
Strategy 5: Prioritize Incident Response
Blueprint: Build the Best in Cyber Defense
00:00
How to Deal With the Risk of False Positives
An incident can often look like something you've seen before and then be totally different than what you thought it was to begin with. And so the danger of acting on bias, the danger of bias in an investigation or an incident is getting it wrong. I would also offer, in my experience, the most times I see a eviction in response occur,. It's not where we, it's notWhere we see exfiltration, it actually like in progress happening right now... Rather, it's we now understand the extent of access the adversary has usually measured on the identity plane. Then we're denying the adversary's ability to leverage that access they have in the identity Plane.
Transcript
Play full episode