Enterprise Security Weekly (Audio)

Reality check on SOC AI; Enterprise News; runZero and Imprivata RSAC interviews - Erik Bloch, HD Moore, Joel Burleson-Davis - ESW #408

7 snips
May 26, 2025
Erik Bloch, CISO at Illumio, highlights the mismatched expectations around AI in Security Operations Centers, emphasizing alert fatigue and vendor discrepancies. HD Moore, CEO of runZero, shares insights on the broken state of vulnerability management, revealing blind spots and the need for better tools. Joel Burleson-Davis, CTO of Imprivata, discusses unique cybersecurity challenges across industries, stressing the importance of tailored solutions. They explore the skepticism surrounding AI's effectiveness and the evolving landscape of cybersecurity.
Ask episode
AI Snips
Chapters
Books
Transcript
Episode notes
ANECDOTE

SOC as a Verb vs. Noun

  • Erik Bloch describes the enterprise SOC as a verb delivering bespoke services to an organization.
  • He differentiates between enterprise SOCs and MSSP SOCs, emphasizing the human element in enterprises.
INSIGHT

Phishing Dominates SOC Work

  • Phishing emails remain the predominant workload for SOC teams even in 2025.
  • It's effective because it's cheap and easy, despite evolving attack techniques.
INSIGHT

Profit vs. SOC Problem Solving

  • SOC tools and vendors often prioritize profit over solving problems.
  • This misalignment causes persistent alert noise and minimal true positive detections in SOCs.
Get the Snipd Podcast app to discover more snips from this episode
Get the app