Загрузка...

Stop, Assess, Act: A Detective's Approach to Incident Response with Stuart Bird, DFIR Leader

Stuart Bird has spent nearly four decades dealing with the worst moments organisations, and people, will ever face.

Twenty-one years in UK law enforcement, including early high-tech crime work triggered by Operation ORE, gave him an investigative foundation that most in the industry simply don't have. Since moving into the private sector, he's managed over 1,000 cyber incidents globally, from ransomware and data breaches to insider threats and APTs.

In this episode, Stuart breaks down what actually happens in the first 24 to 72 hours of a cyber incident, why most organisations are already several steps behind by the time they pick up the phone, and what the detective's mindset, who, what, where, when, why, how, brings to incident response that no tool can replicate.
We cover the common mistakes he sees time and again: CEOs pushing to pay the ransom before any proper assessment, teams that try to fix it themselves for five days before calling for help, and playbooks that have never been tested and don't reflect reality. Stuart also makes the case that organisations are thinking about incident response the wrong way, focusing on the end game rather than the six or seven points in the kill chain where an attack could have been stopped before the encryption ever lands.
If you're a CISO, IT or security manager, or business owner trying to understand what good incident response actually looks like, this is a conversation worth your time.

Видео Stop, Assess, Act: A Detective's Approach to Incident Response with Stuart Bird, DFIR Leader канала Secon
Яндекс.Метрика
Все заметки Новая заметка Страницу в заметки
Страницу в закладки Мои закладки
На информационно-развлекательном портале SALDA.WS применяются cookie-файлы. Нажимая кнопку Принять, вы подтверждаете свое согласие на их использование.
О CookiesНапомнить позжеПринять