Security Confidential S17 E4 Henrik Parkkinen

This week on Dark Rhiino Security’s Security Confidential podcast, Host Manoj Tandon talks to Henrik Parkkinen. Henrik Parkkinen is a globally recognized security leader from Sweden with over 20 years in the cybersecurity field. His experience spans both offensive and defensive security, developed through a combination of hands-on technical roles, management and leadership positions. Henrik is known for his strategic thinking, strong leadership, and ability to communicate complex security concepts across all levels of an organization—from engineers to board members. His impact in the industry has earned him numerous accolades, including recognition as a Top 12 GRC Leader in 2025, one of the Top 10 Cybersecurity Leaders in EMEA, and a finalist for Best Cyber Blog of the Year.

00:00 Introduction

02:36 Love for Technology

06:35 Pathway to skills

14:38 The contextual aspect of security

20:35 What is worth protecting

29:00 You are the translator

46:10 How is your approach changing to AI?

52:34 Free resources from Henrik

Transcript

Manoj Tandon:
Hello everyone, this is your host, Manoj Tandon. Welcome to another episode of Dark Rhiino Security’s Security Confidential. We have a fantastic guest today. Before I introduce him, please hit the Like and Subscribe button—it helps with the algorithms and allows us to keep bringing you great content and amazing guests. Without further ado, I’d like to introduce Mr. Henrik Parkkinen. You should look him up—he’s a globally recognized cybersecurity leader from Sweden with over 20 years of experience on both the offensive and defensive sides. He’s helped bridge the gap between the technical aspects of the profession and executive decision-making in the C-suite. He’s received numerous awards, including being named a Top 12 GRC Leader of 2025, one of the Top 10 Cybersecurity Leaders in EMEA, and a finalist for Cyber Blog of the Year.

Henrik, I don’t know how you find time for it all, but we’re honored to have you.

Henrik Parkkinen:
Thank you so much for having me on the podcast. Honestly, I don’t know how I manage it either! I just try not to waste time and to have fun along the way—that’s probably the secret sauce. It’s a passion and a hobby for me as much as it’s a career.

Manoj Tandon:
So this is a passion for you, not work.

Henrik Parkkinen:
Exactly. I’m fortunate to love what I do. Participating in podcasts like this and being a voice in the security industry is something I enjoy. I don’t monetize it—it’s purely out of passion.

Manoj Tandon:
That’s great. Give us a bit of your origin story. Did you always want to work in cybersecurity?

Henrik Parkkinen:
It started young. My dad was a technology enthusiast, and I grew up surrounded by gadgets—Sega consoles, the first Xbox, Commodore Amiga, and early PCs. Technology fascinated me, but when I went to upper secondary school, I actually studied economics for three years. I thought I’d end up in finance. After graduation, my mother found a one-year IT Security and Networking course and suggested I try it. I figured, why not? It was just twelve months. Once I started, I was hooked. It all clicked—technology made sense to me. It was hands-on, practical, and engaging. My friends thought I was crazy—this was right after the IT crash around 2000—but here I am.

Manoj Tandon:
If you’d gone into finance, you’d be one of many Swedes there. This path definitely stands out.

Henrik Parkkinen:
True! After that program, I got my first job with one of the biggest IT hosting companies in the Nordics. I worked in Identity and Access Management, and everything I learned in school translated almost directly to real life—just scaled up by 10,000 times. That strong foundation was invaluable.

Manoj Tandon:
You mentioned your training was very practical. Many of our listeners are early in their cybersecurity careers. What advice would you give them about developing practical skills?

Henrik Parkkinen:
Great question. I’m biased because I came in through a hands-on path, but I can’t stress enough the value of a strong foundation—networking, infrastructure, firewalls, and now cloud environments. If you want to go into offensive security, start first on the defensive (blue-team) side. Learn how to build before you learn how to break. Be curious. Today, there are so many incredible learning platforms—cheap or even free. In my day, you had to build your own lab from scratch. Now you can spin up environments in minutes. Also, network with others. Find mentors and join cybersecurity communities. When I started, those didn’t exist—now they’re everywhere.

Manoj Tandon:
That’s great technical advice. But what’s unique about you is that you studied economics—you understand business. I’m going to get flak for saying this, but most cybersecurity practitioners don’t really understand how a business operates. If you’re architecting a solution, it’s not just technical—it’s also about people and processes. Should business knowledge be part of cybersecurity training?

Henrik Parkkinen:
Absolutely. My own program didn’t include leadership or business management. I had to learn that on the job. To succeed as a security leader, you must understand the business context. You need to speak the language of executives and show how security supports company objectives. We’re not here to exist for ourselves; we’re here to enable the organization’s success. You gain influence when you can explain security in business terms and align it with value creation.

Manoj Tandon:
Exactly. Security without funding doesn’t go far—and every industry is different. The strategy for a beverage company is not the same as for a bank or movie studio.

Henrik Parkkinen:
Right. The nature of the business dictates the security posture. Each context is unique. A production worker, a developer, and someone in HR all see “security” differently. You have to tailor your message to each audience—listen first, then speak in their language. We often focus too much on the tech and miss the human side. Ask questions to understand what truly needs enabling.

Manoj Tandon:
So if a random company came to you asking for help building a cybersecurity program, what questions would you start with?

Henrik Parkkinen:
First, I research the company: what they do, how they make money, where they operate. Then I ask, “What does security mean to you?” Most people will say, “It means we don’t get breached.” Then I ask, “Why?” Usually the answer becomes “because of brand reputation or shareholder trust.” That’s when you start understanding priorities—brand, reputation, financial stability, or even people. Those answers guide the program.

Manoj Tandon:
I tell smaller companies something similar—map your revenue chain. Understand how you make money, identify what’s vulnerable in that chain, and protect it. That alone can build a strong baseline.

Henrik Parkkinen:
Exactly. That’s another way of asking, what are your crown jewels? Not all data or assets are equally important. Start by identifying and protecting what’s most critical. Combine that with solid security hygiene—it’s basic, but it still fails most organizations today. Even simple steps—like enforcing MFA, reducing admin rights, or consolidating browsers—can make a huge difference.

Manoj Tandon:
Right. And people accept those controls more readily if they understand why they’re necessary. But what happens when executives just want to “check the boxes”? For example, they ask, “What percentage of the MITRE ATT&CK Framework do we cover?” or “Are we fully compliant?” How do you handle that?

Henrik Parkkinen:
I’ve faced that many times. The honest answer is: there’s no such thing as total immunity. You can check every compliance box and still get breached. The goal isn’t perfect compliance—it’s risk awareness and prioritization. Cyber risk is really just business risk by another name. Focus on what the organization fears most—financial loss, downtime, brand damage—and plan accordingly. Compliance should be a by-product of a strong security program, not the end goal.

Manoj Tandon:
I’m glad you said that—we’ve been preaching it for years! Compliance should follow good security, not drive it.

Henrik Parkkinen:
Exactly. When you focus too much on compliance, you risk sub-optimizing. Security shouldn’t be sacrificed for checkmarks. The fundamental principles of cybersecurity haven’t changed much in decades—they just need to be applied in the right business context.

Manoj Tandon:
So how do you bridge that gap between security and the C-suite?

Henrik Parkkinen:
It takes time and storytelling. One workshop or meeting won’t change minds. You have to communicate in the language of business, not security jargon. Executives already read about breaches daily—they don’t need more fear. Instead, make it tangible: “Here’s what downtime means for your factory.” “Here’s what a breach would do to your reputation.” Frame it in their world. Once they start asking how attacks happen, you’ve got their attention.

Manoj Tandon:
Exactly—make the risk tangible. Otherwise, it’s just abstract tech talk.

Henrik Parkkinen:
Right. You can be technical with your own team, but when addressing leadership, speak in outcomes. Storytelling matters. If you can explain cybersecurity in a way anyone can understand, you’ve already succeeded.

Manoj Tandon:
What kind of pushback do you still hear, even when you take that approach?

Henrik Parkkinen:
The classic: “We’ve never been hacked, so why invest?” That’s where you explain risk tolerance. I usually present three options:

  1. Do nothing. Accept the risk—just understand the consequences.
  2. Do something. Prioritize based on crown jewels and quick wins.
  3. Do everything. Implement the full roadmap (usually impractical).

Most companies fall into the middle ground—start with hygiene and build from there.

Manoj Tandon:
And what about testing recovery? Many businesses assume backups will save them, but most never test them.

Henrik Parkkinen:
Exactly. They say they back up, but they rarely test restoring. Even worse, some discover that their critical assets—their crown jewels—aren’t included in backups at all. So yes, I always recommend testing recovery and starting with asset identification. You can’t protect or restore what you haven’t identified.

Manoj Tandon:
We still see default passwords and unpatched systems everywhere—basic hygiene issues.

Henrik Parkkinen:
It’s amazing, isn’t it? Shadow IT makes it even worse. In the old days, spinning up a rogue server took effort. Now it’s just a few clicks in the cloud.

Manoj Tandon:
How is AI changing your approach?

Henrik Parkkinen:
AI is fascinating. But I think the industry is repeating the same mistakes we made with the cloud. Back then, we jumped in headfirst, only later worrying about data governance and compliance. Now we’re doing the same with AI—adopting it before fully understanding the risks. I’m a fan of AI, but we need governance frameworks from the start, not years later.

Manoj Tandon:
Human nature doesn’t change—convenience always wins over security, and speed beats quality.

Henrik Parkkinen:
Exactly. We’re driven by opportunity and competition. But we could do better at anticipating the future. We’ve never been more equipped—with data, knowledge, and tools—to prepare for what’s coming. Yet the pace of change is so fast that we rarely stop to think.

Manoj Tandon:
We’ll have to have you back in six months or a year to see how this all evolves. Before we wrap, anything you’d like to promote—books, appearances, or resources?

Henrik Parkkinen:
Yes—if anyone wants to dive deeper into what I share, visit henrikparkkinen.com. Everything there is free—no paywalls or subscriptions. And thank you, Manoj, for inviting me. What you’re doing with this podcast is incredibly valuable for the industry—sharing knowledge and giving back.

Manoj Tandon:
Thank you, Henrik. That means a lot coming from you. We’re just trying to educate people and help them stay safer.

It’s been great having you, and I look forward to continuing the conversation soon—we’ve only scratched the surface.

Henrik Parkkinen:
Thank you, Manoj. It’s been a pleasure.

Read more about Henrik on his LinkedIn

Check out the vCISO bot we created

Check out the other episodes in Season 17:

Ep. 0 Jon DiMaggio – Tracking Cyber Criminals

Ep. 1 John Carse – Why Your Browser Is Your Biggest Risk

Ep. 2 Alex Sharpe – Is Your Job Safe From AI?

Ep. 3 Chuck Brooks – Thinking Beyond the Checkbox

Ep. 4 Henrik Parkkinen – Adapting to AI & Rethinking What We Protect

Ep. 5 Alex Sharpe – Are AI Models Being Trained with Lies?

Ep. 6 Santosh Kaveti – Disaster Recovery Isn’t Optional

Ep. 7 Bob Burke – Think MFA is Enough? Think Again.

Ep. 8 Ed Gaudet – The Biggest Mistakes in Healthcare Security

Ep. 9 Husam Shbib – The Hacker’s Playbook

Ep. 10 Shayla Treadwell – The Psychology Behind Cyber Resilience

Henrik Parkkinen is a globally recognized security leader from Sweden with over 20 years in the cybersecurity field.

His experience spans both offensive and defensive security, developed through a combination of hands-on technical roles, management and leadership positions.

Henrik is known for his strategic thinking, strong leadership, and ability to communicate complex security concepts across all levels of an organization—from engineers to board members.

His impact in the industry has earned him numerous accolades, including recognition as a Top 12 GRC Leader in 2025, one of the Top 10 Cybersecurity Leaders in EMEA, and a finalist for Best Cyber Blog of the Year.

Dark Rhiino Security’s Security Confidential is a weekly Cybersecurity podcast where Host, Manoj Tandon, talks to Infosec and Cybersecurity professionals about the current issues going on in our industry. Guests are able to share their stories about how they began their journey into cybersecurity and connect with our audience. Listeners are able to tune in through Spotify, Apple Podcasts, Google Podcasts, Amazon Music, iHeartRadio, Youtube, LinkedIn, and more.

For inquiries, please email media@darkrhiinosecurity.com

Share and spread the word!

Leave a Comment

Your email address will not be published. Required fields are marked *

Chat Icon
Scroll to Top