Threat Talks
Threat Talks - Your Gateway to Cybersecurity Insights
Threat Talks is your cybersecurity knowledge hub. Unpack the latest threats and explore industry trends with top experts as they break down the complexities of cyber threats. We make complex cybersecurity topics accessible and engaging for everyone, from IT professionals to every day internet users by providing in-depth and first-hand experiences from leading cybersecurity professionals. Join us for monthly deep dives into the dynamic world of cybersecurity, so you can stay informed, and stay secure!
Where to listen?
Podcasts in the app Replaio Radio Coming soonPodcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts
Episodes
Framework Fatigue: Why NIST Rebuilt the Cybersecurity Framework 07.07.2026 28:02
Ten years after its first release, the NIST Cybersecurity Framework got a full rebuild. Not because it failed, but because everyone started using it, and it was never built for everyone. In this episode, host Lieuwe Jan Koning talks with Amy Mahn, IT Standards Advisor at NIST, and Daniel Eliot, Lead for Small Business Engagement at NIST’s Applied Cybersecurity Division, about what CSF 2.0 actually...
Why Do You Trust Your AI Agent? 30.06.2026 24:23
Agentic AI is powerful, and someone recently found that out the hard way when an AI tool, given free rein with a user’s own permissions, deleted her entire mailbox. That cautionary tale opens this Threat Talks Deep Dive, where host Lieuwe Jan Koning talks with Rob Maas, Field CTO of ON2IT, about what Zero Trust looks like when the thing you’re securing is an AI agent. Drawing on Rob’s recent blog...
Mythos is not the AI Apocalypse 23.06.2026 22:05
Mythos found a 23-year-old vulnerability in FreeBSD that no human team had caught. Your 30-day patch cycle assumes years before it gets weaponized. Today that window is one day. Next year it will be one hour. Lieuwe Jan Koning, Co-founder & CTO at ON2IT, sits down with Rob Maas, Field CTO at ON2IT, to break down what Anthropic's Mythos actually found, why the public release (Fable) still frust...
What about Iran? One Word Document, Three Backdoors 16.06.2026 22:14
Every big nation state has a cyber army: China, Russia, the US, Europe. But what about Iran? Meet Boggy Serpens, a group tied to Iran’s civilian intelligence service whose entire business is breaking in and staying in, then handing the keys to whoever strikes next. Their playbook, Operation OLALAMPO, needs just one booby-trapped Word document to plant three separate backdoors on your network. A T...
Europe Is Losing the Sea Cable Race 09.06.2026 35:10
In 2026, 40 new submarine cables go live. Most won't land in Europe. Europe is losing the sea cable race, and most people haven't noticed yet. In this second part of our sea cables conversation, host Peter Ernst sits down with Ernst Noorman, the Netherlands' Cyber Ambassador-at-Large and a member of the ITU Advisory Body on Submarine Cable Resilience, to move from the “how” of sea cables to the “w...
Russia Cutting Cables? 02.06.2026 32:30
The headlines say Russia’s shadow fleet is cutting cables. The experts say most faults come from clumsy ship anchors. Ninety-nine percent of global internet traffic runs across the ocean floor, and the conversation about what threatens it is mostly wrong. In this episode of Threat Talks, Peter van Burgel, CEO of AMS-IX, sits down with Ernst Noorman, Cyber Ambassador at Large for the Netherlands an...
Hero Culture and a $1 Million Mistake 26.05.2026 20:03
A company skips a security check two days before Black Friday and loses $1 million when transactions land in the wrong bank accounts. A machine learning team is told no on production data access, gets it via SharePoint anyway, and a year later the data is on contractor laptops nobody can account for. Two stories, one pattern: when security blocks, the risky work doesn’t stop – it just happens wit...
When Compliance Replaces Security 19.05.2026 23:27
A SaaS company buys enterprise ChatGPT for 800 staff and strangely only uses 30 seats. A corporate signs annual risk exemptions for five years until the exception list itself is mistaken for a working security process. Same root cause, two symptoms. Compliance is not security. Security culture is company culture. If your employees do not trust their managers, no policy you write will save you. Lie...
The Agent Problem 12.05.2026 21:27
Your AI agents are users now. They have your permissions. They read your email. They send messages. And they act on instructions that anyone with an internet connection can drop into your inbox. In this episode of Threat Talks, Lieuwe Jan Koning, Co-founder and CTO at ON2IT Cybersecurity, sits down with Jack Cable, CEO and Co-founder of Corridor and former lead of Secure by Design at CISA, to walk...
Your Sales Team is now a Developer 05.05.2026 33:10
The biggest security threat in your organization right now? Your sales team. AI coding tools have crossed into every department, and most organizations have no idea what's being built or deployed in their name. In this episode of Threat Talks, Lieuwe Jan Koning, Co-founder and CTO at ON2IT Cybersecurity, sits down with Jack Cable, CEO and Co-founder of Corridor and former lead of Secure by Design...
The Hidden Risk of Your Infrastructure 28.04.2026 26:42
Volt Typhoon spent years pre-positioning inside US critical infrastructure. Salt Typhoon pulled off one of the largest espionage campaigns in history. They didn't break in. They were already there. So what do you actually do about it? Caitlin Clarke , Senior Director of Cybersecurity Services at Venable and former Special Assistant to the President for Cybersecurity and Emerging Technology, joins...
America Just Changed the Rules of Cyber War 21.04.2026 26:42
If you're waiting for the executive orders to act, you're already behind. The U.S. has just released a new national cyber strategy. The core message is clear: stop waiting to be hit, and start making it costly to try. In this episode of Threat Talks , Caitlin Clarke, Senior Director of Cybersecurity Services at Venable and former Special Assistant to the President for Cybersecurity & Emer...
The EU is forcing the conversation 14.04.2026 33:44
We always worried about lock-in. But the real risk is getting locked out – of your cloud. Your data may sit in Europe. Your systems may run on trusted platforms. But if access is restricted tomorrow – by a provider, a government, or a legal decision - what actually happens? Can you still operate? In this episode of Threat Talks , Lieuwe Jan Koning (co-founder and CTO at ON2IT Cybersecurity) speak...
Europe vs China vs US: Who Controls Your Tech? 07.04.2026 33:02
You don’t control the technology your business runs on. That’s an uncomfortable reality. But the truth is: your infrastructure runs on foreign technology. Your data depends on external suppliers. And if they fail – you feel it. The EU has decided to step in. In this episode of Threat Talks , Lokke Moerel (Professor of Global ICT Law at Tilburg University and leading expert in EU cybersecurity...
Breached OT Kills. Zero Trust 2.0 Doesn’t 31.03.2026 16:51
Not long ago, OT environments were isolated islands. Control systems ran independently, accessible only through dedicated workstations requiring physical presence. The factory floor and the IT department might as well have been on different planets. That world is gone. Today’s OT environments are connected. Remote access from IT workspaces to control systems is routine. And this is just th...
React2Shell Explained 24.03.2026 14:48
Log4j caught everyone off guard. React2Shell might be doing the same right now. Across thousands of React apps, exposure is already baked in - accelerated by vibe coding and shipped without scrutiny. In some cases, one request is all it takes. React2Shell turns that exposure into remote code execution in React and Next.js environments -triggered by a single HTTP POST request. In this episode of T...
Zero Trust in the AI Era 17.03.2026 22:54
AI can fake your voice. Deepfakes can move millions of dollars in minutes. And attackers no longer need to break trust - they can simulate it. Security teams are entering an era where nothing can be trusted at face value. In part two of our Zero Trust series with Dr. Zero Trust, Chase Cunningham, he and Lieuwe Jan Koning (Co-Founder and CTO at ON2IT Cybersecurity) explore what the future of Zero T...
Zero Trust: From Revolution to Reality 10.03.2026 20:21
Zero Trust is easy to say. Hard to execute. Most organizations try to build it themselves. Most underestimate the complexity. Most get stuck in architecture diagrams instead of protecting what actually matters: data. If execution determines success – should you really be doing it alone? In this episode of Threat Talks , Lieuwe Jan Koning , Co-Founder and CTO at ON2IT Cybersecurity, sits down with...
China is Already Inside your infrastructure 03.03.2026 29:45
China is Already Inside your infrastructure. And the EU is done ignoring it. In this exclusive first discussion of the upcoming EU Cybersecurity Act revision, Bart Groothuis, MEP, joins Lieuwe-Jan Koning, CTO and Co-Founder, to explain why vendor dependency is now a board-level security risk. Groothuis breaks down how the revised EU Cybersecurity Act will shift Europe from soft guidance to hard e...
OpenClaw and The Dark Side of Agentic AI 24.02.2026 19:56
Your biggest threat this year isn’t malware. It’s your own AI assistant. OpenClaw connects an LLM directly to your terminal, browser, email, and chat. It runs with your permissions. It executes tasks without hesitation. Days after launch, researchers found a One-Click RCE. Cisco called it a security nightmare. Gartner called it an unacceptable risk. OpenClaw (formerly known as Clawdbot and Moltb...
Inside the MongoBleed Memory Leak 17.02.2026 13:57
Imagine your memory just became the attack surface. That’s MongoBleed. Or as others know it: CVE-2025-14847 . No passwords to crack, no complex exploit chain. Just normal protocol behavior, repeated at scale. Each request leaks a little more MongoDB memory until something valuable shows up, even in environments that already follow network segmentation best practices. Rob Maas (Field CTO, ON2IT) h...
How to pass any cybersecurity certification 10.02.2026 21:59
Certifications play a central role in cybersecurity career development. Yet many experienced engineers find themselves failing exams they should easily pass. The problem isn’t a lack of knowledge or skills. It’s the disconnect between real-world security work, and certifications built around memorization, UI trivia, and version-specific details that will be obsolete in two months. In this episode...
The Battle of Defending a Digital City 03.02.2026 47:12
When it comes to running an airport, there’s no room for error. Any casualty is one too much. That’s the reality of all airports, including DFW Airport. It’s a 28-square-mile operation, bigger than the island of Manhattan, functioning as a city with its own police, fire services, OT environments, and always-on digital infrastructure. In this Threat Talks episode, Lieuwe-Jan Koning (Co-Founder...
From IPs to people 27.01.2026 18:12
Detection fails without identity. When activity isn’t tied to a person, anomalies stop telling a story - they’re just signals without context. And when your logs only show IP addresses, your security team is left responding to shadows, not real risk. In this Threat Talks Deep Dive, Rob Maas (Field CTO, ON2IT) and Nicholai Piagentini (Technical Enablement Engineer, ON2IT) show how identity-based...
Beyond NIS2 Compliance 21.01.2026 47:38
Most organizations ask one question: “Are we compliant?” The question that actually matters is: “Will we still be operating when things go wrong?” In this Threat Talks episode, Lieuwe Jan Koning speaks with Jasper Nagtegaal about what NIS2 is really trying to change - and why cyber resilience fails when organizations treat it as a policy exercise instead of a business risk. This isn’t about re...
Similar podcasts
Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.