Follow the White Rabbit - IT Security Podcast - English Edition cover art

Follow the White Rabbit - IT Security Podcast - English Edition

Follow the White Rabbit - IT Security Podcast - English Edition

By: Link11
Listen for free

"Wake up, Neo. The Matrix has you." Welcome to the rabbit hole of cybersecurity. Instead of a red pill, we offer something much more valuable: clarity in a world of digital chaos. With cyberattacks surging globally and costing businesses billions while threatening critical infrastructure, staying ahead of the curve isn't just for IT pros - it’s a necessity for everyone. Follow the White Rabbit for your backstage pass to the frontlines of IT security. Hosted by Kofi Osae-Attah, the information security officer at Link11, we explore the strategies of modern attackers and the cutting-edge defenses that protect our digital future. Why subscribe? Global Insights: From our headquarters in Frankfurt, Germany, we discuss cyber resilience that transcends borders. Cutting-Edge Tech: Discover how AI and machine learning are revolutionizing DDoS attacks and automated defense mechanisms. Regulatory Roadmap: We demystify NIS2, the Cyber Resilience Act, and the EU AI Act to reveal what matters most for your business. Expert Access: Join us for candid conversations with industry leaders and Link11’s top security architects. Whether you're a CISO, tech enthusiast, or business owner navigating the cloud, we provide the insights you need to protect yourself against data breaches, identity theft, and infrastructure disruptions. Follow the White Rabbit. Your journey into the heart of cybersecurity starts now. Keep calm and get protected.Copyright 2026 Link11 Politics & Government
Episodes
  • #13: The Cloud Sovereignty Myth: What "Encrypted in Europe" Actually Means
    Sep 24 2026

    That's the answer that almost every European company gives when asked about cloud security. According to Clémence Caron, however, it's worth almost nothing. The real question is never where your data sits. It's who can be compelled to access it, regardless of the server's location. In this episode of Follow the White Rabbit, Link11 CISO Kofi Osae-Attah sits down with Clémence Caron, a cloud and AI security specialist at Google Cloud. Clémence started her career engineering security for naval vessels. In this episode, she and Kofi talk about what digital sovereignty requires and how checkbox compliance is quietly letting through.

    The conversation is refreshingly candid, especially for someone who works for a hyperscaler. Clémence doesn't sell sovereignty as a product. She frames it as a risk-tiered decision that depends entirely on what you're protecting and from whom. Her thesis is clear: You can't fight AI-speed attacks with human-speed defenses. However, before companies can implement automated detection, they must first address issues that cost almost nothing, such as misconfigured service accounts. Misconfigured service accounts, Shared admin privileges. They lack a documented incident response process. These are the basics that, if done right, would stop most attacks before they start.

    The sharpest moment comes when Kofi asks whether real digital sovereignty is achievable. Her answer differs from what cloud marketing would tell you: You'll never be fully independent, and that's probably fine, if you choose your risks wisely. Sovereignty isn't a checkbox or a setting. It's a series of deliberate decisions about what you need to protect, what you're willing to lose, and how quickly you can recover if something goes wrong.

    Takeaways
    1. Location does not equate to control. Data stored in a European data center can still be accessible under foreign law. The important questions are who can be compelled to access the data and whether encryption and key management can prevent that access.
    2. You cannot fight AI-speed attacks with human-speed responses. A human analyst looking at 500 alerts per minute will always be too late. Automation is no longer optional. However, none of this matters if your service accounts have admin access to everything.
    3. The basics are still the first line of defense: Least privilege. Patching. Key rotation. Documented incident response. These measures aren't exciting, but they stop most attacks before they can be detected. They're also inexpensive.
    4. Compliance is a starting point, not a finish line. Certifications can force companies to start thinking about security. However, if the goal is merely to check a box rather than to understand risk, you've created paperwork, not protection.
    5. Sovereignty is a spectrum, not an on/off switch. From public cloud with managed encryption to fully air-gapped on-prem, there is no single right answer. The right answer depends on what needs to be available and confidential and how quickly you can recover if something goes wrong.

    Subscribe to Follow the Rabbit

    If this episode changed the way you think about cloud security, digital sovereignty, or the difference between compliance and real protection, share it! Subscribe on your preferred platform and share it with your cloud and compliance teams, as well as with anyone who thought that keeping data in Europe was sufficient.

    Links

    Clémence Caron – Cloud & AI Security Specialist, Google Cloud

    CLOUD Act – US Law & Its Implications for European Data

    BSI: Cloud Computing Security Recommendations

    Show More Show Less
    50 mins
  • #12: The Emotet Takedown: How Chaos, Beer, and an Uncontrollable Coalition Beat a $2 Billion Criminal Network
    Sep 10 2026

    There are 1.6 million infected machines. Hundreds of millions in damage. The engine behind the world's worst ransomware disappeared overnight. The man who spent a year and a half making that happen says the secret weapon was chaos. His team was disorganized, unpredictable, and sometimes unreliable. Some nights, the man leading the charge was just out drinking beer. Brian Hein argues that this is exactly why the criminals couldn't beat them. In this episode of Follow the White Rabbit, Link11 CISO Kofi Osae-Attah sits down with Brian, a threat researcher, DNS intelligence analyst, and contributor to the World Economic Forum's Cybercrime Atlas, to talk about what it actually took to kill Emotet.

    Brian likes to ask rooms full of security professionals a question: If your company shut down its threat intelligence program tomorrow, would the criminals even notice? His argument is uncomfortable yet precise. Most of what the security industry produces is performative theater: reports that no one reads, dashboards that no one acts on, and indicators that no one uses. He calls it negligent intelligence theater. Real impact, he says, looks different. It resembles an uncontrollable coalition of carriers, researchers, and law enforcement, each chipping away at the same problem from different angles. None of them coordinate perfectly, and that's the point.

    The conversation also goes in an unexpected direction: the human infrastructure behind cybersecurity. Trust groups die out when no one brings in new blood. Conferences where a 45-year-old is one of the youngest people in the room. It discusses how geopolitics fractures longstanding alliances and why recipes for hummus and maple syrup candies are sometimes the fastest way to rebuild them. Brian's message to the next generation at their first hacker congress is that there is no wall. There is no door. Just walk in.

    Takeaways
    1. Disorganization was the weapon. The Emotet coalition worked precisely because it was unpredictable. When Brian was unavailable because he was at a bar, the attack patterns shifted. Criminals can't model chaos. That lesson scales.
    2. Most threat intelligence is theater. Reports are skimmed. Dashboards are ignored. The important question is whether your work influenced a decision. If not, you're producing performance art.
    3. Board communication is storytelling, not reporting. Brian reframed Emotet as taking out a hostile competitor with a $2 billion revenue pipeline, which got executive attention. That got the attention of executives. The technical details weren't necessary.
    4. The community is one retirement wave away from a knowledge crisis. The pandemic eliminated travel budgets. Conferences are filled with the same senior professionals. Junior professionals aren't being brought in, and trust groups can't survive without new blood.
    5. Attribution matters, but not to everyone. To a board member, whether it was Paul from South Dakota or a North Korean state actor makes no difference. However, it matters enormously to law enforcement and policy. Know your audience before opening your report.

    Subscribe to Follow the Rabbit

    If this episode made you think differently about the purpose of threat intelligence and who it serves, share it. Subscribe on your preferred platform, leave a review, and share it with the next junior analyst who hasn't attended a conference. They need to hear how this conversation ends.

    Links

    Brian Hein – Threat Researcher, DNSFilter | World Economic Forum Cybercrime Atlas | Former Deutsche Telekom

    DNSFilter – Secure DNS & Threat Intelligence

    WEF_Cybercrime_Atlas_Impact_Report_2025.pdf

    Europol: Operation LadyBird – Emotet Takedown

    Show More Show Less
    39 mins
  • #11: 63% of CISOs Have Experienced Burnout. Boards Still Call It a People Problem.
    Jul 16 2026
    The average CISO tenure has dropped from 26 months to six to nine months. Not because the role attracts the wrong people, but because it is structurally designed to fail. In this episode of Follow the White Rabbit, Link11 ISO Kofi Osae-Attah talks to Jeroen Schipper, Chief Security Advisor at DEFION Security about the crisis hiding in plain sight inside security leadership. Jeroen was CISO of The Hague for seven years, a city that hosts the International Criminal Court, NATO, Europol, and the Dutch royal family. He could predict cyberattacks within 48 hours of any politically sensitive event at the ICC. He knows what sustained pressure feels like from the inside and the cost when organisations refuse to treat it as a structural problem.The conversation looks at a dynamic that most boards still misread. A CISO identifies the risk, writes the analysis, hands over the signed risk acceptance letter – and still takes the blame when something goes wrong. The question that follows an incident is never "why didn't the board act?" It's always "what did the CISO miss?" That gap between responsibility and authority isn't just unfair. It's a security vulnerability. A burned-out CISO experiences what research calls risk blindness – a desensitisation caused by chronic overload that affects exactly the kind of judgment the organisation is depending on. And unlike an ER doctor, there's rarely anyone who can step in and cover. The good people leave. The revolving door keeps spinning. And every few months, one of the most critical roles in the entire risk structure starts over from scratch.He organised "Hack The Hague", which involved inviting 120 ethical hackers to attack the city's live infrastructure in the middle of City Hall. This event helped to establish long-lasting board-level commitment to security. His advice for boards is simple: talk to your CISO. Ask what they need. Ask how you can help. If that conversation happened in every boardroom, it could create the shift the profession has been waiting for.TakeawaysCISO burnout is a governance issue, not a personnel issue. 63% of CISOs worldwide have experienced burnout. The role is set up to fail structurally: you are responsible for outcomes you don't control, you report to boards that see security as a cost centre and you are blamed when the risks you have flagged are not addressed.The risk acceptance letter is not a shield. When a CISO documents a risk, escalates it and gets it signed off, only to take the blame when something goes wrong, accountability without authority becomes a trap. Too many CISOs fall into this trap unwittingly.Protect the CISO to protect the organisation. A burned-out CISO develops risk blindness. When someone in your most critical security role leaves after six months, all their knowledge of your environment leaves with them. The revolving door itself is a vulnerability.Hack The Hague worked because commitment came from the top. Inviting 120 hackers to attack live city infrastructure in the middle of City Hall sounds radical. It worked because the council approved it. Start smaller – with a bug bounty programme or a responsible disclosure policy, for example – but get the buy-in first.One conversation can shift the dynamic. Boards don't need a new framework. They need to ask their CISO what they need and how they can help. Making the board the entity that owns the risk, rather than just the CISO, changes everything downstream.Subscribe to Follow the RabbitIf this episode has made you think about the weight that is being carried by one person in your organisation that was never designed to be carried by one person, share it. Subscribe on your preferred platform, leave a review and share it with every board member, CEO and security leader who still believes that CISO burnout is an HR issue.LinksJeroen Schipper – Chief Security Advisor, DEFION Security | Former CISO of The Hague | First-ever CISO of the Year, Netherlands | LinkedinHack The Hague – Bug Bounty & Ethical Hacking ProgrammeENISA: NIS2 Directive – Board Accountability for CybersecurityDORA – Digital Operational Resilience ActISC²: CISO Burnout & Workforce Research
    Show More Show Less
    37 mins
adbl_web_anon_alc_button_suppression_t1
No reviews yet