Vincent Berg, CTO and co-founder of Enfield Secure, started his journey in information security at age 15, organizing LAN parties and later diving into the hacker scene on IRC channels in the late 1990s. After studying computer science and earning a Master’s in Computer Security, he worked at a startup before joining IOactive, where he consulted for major tech clients like Microsoft. A key breakthrough came when he was sent alone to a German client, successfully hacking a complex JavaScript stack and gaining confidence in his abilities. He values practical, hands-on work over academic theory, noting that many academics lack real-world experience. Enfield Secure, a boutique infosec firm with offices in Amsterdam and Seattle, helps large technology companies secure their products through pentesting and code reviews. The company has a global team and prioritizes hiring the right talent regardless of location. Vincent avoids self-promotion, preferring to stay low-profile and focus on the work itself. He dislikes the term “cyber,” instead using “information security,” and believes that growth often comes from being placed in uncomfortable situations. His career reflects a blend of technical skill, humility, and a commitment to practical security solutions.
This is Lawrence and Bruno and welcome to Cyberscirty Talks. The interview podcast for Cyberscirty professionals and for those who aspire to become one. My name is Laosja and with me is my co-host Bruno Leinborg. Together we interview industry experts and explore what it's like to work in Cyberscirty domain. Join us on our journey and listen to our bi-weekly episodes and learn about latest trends, real life horror stories and everything you need to know about this fascinating industry. Welcome back to Cyberscirty Talks. During this episode we spoke with Vincent Berg, the CTO and co-founder of Enfield Secure. His interest for InfoSec started when he was just 15 years old, organizing his own land parties. This is now 18 years ago. Vincent earned his stripes working with some of the biggest tech companies in the world. And some of them are still as clients today. During this episode we talked about the beginnings of Enfield Secure. Why humans are more important than technology and what it's like to build a company based in Seattle. Vincent Berg, welcome today at the Cyberscirty Talks. We're very excited to have you here and let's start off with some short questions. What you need to know about me? What meal do you start your day with? What meal do I start my day with? I tend to be a sandwich. Very boring. A sandwich slice of cheese on it, a bit of butter. Very dutch. Very dutch. Cup of coffee. Android or iOS? Android. What is your favorite phone app? I don't know. What's app probably? What's app? Work from home, office or a mix? A mix. Why? Well, I have a baby so there's a lot of chaos in my household. So every once in a while I work a few hours from home and my office is in a minute away from my apartment. Coincidentally. Well, it's not coincident. It's not a coincidence. Are you a gamer? No. Okay, why? I do not know. I used to play some computer games when I was a kid but I spent so much time behind the screen that I don't do that much. My wife is more of a gamer than I am. Okay. It's an interesting, interesting, different. All the supply in senior house. It's probably one of the oldest LEGO mind storms for the first version somewhere. That's somewhere laying around. Okay. Laptop desktop server or VM? Server. Guilty pleasure. Tracking illicit boost made from Romania. Brought to me by Romania. What are we talking about? No, so my wife is originally from Romania. We met in a Netherlands. She was already living here and in Romania they make something called swika. It's a plant based liquor. It's very strong. The cashier through winter is sitting on top of a mountain in Romania. Life isn't very great. This is what you drink. My parents-in-law were just in Amsterdam. Like a week ago to visit their granddaughter. They brought me another two liters. I probably should have brought something. I'm sorry. That's fine. Maybe for next time. We're recording on Friday morning. Yeah, yeah. Indeed. So much weekend. What's the first thing that comes to mind when I mention cyber security? My career. I don't know. Cyber cyber security. I'm not a big fan of the term cyber. I hate it. Security in that sense then. Security information security in FOSAC. Those are terms I tend to use. It's because cyber is like cyber. I don't know. I'm not a big fan. What is the password to your email? I don't even know my password. I have the password manager. Very nice. Very secure. The beginnings. Vincent, we're super excited to have you. Thanks for joining the show. We also met earlier during one of the meet-up events. I think you're one of the best pentas professionals in the Netherlands. And also the co-founder of the successful Infosac scale-up Enville Secure. And you recently became a father. Congratulations. Thank you. How do you juggle between all these different responsibilities? I don't know. I'm not sleeping as much as I would like, probably. Yeah, there's a lot going on. But it's also fun. I don't like sitting still either. Yeah. And we like sitting still to read a book. But there's always something going on in my life, so. Vincent, you're a very tall guy. So I would be scared if I ran into you in the elevator. But what would you say during an elevator pitch about Enville Secure? What kind of services do you provide? Your customers. And who are your customers right now? OK. Well, I'm Vincent. I'm the CEO of Enville Secure. And we're a small boutique information security firm that helps some of the largest technology firms on the planet with improving their security of their products, whether that is software, hardware, firmware, everything in between. And we have some of the smartest hacker security professionals on the planet working for us. We're hackers for hire, but we're on the good side. So we help you make your products and offer you more secure. And I was in for secure now build up what's the company like in size and locations. I think you guys are across the globe. Yes, we are. Yeah, we're pretty spread out. So we've got two offices, a small office in Amsterdam headquarters in Seattle. A good chunk of our people are based in Seattle. We have some people all over the states, several great engineers in Argentina and several in Europe to an Amsterdam, one in Paris and one in Spain. That's always quite difficult to juggle from like, I don't know, company management perspective. RCFO hates it because he needs to be aware of all the rules everywhere and all of that. We make it work and it's also, it shows something right. We could say like we're only one geographical location. Everyone has to come into the office. We're not that type of firm. And we want the right people. So if you're fit, it doesn't really matter where you are. And I think you're quite a low profile in the cybersecurity market. Is this is the the the the liberty choice? I think some things don't really fit my personality. So you have from the moment I started coming into professional info segment, that you always had the people that their dream was to stand on stage at blackout or to make a name for themselves. We're doing really fancy research or whatever. And that has never really been me. I've done some pretty cool things. From a technical perspective, I work with amazing people, some very well-known names over the years. I've never really had an insane drive to put myself out there, maybe because to scare to do that, to make mistakes too. I'm not someone that really puts themselves out on the forefront. I talk a lot, but I don't I don't I don't I have less of that standard American attitude. Like look at me here. I'm on stage. I'm the best hacker in the world. That type of stuff. Now I don't. So I feel safe relatively safe. Well, then you're in for right. Let's start the show. Now, before we jump into it, could you explain a bit about your background? Can you welcome through your impressive career so far? Sure. So, well, what's your start? Well, I started messing with computers from kind of it's a 12 or so where my dad was like, "Oh, I think this computer business is going to go somewhere." And he bought it 486 Essex. And I started messing with that. So that was Microsoft does machine. And then someone I played volleyball at the time, someone told me, "Hey, if you know how to program and with quick basic, you can learn how to make your own computer games." So that was when I actually played some games. So I was like 13 maybe. So I started learning about that and then we got the internet and then I started going online. And very quickly I gravitated towards security people. Right. So, and we're talking late 90s. So, and you had all these forums and news groups and all of that. And then you had a bunch of people that all bonded together on IRC channels and started swapping technical tips, tricks, exploits, bugs. You name it. What are IRC channels? Internet relay channel. It does still exist. It does still exist. It's for the young kids nowadays. It's what you guys call Slack, but then it doesn't have fancy gifts and animations and any of that stuff. Just text-based. Very simple. Yeah, that's how people lived within 90s. Okay. And that was there in your teenage year? Yeah, during my teenage years. So I learned how to program by going online. Right. I started calling Python and C. And I made a lot of friends, some enemies, in the hacker scene that you had at the time. And at the time there was very little professional info check. So I remember one of the first professional forums was loft in the US. And that's sort of when it started, like professional info check. The only thing you had at the time was anti-fire companies. It was like a thing. And some people selling firewalls, but nothing else. And since then it really became an actual industry that does billions. And forgot about it. When you were younger, did you maybe push the boundaries, did you maybe see what was open at your high school? Or did you maybe-- Sure. I can point some questions. No, yeah, but I've been, I've been always been a little, as I said, I don't like to put myself on the forefront and standing in front of a judge explaining what you did is putting yourself at the forefront. So I do remember participating in some of these things, or doing some of these things myself. And at the moment I turned 18 that for most of that it was over, because it was kind of done. And I was like, yeah, I get tried as an adult now. Probably not the best idea.
But again, it was a very different time, right? It was very, it was a whole lot of incense and a lot of people that know or still send me regularly in touch with from those days. Pretty much everyone ended up having a very successful career, either in Infosac, Oregon, IT, tech. At the time, there was more intellectual curiosity, right? No one did anything for money. There wasn't a thing. Very interesting already as a teenager starting this journey. Then you had to decide upon a study, what did you go for? I went to 20. So I grew up close as well, and I went to 20 and so today because I was relatively close by, safe. And I studied computer science because I didn't know what else to do. In hindsight, I probably should have done something else. And yeah, I showed up there and I already knew how the program and all of that. So the first year of my studies were, I struggled with, say, the math subjects and all of that calculus and that type of stuff. And yeah, I don't know. I still did some security work. I struggled a bit with studies trying to figure out who I was, what I wanted. Like a lot of people. I had quarterly life crisis, people talk about something like that. And at some point through a student body of mine, I got a job at the first little side job at the startup in ends today. Company is still around, called Noverlow. And at the time it was called something different, but the company made very boring business software. And I mean it in the nicest way possible. It's just business software that helps small medium-sized businesses doing their thing, administration type stuff. And we developed all these frameworks and we invented a lot of stuff from scratch, right? And that was a lot of fun. So that was like, at some point I've worked there also full time, I think, for two years or so. But I was kind of done there. I was like, this is not going to be it. Maybe I should go study again. So I tried for a while, part time, Master in Philosophy of Science, Technology and Society. Stop doing that because it was too much, combining it with work. But I really liked that. I've always had a bit broader interest in just tech. And then worked again full time for a year. And then I went back and did a Master in Computer Security. And I was working for this, this startup. And the startup was going places. Some of my good friends that I'm still very close to this day. I met there or a note through there. So that was nice. And then, but I was like, eh, and then at some point in the summer, I got a phone call from an old buddy from Belgium. And he called me, it's like, dude, where man short, can you come to the UK and work for Microsoft? This is a long time ago. I guess I can't imagine that. Small company. Small company. Yeah, sure. And I was terrified. I'm like, dude, I don't know if I can do this, man. He's like, well, we're a man short. And we know each other from back in the day in the scene. And we always stayed in touch a bit. And he was working in InfoSecurity for several years, flying all over the world. And I was sort of stuck in Anzui in 20. And 20 is beautiful. They'll get me wrong. But it's not the most exciting place from the planet. So he called me and I'm like, dude, I don't know if I can do this. He was like, well, we have to do a code review of this big product and blah, blah, blah. And I'm like, how long is it? Well, four weeks. So I took my holiday and went to the UK for four weeks, sat in Cheltenham in a hotel. And there was a very tiny Microsoft office there. And that's where we did the project. And it went really well. So. And I got offered a job by his employer. And I turned it down because I'm like, I already paid for next year's Master degree, which was a Master in Computer Security. I was like, I already paid a $1500 bucks or whatever it was, college money. So I went back to study. And then I did that for six more months. Did some courses and I'm like, I hate this. Some courses were actually interesting, right? Like it's not like I didn't learn anything. And some things are completely out of my league. Like I remember having to go to Einthoven to do cryptography. And I'm like, yeah, there's no way I can pass this. My math skills are nowhere near that good. That was mostly fed up with this really academic attitude of people. And I know it serves a purpose. So I'm not trying to rack on academics here. I'm just saying that in information security, there were a lot of academics telling me all kinds of things, all kinds of theoretical things, how to build secure software or whatever. And they hadn't touched the compiler in the last 20 years. They spent all the time writing scientific papers and all of that. And again, there is value in all of that. It's just not me. I think I'm a little bit more practical. I can read scientific papers. I can maybe write some academic papers. I don't know. I can do research, all of that. But I've always been a little bit more hands on, right? More applied. So I kind of fed up with that. And I'm like, yeah, what am I doing here? And then the client basically said, well, we want these two people back. What's the client? Microsoft? Yeah, this is Microsoft. So they said we want to do a follow-up kick and we want FinSend be part of the team again. So I get a phone call from the States. Okay, do you want to do this? Okay, so in February, something I flew out there. Did another gig for a couple of weeks. And that went well. And the company was working for basically, I have the contract with Microsoft. It's called IOactive. So pretty well known. And they then offered me a job. CEO called me and she said, did you want to work for me? Like full time. And I said, yeah, I guess I'm done. So I signed the contract, flew back to Amsterdam yesterday, told all my friends, everybody I was like, oh my god, are you moving? And now I'm moving anywhere. So I kept living in Amsterdam. And then I did that for, I don't know, six years, I think. Humans over technology. And can you take us back to those days that you took on the international job? So a young guy, a freak of nature, super tall guy, going to the US by himself. What was it like? So first I did a few projects in Europe. So that was always, but still I had never been to the UK, so flying there. And that was kind of fun. And then we were at a conference in Berlin. And then one of my coworkers that I was supposed to go down to a client in Germany with, he fell ill. So instead of being a one week two person gig, they changed it into like a two person or a two week one person gig. And they sent me out there. And this was, I think my third project, as a consultant, and I was terrified because there's a brand new client, really big, well known name in Germany. It's like, I don't know. But if they only speak German, my German is not that great. And they sent me out there, right? And I think that was the first time that I realized, okay, I can actually do this like because I'm not with my buddy anymore. Like the first two, three times I was with my buddy. And like I sort of protected him. He's like, he knew how everything went. He did, this is how you do a phone call with a client. This is how you, and I could just focus on say doing the code review, the pentastame, all of that stuff. And now I couldn't hide behind anyone, right? And I had the company, but at the time they didn't have anyone else in Europe. I think there was two people. One of whom was ill back home in Belgium and me. So it's not like I had someone in my time zone to back me up. So they sent me out there to the clients and there's all these scary, angry German engineers there. And I'm like, I'm walking in there. And I'm like, I'm like, I'm like in my mid, how old was that? And I'll lay 20s, 27, 28 or something. Yeah, and I walk in there. I was like, oh my god, these people pay a lot of money for my time. And now I have to know everything, right? What if I'm wrong? And I started working with some of them and a lot of them were surprisingly nice. And I did end up the product, that a specific product that I was looking at. I completely hacked it to pieces, right? And that's why I remember I did a code review and a complex JavaScript stack and JavaScript on top of it. And it broke out several sandboxes completely on everything. And I had to do a demo of that. So I did a live demo and I remember being on the phone with the people while I was in Germany on site. And then we were on the phone with some developers in I think San Jose, California. And I remember being silent on the phone after I was done with my demo. Like at the end, you have like the little root shell. And then it was like, wow, we're in trouble, aren't we? I was like, no, no, you're fine. You just do these and these things and read my report. And it was sort of when it sort of clicked like, okay, maybe I can actually do this. I did this on my own. Maybe I, maybe I can do this. You needed that push the confirmation that you can do this. And maybe, but I do, I also firmly believe you also always need to be not always, but sometimes need to be put in uncomfortable positions. Otherwise, you get complacent and you won't improve yourself, right? But it probably was the, it was the start of the realization, okay, maybe I can do this. Maybe I can go somewhere. Maybe I can make this turn this job into something of success, because I'm still scared, right? I don't know. I've never been to the US, older people, they talk, there's a lot of people that I know from the internet, they have a big reputation. Some of them I know my coworkers, I can want to prove yourself. I think everyone has that, right? >> And other break through moments in your career, did you feel like, okay, this was very challenging, not knowing how to proceed, but did you turn it into a great success? >> Yes, several, but I'm not sure which ones are really interesting to talk about, right? Like, what I realized relatively early on is so you grow up as being this geek, this nerd that talks to this friends and you have all these technical debates, right? It's always very, very important.
black and white. It's like Linux is better than freebies D and everyone who uses Windows sucks and or whatever is the debate all the time. And it's the same with the introducing questions, right? Android or iOS and then people argue about this Anthels. And you do that a lot and especially in those days, right? You should use this Linux distro or this is better or this this really sucks security wise. And it took me a really long time to realize that a lot of that is just complete waste of energy. I mean, not completely. You still have to evaluate things on a technical merit. And it is sort of important. But at the end of the day, the technology is about humans, right? So and being a consultant. So I'm not talking about people that work at a big firm and that just get to spend all their time on technology, sort of the company's bureaucracy, right? As a consultant, what is even more important than understanding the tech and being able to command the tech to do what it is you want or to explain it is being able to communicate to humans, right? At the end of the day, that's what matters. I can pound with my fist on the table and scream. I say, this is a really bad buck in your code and you need to fix this right now. But if I can't bring this to a developer's attention in the right way because I pissed them off or I cannot make the argument to his manager that they need to invest more money into improving the quality of their code or whatever, then I've lost, right? Then and then none of it makes any sense. And so I think those communication skills are in a lot of cases pretty important. And one thing that I always say that the difference between being a hacker and a consultant, right? Like we have, there's overlap there. There's great hackers that can also be great consultants, right? They do have the communication skills. There's also great hackers that I wouldn't put in front of a client ever at all, right? I would let them do their own thing and they're brilliant. Way more brilliant than I am with technical stuff, whatnot. But then I need someone else to massage whatever it is that they did. And to make sure that that's palatable to us, like an actual manager or company, you name it, right? Something that can be consumed publicly. This is Ann Vell Secure. Can you elaborate on Ann Vell Secure? What are you guys doing? And also what's your role as a CTO? So Ann Vell Secure started almost five years ago officially. So that is what February 2017. And it was me and my best buddy from my time in the US sitting down. And I think I flew to, if I'm not mistaken, I flew to Mexico for short holiday and then we flew to Seattle where I lived for several years and we met when we sat down at the sketch and table. Like, are we going to do this? And he had the plans for a while, right? So in that sense, it came from him, initial name came from him. What gap did you guys identify? What was the initial idea to start your own business? I don't think we identified a gap because what, so in the sense that there's a lot of other companies that do what we do or try to do what we do, but we identified a lot of frustrations with how some of these companies are being run. So a big problem, especially in the US, is that it's really hard to run a security consulting firm when you're in a city where there's Amazon Microsoft, Google has offices that Apple there. There's a little bit of the market for talent, good cybersecurity talent. Yeah, it's booming and it's a sellers market. So it's hard, how do you keep your employees interested? How do you keep them to stay at your place? Because no one can find security talent. It's really hard. So, and there were a lot of people that I work with over the years that worked at different firms so that I directly work with together and that either hand frustration at their firms. And we think that we run a more open professional company. But those details are pretty, you just see that more as an employee. I also do think you see that in our retention rates, right? We barely lost anyone. We just keep growing. People really like working. What's the difference then between you and the Google or Amazon? Well, well, skill, obviously. I mean, it's not like there's much, there's no secretaries. There's no, like if you want to talk to the CEO, he's right there, go ping him until he's fine. You have his phone number, right? And people do that all the time. There's no, like, oh, you need to go through all these barriers too. And there's a lot of transparency, right? But you do work with some of those clients if you're not mistaken. We do work with some really big tech firms, correct? And that's kind of surprising to some people. But I think that is based on the reputation of the people that we've had. We've had, we have a lot of people that have a decade, two decades or more experience in cyber security in the infrastructure industry. And then you work at all these different firms. You make all these contacts and people move on. They go from that firm to another firm or whatever. And then they go, you know what? I always like working with Vincent. And I'm sure there's people that don't, right? But there will be people that have that. And then they go, oh, where's Vincent now? They're check-in, he's now at this firm. Okay, it looks like he's still doing consulting. Let me send him an email. Let's see what happens, right? Or we end up finding a new client and then the client that also has people moving on to somewhere else. And then they come back. So they bring us to their new employer because a lot of people in security, the people that work tend to work for the tech firms. They move around a lot, especially in the US, right? I mean, average tenure for a lot of people like two, three years, something like that. Like if you can get the chance to get more money somewhere else, you know, your employer doesn't really care about you. You're like a cog in the machine. So you move on. So you're sitting down with your buddy in Mexico and you decide to start maybe your own business in Seattle in a very competitive market. What service did you want to provide to these customers? I don't know how we ever have rode it down. High-end information, security consulting, boutique security consulting. There are security consulting firms that have 500 or a thousand employees, and I'm sure on some level we can say like, "Oh, that's the dream that's where we want to get, right? And we'll be rich and I ride off into the sunset." That has never been a goal, right? The goal was to build a company that we can be proud of that has a set of core values that we really can stand behind and to do just cool work, right? If you get, if we ask someone with the engineers like, "Okay, what is a dream client?" Right? And this is not a client of ours, I can say this. Tesla would be a dream client. Why? I mean, Tesla's hip. There's a lot of cool tech there, right? We would love, we would love Elon if you're listening please. Send us a car. Shout out. We would love to get the opportunity there to work on something like that. So we have a lot of people that are still very passionate about technology while realizing that at the end of the day it's also about relationships in humans and all of that. But that for me is also the kick, right? Seeing some things pre-released or knowing that I helped turn on a few little screws and make things a little bit better on these platforms that literally touch the lives of billions of people, literally. Yeah, that's amazing. Well, where you're that confident that just the two of you at the kitchen table could play in that leak? Yeah, for the simple reason that we've already done that for a long time, right? So, what we were not confident about is could we convince some of these people on the big lead to go with us versus the established names or direct competitors, right? That was that was the big unknown. We didn't we didn't know. Especially if you're such a young organization. Yeah, I mean, and there were same as with some some people that now work for us, some of them took a while before they were convinced like, okay, they can actually pull it off or maybe it actually starts going somewhere. Before that no one wanted to jump ship and make sense, right? If you have a mortgage, or you have a wife or a kid, you're not immediately going to jump to this unproven company that two people have just said, and I just say, we're really cool. Look, we have a website. Do you have clients? No, but I'm sure we'll find some, right? That is the leap of faith. It's you and the professional. Exactly. And it's also like and the bigger the biggest leaps of faith were made by the first few employees. And those are all people that we worked with. They came from different firms that felt as a really big responsibility for me and for Chris as well. Yeah, I've just simply put like, okay, they make a jump like we really want to make this a cool place to work. We have to we have to do what we promised that, right? And that was running an open transparent company, giving everyone a stake in the future and success of the company, right? And to do that, we have a lot of shares. Yeah, there's with options and shares, right? If you leave, or if you were to leave, then you can exercise your options and you can then sell your shares. If the company would ever get sold, then yeah, everyone would have a piece of the pie. And depending how long you've been there, that piece of the pie will be bigger. And yeah, the earliest people, of course, they have a bigger piece that's. Yeah, and this is in the consulting, not something you see that often, right? It tends to be you have a book from Meister, I think, the professional service firm where they talk, and that's sort of somewhat similar, right? We might work with more sexy tech, but at the end of today, we're a professional services firm. We deliver professional services to our clients.
While our other professional service firms, law firms, notaries, accountants, right? And a lot of these firms you have, a bunch of partners, the partners run the firm at the end of the year. They look how much money that we make, we give a ton of it to ourselves, right? I mean, and like I'm a partner at this firm, right? Because this is a partner. We're very differently around. We have a lot of people that really we try to get everything out of the way so that they can focus on technical work. That's what they like doing. They don't want to do management stuff, putting signatures on a piece of paper, right? I do stuff like, oh, I have to cycle through the rain to the Amsterdam court house to get some documents notarized. Like, a lot of people are not willing, like they like, I don't want to do that. But we had the discussion before. I think you're not the best paid person. Some of your engineers might even make a bigger buck than you do. Yeah, yeah, you make a good deal that is fair for each and every one, right? And I also think it's, like at the end of the day, everyone goes to work for money, right? I mean, that's why you're there, right? But for a lot of people, if you provide them an engaging place to work, and they're happy with the salary, right? And they can do in a private life what they want to do. And they have cool co-workers and a cool job, and it's not too stressful or whatever. That's how you make the argument, right? Because I know I can't compete with, or we as a firm can compete with, what the salaries that say a Seattle, like a Google or an Amazon, or whoever else is there, what they could potentially offer, right? And don't mention the stock and all of that. Yeah. So if we can't compete with that, yeah, then you try to make a deal that's fair. And we have made, we have salary bands and all of that that's published. And it also live in a cheaper place. It's also even that. If I would move to Seattle, I would immediately get a salary bump. But that is. Because it's that's. It is. Everything is more expensive there, right? So it's also that, right? If you live somewhere way cheaper, yeah. But it's super cool. If you look when you started the firm where you guys are now, but you came from more technical background, being the technical, the pentester yourself. Now you're CTO, you're probably more managing people, you're responsible for people's lives. How does that do? One moment, don't completely responsible for that life, for their work lives. Let me be clear. Like everything else, they should have to be responsible. They should have to be responsible. That's true. Yeah, so that's sort of an adjustment I'm still going through, right? I still do engagements. I still work directly with clients. I still write technical reports. I actually do go to views or whatever. I also still really like doing that. But as we get bigger, I have to do more and more of the actual executive stuff, right? So. And that's really exciting, right? We're talking earlier about being challenged. I mean, it's an immense challenge. I don't know if I can do it. I don't know. Right now, I think things are going well. And I'm relatively successful. But so what if we grow to 50 people or 80? Right? I don't know if that's even feasible. Let's say we're 80 people. Being a CTO for firm of 80 people is very different. That means that there's no more cycles for me. What's so ever to do any technical work? I still like doing that too. I still like. Like the thing. I'm still good at it too, right? I have to keep up also. You have to keep up. So. Maybe that means that I would not be the right person anymore. Or maybe I can grow into that role. And I really will not. We'll slowly, on some levels, lose some of the technical skills. Because what's the future of the companies? There's still a problem you guys want to solve? No, there's not the regular problem that we want to solve. We want to grow in different directions. I see us maybe build up several different service lines, right? As we grow. Right now, we're really focused on growing the hardware side of things. And as we work with several of the hyperscalers. So that is just a ton of fun, right? You get to see the core technology. For some people that don't know hyperscalers? Hyperscalers are all the big cloud providers, basically. So an Azure Google Cloud AWS. The people that achieve a certain skill in terms of computing and amount of data centers and connectivity that no one really can replicate. And while a lot of people just outsource this, right? You don't need an insane amount of capital expenditures. Nowadays to start a company, you just start with a credit card, monthly fees, your higher service or rent servers. And then maybe at some point you will bring stuff in-house because it gets cheaper again. I mean, you didn't have your own server. So you have this hybrid solution or whatever. I think that's what most people will end up. But I really like that because there's a ton of security challenges there. Everyone is moving to the cloud, is on the cloud, everyone is doing things there. And if you say you're an IoT device manufacturer, so we do that type of stuff too, right? You make some, I don't know, a phrase that has to talk to the cloud for whatever reason to sink your shopping list, that type of stuff. These type of people tend to be good at making frages, right? And then they hire this other consulting firm that gives that does like a design for a little user interface. They hire a bunch of chips and baseboards from some designer in China, whatever. They integrate all of the stuff. These are not the type of people that are then also have the skills and knowledge to securely set up a data center and keep all this data great, right? So it makes way more sense for them to go about without sourcing all of that. All right? We run on Azure and Azure has specific IoT platforms and we integrate on top of that. And we can focus on making a fridge that's internet enabled. Security wise, that's probably out of the box a whole of better than they could do on their own, because you get to leverage the knowledge of all the Microsoft employees. They will have an insane cybersecurity budget. Then you have a ton of other people looking at Microsoft offerings on this. And they screw up, sure, but it's tiny companies you can't achieve that skill. And I'm sure you can find some companies where the technical people are so good that they can do everything themselves. But in most cases, you'll probably be too arrogant and you will probably screw up. Yeah. Do you see a big future for Enfield in that direction? Yeah, I mean, we do what in that direction when we're growing there and we'd love to do more. Again, the moment something becomes super commoditized, say, your standard network pan testing, it's not like we're not interested. It doesn't really get our engineers to excite it, right? And we already we also have clients where we do some more road work, whatever. And that's fine, right? But everyone is still there for the cherries on the pie. Everyone is still there for those test labs, right? Everyone wants to do his cool gigs for the school clients or whatever. And then you suck up doing some more boring work for a while until you get to do those clients. I do the same thing. Right? I'm also so doing some expert. I'm like, God, did some of the stuff 10 years ago? This is not too exciting, right? But that's amazing that you do. The things you love really on the top of the pyramid, I would say. Yeah, I guess. But that's also how you attract probably the best people in the industry. So that's. Yeah, we try, right? And don't forget, some of that slightly less interesting work. An interesting in a sense of your super highly technical, you always want to work on the newest of the newest or the hardest to hack or the most complex, whatever. The slightly less interesting gigs. I mean, that's what we built the company on top of, right? There's no external capital in the company. There's no investors or anything, right? It was just, we and Chris not paying each other, paying ourselves, going for a trying to get some gigs and then slowly getting it rolling. And now we can hire someone. Or if we win this gig, we can hire someone based on that gig. And then after all, we were finally able to pay ourselves a salary. And we did it with some of that we're being boring. And slowly we're now getting more and more exciting gigs. And exciting clients. And it's amazing if we've done it for about four and a half years. Yeah, that's amazing, Jeremy. Well done. Talent over certifications. And you don't care about maybe educational background. Do you look into certifications? That's a question we get a lot. So we do look at certifications. We never really require it, right? The certifications do help, right? Some of our clients mandate it. Because it's so hard to evaluate for our clients, our clients, or anyone retaining service security services, how do you evaluate if someone is any good? You have no clue. Yeah, everyone can say, "I'll do the pentes." Okay, but I don't know. I'm hiring you for a technical expertise. How do you know that you're a good pentester? Well, that's why all these certifications came in. It would be right. You have to crest in the UK and all kinds of stuff. So if someone comes with certifications of a resume, I wouldn't, I think it's a plus, a little plus. It's a tiny plus. Mostly because I'm not too much a fan of the certification process. I know how much is being cheated there and all of that. There's all kinds of stuff going on. And it tends to be checkboxing stuff, right? Okay, yeah, you know, you can jump through a few hoops. That's what you've proven to me with it. However, if you don't have certain skills yet, going through the course and seriously studying for something, I mean, it does give you that jump up, that proof of like, hey, I can do a certain thing. Are there any certifications you recommend, maybe OCP, if you look at the offensive side? I don't directly have any. I mean, first of all, there are too many. I think. What do you have? I don't have any. There we go. That's a moral education. Well, I mean, I have a bachelor degree. But no, I don't have any form.
certain amount of certification and that's not it never was too necessary so I never bothered a client won't ask for it but say if we talk if I talk with a junior engineer or someone who's and they're doing a bunch of engagements for us and it's really hard to also find the time and energy as business we are as much as Anfell has grown to give people the proper amount of time to actually reach the next level or research other things or get better at doing something become a better web app and test or whatever so then you go like okay maybe it makes sense to do a certification right so we have a training budget for everyone we can do and then of course the training budget also for going to conferences and all of that My greatest hack I can imagine that you are a Dutch guy going on these tours in the US maybe that's not really your style but is there one particular hack that you would find very cool to share from a show based perspective well so I think most of my coolest hacks I never really did as from a research perspective well there's two things maybe so one thing that I'm proud of I never did much public research time all kinds of reasons but one thing that I did which is a sort of a silly proof of concept in 2010-2011 so a while ago now I got this I was dealing with the client and the client this was in the UK and the client was making smart meters and I wasn't the hard work guy I still am not but I know my way around but at some point I was talking with him about traffic analysis and he didn't understand what that entails and traffic analysis is sort of very simply but like hey we cannot break the crypto I can just look at things like timing information who communicates with what and where and how big other messages going back and forth based on that you can sometimes deduce certain things and to give an example of that early in my career we found an issue there where you had like those little drop down you can type right and this is for medical application so if you type HIV right it would like slowly fill that out but because the packet sizes and I could rebuild the tree I could not break the crypto I'm not that smart I cannot break the SSL encryption or whatnot but I could figure out still what someone was typing in there in that medical application which of course is immediately probably she sends that right that's a big thing I should not be able to figure out what it is that this person is searching for so I took this concept and then the client I understand it and talking about defining moments in my career maybe this is one I talk with the client and I'm like I need a better example I need an example of everyone understands so I made this very contrived and I'll readily admit that it's contrived but readily a proof of concept where I took Google Maps and I said here's Google Maps Google Maps runs over SSL like there's a little locking your browser you can't break it right Google Maps and I'm going to build up a little database of all the squares and everyone knows if you're on a slow connection Google Maps if you zoom in or use a multi-series little square slowly being loaded so basically I scraped all these squares from several cities like Amsterdam Parish and I made this little tool the only thing it did and really crapily because I'm not a machine learning guy whatever it was really crappy code 2010 or 2011 I made this proof of concept just by figuring out by the sizes what it is that you were looking at on Google Maps and you can find this video on YouTube so that immediately makes it apparent I can point this video to someone I show it to someone and go like look here I'm breaking I'm not breaking the crypto I'm not that smart right I'm only analyzing what's going over the wire back and forth and I can still figure out the fact that you click there and zoom in twice and figure hey you're looking at Paris these coordinates if you let it to the one with the coordinates so I did that and of course it helped the clients okay now I really get it right and that I even flew to Australia for that for Ruckscon to give a talk about it this short talk I wasn't very happy I'm still not a great speaker never did in much sense here and there but and it got released I remember being on the front page of /DOT this is for the old kids or for the younger kids here that was what Reddit now is or whatever or hacker news or something /DOT still out there and Bruce Schneider on his blog posted it so that's my claim to fame that Bruce Schneider once posted something about something I put out there and I'm sure that you can follow what people are doing and Google map and all that sure but it was a contrived example in the sense that you can never ever first of all scrape everything all those images from Google first of all Google will ban you and second of all it's talking petapites of information and second of all then you will have too many false positives right there's too much data in there and you cannot get that much data out of these packet sizes at some point you just it will stop working but at least an example of everyone can follow like hey /DOT and that's a trick /DOT I've seen this in not just in theory in my contrived research example to explain it to people I've seen it in actual medical software medical devices and also other places so this stuff is out there /DOT of very impressive heck /DOT it was nice /DOT it was nice /DOT I think it was a bit of a hack or at least something for the possibility /DOT OK thank you so much Vincent that was really a great pleasure to have you and all the best with the further expansion of NFeel Secure and also the family life here in NFeel Secure /DOT yes maybe for the expansion of the family too who knows /DOT thank you /DOT thank you for listening to Cyber Scready Talks we hope you've enjoyed this episode with the latest trends, war stories and exciting career and it goes if you enjoyed the show please review this podcast on your favorite podcast app also could you do me one small favor could you please share this podcast with one friend that you think would like to show just as much as you do thank you and for all further information please go to csrecruedman.nl/talks and subscribe to this podcast we will be back with another exciting episode in just two weeks so see you next time and stay safe
Podcast Summary
Key Points:
- Vincent Berg is CTO and co-founder of Enfield Secure, a boutique infosec firm based in Seattle and Amsterdam.
- His interest in cybersecurity began at age 15 with LAN parties; he later studied computer science and earned a Master’s in Computer Security.
- He gained early experience at a startup and then worked for IOactive, doing code reviews and pentests for major clients like Microsoft.
- A pivotal moment was a solo project for a German client, where he successfully hacked a complex JavaScript stack, building his confidence.
- He emphasizes practical, hands-on work over academic theory, and believes in putting people in uncomfortable positions to grow.
- Enfield Secure has a global team with offices in Amsterdam and Seattle, and values hiring the right people regardless of location.
- Vincent dislikes the term “cyber,” preferring “information security,” and avoids self-promotion, focusing instead on the work.
Summary:
Vincent Berg, CTO and co-founder of Enfield Secure, started his journey in information security at age 15, organizing LAN parties and later diving into the hacker scene on IRC channels in the late 1990s. After studying computer science and earning a Master’s in Computer Security, he worked at a startup before joining IOactive, where he consulted for major tech clients like Microsoft. A key breakthrough came when he was sent alone to a German client, successfully hacking a complex JavaScript stack and gaining confidence in his abilities.
He values practical, hands-on work over academic theory, noting that many academics lack real-world experience. Enfield Secure, a boutique infosec firm with offices in Amsterdam and Seattle, helps large technology companies secure their products through pentesting and code reviews. The company has a global team and prioritizes hiring the right talent regardless of location.
Vincent avoids self-promotion, preferring to stay low-profile and focus on the work itself. He dislikes the term “cyber,” instead using “information security,” and believes that growth often comes from being placed in uncomfortable situations. His career reflects a blend of technical skill, humility, and a commitment to practical security solutions.
FAQs
It's an interview podcast for Cyberscirty professionals and aspirants, hosted by Laosja and Bruno Leinborg, featuring industry experts discussing trends, horror stories, and career insights in bi-weekly episodes.
Vincent Berg is the CTO and co-founder of Enfield Secure, a boutique information security firm that helps large tech companies secure their products. They are hackers for hire on the good side, improving security of software, hardware, and firmware.
He started at age 12 with a computer, learned programming at 13, and gravitated toward security communities on IRC and forums in the late 90s, trading exploits and tips. He later studied computer science and worked at a startup before joining IOactive to work with Microsoft.
He dislikes the term 'cyber' and prefers 'information security' or 'InfoSec' instead.
Enfield Secure is spread across the globe with offices in Amsterdam and Seattle, and employees in the US, Argentina, and Europe. They prioritize hiring the right people regardless of location, allowing remote work.
He is not driven by fame or stage presence, unlike some in the industry. He prefers to avoid the spotlight and focus on technical work rather than self-promotion.
Chat with AI
Loading...
Pro features
Go deeper with this episode
Unlock creator-grade tools that turn any transcript into show notes and subtitle files.