) - Mapping the attack surface before touching anything (04:54) - Eleven findings in the first responsible disclosure (08:50) - The Media Cloud help page and the live TOTP QR code (11:19) - How the password reset removes your second factor (14:29) - The 1 to 5 million euro estimate, and what to fix Key Topics Covered Attack surface discovery against a large public broadcaster Responsible disclosure done well: response time, remediation, and recognition Where the next generation of defenders comes from, and how they choose a side Related ON2IT Content & Referenced Resources: Threat Talks: https://threat-talks.com/ ON2IT (Zero Trust as a Service): https://on2it.net/ AMS-IX: https://www.ams-ix.net/ams
You already had the threat intel. The IP was on your blocklist, the file hash was known bad. So why did your MDR only raise an alert instead of blocking it? Lieuwe Jan Koning, Co-founder & CTO at ON2IT, and colleague Nicholai Piagentini, Technical Enablement Engineer at ON2IT, make the case for preemptive cybersecurity: the shift from detect-and-clean-up to block-first, and what it means for the future of MDR. Timestamps: (00:00) - Preemptive cybersecurity: what it means for MDR (00:59) - Why detect-and-clean-up is not enough (the leaking tap) (01:42) - You knew the threat: block first (03:34) - Fusing the SOC and operations teams (05:57) - Speed, seconds, and AI versus AI (08:15) - Data freedom and vendor lock-in (10:33) - Dynamic policy without breaking change control Key Topics Covered: Preemptive cybersecurity as the Gartner-flagged direction, and why MDR has to move past detect-and-respond Turning known indicators of compromise into automated blocks at the endpoint, network, and cloud Collapsing the SOC and operational teams so detection and enforcement act as one Sub-second response, AI-driven attacks, and why MTTD and MTTR need to converge Data freedom and data sovereignty, and avoiding vendor cloud lock-in Related ON2IT Content & Referenced Resources: Threat Talks website: https://threat-talks.com/ ON2IT (Zero Trust as a Service): https://on2it.net/ AMS-IX: https://www.ams-ix.net/ams
The new NIST Cybersecurity Framework 2.0 is out, and most teams still ask the same question: what do I do tomorrow? Lieuwe Jan Koning sits down with NIST's Amy Mahn and Daniel Elliott to turn the framework into a concrete next step. Governance is now its own function. Profiles tell you where you are and where you need to be. And the Quick Start Guides give a 15-page answer to a problem most people think needs 300 pages. If you run security with limited resources, this episode shows you where to start and why the whole thing is free. Timestamps 00:00:00 The framework changed. What do you do tomorrow? 00:02:00 Why Govern became its own function 00:05:49 Profiles: current state, target state, gap analysis 00:08:08 Community profiles: sharing across a sector 00:10:29 Quick Start Guides and mappings to ISO 27001, SOC 2, HIPAA 00:14:24 No CISO? Where small businesses start 00:17:50 The future of CSF and how to contribute Key Topics Covered Why governance moved out of "Identify" and became its own function in CSF 2.0, and what that signals about cyber risk at board level. How organizational and community profiles turn the framework into a current-state, target-state, and gap analysis you can act on. Why CSF 2.0 stopped being a single PDF and became guides, spreadsheets, mappings, and search tools. How CSF maps to ISO 27001, SOC 2, and HIPAA so you report once instead of many times. Where a small business or an IT manager wearing every hat should actually begin. Related ON2IT Content & Referenced Resources: NIST Cybersecurity Framework 2.0: https://www.nist.gov/cyberframework NIST CSF Quick Start Guides: https://www.nist.gov/cyberframework/quick-start-guides National Cybersecurity Center of Excellence (NCCoE): https://www.nccoe.nist.gov/ NIST CSF contact: csf@nist.gov Threat Talks website: https://threat-talks.com/
Running a SOC was always hard. With AI in attackers' hands, hard becomes impossible, unless you change how you work. Rob Maas, Field CTO at ON2IT, sits down with Lieuwe Jan Koning, Co-founder & CTO at ON2IT, on why detection and response no longer buys you time. Open-source AI now finds a way into a portal in about 15 minutes, no pentester required. The fix is preemptive cybersecurity: prevention first, automated countermeasures, and a zero trust culture that turns your SOC from analyst-driven to software-driven, with the analyst still in the driver's seat. Timestamps: 00:00:00 When hard becomes impossible 00:01:37 The biggest change in SOC history 00:05:16 What attackers can now do with AI 00:08:13 Why patching can't be your core defense 00:11:58 The analyst becomes the quality gate 00:13:11 Preemptive cybersecurity, explained 00:24:33 Advice for SOC managers
Salesforce, Google, Okta, Louis Vuitton, Allianz, Odido: all breached under the same name. Shiny Hunters may not even be one group. It is a brand that different criminal crews borrow to extort their victims, because the reputation does half the work. The uncomfortable part is how simple it is. No fancy malware, no zero-days. Almost every documented breach started with a phishing call to the help desk, over-permissive credentials, and data copied straight out of a SaaS platform. Host Lieuwe Jan Koning, Co-founder & CTO at ON2IT, sits down with Field CTO Rob Maas and ON2IT researcher Yuri Witt to trace how these attacks land, why the attacker's name never matters to your defense, and the basic controls that stop them: multi-factor authentication, IP access control on your SaaS tenants, no over-permissive accounts, and deleting the toxic data you no longer need. If you run SaaS at scale, treat this as a checklist for the controls most teams still have not switched on. Charpters: 00:00:00 One name behind a dozen mega-breaches 00:01:06 Shiny Hunters: a group, or a brand? 00:04:16 The leak site: extortion as a marketplace 00:05:37 How they get in: phishing the help desk 00:07:54 Basic defenses: MFA, no admin rights, block downloads 00:09:36 Pay up or we leak: the Odido case 00:11:24 Lock down SaaS, delete toxic data, and Zero Trust
The hacker who will attack your organization in five years is in school right now, and nobody is teaching that kid what to do online. HackShield is trying to change that. Lieuwe Jan Koning, Co-founder & CTO at ON2IT, sits down with Tim Murck, co-founder of HackShield, on why security awareness training for adults keeps failing, and what a game built for seven to twelve year olds can teach every CISO about human risk. If your plan is to train 2,000 people to never click the wrong link, this is the episode that explains why you have already lost, and what to do instead.
The hacker who will attack your organization in five years is in primary school right now, and nobody is teaching them anything. Tim Murck, Co-founder & Chief Product Officer at HackShield, joins Lieuwe Jan Koning, Co-founder & CTO at ON2IT, to explain how a game turns kids aged 7 to 12 into junior cyber agents instead of future attackers. The method is not fear. It is teaching kids to ask one question: how are they going to trick me? 🔗 Episode resources, transcript and show notes: https://threat-talks.com 📝 Read the companion blog post: https://threat-talks.com/the-hacker-wholl-hit-you-in-5-years-is-in-school/ 🎙️ Subscribe on Spotify and Apple Podcasts, links below. Threat Talks is a podcast by ON2IT cybersecurity and AMS-IX. We delve deep into the dynamic world of cybersecurity, one episode at a time. New episode every Tuesday. #ThreatTalks #ZeroTrust #cybersecurity #hackshield #securityawareness #cybereducation #kidsonlinesafety Charpters: 00:00:00 The hacker who will attack you is in school now 00:00:27 From actor to HackShield: meet Tim Murck 00:02:00 The mission: digital scouting for kids 7 to 12 00:03:53 Junior cyber agents and the Dutch police 00:05:26 Inside the HackShield universe 00:10:02 Adversarial thinking and the grooming theme 00:13:35 Why age 7 to 12, and the school system's blind spot 00:14:53 Ban phones, or teach kids to swim? 00:18:42 The numbers: half a million Dutch kids, 850,000 worldwide
What if AI stopped being the assistant to cybercriminals and became the attacker itself? That's no longer hypothetical. JADEPUFFER is the first documented case of ransomware run entirely by an AI agent: it broke into a production database, hit a wall mid-attack, then found another way in within 31 seconds, faster than most human penetration testers can react. Rob Maas, Field CTO at ON2IT, sits down with Yuri Wit, SOC DevOps Engineer at ON2IT, to trace how agentic malware evolved out of AI-assisted attacks into a threat that plans, executes, and pivots entirely on its own. 🔗 Episode resources, transcript and show notes: https://threat-talks.com 📝 Read the companion blog post: 🎙️ Subscribe on Spotify and Apple Podcasts, links below. Threat Talks is a podcast by ON2IT cybersecurity and AMS-IX. We delve deep into the dynamic world of cybersecurity, one episode at a time. New episode every Tuesday. #ThreatTalks #ZeroTrust #firewallsecurity #NetworkSecurity #CyberSecurity #infosec Charpters: 00:00:00 Cold open: can AI become the attacker? 00:01:42 PromptLock and PromptSteal: proof of concept to real world 00:04:24 The agentic malware trend and the local LLM question 00:07:24 JADEPUFFER: ransomware run entirely by an AI agent 00:09:58 Proof of concept, or a live-fire test? 00:11:30 Intent-driven attacks and shrinking detection windows 00:16:34 Zero Trust: what to do about it starting now 🔔 Follow and Support our channel! 🔔 === ► YOUTUBE: https://youtube.com/@ThreatTalks ► SPOTIFY: https://open.spotify.com/show/1SXUyUEndOeKYREvlAeD7E ► APPLE: https://podcasts.apple.com/us/podcast/threat-talks-your-gateway-to-cybersecurity-insights/id1725776520 👕 Receive your Threat Talks T-shirt https://threat-talks.com/ 🗺️ Explore the Hack's Route in Detail 🗺️ https://threat-talks.com 🕵️ Threat Talks is a collaboration between @ON2IT and @AMS-IX
Three out of four firewall rule sets ON2IT’s SOC inherits from new customers share the same blind spots, and none of the fixes cost extra licensing. In this episode, Lieuwe Jan Koning, Co-founder & CTO at ON2IT, sits down with Jelle Konings, security optimization specialist in ON2IT’s Security Operations Center, to walk through the mistakes his team finds on almost every inherited network: no logging enabled, no identity tied to traffic, no default deny rule at the bottom of the rule base, and port-based rules standing in for real application control. Most environments he inherits sit around 30 to 40 percent application-based policy coverage against a 60 to 80 percent target. You will hear what to check first when you inherit a firewall, how long a realistic clean-up takes (weeks, months, sometimes over a year), and why an encrypted VPN tunnel riding on port 443 can move data out the door without a single alert firing. 🔗 Episode resources, transcript and show notes: https://threat-talks.com 📝 Read the companion blog post: https://threat-talks.com/blog/four-firewall-mistakes-still-wrecking-networks-in-2026/ 🎙️ Subscribe on Spotify and Apple Podcasts, links below. Threat Talks is a podcast by ON2IT cybersecurity and AMS-IX. We delve deep into the dynamic world of cybersecurity, one episode at a time. New episode every Tuesday. #ThreatTalks #ZeroTrust #FirewallSecurity #NetworkSecurity #CyberSecurity #InfoSec Chapters: 00:00 Cold open: the top firewall mistakes of 2025 00:21 Meet Jelle Konings, security optimization specialist 01:16 Mistake 1: No visibility into your network 03:36 Mistake 2: Skipping User-ID mapping 06:01 Mistake 3: No default deny rule 07:44 Fixing it: from logs to default deny 09:09 Bonus mistake: port-based vs. application-based rules 13:20 Will 2026 be any different?
Would you still use ChatGPT if your boss, or the AI provider, could read every single prompt you typed in? Most of us type something we would never share publicly into an AI tool every day. In this Threat Talks Deep Dive, Field CTO Rob Maas sits down with ON2IT senior developer Derk Bell to unpack the privacy problem hiding inside everyday AI use, and a genuinely clever way to solve it. The problem is bigger than a single prompt. An AI request carries far more context than a Google search: your conversation history, your files, and (with agents and MCP) automatic, autonomous access to your CRM, your email, your calendar and your codebase. A lot of that data is shipped off to a remote provider, often without you realizing it. Today we just trust those providers not to misuse it. As Derk points out, “trust us” is the exact opposite of Zero Trust: never trust, always verify. So how do you verify? Derk walks through Confer, the privacy-first AI service from Signal Protocol co-creator Moxie Marlinspike. Using the analogy of a tamper-proof, locked calculator box for an “anonymous” employee survey, he explains how Confer lets you actually check the wiring: a hardware Trusted Execution Environment that isolates and encrypts the running program, remote attestation that lets you verify the exact open-source code handling your prompt, a Signal-style encrypted channel to talk to it, and hardware-bound keys that are thrown away the moment your session ends, so even the operator can never read your data. We close on who needs this most (developers protecting trade secrets, executives working on M&A or strategy, and anyone bound by GDPR) and whether the big AI labs will adopt this the way the whole industry adopted Signal. The takeaway: privacy and powerful AI do not have to be a trade-off. “Trust us” was never a security strategy. 🔗 Episode resources, transcript and show notes: https://threat-talks.com 📊 Grab the infographic referenced in the episode in the show notes to follow the technical steps. 🎙️ Subscribe to the podcast on Spotify, Apple Podcasts, or your podcast app of choice. Threat Talks is a podcast by ON2IT cybersecurity and AMS-IX. We delve deep into the dynamic world of cybersecurity, one episode at a time. New episode every Tuesday. Chapters: 00:00 Would you still use ChatGPT if your boss read every prompt? 01:00 Why AI is different from a Google search: context 02:08 "Trust us" and why that is the opposite of Zero Trust 03:22 It gets worse: AI agents, MCP and autonomous access 05:52 Enter Moxie Marlinspike, Signal, and Confer 06:30 The analogy: an "anonymous" employee survey in a locked box 10:16 Inside Confer: the TEE, attestation and the encrypted channel 14:21 End the session, throw away the keys 16:08 Who needs this? Developers, executives, GDPR-bound teams 18:29 Wrap-up: privacy and powerful AI can coexist
Ten years after its first release, the NIST Cybersecurity Framework got a full rebuild. Not because it failed, but because everyone started using it, and it was never built for everyone. In this episode, host Lieuwe Jan Koning talks with Amy Mahn, IT Standards Advisor at NIST, and Daniel Eliot, Lead for Small Business Engagement at NIST’s Applied Cybersecurity Division, about what CSF 2.0 actually changes and why it took a multi-year public process to get there. The original framework was written with critical infrastructure operators in mind. A decade later, hospitals, school districts, and small businesses were all using it too, often without the staff or budget the framework quietly assumed they had. NIST collected more than 4,000 comments from organizations across over 100 countries to find out what was missing. The result includes a new Govern function that puts cybersecurity risk decisions in front of leadership and the board, a deliberately technology agnostic and vendor agnostic design that keeps the framework useful no matter which tools an organization runs, a Quick Start Guide aimed at organizations without a dedicated security team, and a sharper focus on supply chain risk. Amy and Daniel also explain why “vendor agnostic” is a feature, not a gap: it’s what lets an organization decide for itself who or what is best suited to close a given risk, instead of a framework quietly picking winners. Part 2, “CSF 2.0: Beyond the Framework,” continues the conversation and covers implementation in practice. Threat Talks is a podcast by ON2IT cybersecurity and AMS-IX. New episode every Tuesday. Follow Threat Talks to stay up to date on the topic of cybersecurity. Chapters: 00:00 Framework fatigue, the problem NIST heard 01:12 Welcome to Threat Talks 02:05 Meet Amy Mahn and Daniel Eliot (NIST) 03:40 What the original CSF got right, and where it broke down 07:15 Four thousand comments, one framework 10:30 The new Govern function 14:05 Why CSF 2.0 is technology agnostic and vendor agnostic 17:20 The Quick Start Guide for teams without a security team 20:10 Supply chain risk gets its own seat at the table 22:45 What Part 2 will cover 24:48 Closing thoughts
Agentic AI is powerful, and someone recently found that out the hard way when an AI tool, given free rein with a user’s own permissions, deleted her entire mailbox. That cautionary tale opens this Threat Talks Deep Dive, where host Lieuwe Jan Koning talks with Rob Maas, Field CTO of ON2IT, about what Zero Trust looks like when the thing you’re securing is an AI agent. Drawing on Rob’s recent blog post (and the Zero Trust pillars shared by CISA and Forrester’s Zero Trust eXtended framework), they work through each pillar in turn. The recurring theme is “just-in-case” privileges: the broad access we hand humans on the assumption they’ll use judgment. Agents have no such judgment. Give one an intent and it will use everything it has to reach the goal, and it can spin up parallel instances to get there faster. Across Identity, Devices, Network, Applications & Workloads, and Data, Rob makes the case for: Non-human identities with just-in-time, quickly-rotated privileges, so a leaked token can’t be reused forever. Tightly constrained execution environments (VM, container, serverless) that only touch what the agent truly needs. Identity-based network segmentation, so an agent working with CRM data can never reach the financial system. Allow-listed MCP tooling, because tool sprawl is the new shadow IT. New data controls for a world where everything (prompts, retrieval, documents) is data flowing to and from a model. He’s candid about the gaps, too: there’s no generic “AI firewall” yet, prompt injection has no guaranteed fix, and the hardest control points now live in the details of how individual developers configure their tools. The optimistic note: because agent-to-model and agent-to-agent calls can be logged, you can actually see what an agent is doing, an advantage over the opacity of the human mind. The episode closes on what’s still missing and a clear first step for any organization: get an overview of every agent and MCP server in use, and the access each one has. Threat Talks is a podcast by ON2IT cybersecurity and AMS-IX. New episode every Tuesday. Follow Threat Talks to stay up to date on the topic of cybersecurity.
Mythos found a 23-year-old vulnerability in FreeBSD that no human team had caught. Your 30-day patch cycle assumes years before it gets weaponized. Today that window is one day. Next year it will be one hour. Lieuwe Jan Koning, Co-founder & CTO at ON2IT, sits down with Rob Maas, Field CTO at ON2IT, to break down what Anthropic's Mythos actually found, why the public release (Fable) still frustrates security professionals, and whether the FABLE framework gives defenders a realistic path forward. Rob's verdict: there is truth in what Anthropic claims. It is not as catastrophic as the marketing suggests. But if your fundamentals are not in place, the time to fix that is now. 00:00:00 Introduction 00:00:46 What is Mythos? From Project Glasswing to Fable 00:03:13 What Mythos actually found: FreeBSD, Palo Alto, real patches 00:05:57 The zero-day clock: from years to one hour 00:09:00 The FABLE framework and the CSA "Mythos Ready" paper 00:15:24 Authentication, segmentation, and egress filtering 00:20:51 Myth or reality: Rob's verdict Subscribe to Threat Talks and turn on notifications for deep dives into the world's most active cyber threats and hands-on exploitation techniques. 🔔 Follow and Support our channel! 🔔 === ► YOUTUBE: / @threattalks ► SPOTIFY: https://open.spotify.com/show/1SXUyUE... ► APPLE: https://podcasts.apple.com/us/podcast... 👕 Receive your Threat Talks T-shirt https://threat-talks.com/ 🗺️ Explore the Hack's Route in Detail 🗺️ https://threat-talks.com 🕵️ Threat Talks is a collaboration between @ON2IT and @AMS-IX
Every big nation state has a cyber army: China, Russia, the US, Europe. But what about Iran? Meet Boggy Serpens, a group tied to Iran’s civilian intelligence service whose entire business is breaking in and staying in, then handing the keys to whoever strikes next. Their playbook, Operation OLALAMPO, needs just one booby-trapped Word document to plant three separate backdoors on your network. A Telegram-bot command channel that hides inside everyday encrypted chat traffic, a Rust “Ghost” backdoor built to defeat analysis, and a legitimate AnyDesk install quietly turned against you. The layered defense for every stage: email and file controls, behavioral EDR, egress policy, threat intel, and Zero Trust segmentation. The twist: why this operation mostly failed, plus the tells that the malware was partly written with AI. Filmed live at the ON2IT SOC, host Lieuwe Jan Koning runs a red team vs blue team session with analysts Yuri Wit, the “proxy Iranian” attacker, and Rob Maas on defense. Watch the full episode to see each move, and the exact control that stops it. 🔗 Episode resources, transcript and show notes: https://threat-talks.com 🎙️ Subscribe to the podcast on Spotify, Apple Podcasts, or your podcast app of choice. Threat Talks is a podcast by ON2IT cybersecurity and AMS-IX. We delve deep into the dynamic world of cybersecurity, one episode at a time. New episode every Tuesday. Chapters (paste into YouTube description) 00:00 Every nation state has a cyber army: what about Iran? 00:21 Meet the guests: Yuri (red team) and Rob (blue team) 01:17 Boggy Serpens and Operation OLALAMPO: Iran's access brokers 04:20 Infection via Office macros, and the social-engineering layer 07:18 You opened the document: three payloads 08:06 Backdoor 1: Telegram-bot command and control 12:55 Backdoor 2: the Rust "Ghost" backdoor, and why it's so hard to analyze 16:03 Backdoor 3: legitimate AnyDesk, pre-loaded for the attacker 17:59 Zero Trust and network segmentation 18:59 Did it work? AI tells, and staying vigilant
In 2026, 40 new submarine cables go live. Most won't land in Europe. Europe is losing the sea cable race, and most people haven't noticed yet. In this second part of our sea cables conversation, host Peter Ernst sits down with Ernst Noorman, the Netherlands' Cyber Ambassador-at-Large and a member of the ITU Advisory Body on Submarine Cable Resilience, to move from the “how” of sea cables to the “why it matters.” We compare two places that were once called the two hardest spots in the world to build digital infrastructure, Amsterdam and Singapore, and unpack how Singapore solved its crunch with 32 cable landings, five years of zero cable faults, and a green-energy-first tender process, while the Netherlands risks resting on a 30-year-old head start. Along the way: the difference between sovereignty and autonomy, why “always the cheapest option” no longer works, the EU Cyber Resilience Act and security by design, what NIS2 means for boards and CEOs personally, and why Europe needs to stop being modest about Airbus-sized wins. Chapters 00:00 — 40 new cables, most skip Europe 00:30 — Meet Ernst Noorman & the ITU advisory body 02:00 — The sea cable map is being redrawn 04:08 — Why the Netherlands risks losing its head start 06:26 — How Singapore solved it: 32 landings, zero faults 08:09 — Tax cuts for digital, would Europe ever? 08:59 — Sovereignty vs autonomy: it's about choice 15:02 — You can't own the whole stack (ASML, Nokia, Ericsson) 15:53 — Why “always the cheapest” stops working 17:47 — The Cyber Resilience Act & security by design 18:51 — The water-from-the-tap analogy 19:51 — What boards and CEOs must actually ask 25:30 — Back to Singapore: government-led, by design 29:39 — The good news: Europe's real strengths 36:15 — What needs to happen in the next 3–5 years Threat Talks is a podcast by ON2IT and AMS-IX. Subscribe for more on Zero Trust, cyber resilience, and the infrastructure behind the internet.
The headlines say Russia’s shadow fleet is cutting cables. The experts say most faults come from clumsy ship anchors. Ninety-nine percent of global internet traffic runs across the ocean floor, and the conversation about what threatens it is mostly wrong. In this episode of Threat Talks, Peter van Burgel, CEO of AMS-IX, sits down with Ernst Noorman, Cyber Ambassador at Large for the Netherlands and member of the ITU Advisory Board on Submarine Cable Resilience, to separate geopolitical noise from engineering reality, and explain what actually puts global internet connectivity at risk. Timestamps 00:00:00 Introduction 00:00:55 The ITU Advisory Board on Submarine Cable Resilience 00:05:04 Shadow Fleets, Geopolitics, and the Sabotage Myth 00:10:30 Shunts, Faults, and What Actually Breaks Cables 00:15:47 Why Satellite Cannot Replace Submarine Cables 00:17:06 Digital Sovereignty and the Big Tech Cable Takeover 00:28:16 What Every CEO Should Put on the Agenda Key Topics Covered • Why most submarine cable faults come from anchors, fishing nets, and natural events, not state actors • How aging repair ships and bureaucratic permitting barriers make restoration slow in most of the world • Why satellite (including Starlink) cannot replace subsea fiber at any meaningful scale • How big tech dominance over new cable investment creates digital sovereignty risks for governments and large organizations • What NIS2 means for CEO accountability on digital infrastructure resilience Related ON2IT Content & Referenced Resources ITU Advisory Board on Submarine Cable Resilience: https://www.itu.int/digital-resilience/submarine-cables/advisory-body/ ICPC (International Cable Protection Committee): https://www.iscpc.org Dutch Cybersecurity Council / CEO manual on NIS2: https://www.cybersecuritycouncil.nl Dutch Cybersecurity Act (NIS2 implementation): https://www.dutchncca.nl/the-cybersecurity-act Threat Talks: https://threat-talks.com/russia-cutting-cables-whos-protecting-it/ ON2IT (Zero Trust as a Service): https://on2it.net AMS-IX: https://www.ams-ix.net/ams Subscribe to Threat Talks and turn on notifications for deep dives into the world’s most active cyber threats and hands-on exploitation techniques. 🔔 Follow and Support our channel! 🔔 ► YOUTUBE: / @threattalks ► SPOTIFY: https://open.spotify.com/show/1SXUyUE… ► APPLE: https://podcasts.apple.com/us/podcast… 👕 Receive your Threat Talks T-shirt https://threat-talks.com/ 🗺️ Explore the Hack’s Route in Detail 🗺️ https://threat-talks.com 🕵️ Threat Talks is a collaboration between @ON2IT and @AMS-IX
A company skips a security check two days before Black Friday and loses $1 million when transactions land in the wrong bank accounts. A machine learning team is told no on production data access, gets it via SharePoint anyway, and a year later the data is on contractor laptops nobody can account for. Two stories, one pattern: when security blocks, the risky work doesn’t stop – it just happens without you. Lieuwe Jan Koning, Co-founder and CTO at ON2IT Cybersecurity, sits down with Sina Yazdanmehr, Founder and Managing Director of Aplite GmbH, on the prevention paradox, why a “no” from the CISO is an illusion of control, and how a technical security team turns into a business partner instead of a roadblock. Timestamps 00:00:00 Introduction 00:01:55 The $1 million Black Friday story 00:04:14 Hero culture rewards shipping, not prevention 00:06:55 The prevention paradox 00:08:00 NIS2 and executive accountability 00:09:00 Avoiding the Department of No 00:12:18 Production data on contractor laptops 00:16:13 The technical CISO as business partner Key Topics Covered Why hero culture quietly trains organizations to bypass security under deadline pressure The prevention paradox: why the person who avoids a loss never gets the credit What happens after a CISO says no: shadow workflows, friendly handovers, and data on laptops nobody owns What a counter-proposal in risk-based language gets you that a flat refusal does not Related ON2IT Content & Referenced Resources Aplite GmbH: https://aplite.de Previous Threat Talks with Sina Yazdanmehr (Security Culture part 1): https://youtu.be/1JnAsXDCKzM?si=qFlMxC617E30U1dW Previous Threat Talks with Sina Yazdanmehr: https://www.youtube.com/watch?v=wBodTl_nY1w Previous Threat Talks with Sina Yazdanmehr: https://www.youtube.com/watch?v=fBwdGXf-0dY Threat Talks: https://threat-talks.com/ ON2IT (Zero Trust as a Service): https://on2it.net/ AMS-IX: https://www.ams-ix.net/ams Subscribe to Threat Talks and turn on notifications for deep dives into the world's most active cyber threats and hands-on exploitation techniques. 🔔 Follow and Support our channel! 🔔 === ► YOUTUBE: / @threattalks ► SPOTIFY: https://open.spotify.com/show/1SXUyUE... ► APPLE: https://podcasts.apple.com/us/podcast... 👕 Receive your Threat Talks T-shirt https://threat-talks.com/ 🗺️ Explore the Hack's Route in Detail 🗺️ https://threat-talks.com 🕵️ Threat Talks is a collaboration between @ON2IT and @AMS-IX
A SaaS company buys enterprise ChatGPT for 800 staff and strangely only uses 30 seats. A corporate signs annual risk exemptions for five years until the exception list itself is mistaken for a working security process. Same root cause, two symptoms. Compliance is not security. Security culture is company culture. If your employees do not trust their managers, no policy you write will save you. Lieuwe Jan Koning, Co-founder and CTO at ON2IT Cybersecurity, sits down with Sina Yazdanmehr, Founder and Managing Director of Aplite GmbH, on why security policy depends on trust, why a signed risk acceptance is a legal act, and what a leadership cadence on security communication actually looks like. Timestamps 00:00:00 Introduction 00:02:20 When risk exceptions become culture 00:07:50 Turning a five-year exemption list around 00:09:07 Working with auditors instead of around them 00:13:14 The trust gap: enterprise tools and personal accounts 00:19:27 Security culture is company culture 00:22:21 Wrap and what is next Key Topics Covered Why employee trust in management determines whether any security policy lands How sanctioned enterprise tools, AI included, quietly fail when context and trust are missing The legal weight of a signed risk acceptance, and why most managers treat it as paperwork What a working leadership cadence on security communication actually looks like Related ON2IT Content & Referenced Resources Aplite GmbH: https://aplite.de Previous Threat Talks with Sina Yazdanmehr: https://www.youtube.com/watch?v=wBodTl_nY1w Previous Threat Talks with Sina Yazdanmehr: https://www.youtube.com/watch?v=fBwdGXf-0dY Threat Talks: https://threat-talks.com/ ON2IT (Zero Trust as a Service): https://on2it.net/ AMS-IX: https://www.ams-ix.net/ams Subscribe to Threat Talks and turn on notifications for deep dives into the world's most active cyber threats and hands-on exploitation techniques. 👕 Receive your Threat Talks T-shirt https://threat-talks.com/ 🗺️ Explore the Hack's Route in Detail 🗺️ https://threat-talks.com 🕵️ Threat Talks is a collaboration between @ON2IT and @AMS-IX
Your AI agents are users now. They have your permissions. They read your email. They send messages. And they act on instructions that anyone with an internet connection can drop into your inbox. In this episode of Threat Talks, Lieuwe Jan Koning, Co-founder and CTO at ON2IT Cybersecurity, sits down with Jack Cable, CEO and Co-founder of Corridor and former lead of Secure by Design at CISA, to walk through the “lethal triangle” (the three conditions that turn helpful AI into a breach vector) and what CISOs should be doing right now, before the technology runs further ahead of the controls. Timestamps 00:00 – 01:36 Cold Open: The User Inside Your Software 01:36 – 04:23 What Agentic AI Actually Is 04:23 – 07:20 The Lethal Triangle: Three Conditions for a Breach 07:20 – 10:05 Why Prompt Injection Has No Fix Today 10:05 – 14:09 Sanctioning Agents Without “Allow Fatigue” 14:09 – 18:45 OpenClaw: Should Your CISO Authorize It? 18:45 – 21:17 Sandboxing, Sub-Agents, and What to Do Right Now Key Topics Covered The “lethal triangle” – sensitive access, untrusted input, and the ability to take unapproved actions – and why every basic email agent already breaks all three rules Why prompt injection cannot be reliably solved by another LLM, and why deterministic guardrails (sandboxing, allow-lists, human-in-the-loop) are the only durable answer today Why “allow, allow, allow” fatigue makes per-action approvals largely theatrical, and why routing approvals through a separate model is a real, if partial, improvement Why Jack Cable’s CISO answer on OpenClaw and similar general-purpose agents today is short: don’t authorize (and what to deploy in its place)
The biggest security threat in your organization right now? Your sales team. AI coding tools have crossed into every department, and most organizations have no idea what's being built or deployed in their name. In this episode of Threat Talks, Lieuwe Jan Koning, Co-founder and CTO at ON2IT Cybersecurity, sits down with Jack Cable, CEO and Co-founder of Corridor and former lead of Secure by Design at CISA to talk about why the answer isn’t to block innovation. What's in this episode for you: The non-engineer coding problem. AI coding agents have put software creation in the hands of anyone with a laptop, and the security implications are only starting to land. Why blocking doesn't work. Teams self-provision anyway, individual accounts, zero visibility. Shadow vibe coding is far worse than sanctioned use, and organizations that block fall behind. How to actually solve it. Platform-level mitigations that prevent known vulnerability classes regardless of who wrote the code: standard auth libraries, dependency management, MFA on anything externally deployed. Timestamps 00:00 – Introduction 01:41 – Where It All Started: Hacking the Air Force at 18 06:25 – What Jack Found: 350 Vulnerabilities Across Google, Facebook and the DoD 12:24 – How AI Coding Agents Changed Software Development 17:04 – How Secure Is the Code That AI Coding Agents Write 28:53 – What CISOs Need to Know About Agentic AI Security 31:50 – Next Week and Wrap-Up Key topics covered How software development has changed with the arrival of AI coding agents Why sanctioned AI coding use requires visibility into tools, licenses, and configurations What the right guardrails look like for engineering teams vs. non-technical teams Resources Corridor: https://corridor.dev Threat Talks – New US Cyber Strategy [URL] Threat Talks: https://threat-talks.com/ ON2IT (Zero Trust as a Service): https://on2it.net/ AMS-IX: https://www.ams-ix.net/ams Subscribe to Threat Talks and turn on notifications for deep dives into the world’s most active cyber threats and hands-on exploitation techniques. 🔔 Follow and Support our channel! 🔔 === ► YOUTUBE: / @threattalks ► SPOTIFY: https://open.spotify.com/show/1SXUyUE... ► APPLE: https://podcasts.apple.com/us/podcast... 👕 Receive your Threat Talks T-shirt https://threat-talks.com/ 🗺️ Explore the Hack's Route in Detail 🗺️ https://threat-talks.com 🕵️ Threat Talks is a collaboration between @ON2IT and @AMS-IX
Ranking source
Apple Podcasts rankings via the Mato Topic Intelligence Platform.
Observed September 20, 2026.
Apple and Apple Podcasts are trademarks of Apple Inc., registered in the U.S. and other countries.
Pairs with
Bring this source into Mato to read its transferable patterns, then turn them into an original show for your own audience.