Hello, I'm Per Morten

I'm the Head of Information Security at Firi.com, a cryptocurrency exchange in Norway, with over 20 years of experience in cybersecurity. I work with threat intelligence, incident response, and security architecture.

About Me

Head of Information Security at Firi.com

Responsible for information security strategy and operations at a Norwegian cryptocurrency exchange, managing security frameworks and compliance with financial regulations.

Incident Response

Led mIRT (mnemonic Incident Response Team) handling incidents including ransomware attacks, persistent threats, and breaches at organizations like Stortinget and DSS.

Threat Intelligence

Built threat intelligence frameworks for the Nordic financial sector as Head of Threat Intelligence at Nordic Financial CERT.

Security Research

Discovered CVE-2023-35078 vulnerability in Ivanti EPMM. Member of Underworld.no and RSA Conference Europe program committee.

Professional Experience

2025-

Head of Information Security

Firi.com

Managing information security strategy and operations for a Norwegian cryptocurrency exchange, maintaining security frameworks and compliance with financial regulations.

  • Overseeing comprehensive information security framework
  • Developing and implementing security policies and procedures
  • Leading security team in threat identification and mitigation
  • Ensuring compliance with financial industry standards
  • Managing security operations for cryptocurrency trading platform
2018-2025

Team Leader

Mnemonic AS

Led Threat Intelligence services and Incident Response Team (mIRT) for internal and external customers, handling security incidents across various sectors.

  • Led incident response for Stortinget (Norwegian Parliament) compromise
  • Managed DSS (Department Security Service) breach response
  • Handled multiple ransomware attacks and APT incidents
  • Developed threat intelligence frameworks for enterprise clients
  • Discovered CVE-2023-35078 zero-day vulnerability in Ivanti EPMM
2013-2018

Head of Threat Intelligence

Nordic Financial CERT

Built threat intelligence frameworks for the Nordic financial sector, contributing to the organization's development.

  • Defined and established cyber threat intelligence framework for Nordic financial sector
  • Led organizational development and CERT function establishment
  • Supported Incident Response Teams with guidance during serious security incidents
  • Coordinated threat intelligence sharing across Nordic financial institutions
2012-2013

Security Engineer

Intel Security (McAfee)

Served as the only pre-sales support in Norway for Intel Security, covering the company's comprehensive product portfolio from endpoint security to cloud services.

  • Specialized support for SIEM solutions (Intel Security ESM)
  • Expertise in Web Gateway and Network Security Platform (NSP)
  • Advanced Threat Defence functionality implementation
  • Nordic team collaboration covering Norden and Baltics
2009-2012

Head of Security Intelligence and Counter Threat

DNB Bank AS

Led a team covering ICT threat landscape, IT security architecture, and incident handling (IRT) within DNB IT's Information Security and IT Risk Management division.

  • Led team of 800+ IT professionals across Oslo, Bergen, and Trondheim
  • Managed PKI procurement project for enterprise-wide Public Key Infrastructure
  • Led MSSP procurement project for managed security services
  • Part of extended management group for IT and CISO leadership

Core Competencies

Threat Intelligence

  • Cyber Threat Intelligence Framework Development
  • Adversary Intelligence & OSINT Research
  • Threat Landscape Analysis
  • Zero-day Vulnerability Discovery

Incident Response

  • Advanced Persistent Threat (APT) Response
  • Ransomware Attack Management
  • High-profile Breach Investigation
  • Digital Forensics & Analysis

Leadership & Strategy

  • Team Leadership (800+ professionals)
  • Security Architecture Design
  • Risk Management & Compliance
  • Executive Communication

Technical Expertise

  • Cryptocurrency Exchange Security
  • Financial Services Compliance
  • SIEM Platforms (Intel Security ESM)
  • Cloud Security (Azure, AWS, Google)
  • Python Scripting & Automation

Achievements & Recognition

🏆

CVE Discovery

Discovered CVE-2023-35078 vulnerability in Ivanti EPMM.

🎤

Conference Speaker

Presented at conferences including HackCon, Digital Crimes Consortium, and TF-CSIRT on threat actors and exploits.

🔒

CISSP Certified

Certified Information Systems Security Professional since 2008.

🌍

Europol EC3

Presented analysis of banking trojans to law enforcement at Europol EC3, including FBI and police from EU, Australia, and USA.

👥

Community Involvement

Member of Underworld.no and RSA Conference Europe program committee.

🏛️

High-Profile Incidents

Led incident response for Norwegian Parliament (Stortinget) and Department Security Service (DSS) breaches.

Cryptocurrency Security

Head of Information Security at Firi.com, a Norwegian cryptocurrency exchange.

A little more about me

Frequently asked questions

The short version of what it is like to work with me and what I value.

Does he keep his word?

I take commitments seriously. If circumstances change, I communicate early, explain why, and work toward a practical solution.

How does he handle pressure?

With calm, curiosity, and a focus on facts. I try to create clarity for others and turn complex problems into manageable next steps.

What matters most to him?

People, integrity, and doing useful work. Security is ultimately about protecting the people and communities behind the systems.

Is he approachable?

Yes. Whether the topic is a security incident, a new idea, or a difficult question, I believe good conversations start with listening.

Get in Touch

Connect with Me

Contact me to discuss cybersecurity, threat intelligence, or security projects.

Email: hello@sandstad.email
Underwold.no: underwold.no
Response Time: Usually within 24 hours

Send me a message