SecurityCafé

Quint Ketting Menno van der Horst

“Pull up a chair at the Security Café – your monthly deep dive into the hottest cybersecurity news and trends. Each episode brings you an inspiring guest and a story that will spark your imagination. Produced by Quint & Menno (Atos), this is where insights meet conversation. Don’t just stay informed—join the discussion!”

  1. 11h ago ·  Bonus

    # Practice for the worst — Kelvin Rorive Live from CybersecNL — Episode 2 of 7

    Recorded at the Atos booth, CybersecNL 2026. Kelvin Rorive is CISO at ICT Group and runs the Cyber Chain Resilience Consortium (CCRC), which prepares organisations and their suppliers to handle a crisis together. Hosted by Menno van der Horst with Quint Ketting. ## Timestamps 00:00 Day one, and nobody is quite awake yet 01:12 Kelvin: CISO at ICT Group, and what CCRC does 02:05 Why this conference feels like a family reunion 03:09 The message at the booth: practice for the worst 03:34 Survivability — a word picked up from a Ukrainian speaker 04:03 Weerbaarheid, veerkracht, and a telco under drone attack 05:25 Fine for the top 10. What about everyone below? 06:09 "My IT manager will handle it" — and why he won't 07:00 Quint: I talk about business risk, not about cyber 08:31 Crisis in the chain: rehearse it with your supplier present 10:08 Exercises spill over into day-to-day cooperation 10:28 The factory that has to stop because the trucks don't come 12:02 One organisation escalates 1-2-3. The other runs it in reverse. 13:23 CEOs walking out of the room with a list 13:44 Putting the CEO in the hot seat, and not letting them delegate 15:11 What not to do: questionnaire bombardment, and AI filling them in 15:47 Know the CISOs of your critical suppliers personally 16:21 The security family, and why you don't abuse it 18:14 FI-ISAC: competitors around one table, one shared goal 19:41 Compliance is not security 20:11 An APT campaign where every control was green 20:42 NIS2, and whether Europe adapts fast enough 22:11 The balance is shifting from prevention to resilience 22:40 The most important word is not cyber. It is resilience. ## Key takeaways - Survivability sits one level beyond resilience. It starts from the assumption that everything can be broken: people, buildings, data, networks. - A cyber crisis gets handed to the IT manager and then escalates into a chain crisis long before anyone at board level notices. - A crisis exercise only tests the chain if your critical supplier is in the room. Mismatched escalation ladders, unclear responsibilities and missing contacts surface in minutes. - Supplier questionnaires are close to worthless now. They are answered by AI, approved unread, and can be manipulated with instructions hidden in the document. - What works instead is a real relationship with the CISOs of your critical suppliers, used sparingly enough that a call means something. - Compliance is the floor, not the ceiling. Green controls and a long-running intrusion coexist comfortably. - Preventive measures still matter, but the centre of gravity has moved to resilience. Assume something gets through and train the goalkeeper. ## Mentioned Cyber Chain Resilience Consortium — https://ccrc.nl ICT Group — https://ict.eu FI-ISAC, the financial sector information sharing community CybersecNL 2026 — https://www.cybersecnl.nl ## Also in this series Ramsés Gallego on speed and governance — out now. Martin de Vries on sector differences — publishing 24 September. --- SecurityCafe. Powered by Atos.

    # Practice for the worst — Kelvin Rorive

Live from CybersecNL — Episode 2 of 7
  2. 2d ago ·  Bonus

    Speed, governance and a changing landscape — Ramsés Gallego

    # Speed, governance and a changing landscape — Ramsés Gallego Special: Live from CybersecNL — Episode 1 of 7 Recorded live at the Atos booth, CybersecNL 2026. Ramsés Gallego is Chief Technologist at DXC, ISACA Hall of Fame, and president of the ISACA Barcelona chapter. Hosted by Menno van der Horst with Quint Ketting. ## Timestamps 00:00 Welcome and introductions 00:42 Why DXC came to CybersecNL: detect more, respond faster 01:28 Rivals, never enemies — why competitors share a stage 02:24 The other side collaborates better than we do 04:28 What integrators owe their customers: service over technology 06:34 A second risk equation: means, motives, opportunities 07:32 Are our frameworks still fit for purpose? 08:29 COBIT 2019 is ageing, and ISACA's AI certification track 09:53 "The human in the loop is dead" — as a reflex, not as a role 10:35 Quantum: RSA, Diffie-Hellman and elliptic curve on the clock 11:55 The part nobody talks about: code signing and certificates 12:38 ISACA Quantum Pulse Poll — the skills gap in numbers 13:21 It is not IT you are protecting. It is the business. 14:01 Trucks that stop delivering, invoices quietly altered 15:02 Why risk has to come from the business, not only the CISO 16:26 Enterprise risk management: risk is always plural 17:22 Should we still be calling it cybersecurity at all? 18:17 Business continuity is not resilience 18:54 The positive side of risk 19:34 Why a car has brakes 20:22 Three pillars: identity, data, applications 21:51 Non-human identities and the 100-to-1 future 23:18 Governance is not management, and we need AI-natives ## Key takeaways - The classic risk equation still holds, but means, motives and opportunities now sits next to it. AI has collapsed the cost of all three. - Business first. Customers do not speak Kubernetes, they speak euros. The database was not hacked — the business was. - Identity remains the cornerstone. Two of the three major incidents discussed on the CybersecNL main stage were identity related. - Non-human identity is the governance problem of the next few years. Almost nobody can say how many agents they run, let alone which accounts sit behind them. - Quantum is not only an encryption story. Code signing, certificates and anything that depends on keeping a secret are in scope. - Brakes let you go fast. Security exists so the business can move, not so it can stop. - Ramsés states that ISACA is already building COBIT 7, returning to a numbered release. Not independently confirmed at the time of publishing. - The 10-to-1 non-human to human identity ratio, and the projected 100-to-1, are cited from industry statistics and not sourced on air. - The 5-to-12-year window for cryptographically relevant quantum computing is Ramsés' own estimate. - ISACA Quantum Pulse Poll figures (2,586 respondents, 67 percent expecting new skill requirements) are quoted from memory. ## Mentioned ISACA — https://www.isaca.org DXC Technology — https://dxc.com Quantum World Association The brakes analogy is credited to Art Wong. ## Also in this series Martin de Vries on sector differences and why we may need a NIST 3 — referenced in this episode, publishing 24 September. Aernout Reijmer on collaboration after ASML — publishing 29 September. --- SecurityCafe. Powered by Atos.

    Speed, governance and a changing landscape — Ramsés Gallego
  3. Sep 9

    SecurityCafe — Andreas Wuchner: AI, the boardroom, and the bill nobody budgeted for

    Andreas Wuchner ran large-scale security organisations for some 30 years and now invests in and advises startups, family offices, VC and PE firms. On geopolitical risk, AI governance, and what AI actually costs. Chapters00:00 — Welcome01:00 — In the news: 900+ agents coordinating over a shared channel05:07 — Geopolitical risk is real, and NIST/ISO don't map it07:39 — The CybersecNL keynote: is what we built still good enough?11:40 — "What brings you in jail is non-compliance"13:00 — The AI governance tooling wave14:44 — Punish vs enable: pocket money for Big Tech kills a startup16:53 — The minimum viable control set17:43 — Fines: where does that money actually go?22:50 — What AI means for the business, from a board seat26:30 — Three types of adopters, and AI-native hiring in seven days32:04 — "Meat proxies": what the AI-native crowd calls the rest of us34:47 — AI is not cheap: what a €200 subscription really costs37:10 — $20 per run vs $2.84, same job39:22 — Outsourcing efficiency promises vs rising AI costs41:44 — Augmentation vs a greenfield agentic machine room43:43 — Cooling, solar, subsea, space: the infrastructure race47:19 — What to read, what to watchKey takeawaysA policy keeps you out of jail — and that's all it does. Regulators ask for governance; many tick that box with a document. Anyone declaring AI governance "done" is at the beginning. Define the non-negotiables, then get out of the way. The organisations doing this well name 10 to 50 controls that are not up for discussion and let the rest develop over time — a minimum viable control set. The alternative is the department of no. Token economics is a skill, not a budget line. The same investment-document analysis ran at roughly $20 per company; converting inputs to markdown first brought it to $2.84. A week-long AI strategy course for managers does nothing for the layer that spends the money. MentionedLog Force — a project in Spain predicting indicators of compromise before they become threats, and spotting when agentic systems start hallucinating. Not a commercial product yet.Tehran — the espionage series from What to WatchUber's €824,990,000 fine from the Dutch DPA for fully automated driver deactivation, under GDPR Article 22: https://www.autoriteitpersoonsgegevens.nl/en/current/uber-fined-nearly-825-million-euros-for-automated-driver-blockingThe Odido breach (February 2026): some 6.4 million people and 600,000 companies, including over 5 million ID document numbers. https://nos.nl/artikel/2604461-odido-hackers-publiceren-resterende-klantdata-ook-miljoenen-id-nummersMeta's settlement over harm to minors: up to $17.1 billion, with 52 US attorneys general — not an EU case. https://www.npr.org/2026/08/26/nx-s1-5944781/meta-settlement-child-safety-lawsuitPowered by Atos

    SecurityCafe — Andreas Wuchner: AI, the boardroom, and the bill nobody budgeted for
  4. Jul 23

    "Sovereignty Is the Wrong Word": Digital Autonomy with Mika Lauhde

    SecurityCafe — "Sovereignty Is the Wrong Word": Digital Autonomy with Mika LauhdeHosts: Menno van der Horst & Quint Ketting Guest: Mika Lauhde, Luxembourg House of Cybersecurity (linkedin.com/in/mika-lauhde-4270711) About this episodeMika Lauhde spent 30 years across Nokia, Huawei, and ENISA before landing at Luxembourg House of Cybersecurity, the national hub keeping Luxembourg's municipalities, SMEs, and economy cyber-resilient. His argument: Europe has the wrong word. Not "sovereignty" — hard borders around who owns what — but autonomy: acting independently while still sharing tools and trust. From GPS glitches during US foreign policy disputes, to Europe always getting the second-best tech (fighter jets included), to a national CERT running entirely on open source — this one covers a lot of ground. In this episode00:11 — Welcome & Mika's background (Nokia, Huawei, ENISA, Luxembourg House of Cybersecurity)02:08 — News: an integrator data-leak claim ("888") and what makes integrator breaches different06:06 — Android's new developer certificate as a "kill switch," African nations building their own internet, UK VPN/age-verification rollout, an EU "tech sovereignty" proposal that leans on non-European hardware09:11 — A US court ruling that may have quietly broken a GDPR assumption on data transfers10:34 — NIS2 finally live in NL (15 Aug) — are our laws fast enough for machine-speed attacks?19:20 — The "SplinterNet," and why Mika argues for shared autonomy over walled-garden sovereignty23:46 — The Cyber Resilience Act's unprecedented recognition of open source (79 mentions)24:19 — AI models as the new trade weapon — allies get the previous generation, like fighter jets26:50 — The GPS/Galileo story, and SES's Iris² as Europe's answer to Starlink30:15 — EU tax rules that quietly disadvantage open source; the Nokia N900 as Europe's "Sputnik moment"33:00 — Luxembourg's national CERT runs entirely on open-source tools34:40 — The call to action: a free open-source toolkit so any EU SME can stand up a cyber ops center36:41 — What to read: Quint's, Mika's, and Menno's picks41:04 — Wrap-upKey takeawaysAutonomy, not sovereignty — sharing open standards beats walling off bordersDependency is invisible until it breaks — GPS glitches led to Galileo, now to Iris²New tech follows old patterns — AI models, like military hardware, come second-best to alliesOpen source is operational, not aspirational — Luxembourg's CERT proves it at national scaleMentionedAccenture leak claims (unconfirmed) · NIS2 (NL) · Cyber Resilience Act · European OSPO network · SES Iris² · Trump v. Slaughter ruling Reads: The Subtle Art of Not Giving a Fck* by Mark Manson (markmanson.net/books/subtle-art) · Max Schrems / noyb (noyb.eu/en/us-supreme-court-just-blew-eu-us-data-transfers) · Bert Hubert's blog (berthub.eu) SecurityCafe is hosted by Menno van der Horst and Quint Ketting. Powered by Atos.

    "Sovereignty Is the Wrong Word": Digital Autonomy with Mika Lauhde
  5. Jun 25

    AI Where It Matters, Not AI Everywhere — with Zeina Zakhour, Global Cyber CTO Atos/Eviden

    AI Where It Matters, Not AI Everywhere — with Zeina Zakhour, Global CTO Cybersecurity at Eviden (Atos) Recorded live at CISO Day, this episode brings Menno van der Horst and co-host Quint Ketting together with Zeina Zakhour, Global CTO for Cybersecurity at Eviden (Atos), for a fast-moving conversation on where cyber is heading and what it really takes to keep up. We open with a sobering reality: many of today's threats are exposing weaknesses that have existed for decades. The panic isn't warranted — but action is. Zeina makes the case that the issue is rarely a lack of technology depth, but a lack of security depth: the basic hygiene and foundational controls that too many organisations still treat as something for "next year." Spoiler — next year is no longer an option. From there we get into the heart of it: — Adaptive, systemic resilience. Security can't be an afterthought bolted on once innovation ships. It has to sit at the core. We dig into why maturity built once and then left alone decays faster than most leaders expect. — Risk first, always. You don't secure a water utility the way you secure a hospital, a retailer or a bank. Every organisation has its own ecosystem and purpose — and that's where Eviden's Prepare, Respond, Adapt approach starts: understanding who you are, then keeping your risk picture live rather than buried in a spreadsheet updated once a year. — AI, agents and the new attack surface. Not "AI everywhere" — AI where the risk, the data and the friction justify it. We talk identity as the number one attack vector, the danger of human-led processes throttling machine-speed tooling, prompt and meta-prompt injection, agent goal drift, kill switches, and what "identity" even means for an autonomous agent that has intent, makes decisions and calls tools. — Chained vulnerabilities. Why "we'll only fix the high-severity CVEs" is the wrong instinct — low-severity issues can be chained into something genuinely exploitable, fast. — Sovereignty vs autonomy. A crucial distinction too many conflate. We get into data residency, technological sovereignty, the model/middleware/GPU reality of "sovereign AI" today, post-quantum, and why Europe can only answer these questions together rather than country by country. We close where good security conversations always seem to land: sharing more, building a bubble of trust, backing European innovation and startups, and staying agile enough to adapt as the ground keeps shifting. Zeina's recommendations: 📑 Atos Cyber Shield blog and Threat Research Center — regular, genuinely interesting analysis on new campaigns and malware variants. 📖 The Five People You Meet in Heaven by Mitch Albom — nothing to do with cyber, everything to do with being worth your time. 🎧 Listen now, and let us know your take in the comments. #SecurityCafe #Cybersecurity #CISO #AISecurity #Resilience #DigitalSovereignty

    AI Where It Matters, Not AI Everywhere — with Zeina Zakhour, Global Cyber CTO Atos/Eviden
  6. May 28

    Data is the New Uranium: Critical Infrastructure, CISOCommunity & AI with Dimitri van Zantvliet (NS)

    A SecurityCafe special, recorded live at CISOday 2026 with Dimitri van Zantvliet — CISO & Cybersecurity Director at Nederlandse Spoorwegen (NS), Chairman of the CISO Community NL and co-founder of CISOday. Host Menno van der Horst is joined by co-host Quint Ketting for a wide-ranging conversation on what it actually takes to defend critical infrastructure in a world where the geopolitical, technological and threat landscape is shifting faster than ever. In this episode: - Why CISOday and the CISO Community NL exist, and how community accelerates maturity across the sector - Becoming a NIS1 critical entity in 2021 and how the war in Ukraine reshaped NS's threat model overnight - Belarusian railway wiperware, Iranian-aligned activity, and the recent railway incident in Florida - Working with NCSC, NCTV, AIVD, the Rail-ISAC and Dutch ISAC to exchange threat intel - Building an in-house CTI team of five — strategic, tactical, operational and technical - The NS Cyber Academy: training people from train drivers to office staff into cyber roles, plus SANS, CISSP and CISA tracks - Why stamina and curiosity beat a classic IT background when hiring — including the case for ex-Olympians, HYROX athletes and journalists - The cultural shift from "my threat intel is my IP" to active two-way sharing across the ecosystem - Supplier risk as a knock-out criterion: no ISO 27001 / SOC 2 Type 2, no business - AI and Gen.AI as the new frontier — from "data is the new gold" to "data is the new uranium" - Quantum on the horizon, and why the impact reaches far beyond encryption - The basics still decide everything: MFA, passwords, segmentation — and the move toward real-time patching - Autonomous agents as the next attack vector we don't yet fully understand - Historical parallels, from the AIDS Trojan on floppy disk to ILOVEYOU and SQL Slammer - Nassim Taleb's Antifragile — and why "prepare, respond, adapt" is the cycle every organisation needs - Cybersecurity is no longer an IT conversation; it's geopolitics, brand, and business continuity Book of the episode: - Antifragile — Nassim Nicholas Taleb About the guest: Dimitri van Zantvliet is CISO & Cybersecurity Director at NS, Chairman of the CISO Community NL and co-founder of CISOday. He joined NS five years ago and has led the organisation's response to the post-2021 shift in geopolitical and cyber risk affecting European critical infrastructure. Working at NS: Dimitri's team is hiring. If cybersecurity at one of the Netherlands' most critical infrastructure providers sounds like your kind of challenge, check the openings at werkenbijns.nl. About SecurityCafe: SecurityCafe is hosted by Menno van der Horst with co-host Quint Ketting — an open conversation about the strategic, technical and human sides of cybersecurity. Produced by Quint Ketting. Subscribe wherever you get your podcasts. This CISOday special was made possible in partnership with Atos.

    Data is the New Uranium: Critical Infrastructure, CISOCommunity & AI with Dimitri van Zantvliet (NS)
  7. May 12 ·  Bonus

    SecurityCafe Special | Mythos – Facts, Fiction and What You Need to Do Now

    About this episode In this special edition of SecurityCafe, Quint Ketting and Koen Maris join host Menno van der Horst for an open, no-nonsense conversation about Mythos — Anthropic's frontier AI model expected to become more widely available around mid-August. No panic, no hype — just an honest look at what will actually change, and what your organization should already have been doing. What we cover Mythos: revolution or evolution? Koen opens with a sharp reality check: if it takes five days to build an exploit today and Mythos brings that down to twenty hours — how much really changes? The hype around Mythos risks drawing attention away from what's already happening. Claude Opus 4.7 is already live, carrying many of the same capabilities, with barely anyone noticing. The real shift: accessibility The barrier to sophisticated attacks is dropping fast. It's not that experts are becoming more dangerous — it's the new wave of attackers without deep technical skills that warrants concern. Quint illustrates the point with his own experience using Claude: from building custom tools to recovering audio from a faulty recording. What this means for your organization Cyber hygiene first. If your foundations aren't in order, you already have a problem — Mythos just makes it more visible and more urgent.Third-party contracts. Patch response clauses of 90 days or more are no longer viable. Time to renegotiate.Asset management. If you don't know what you have, you don't know what to protect. A scan often reveals 40% more assets than organizations think they manage.Exposure management. Unmanaged assets are exactly where attackers will strike first.Patch cycles. Microsoft recently released 250 patches in a single Patch Tuesday — normally 10 to 20. That pattern is not a coincidence.Prepare, Respond, Adapt Koen introduces the PRA framework: we are currently in a fragile peace. Use this window well. Organizations that prepare thoroughly will weather the storm quickly. Those that don't may find themselves in a prolonged and costly recovery. Frontier AI: the next buzzword — and what it actually means Mythos is part of a broader phenomenon. Vendors like Palo Alto are already embedding the same AI engines into their defensive toolsets. The question isn't whether this will affect you — it's whether you'll be ready. Project Glasswing & responsible disclosure Anthropic has given early access to a select group of major technology companies, resulting in both an explosion of patches and new AI-powered defenses. Responsible management of this capability is exactly the right approach — and a model the industry should follow. Key takeaways Start an internal working group now. Structure it with proper governance, board-level reporting, and weekly progress reviews.Review your third-party agreements: do your SLAs still hold in a world of 24/7 patching?Don't wait for Mythos to get your basics right. A low security maturity level cannot be fixed in two months.Frontier AI is the bigger frame. Follow developments across Anthropic, Google, and others — not just the Mythos headlines.Guests linkedin.com/in/menno-van-der-horst-74710794linkedin.com/in/koen-marislinkedin.com/in/quintketting

    SecurityCafe Special | Mythos – Facts, Fiction and What You Need to Do Now
  8. May 7

    Navigating the Future of Cybersecurity, Frontier-AI, and Society: Insights from the Security Café

    SecurityCafe – Liesbeth Holterman, Cyberveilig NederlandHosts: Quint Ketting & Menno Recorded: Eindhoven Studio (our first ever in-person guest!) We always say: Prepare. Respond. Adapt. — Quint's microphone broke mid-recording. We practiced what we preached. 🎙️💀 About Our GuestLiesbeth Holterman is Managing Director of Cyberveilig Nederland — the Dutch trade association for the cybersecurity industry, focused on improving quality, transparency, and the digital resilience of the Netherlands. What We DiscussedData leaks — daily news, preventable problems Breaches are no longer weekly — they're daily. Social engineering, not sophisticated hacking, is the attacker's weapon of choice. The Odido case is a perfect example. Basic cyber hygiene remains the answer. Check your credentials: 👉 HaveIBeenPwned.com AI & Mythos — marketing or menace? Agentic AI can scan environments and find zero-days at scale. Bad actors have been using LLMs for a while already — what's new is that low-skill attackers now have access too. Bruce Schneier calls some of the fear "marketing hype" — but the underlying shift is real. The good news: in 4–5 years, defence will benefit just as much. 👉 Schneier on Security NIS2 & EU legislation Don't know where to start with cyber hygiene? Read NIS2 Article 21 — it's a solid baseline checklist. Legislation is finally getting boards to ask the right questions. 👉 NIS2 Directive | Article 21 Dutch critical infrastructure The Netherlands' legendary efficiency — remote dikes, interconnected logistics, everything online — is also its biggest attack surface. The cybersecurity workforce of tomorrow AI will reshape roles like pen testing and SOC analysis. But the need for cyber professionals is still enormous. The sector isn't thinking strategically enough about what this means. Liesbeth's call: reach out, collaborate, have the conversation. 👉 cyberveilignederland.nl 🎬 RecommendationsQuint → Hanna (Amazon Prime) A girl targeted by a CIA program for what an algorithm predicts she'll do — not what she's done. A thought-provoking lens on AI, surveillance, and pre-emptive power. 👉 IMDb Liesbeth → The Boys (Amazon Prime) Superheroes in the hands of a private corporation guided by profit, not public interest. Sound familiar? 👉 IMDb SecurityCafe — because good security conversations deserve good coffee.

    Navigating the Future of Cybersecurity, Frontier-AI, and Society: Insights from the Security Café

About

“Pull up a chair at the Security Café – your monthly deep dive into the hottest cybersecurity news and trends. Each episode brings you an inspiring guest and a story that will spark your imagination. Produced by Quint & Menno (Atos), this is where insights meet conversation. Don’t just stay informed—join the discussion!”