Podcast thumbnail for Security Café

Security Café

Claim This Podcast

by Quint Ketting Menno van der Horst

28 episodes
Updated Daily
Accepts GuestsHas SponsorsLocation 🇳🇱

Podcast Overview

<p>“Pull up a chair at the Security Café – your monthly deep dive into the hottest cybersecurity news and trends. Each episode brings you an inspiring guest and a story that will spark your imagination. Produced by Quint &amp; Menno (Atos), this is where insights meet conversation. Don’t just stay informed—join the discussion!”</p>

Language

🇺🇲

Publishing Since

2/2/2024

1 verified contact email on file for Security Café

Pitch yourself as a guest, propose sponsorships, or reach out directly to the host.

Recent Episodes

Episode thumbnail for "Sovereignty Is the Wrong Word": Digital Autonomy with Mika Lauhde

July 23, 2026

"Sovereignty Is the Wrong Word": Digital Autonomy with Mika Lauhde

<h1>SecurityCafe — "Sovereignty Is the Wrong Word": Digital Autonomy with Mika Lauhde</h1><p><b>Hosts:</b> Menno van der Horst &amp; Quint Ketting <b>Guest:</b> Mika Lauhde, Luxembourg House of Cybersecurity (<a rel="noopener noreferrer nofollow" href="http://linkedin.com/in/mika-lauhde-4270711" target="_blank">linkedin.com/in/mika-lauhde-4270711</a>)</p><h2>About this episode</h2><p>Mika Lauhde spent 30 years across Nokia, Huawei, and ENISA before landing at Luxembourg House of Cybersecurity, the national hub keeping Luxembourg's municipalities, SMEs, and economy cyber-resilient. His argument: Europe has the wrong word. Not "sovereignty" — hard borders around who owns what — but <b>autonomy</b>: acting independently while still sharing tools and trust. From GPS glitches during US foreign policy disputes, to Europe always getting the second-best tech (fighter jets included), to a national CERT running entirely on open source — this one covers a lot of ground.</p><h2>In this episode</h2><ul><li><b>00:11</b> — Welcome &amp; Mika's background (Nokia, Huawei, ENISA, Luxembourg House of Cybersecurity)</li><li><b>02:08</b> — News: an integrator data-leak claim ("888") and what makes integrator breaches different</li><li><b>06:06</b> — Android's new developer certificate as a "kill switch," African nations building their own internet, UK VPN/age-verification rollout, an EU "tech sovereignty" proposal that leans on non-European hardware</li><li><b>09:11</b> — A US court ruling that may have quietly broken a GDPR assumption on data transfers</li><li><b>10:34</b> — NIS2 finally live in NL (15 Aug) — are our laws fast enough for machine-speed attacks?</li><li><b>19:20</b> — The "SplinterNet," and why Mika argues for shared autonomy over walled-garden sovereignty</li><li><b>23:46</b> — The Cyber Resilience Act's unprecedented recognition of open source (79 mentions)</li><li><b>24:19</b> — AI models as the new trade weapon — allies get the previous generation, like fighter jets</li><li><b>26:50</b> — The GPS/Galileo story, and SES's Iris² as Europe's answer to Starlink</li><li><b>30:15</b> — EU tax rules that quietly disadvantage open source; the Nokia N900 as Europe's "Sputnik moment"</li><li><b>33:00</b> — Luxembourg's national CERT runs entirely on open-source tools</li><li><b>34:40</b> — The call to action: a free open-source toolkit so any EU SME can stand up a cyber ops center</li><li><b>36:41</b> — What to read: Quint's, Mika's, and Menno's picks</li><li><b>41:04</b> — Wrap-up</li></ul><h2>Key takeaways</h2><ul><li><b>Autonomy, not sovereignty</b> — sharing open standards beats walling off borders</li><li><b>Dependency is invisible until it breaks</b> — GPS glitches led to Galileo, now to Iris²</li><li><b>New tech follows old patterns</b> — AI models, like military hardware, come second-best to allies</li><li><b>Open source is operational, not aspirational</b> — Luxembourg's CERT proves it at national scale</li></ul><h2>Mentioned</h2><p>Accenture leak claims <i>(unconfirmed)</i> · NIS2 (NL) · Cyber Resilience Act · European OSPO network · SES Iris² · <i>Trump v. Slaughter</i> ruling <b>Reads:</b> <i>The Subtle Art of Not Giving a F</i>ck* by Mark Manson (<a rel="noopener noreferrer nofollow" href="http://markmanson.net/books/subtle-art" target="_blank">markmanson.net/books/subtle-art</a>) · Max Schrems / noyb (<a rel="noopener noreferrer nofollow" href="http://noyb.eu/en/us-supreme-court-just-blew-eu-us-data-transfers" target="_blank">noyb.eu/en/us-supreme-court-just-blew-eu-us-data-transfers</a>) · Bert Hubert's blog (<a rel="noopener noreferrer nofollow" href="http://berthub.eu" target="_blank">berthub.eu</a>)</p><hr /><p><i>SecurityCafe is hosted by Menno van der Horst and Quint Ketting. Powered by Atos.</i></p>

Episode thumbnail for AI Where It Matters, Not AI Everywhere — with Zeina Zakhour, Global Cyber CTO Atos/Eviden

June 25, 2026

AI Where It Matters, Not AI Everywhere — with Zeina Zakhour, Global Cyber CTO Atos/Eviden

<p><b>AI Where It Matters, Not AI Everywhere — with Zeina Zakhour, Global CTO Cybersecurity at Eviden (Atos)</b></p><p>Recorded live at CISO Day, this episode brings Menno van der Horst and co-host Quint Ketting together with Zeina Zakhour, Global CTO for Cybersecurity at Eviden (Atos), for a fast-moving conversation on where cyber is heading and what it really takes to keep up.</p><p>We open with a sobering reality: many of today's threats are exposing weaknesses that have existed for decades. The panic isn't warranted — but action is. Zeina makes the case that the issue is rarely a lack of technology depth, but a lack of security depth: the basic hygiene and foundational controls that too many organisations still treat as something for "next year." Spoiler — next year is no longer an option.</p><p>From there we get into the heart of it:</p><p>— <b>Adaptive, systemic resilience.</b> Security can't be an afterthought bolted on once innovation ships. It has to sit at the core. We dig into why maturity built once and then left alone decays faster than most leaders expect.</p><p>— <b>Risk first, always.</b> You don't secure a water utility the way you secure a hospital, a retailer or a bank. Every organisation has its own ecosystem and purpose — and that's where Eviden's <i>Prepare, Respond, Adapt</i> approach starts: understanding who you are, then keeping your risk picture live rather than buried in a spreadsheet updated once a year.</p><p>— <b>AI, agents and the new attack surface.</b> Not "AI everywhere" — AI where the risk, the data and the friction justify it. We talk identity as the number one attack vector, the danger of human-led processes throttling machine-speed tooling, prompt and meta-prompt injection, agent goal drift, kill switches, and what "identity" even means for an autonomous agent that has intent, makes decisions and calls tools.</p><p>— <b>Chained vulnerabilities.</b> Why "we'll only fix the high-severity CVEs" is the wrong instinct — low-severity issues can be chained into something genuinely exploitable, fast.</p><p>— <b>Sovereignty vs autonomy.</b> A crucial distinction too many conflate. We get into data residency, technological sovereignty, the model/middleware/GPU reality of "sovereign AI" today, post-quantum, and why Europe can only answer these questions together rather than country by country.</p><p>We close where good security conversations always seem to land: sharing more, building a bubble of trust, backing European innovation and startups, and staying agile enough to adapt as the ground keeps shifting.</p><p><b>Zeina's recommendations:</b> 📑 Atos <i>Cyber Shield</i> blog and Threat Research Center — regular, genuinely interesting analysis on new campaigns and malware variants. 📖 <i>The Five People You Meet in Heaven</i> by Mitch Albom — nothing to do with cyber, everything to do with being worth your time.</p><p>🎧 Listen now, and let us know your take in the comments.</p><p>#SecurityCafe #Cybersecurity #CISO #AISecurity #Resilience #DigitalSovereignty</p>

Episode thumbnail for Data is the New Uranium: Critical Infrastructure, CISOCommunity & AI with Dimitri van Zantvliet (NS)

May 28, 2026

Data is the New Uranium: Critical Infrastructure, CISOCommunity & AI with Dimitri van Zantvliet (NS)

<p>A SecurityCafe special, recorded live at CISOday 2026 with Dimitri van Zantvliet — CISO &amp; Cybersecurity Director at Nederlandse Spoorwegen (NS), Chairman of the CISO Community NL and co-founder of CISOday. Host Menno van der Horst is joined by co-host Quint Ketting for a wide-ranging conversation on what it actually takes to defend critical infrastructure in a world where the geopolitical, technological and threat landscape is shifting faster than ever.</p><p>In this episode:</p><p>- Why CISOday and the CISO Community NL exist, and how community accelerates maturity across the sector</p><p>- Becoming a NIS1 critical entity in 2021 and how the war in Ukraine reshaped NS's threat model overnight</p><p>- Belarusian railway wiperware, Iranian-aligned activity, and the recent railway incident in Florida</p><p>- Working with NCSC, NCTV, AIVD, the Rail-ISAC and Dutch ISAC to exchange threat intel</p><p>- Building an in-house CTI team of five — strategic, tactical, operational and technical</p><p>- The NS Cyber Academy: training people from train drivers to office staff into cyber roles, plus SANS, CISSP and CISA tracks</p><p>- Why stamina and curiosity beat a classic IT background when hiring — including the case for ex-Olympians, HYROX athletes and journalists</p><p>- The cultural shift from "my threat intel is my IP" to active two-way sharing across the ecosystem</p><p>- Supplier risk as a knock-out criterion: no ISO 27001 / SOC 2 Type 2, no business</p><p>- AI and <a rel="noopener noreferrer nofollow" href="http://Gen.AI" target="_blank">Gen.AI</a> as the new frontier — from "data is the new gold" to "data is the new uranium"</p><p>- Quantum on the horizon, and why the impact reaches far beyond encryption</p><p>- The basics still decide everything: MFA, passwords, segmentation — and the move toward real-time patching</p><p>- Autonomous agents as the next attack vector we don't yet fully understand</p><p>- Historical parallels, from the AIDS Trojan on floppy disk to ILOVEYOU and SQL Slammer</p><p>- Nassim Taleb's Antifragile — and why "prepare, respond, adapt" is the cycle every organisation needs</p><p>- Cybersecurity is no longer an IT conversation; it's geopolitics, brand, and business continuity</p><p>Book of the episode:</p><p>- Antifragile — Nassim Nicholas Taleb</p><p>About the guest:</p><p>Dimitri van Zantvliet is CISO &amp; Cybersecurity Director at NS, Chairman of the CISO Community NL and co-founder of CISOday. He joined NS five years ago and has led the organisation's response to the post-2021 shift in geopolitical and cyber risk affecting European critical infrastructure.</p><p>Working at NS:</p><p>Dimitri's team is hiring. If cybersecurity at one of the Netherlands' most critical infrastructure providers sounds like your kind of challenge, check the openings at <a rel="noopener noreferrer nofollow" href="http://werkenbijns.nl" target="_blank">werkenbijns.nl</a>.</p><p>About SecurityCafe:</p><p>SecurityCafe is hosted by Menno van der Horst with co-host Quint Ketting — an open conversation about the strategic, technical and human sides of cybersecurity. Produced by Quint Ketting. Subscribe wherever you get your podcasts.</p><p>This CISOday special was made possible in partnership with Atos.</p>

28 total episodes available

Deep-dive analytics for Security Café

Frequently asked questions

Have a different question and can't find the answer you're looking for? Reach out to our support team by sending us an email and we'll get back to you as soon as we can.

What is Security Café?
<p>“Pull up a chair at the Security Café – your monthly deep dive into the hottest cybersecurity news and trends. Each episode brings you an inspiring guest and a story that will spark your imagination. Produced by Quint &amp; Menno (Atos), this is where insights meet conversation. Don’t just stay informed—join the discussion!”</p>
How often does this podcast release new episodes?

This podcast updates daily.

Where can I listen to this podcast?

This podcast is available on 4 platforms including Apple Podcasts, Spotify, and more. You can also use the RSS feed directly.

Does this podcast accept guests?

Yes, this podcast regularly features guests.

Legal Disclaimer

Pod Engine is not affiliated with, endorsed by, or officially connected with any of the podcasts displayed on this platform. We operate independently as a podcast discovery and analytics service.

All podcast artwork, thumbnails, and content displayed on this page are the property of their respective owners and are protected by applicable copyright laws. This includes, but is not limited to, podcast cover art, episode artwork, show descriptions, episode titles, transcripts, audio snippets, and any other content originating from the podcast creators or their licensors.

We display this content under fair use principles and/or implied license for the purpose of podcast discovery, information, and commentary. We make no claim of ownership over any podcast content, artwork, or related materials shown on this platform. All trademarks, service marks, and trade names are the property of their respective owners.

While we strive to ensure all content usage is properly authorized, if you are a rights holder and believe your content is being used inappropriately or without proper authorization, please contact us immediately at hey@podengine.ai for prompt review and appropriate action, which may include content removal or proper attribution.

By accessing and using this platform, you acknowledge and agree to respect all applicable copyright laws and intellectual property rights of content owners. Any unauthorized reproduction, distribution, or commercial use of the content displayed on this platform is strictly prohibited.