Cloud Security Podcast by Google

EP125 Will SIEM Ever Die: SIEM Lessons from the Past for the Future

13 snips
Jun 12, 2023
Ask episode
AI Snips
Chapters
Transcript
Episode notes
ADVICE

Focus on Business Risk

  • Prioritize protecting the business itself, not just its machines.
  • Focus on business risks like downtime and data loss, not just malware.
INSIGHT

Threat Chains over Single Indicators

  • Relying on single indicators like firewall drops is unreliable due to high false positives.
  • Combine multiple indicators into threat chains for more accurate detection.
ADVICE

SIEM for Patterns, Not Signatures

  • Avoid using SIEM for detecting specific known threats; use IDS/EDR instead.
  • Focus SIEM on patterns, anomalies, and behaviors for zero-day threat detection.
Get the Snipd Podcast app to discover more snips from this episode
Get the app