Threat Talks - Your Gateway to Cybersecurity Insights

Threat Talks

Threat Talks is your cybersecurity knowledge hub. Unpack the latest threats and explore industry trends with top experts as they break down the complexities of cyber threats. We make complex cybersecurity topics accessible and engaging for everyone, from IT professionals to every day internet users by providing in-depth and first-hand experiences from leading cybersecurity professionals. Join us for monthly deep dives into the dynamic world of cybersecurity, so you can stay informed, and stay secure!

  1. 1 Sept

    NIST CSF 2.0: No CISO, No Excuse

    The new NIST Cybersecurity Framework 2.0 is out, and most teams still ask the same question: what do I do tomorrow? Lieuwe Jan Koning sits down with NIST's Amy Mahn and Daniel Elliott to turn the framework into a concrete next step. Governance is now its own function. Profiles tell you where you are and where you need to be. And the Quick Start Guides give a 15-page answer to a problem most people think needs 300 pages. If you run security with limited resources, this episode shows you where to start and why the whole thing is free. Timestamps 00:00:00 The framework changed. What do you do tomorrow? 00:02:00 Why Govern became its own function 00:05:49 Profiles: current state, target state, gap analysis 00:08:08 Community profiles: sharing across a sector 00:10:29 Quick Start Guides and mappings to ISO 27001, SOC 2, HIPAA 00:14:24 No CISO? Where small businesses start 00:17:50 The future of CSF and how to contribute Key Topics Covered Why governance moved out of "Identify" and became its own function in CSF 2.0, and what that signals about cyber risk at board level.How organizational and community profiles turn the framework into a current-state, target-state, and gap analysis you can act on.Why CSF 2.0 stopped being a single PDF and became guides, spreadsheets, mappings, and search tools.How CSF maps to ISO 27001, SOC 2, and HIPAA so you report once instead of many times.Where a small business or an IT manager wearing every hat should actually begin.Related ON2IT Content & Referenced Resources:  NIST Cybersecurity Framework 2.0: https://www.nist.gov/cyberframework NIST CSF Quick Start Guides: https://www.nist.gov/cyberframework/quick-start-guides National Cybersecurity Center of Excellence (NCCoE): https://www.nccoe.nist.gov/ NIST CSF contact: csf@nist.gov Threat Talks website: https://threat-talks.com/

    NIST CSF 2.0: No CISO, No Excuse
  2. 4 Aug

    The Hacker Who'll Hit You in 5 Years Is in School

    The hacker who will attack your organization in five years is in primary school right now, and nobody is teaching them anything. Tim Murck, Co-founder & Chief Product Officer at HackShield, joins Lieuwe Jan Koning, Co-founder & CTO at ON2IT, to explain how a game turns kids aged 7 to 12 into junior cyber agents instead of future attackers.  The method is not fear. It is teaching kids to ask one question: how are they going to trick me? 🔗 Episode resources, transcript and show notes: https://threat-talks.com 📝 Read the companion blog post: https://threat-talks.com/the-hacker-wholl-hit-you-in-5-years-is-in-school/🎙️ Subscribe on Spotify and Apple Podcasts, links below. Threat Talks is a podcast by ON2IT cybersecurity and AMS-IX. We delve deep into the dynamic world of cybersecurity, one episode at a time. New episode every Tuesday. #ThreatTalks #ZeroTrust #cybersecurity #hackshield #securityawareness #cybereducation #kidsonlinesafety Charpters: 00:00:00 The hacker who will attack you is in school now 00:00:27 From actor to HackShield: meet Tim Murck 00:02:00 The mission: digital scouting for kids 7 to 12 00:03:53 Junior cyber agents and the Dutch police 00:05:26 Inside the HackShield universe 00:10:02 Adversarial thinking and the grooming theme 00:13:35 Why age 7 to 12, and the school system's blind spot 00:14:53 Ban phones, or teach kids to swim? 00:18:42 The numbers: half a million Dutch kids, 850,000 worldwide

    The Hacker Who'll Hit You in 5 Years Is in School
  3. 28 Jul

    JADEPUFFER: The AI Malware With No Human in the loop

    What if AI stopped being the assistant to cybercriminals and became the attacker itself? That's no longer hypothetical. JADEPUFFER is the first documented case of ransomware run entirely by an AI agent: it broke into a production database, hit a wall mid-attack, then found another way in within 31 seconds, faster than most human penetration testers can react. Rob Maas, Field CTO at ON2IT, sits down with Yuri Wit, SOC DevOps Engineer at ON2IT, to trace how agentic malware evolved out of AI-assisted attacks into a threat that plans, executes, and pivots entirely on its own. 🔗 Episode resources, transcript and show notes: https://threat-talks.com 📝 Read the companion blog post: 🎙️ Subscribe on Spotify and Apple Podcasts, links below. Threat Talks is a podcast by ON2IT cybersecurity and AMS-IX. We delve deep into the dynamic world of cybersecurity, one episode at a time. New episode every Tuesday. #ThreatTalks #ZeroTrust #firewallsecurity  #NetworkSecurity #CyberSecurity #infosec  Charpters: 00:00:00 Cold open: can AI become the attacker?00:01:42 PromptLock and PromptSteal: proof of concept to real world00:04:24 The agentic malware trend and the local LLM question00:07:24 JADEPUFFER: ransomware run entirely by an AI agent00:09:58 Proof of concept, or a live-fire test?00:11:30 Intent-driven attacks and shrinking detection windows00:16:34 Zero Trust: what to do about it starting now 🔔 Follow and Support our channel! 🔔=== ► YOUTUBE: https://youtube.com/@ThreatTalks► SPOTIFY: https://open.spotify.com/show/1SXUyUEndOeKYREvlAeD7E► APPLE: https://podcasts.apple.com/us/podcast/threat-talks-your-gateway-to-cybersecurity-insights/id1725776520 👕 Receive your Threat Talks T-shirthttps://threat-talks.com/ 🗺️ Explore the Hack's Route in Detail 🗺️https://threat-talks.com 🕵️ Threat Talks is a collaboration between @ON2IT and @AMS-IX

    JADEPUFFER: The AI Malware With No Human in the loop
  4. 21 Jul

    Four Firewall Mistakes Still Wrecking Networks in 2026

    Three out of four firewall rule sets ON2IT’s SOC inherits from new customers share the same blind spots, and none of the fixes cost extra licensing. In this episode, Lieuwe Jan Koning, Co-founder & CTO at ON2IT, sits down with Jelle Konings, security optimization specialist in ON2IT’s Security Operations Center, to walk through the mistakes his team finds on almost every inherited network: no logging enabled, no identity tied to traffic, no default deny rule at the bottom of the rule base, and port-based rules standing in for real application control. Most environments he inherits sit around 30 to 40 percent application-based policy coverage against a 60 to 80 percent target. You will hear what to check first when you inherit a firewall, how long a realistic clean-up takes (weeks, months, sometimes over a year), and why an encrypted VPN tunnel riding on port 443 can move data out the door without a single alert firing. 🔗 Episode resources, transcript and show notes: https://threat-talks.com 📝 Read the companion blog post: https://threat-talks.com/blog/four-firewall-mistakes-still-wrecking-networks-in-2026/🎙️ Subscribe on Spotify and Apple Podcasts, links below. Threat Talks is a podcast by ON2IT cybersecurity and AMS-IX. We delve deep into the dynamic world of cybersecurity, one episode at a time. New episode every Tuesday. #ThreatTalks #ZeroTrust #FirewallSecurity #NetworkSecurity #CyberSecurity #InfoSec Chapters:  00:00 Cold open: the top firewall mistakes of 202500:21 Meet Jelle Konings, security optimization specialist01:16 Mistake 1: No visibility into your network03:36 Mistake 2: Skipping User-ID mapping06:01 Mistake 3: No default deny rule07:44 Fixing it: from logs to default deny09:09 Bonus mistake: port-based vs. application-based rules13:20 Will 2026 be any different?

    Four Firewall Mistakes Still Wrecking Networks in 2026

Ratings & Reviews

5
out of 5
6 Ratings

About

Threat Talks is your cybersecurity knowledge hub. Unpack the latest threats and explore industry trends with top experts as they break down the complexities of cyber threats. We make complex cybersecurity topics accessible and engaging for everyone, from IT professionals to every day internet users by providing in-depth and first-hand experiences from leading cybersecurity professionals. Join us for monthly deep dives into the dynamic world of cybersecurity, so you can stay informed, and stay secure!

You Might Also Like