From 13 Year Old Hacker to Cybersecurity Leader with Mischa van Geelen
Geen categorie
News
6 November 2025

From 13 Year Old Hacker to Cybersecurity Leader with Mischa van Geelen

Welcome to Season 5 of the Cyber Security District Podcast. In this episode of the Cyber Security District Podcast, we sit down with Mischa van Geelen, one of the Netherlands’ most remarkable cybersecurity professionals. His journey from a self-taught teenage hacker to leading incident response at some of Europe’s largest financial institutions is a story of talent, perseverance, and vision.

At just 13 years old, Mischa discovered a critical vulnerability at a major Dutch bank. By 15, he became the youngest full-time penetration tester at a global consultancy. In his twenties, he co-founded one of the Netherlands’ top incident response firms, served as TISO at major payment institutions such as iDEAL and the European Payment Initiative (EPI), and is now preparing to launch his next venture.

Meet Mischa van Geelen

Mischa van Geelen’s story is anything but traditional. Entirely self-taught, he began exploring cybersecurity as a teenager, motivated by curiosity and the desire to understand how systems worked, and how they could break. His early discovery of a banking vulnerability set the stage for a lifelong career dedicated to improving digital resilience.

From rebuilding a college’s IT infrastructure after a ransomware attack to leading cybersecurity programs at payment giants, Mischa’s approach combines deep technical skill with a strategic understanding of business risk. He’s candid about the realities of burnout, “watermelon compliance,” and the gaps between regulation and real security. As he puts it,

“Security shouldn’t just check boxes. It should enable organizations to move faster and safer.”

Cyber Resilience Beyond the Firewall

In the conversation, Mischa talks about the difference between theoretical security and operational reality. Many companies, he argues, are still stuck in a reactive cycle, focusing on compliance rather than true resilience.

Drawing from his experience leading incident response operations, he emphasizes that most breaches reveal the same core problems: poor communication, untested processes, and the absence of clear ownership. According to Mischa, resilience begins with culture, not tools.

He explains,

“Technology is never the hardest part. The real challenge is getting people aligned, communicating under pressure, and making the right calls when everything’s on fire.”

His perspective is grounded in years of hands-on experience managing crises and rebuilding trust after incidents. The episode offers rare insight into how technical expertise and leadership must come together during high-stakes moments.

The Hidden Cost of “Watermelon Compliance”

One of the most thought-provoking parts of the discussion is Mischa’s critique of what he calls “watermelon compliance.” On the surface, everything looks green: metrics are positive, audits are passed, but underneath, the organization is red, with unresolved vulnerabilities and unprepared teams.

He warns that this false sense of security can be more dangerous than clear, visible risks. He explains,

“A company can be compliant and still completely insecure,”. “Compliance doesn’t stop ransomware, and it doesn’t help you recover faster.”

Mischa argues that meaningful security programs must measure readiness and adaptability, not just checkbox compliance. His approach focuses on creating a shared understanding between technical and business leaders, something he believes is key to long-term success.

From Incidents to Innovation

After years on the frontlines of incident response, Mischa is channeling his experience into building new solutions. He believes the industry needs tools and frameworks that go beyond prevention, empowering teams to respond faster and learn from every event.

“Most organizations treat incidents as failures, but they’re opportunities to get better. Every attack shows you exactly where your blind spots are, if you’re willing to look.”

Since recording the episode, Mischa has continued expanding his team and preparing to launch his next venture, focused on helping organizations close these gaps through smarter automation and better data visibility.

Looking Ahead

Mischa’s career illustrates what’s possible when curiosity meets conviction. From finding his first vulnerability at 13 to leading security at Europe’s most trusted payment providers, his journey reflects the evolution of cybersecurity itself, from reactive defence to strategic business enabler.

His message is clear: security leaders must balance technical depth with empathy, communication, and clarity under pressure. These are the traits that separate effective responders from the rest.

As the cyber landscape continues to evolve, Mischa’s perspective serves as a reminder that real resilience begins long before an incident happens.

Watch the full episode on YouTube:

RESOURCE GUIDE

Cyber Security Salary Guide 2024

Whether you’re considering a job change or seeking a promotion, our guide helps you understand what you should be earning and plan your career effectively.
Accurate Salary Insights: Helping you negotiate fair compensation
Labour Market Trends: Helping you understand the emerging roles in cybersecurity
Salary Conditions Data: Helping you understand which roles offer the best benefits
Hiring Manager Demands: Helping you stay relevant which changing hiring demands

More articles

Securing the World’s biggest HR Firm with Martijn Nykerk, CISO at Randstad

Season 6 of Cyber Security District podcast is here and we sit down with Martijn…

2026 Cybersecurity Salary Guide

Are you wondering how your salary compares in today’s cybersecurity job market? Or are you…

From FinTech Founder to Cyber Investor with Chris Zadeh

Season 6 of Cyber Security District podcast is here, and we sit down with Chris…

From 3x CISO to Founder: Building the Tool She Always Needed with Jaya Baloo

Season 6 of Cyber Security District podcast is here, and we sit down with Jaya…

How to Write a Great Cybersecurity Job Description for the Dutch Market

Write a Cybersecurity Job Description That Attracts Top Talent in 2026

Attracting top cybersecurity professionals in 2026 requires more than posting a generic job ad. The…

Top Cybersecurity Hiring Trends in the Netherlands for 2026

Cybersecurity hiring in the Netherlands continues to evolve as organisations face stricter regulations, AI-driven threats,…

Checklist for Hiring Your First Cybersecurity Professional in 2026

Cybersecurity is no longer optional for small and mid-sized Dutch companies. In 2026, stricter European…

Why AI-Ready Cybersecurity Skills Are a Must in 2026 Dutch Market

Why AI-Ready Cybersecurity Skills Are a Must in 2026

Cybersecurity in 2026 looks very different than it did just a few years ago. Dutch…

How Dutch Companies Can Build a Cybersecurity Team in 2026

How Dutch Companies Can Build a Cybersecurity Team in 2026

Building a strong cybersecurity team is one of the most strategic investments a Dutch organisation…

Cybersecurity Jobs in Demand in Europe for 2026

Cybersecurity Jobs in Demand in Europe for 2026

Demand for cybersecurity professionals in Europe continues to grow. Organisations are expanding digital services and…