Welcome to Season 5 of the Cyber Security District Podcast. In this episode of the Cyber Security District Podcast, we sit down with Mischa van Geelen, one of the Netherlands’ most remarkable cybersecurity professionals. His journey from a self-taught teenage hacker to leading incident response at some of Europe’s largest financial institutions is a story of talent, perseverance, and vision.
At just 13 years old, Mischa discovered a critical vulnerability at a major Dutch bank. By 15, he became the youngest full-time penetration tester at a global consultancy. In his twenties, he co-founded one of the Netherlands’ top incident response firms, served as TISO at major payment institutions such as iDEAL and the European Payment Initiative (EPI), and is now preparing to launch his next venture.
Meet Mischa van Geelen
Mischa van Geelen’s story is anything but traditional. Entirely self-taught, he began exploring cybersecurity as a teenager, motivated by curiosity and the desire to understand how systems worked, and how they could break. His early discovery of a banking vulnerability set the stage for a lifelong career dedicated to improving digital resilience.
From rebuilding a college’s IT infrastructure after a ransomware attack to leading cybersecurity programs at payment giants, Mischa’s approach combines deep technical skill with a strategic understanding of business risk. He’s candid about the realities of burnout, “watermelon compliance,” and the gaps between regulation and real security. As he puts it,
“Security shouldn’t just check boxes. It should enable organizations to move faster and safer.”
Cyber Resilience Beyond the Firewall
In the conversation, Mischa talks about the difference between theoretical security and operational reality. Many companies, he argues, are still stuck in a reactive cycle, focusing on compliance rather than true resilience.
Drawing from his experience leading incident response operations, he emphasizes that most breaches reveal the same core problems: poor communication, untested processes, and the absence of clear ownership. According to Mischa, resilience begins with culture, not tools.
He explains,
“Technology is never the hardest part. The real challenge is getting people aligned, communicating under pressure, and making the right calls when everything’s on fire.”
His perspective is grounded in years of hands-on experience managing crises and rebuilding trust after incidents. The episode offers rare insight into how technical expertise and leadership must come together during high-stakes moments.
The Hidden Cost of “Watermelon Compliance”
One of the most thought-provoking parts of the discussion is Mischa’s critique of what he calls “watermelon compliance.” On the surface, everything looks green: metrics are positive, audits are passed, but underneath, the organization is red, with unresolved vulnerabilities and unprepared teams.
He warns that this false sense of security can be more dangerous than clear, visible risks. He explains,
“A company can be compliant and still completely insecure,”. “Compliance doesn’t stop ransomware, and it doesn’t help you recover faster.”
Mischa argues that meaningful security programs must measure readiness and adaptability, not just checkbox compliance. His approach focuses on creating a shared understanding between technical and business leaders, something he believes is key to long-term success.
From Incidents to Innovation
After years on the frontlines of incident response, Mischa is channeling his experience into building new solutions. He believes the industry needs tools and frameworks that go beyond prevention, empowering teams to respond faster and learn from every event.
“Most organizations treat incidents as failures, but they’re opportunities to get better. Every attack shows you exactly where your blind spots are, if you’re willing to look.”
Since recording the episode, Mischa has continued expanding his team and preparing to launch his next venture, focused on helping organizations close these gaps through smarter automation and better data visibility.
Looking Ahead
Mischa’s career illustrates what’s possible when curiosity meets conviction. From finding his first vulnerability at 13 to leading security at Europe’s most trusted payment providers, his journey reflects the evolution of cybersecurity itself, from reactive defence to strategic business enabler.
His message is clear: security leaders must balance technical depth with empathy, communication, and clarity under pressure. These are the traits that separate effective responders from the rest.
As the cyber landscape continues to evolve, Mischa’s perspective serves as a reminder that real resilience begins long before an incident happens.
Watch the full episode on YouTube:







