• #13: The Cloud Sovereignty Myth: What "Encrypted in Europe" Actually Means
    Sep 24 2026

    That's the answer that almost every European company gives when asked about cloud security. According to Clémence Caron, however, it's worth almost nothing. The real question is never where your data sits. It's who can be compelled to access it, regardless of the server's location. In this episode of Follow the White Rabbit, Link11 CISO Kofi Osae-Attah sits down with Clémence Caron, a cloud and AI security specialist at Google Cloud. Clémence started her career engineering security for naval vessels. In this episode, she and Kofi talk about what digital sovereignty requires and how checkbox compliance is quietly letting through.

    The conversation is refreshingly candid, especially for someone who works for a hyperscaler. Clémence doesn't sell sovereignty as a product. She frames it as a risk-tiered decision that depends entirely on what you're protecting and from whom. Her thesis is clear: You can't fight AI-speed attacks with human-speed defenses. However, before companies can implement automated detection, they must first address issues that cost almost nothing, such as misconfigured service accounts. Misconfigured service accounts, Shared admin privileges. They lack a documented incident response process. These are the basics that, if done right, would stop most attacks before they start.

    The sharpest moment comes when Kofi asks whether real digital sovereignty is achievable. Her answer differs from what cloud marketing would tell you: You'll never be fully independent, and that's probably fine, if you choose your risks wisely. Sovereignty isn't a checkbox or a setting. It's a series of deliberate decisions about what you need to protect, what you're willing to lose, and how quickly you can recover if something goes wrong.

    Takeaways
    1. Location does not equate to control. Data stored in a European data center can still be accessible under foreign law. The important questions are who can be compelled to access the data and whether encryption and key management can prevent that access.
    2. You cannot fight AI-speed attacks with human-speed responses. A human analyst looking at 500 alerts per minute will always be too late. Automation is no longer optional. However, none of this matters if your service accounts have admin access to everything.
    3. The basics are still the first line of defense: Least privilege. Patching. Key rotation. Documented incident response. These measures aren't exciting, but they stop most attacks before they can be detected. They're also inexpensive.
    4. Compliance is a starting point, not a finish line. Certifications can force companies to start thinking about security. However, if the goal is merely to check a box rather than to understand risk, you've created paperwork, not protection.
    5. Sovereignty is a spectrum, not an on/off switch. From public cloud with managed encryption to fully air-gapped on-prem, there is no single right answer. The right answer depends on what needs to be available and confidential and how quickly you can recover if something goes wrong.

    Subscribe to Follow the Rabbit

    If this episode changed the way you think about cloud security, digital sovereignty, or the difference between compliance and real protection, share it! Subscribe on your preferred platform and share it with your cloud and compliance teams, as well as with anyone who thought that keeping data in Europe was sufficient.

    Links

    Clémence Caron – Cloud & AI Security Specialist, Google Cloud

    CLOUD Act – US Law & Its Implications for European Data

    BSI: Cloud Computing Security Recommendations

    Show More Show Less
    50 mins
  • #12: The Emotet Takedown: How Chaos, Beer, and an Uncontrollable Coalition Beat a $2 Billion Criminal Network
    Sep 10 2026

    There are 1.6 million infected machines. Hundreds of millions in damage. The engine behind the world's worst ransomware disappeared overnight. The man who spent a year and a half making that happen says the secret weapon was chaos. His team was disorganized, unpredictable, and sometimes unreliable. Some nights, the man leading the charge was just out drinking beer. Brian Hein argues that this is exactly why the criminals couldn't beat them. In this episode of Follow the White Rabbit, Link11 CISO Kofi Osae-Attah sits down with Brian, a threat researcher, DNS intelligence analyst, and contributor to the World Economic Forum's Cybercrime Atlas, to talk about what it actually took to kill Emotet.

    Brian likes to ask rooms full of security professionals a question: If your company shut down its threat intelligence program tomorrow, would the criminals even notice? His argument is uncomfortable yet precise. Most of what the security industry produces is performative theater: reports that no one reads, dashboards that no one acts on, and indicators that no one uses. He calls it negligent intelligence theater. Real impact, he says, looks different. It resembles an uncontrollable coalition of carriers, researchers, and law enforcement, each chipping away at the same problem from different angles. None of them coordinate perfectly, and that's the point.

    The conversation also goes in an unexpected direction: the human infrastructure behind cybersecurity. Trust groups die out when no one brings in new blood. Conferences where a 45-year-old is one of the youngest people in the room. It discusses how geopolitics fractures longstanding alliances and why recipes for hummus and maple syrup candies are sometimes the fastest way to rebuild them. Brian's message to the next generation at their first hacker congress is that there is no wall. There is no door. Just walk in.

    Takeaways
    1. Disorganization was the weapon. The Emotet coalition worked precisely because it was unpredictable. When Brian was unavailable because he was at a bar, the attack patterns shifted. Criminals can't model chaos. That lesson scales.
    2. Most threat intelligence is theater. Reports are skimmed. Dashboards are ignored. The important question is whether your work influenced a decision. If not, you're producing performance art.
    3. Board communication is storytelling, not reporting. Brian reframed Emotet as taking out a hostile competitor with a $2 billion revenue pipeline, which got executive attention. That got the attention of executives. The technical details weren't necessary.
    4. The community is one retirement wave away from a knowledge crisis. The pandemic eliminated travel budgets. Conferences are filled with the same senior professionals. Junior professionals aren't being brought in, and trust groups can't survive without new blood.
    5. Attribution matters, but not to everyone. To a board member, whether it was Paul from South Dakota or a North Korean state actor makes no difference. However, it matters enormously to law enforcement and policy. Know your audience before opening your report.

    Subscribe to Follow the Rabbit

    If this episode made you think differently about the purpose of threat intelligence and who it serves, share it. Subscribe on your preferred platform, leave a review, and share it with the next junior analyst who hasn't attended a conference. They need to hear how this conversation ends.

    Links

    Brian Hein – Threat Researcher, DNSFilter | World Economic Forum Cybercrime Atlas | Former Deutsche Telekom

    DNSFilter – Secure DNS & Threat Intelligence

    WEF_Cybercrime_Atlas_Impact_Report_2025.pdf

    Europol: Operation LadyBird – Emotet Takedown

    Show More Show Less
    39 mins
  • #11: 63% of CISOs Have Experienced Burnout. Boards Still Call It a People Problem.
    Jul 16 2026
    The average CISO tenure has dropped from 26 months to six to nine months. Not because the role attracts the wrong people, but because it is structurally designed to fail. In this episode of Follow the White Rabbit, Link11 ISO Kofi Osae-Attah talks to Jeroen Schipper, Chief Security Advisor at DEFION Security about the crisis hiding in plain sight inside security leadership. Jeroen was CISO of The Hague for seven years, a city that hosts the International Criminal Court, NATO, Europol, and the Dutch royal family. He could predict cyberattacks within 48 hours of any politically sensitive event at the ICC. He knows what sustained pressure feels like from the inside and the cost when organisations refuse to treat it as a structural problem.The conversation looks at a dynamic that most boards still misread. A CISO identifies the risk, writes the analysis, hands over the signed risk acceptance letter – and still takes the blame when something goes wrong. The question that follows an incident is never "why didn't the board act?" It's always "what did the CISO miss?" That gap between responsibility and authority isn't just unfair. It's a security vulnerability. A burned-out CISO experiences what research calls risk blindness – a desensitisation caused by chronic overload that affects exactly the kind of judgment the organisation is depending on. And unlike an ER doctor, there's rarely anyone who can step in and cover. The good people leave. The revolving door keeps spinning. And every few months, one of the most critical roles in the entire risk structure starts over from scratch.He organised "Hack The Hague", which involved inviting 120 ethical hackers to attack the city's live infrastructure in the middle of City Hall. This event helped to establish long-lasting board-level commitment to security. His advice for boards is simple: talk to your CISO. Ask what they need. Ask how you can help. If that conversation happened in every boardroom, it could create the shift the profession has been waiting for.TakeawaysCISO burnout is a governance issue, not a personnel issue. 63% of CISOs worldwide have experienced burnout. The role is set up to fail structurally: you are responsible for outcomes you don't control, you report to boards that see security as a cost centre and you are blamed when the risks you have flagged are not addressed.The risk acceptance letter is not a shield. When a CISO documents a risk, escalates it and gets it signed off, only to take the blame when something goes wrong, accountability without authority becomes a trap. Too many CISOs fall into this trap unwittingly.Protect the CISO to protect the organisation. A burned-out CISO develops risk blindness. When someone in your most critical security role leaves after six months, all their knowledge of your environment leaves with them. The revolving door itself is a vulnerability.Hack The Hague worked because commitment came from the top. Inviting 120 hackers to attack live city infrastructure in the middle of City Hall sounds radical. It worked because the council approved it. Start smaller – with a bug bounty programme or a responsible disclosure policy, for example – but get the buy-in first.One conversation can shift the dynamic. Boards don't need a new framework. They need to ask their CISO what they need and how they can help. Making the board the entity that owns the risk, rather than just the CISO, changes everything downstream.Subscribe to Follow the RabbitIf this episode has made you think about the weight that is being carried by one person in your organisation that was never designed to be carried by one person, share it. Subscribe on your preferred platform, leave a review and share it with every board member, CEO and security leader who still believes that CISO burnout is an HR issue.LinksJeroen Schipper – Chief Security Advisor, DEFION Security | Former CISO of The Hague | First-ever CISO of the Year, Netherlands | LinkedinHack The Hague – Bug Bounty & Ethical Hacking ProgrammeENISA: NIS2 Directive – Board Accountability for CybersecurityDORA – Digital Operational Resilience ActISC²: CISO Burnout & Workforce Research
    Show More Show Less
    37 mins
  • #10: 90 Minutes. One Laptop. Working Malware. AI Just Changed the Rules.
    Jul 2 2026
    A security analyst experimented with a public AI, meticulously crafting malware capable of evading detection. This wasn't done by a nation state or a criminal gang; it was Northwave, a Dutch cybersecurity firm. Their CTO, Christiaan Ottow, a former ethical hacker, oversaw the experiment. In this episode of Follow the White Rabbit, Kofi Osae-Attah talks with Christiaan about the experiment's findings and his belief that we've reached a critical point he and his team predicted in September.Christiaan isn't an alarmist. He was skeptical of LLM hype, but the data changed his mind. His incident response team investigated a breach where they gained rare access to the attacker's staging server and found files documenting the AI's reasoning, plans, and execution steps. The attack used zero-day vulnerabilities, pivoted between cloud environments, and went undetected despite the victim having EDR and next-generation firewalls. The attacker didn't need hacking skills; they just needed to find a way around the AI's guardrails. This is the new baseline. The barrier to entry has collapsed, and attribution is becoming impossible as every threat actor uses the same models.The implications for defenders are stark, but Christiaan's advice is practical. Agentic AI isn't a competitive advantage; it's a baseline requirement. However, speed without structure is dangerous. Automated response needs a fine-grained authority matrix, prompt injection risks need to be engineered around, and most security teams are missing a complete, accurate inventory of their assets and identities. The organizations waiting for proof that this shift is real are about to get it. In the worst possible way.Takeaways:The inflection point has arrived. Christiaan's team predicted it would arrive in April 2026. It arrived on schedule: Anthropic's Mythos, GPT 5.5, and the first fully AI-driven attack investigated by their incident response team all occurred in the same month.AI attackers operate like an entire team. A human hacker has one area of expertise. An AI agent has them all simultaneously: software vulnerabilities, cloud misconfigurations, Windows environments, and identity exploitation. Attribution is becoming nearly impossible.Your defensive AI is also an attack surface. Prompt injection into agentic SOC systems poses a real threat. Treat your AI agent as you would software or a human employee: isolate it technically, provide guardrails, and explicitly train it on what it is allowed to do.Asset and identity inventory is now a top-tier security priority. Knowing what systems you have, what software they run, which API keys exist, and what permissions they carry used to be basic hygiene. Under AI-speed attacks, it's critical infrastructure for incident response.The question isn't whether AI changes the threat landscape. It already has. Run this thought experiment: What if the volume of attacks triples? What if the time between discovering a vulnerability and its exploitation is reduced to zero? If you can't answer these questions, you should.Subscribe to Follow the White RabbitIf this episode made the threat feel more concrete than it did an hour ago, then we've done our job. Subscribe on your preferred platform, leave a review, and share this episode with every CISO, SOC lead, and security engineer in your network. The gap between now and then is smaller than most defenders realize.Links:Christiaan Ottow, CTO, Northwave Cyber Security on Linkedin Kofi Osae-Attah Jr. | LinkedIn How AI-Driven Cyberattacks Are Changing the Threat Landscape in 2026"The Day-Zero Normal" Rob Fuller · Chief Information Security Officer Anthropic: Project Glasswing & Mythos PreviewMITRE ATT&CK: Agentic AI Threat ModelingRecommended book: The Art of Intrusion – Kevin Mitnick
    Show More Show Less
    24 mins
  • #09: Hype vs. Reality: What AI in the SOC Actually Looks Like
    Jun 18 2026

    Right now, everyone's selling AI-powered security operations. The pitch sounds great: faster detection, smarter triage, and less noise. However, if your logging is disorganized, your playbooks don't exist, and no one is responsible for the process, AI won't improve your SOC. It'll just make it faster at doing the wrong thing. In this episode of Follow the White Rabbit, Link11 CISO Kofi Osae-Attah sits down with Erik Van Buggenhout, NVISO co-founder and SANS instructor, to cut through the hype and discuss what AI in the SOC looks like in practice.

    Erik is an AI optimist but, more importantly, he's a realist. He has spent years building security operations at scale and knows exactly where automation succeeds and where it falls short. His take? Up to 70% of incoming alerts can be automated without AI. Static playbooks, when built and maintained properly, do most of the heavy lifting, cheaply and reliably. AI earns its place where context matters, such as in dynamic environments, nuanced triage, and situations where a rigid playbook runs out of answers. The sweet spot isn't AI everywhere. It's AI where judgment is needed and automation everywhere else.

    However, the conversation goes deeper than tools. Who's accountable when an AI agent makes a wrong decision? What will happen to the career path of junior analysts when L1 work disappears? Why does the security industry keep rebranding the same problems with new buzzwords every three years? Erik doesn't sugarcoat any of it, which is exactly what makes this episode worth your time.

    Takeaways:
    1. AI won't fix a broken SOC. Garbage in, garbage out—faster. Before buying any AI tooling, first sort out your log sources, processes, and ownership.
    2. Seventy percent automation is already possible without AI. Static playbooks that are properly maintained can handle most of the alert volume. AI is the next layer, not the foundation.
    3. AI genuinely adds value through context. Managed service providers can't know every customer environment in detail. AI coupled with retrieval-augmented generation can provide that context on a large scale without requiring humans to memorize everything.
    4. Humans remain accountable. AI agents operate with identities and permissions, but responsibility ultimately rests with the person operating them. Having a human in the loop isn't optional; it's a structural necessity.
    5. The industry's buzzword cycle is exhausting and confusing. SIEM became XDR, and now XDR is becoming AI SOC. Same problem, new name. Erik argues for a more pragmatic and less dramatic approach to what's actually changing.

    Listen in and subscribe to Follow the White Rabbit.

    If this episode made you think twice about that AI SOC pitch in your inbox, good! Subscribe on your preferred platform and leave a review. It only takes 30 seconds, and it helps us reach those who need to hear this the most. Share it with your security team, your CISO, or anyone who's been handed an AI tool without a plan.

    Links:

    You'll find Erik on Linkedin and here more about NVISO.

    If you want to dive deeper:

    SOC-CMM – SOC Capability Maturity Model

    SANS Institute – Purple Teaming & SOC Courses

    MITRE ATT&CK – Detection & Response Framework

    Gartner on AI in Security Operations (2024)

    Show More Show Less
    22 mins
  • #08: AI Isn't Just Changing How We're Attacked. It's Changing What We Believe Is Real.
    Jun 4 2026
    Most security teams are having the AI conversation about faster phishing, smarter malware, and automated attacks. However, a larger shift is occurring that barely makes it onto SOC dashboards. AI is now being used to industrialize disinformation on a scale no human-run operation could ever match. There are millions of AI agents, with no upper limit on volume, and the public can't tell what's real anymore. In this episode of Follow the White Rabbit, Link11 ISO Kofi Osae-Attah sits down with Anett Mádi-Nándor, president of the Women4Cyber Foundation and CEO of CyEx.hu, to discuss the intersection of AI, geopolitics, cognitive warfare, and diversity in cybersecurity.Anett brings a rare combination of perspectives: she spent half her career in national security and EU administration and the other half in the private sector building AI-engineered cybersecurity solutions. Her diagnosis of our situation in 2026 is sharp and uncomfortable. We are already in an era of continuous cognitive warfare. Social media algorithms, shaped by a decade of user profiling, are now being weaponized with agentic AI to launder narratives on an industrial scale. The result, she says, is reality apathy: a growing portion of the public that simply stops trying to distinguish truth from manipulation. In doing so, they cede even more ground to adversaries. She argues that Europe's regulatory framework is strong but overly complex. Furthermore, the technical gap between what AI can do and what most organizations understand about it is widening.The conversation doesn't stop at geopolitics. Anett makes a compelling case that diversity in cybersecurity isn't a soft issue — it's a security issue. Biased AI models make biased decisions. Organizations using off-the-shelf HR tools often have no idea how those tools were trained and lack an audit process to find out. Kofi shares his experience of applying for jobs under a different name and receiving more callbacks to illustrate what's at stake when bias in automated systems goes unchecked. What's Anett's answer to all of it? Start with the children. Teach five-year-olds to code and understand networks so they can navigate the digital world critically. Estonia has been doing so for years. The rest of the world is behind.Takeaways:AI has eliminated the volume limit on disinformation. Human-run influence operations were limited by the number of people involved. AI-powered operations aren't. Millions of agents can now simultaneously reshape narratives with no upper bound.Reality apathy is the new attack surface. When people can't distinguish truth from manipulation, they disengage — and that disengagement is exactly what adversaries want. Resilience requires media literacy, not just better firewalls.Replacing humans with AI in cybersecurity is the wrong goal. The right goal is to make humans more effective with the help of AI. AI genuinely adds security value through contextual reasoning — understanding that an HR task completed at 3 a.m. is an anomaly.Bias audits must become standard practice. Organizations that use AI for hiring or triage often don't know how those systems were trained. Just like security red-teaming, bias red-teaming should be mandatory before deployment.Digital education is the most important long-term security investment. Estonia starts teaching programming alongside reading and writing in primary school. This foundational literacy produces a population that's harder to manipulate and better equipped to defend itself.Subscribe to Follow the White Rabbit. If this episode made you think differently about cybersecurity — not just protecting systems, but protecting reality itself — share it. Subscribe on your preferred platform, leave a review, and share with the policymakers, educators, and security leaders who need to hear it.Links: You'll find Anett Mádi-Nátor on LinkedIn. Women4Cyber FoundationEU AI Act – Official Text & OverviewEU Cybersecurity Agency ENISA – AI & CybersecurityEstonia's Digital Education Programme – e-Estonia
    Show More Show Less
    33 mins
  • #07: Your Next Hire Might Be a North Korean Spy
    May 21 2026

    North Korea is infiltrating Fortune 500 companies with fake employees. They create authentic LinkedIn profiles, excel in remote interviews, collect salaries, and secretly steal intellectual property, cryptocurrency, and system access. This isn't a future threat. It's happening right now across more than 40 countries. In this episode of Follow the White Rabbit, Link11 ISO Kofi Osae-Attah sits down with Kritika Roy, a senior threat intelligence researcher at DCSO in Berlin. Together, they map the threat landscape that most security teams only partially see.

    Kritika's work sits at the intersection of geopolitics and cybersecurity — and that intersection is where the full picture emerges. China is running long-term intelligence operations aligned with its five-year economic plan. Russia is focused on disruption and sabotage, especially since invading Ukraine. Iran is tracking dissidents and targeting organizations with Israeli ties. And North Korea? It's doing it all — stealing money to fund weapons programs, embedding operatives inside companies, and learning by doing. The line between nation-state espionage and cybercrime has blurred to the point of being nearly indistinguishable. Threat actors are buying ransomware on the dark web as if it were Amazon. Attribution is becoming more difficult. Defenders are falling behind.

    The most important insight from this conversation isn't technical; it's contextual. Geopolitics determines who targets you, when, and why. A NATO summit, a trade dispute, or an election can trigger a wave of tailored phishing campaigns and targeted intrusions. Kritika's advice to security teams isn't to become intelligence agencies. Rather, it's to read the news, understand the motivations behind attacks, and stop treating every threat with the same level of urgency. Prioritize based on context. If you're hiring remotely, ask your candidates what the local food is like. You'll be surprised at how much that one question can reveal.

    Takeaways:
    1. North Korean IT workers are already inside companies. They are hired through legitimate job platforms, work as regular employees, and use their access to steal money, intellectual property, and system knowledge. The fix? At a minimum, conduct one in-person interview.
    2. Geopolitics is a threat intelligence tool. Phishing lures are timed to coincide with summits, elections, and conflicts. Knowing what's happening in the world allows you to anticipate what's coming at your organization.
    3. The four main threat actors have different goals. China wants intelligence. Russia wants to cause disruption. North Korea wants money and knowledge. Iran targets dissidents and organizations related to Israel. Knowing who you're up against changes everything about how you defend yourself.
    4. The line between cybercrime and nation-state activity is disappearing. Nation-state actors are purchasing off-the-shelf malware on the dark web. Attribution is becoming more difficult. Security teams need to adapt their thinking.
    5. Fundamentals still win. Patch management, identity security, endpoint visibility, and regular red team exercises are not boring basics; they're essential. They're the difference between being resilient and being exposed.

    Subscribe to Follow the White Rabbit.

    If this conversation changed the way you think about hiring, threat intelligence, or geopolitics, tell someone. Subscribe on your preferred platform, leave a review, and share this episode with your security and HR teams. Both need to hear it.

    Links:

    Take a look at Kritika Roy's Linkedin profile or the DCSO Website

    MITRE ATT&CK – North Korea Threat Groups

    FBI Advisory: North Korean IT Worker Threat (2024)

    Mandiant / Google: APT Overview by Nation State

    Show More Show Less
    27 mins
  • #06: From Digital to Systemic Resilience - The Quantum Shift in Cybersecurity
    May 7 2026

    In this episode of Follow the Rabbit, host Kofi Osae-Attah sits down with Luigi Rebuffi, founder of the European Cybersecurity Organization (ECSO) and the Women4Cyber Foundation, for a deep dive. Drawing on his 40-year background in nuclear engineering, Luigi challenges the industry to move beyond digital resilience, which he views as a static buzzword, toward a more holistic, systemic approach to resilience.

    He argues that most organizations are fighting the "old war," treating cybersecurity as a linear compliance checklist. In contrast, systemic resilience is inspired by complex systems theory. It focuses on nonlinear interdependencies (the "mesh"), where a failure in a minor component can lead to a crisis, but where optimized investment in these interactions can also create "double value," improving safety and operational efficiency.

    The conversation also covers the "positive cascade" of the human factor, why government resilience must shift from "fortress" mentalities to flexible meshes, and how a Bayesian approach to risk management can help leaders navigate a non-binary world.

    Takeaways

    1. Resilience Beyond the Digital: Digital resilience is only one sub-element of a larger system. Systemic resilience considers the interaction of all parts - mechanical, environmental, and human - to prevent total collapse.
    2. The "Ferrari" Analogy: You can have the perfect cybersecurity "engine" (tools), but if your "tires" (human training or third-party dependencies) are flat, the system won't be resilient. We must assess the interaction between parts, not just isolated components.
    3. The Human Factor as a Resource: Although the human factor is often blamed as a vulnerability, it is fundamental to resilience. Luigi argues that organizational systems should be designed so that human error doesn't lead to catastrophic failure.
    4. From Linear to Systemic Risk: Traditional risk management is Newtonian, or cause-and-effect. Modern resilience requires a Bayesian approach that maps the probability of "hidden crises" within a complex mesh of factors.
    5. Sovereignty as a Dynamic Mesh: Government resilience shouldn't rely on building a static "fortress." True sovereignty comes from controlling the "mesh" - the links and interactions between existing partners - to maintain control.

    Why Listen?

    Are you tired of the same old "compliance-first" discussions? This episode offers a radical, engineer-led perspective on the future of European strategy. Luigi Rebuffi offers a blueprint for how organizations and governments can stop constructing static fortresses and begin to understand the dynamic interdependencies of the modern world.

    Love the show? Make sure to like, follow, and subscribe to the Follow the Rabbit podcast!

    Links:

    You'll find Luigi on Linkedin.

    Here you find more information about the ECSO.

    Show More Show Less
    27 mins