Check Point’s Daniel Wiley on Balancing Technology and Human Analytics in Cybersecurity
Jun 11, 2024
auto_awesome
Daniel Wiley, Head of Threat Management at Check Point, discusses the highs and lows of cybersecurity startups, effective incident response strategies for SMBs, and the integration of machine analytics and human expertise in managing large amounts of cybersecurity data.
Balancing technology and human analytics is crucial in cybersecurity for effective incident response strategies.
Continuous learning and self-care are essential for resilience and success in the constantly evolving field of cybersecurity.
Deep dives
Importance of Scaling and Making Decisions
To deal with large amounts of data at scale, concessions and tough choices must be made when determining what to focus on. Managing detection for numerous customers alters the approach to detecting threats on a grand scale. The need for detecting signals in a sea of noise requires leveraging various layers of detection capabilities.
Critical Factors for Detection Engineering
Maintaining quality telemetry data is essential for successful detection; ensuring good data sources and tools play a vital role. Many businesses lack fundamental security components like advanced EDR, robust email protections, and capable gateway products, hindering their ability to scale detection effectively. Prioritizing key metrics like telemetry quality and vendor trust enhances detection accuracy.
Evolution of Detection Engineering
As AI becomes more integrated into security technology, detection engineers are increasingly focused on training AI for pattern recognition and deep analytics. While basic detection tasks become more automated, the future may involve training AI engines to identify complex anomalies and unique threat patterns for more advanced detection capabilities.
Advice on Learning and Self-Care in Security Professions
Continuous learning is crucial in security, encouraging exploration and questioning to enhance skills. Taking care of one's physical and mental well-being is vital in handling the emotional toll of security work. Seeking support from colleagues, maintaining relationships, and self-care practices are essential for resilience in dealing with the challenges of the security profession.
In this episode of the Detection at Scale podcast, Jack speaks to Daniel Wiley, Head of Threat Management and Chief Security Advisor at Check Point Software, to discuss the intricacies of balancing technology and human analytics in cybersecurity.
Daniel shares his experiences in building three successful internal startups at Check Point and emphasizes the importance of continuous learning throughout one’s career. He also touches on effective incident response strategies for small- to medium-sized businesses, and the vital role of adaptable data schemas in managing large-scale security operations.
Topics discussed:
The highs and lows experienced in the cybersecurity startup journey, including the importance of quick decision-making and team-building.
Strategies for developing effective IR playbooks tailored for small- to medium-sized businesses to handle security threats efficiently.
The integration of machine analytics and human expertise to manage and interpret large volumes of cybersecurity data.
Managing 24/7 global SOCs, including the challenges of shift rotations and ensuring analysts are not overloaded.
Techniques for determining which data is crucial for cybersecurity efforts and how to handle terabytes of data per second.
The necessity of ongoing education and staying updated with the latest in cybersecurity to maintain effectiveness in the field.
The significance of hiring the right team from the start and making swift, decisive personnel changes when necessary.
Check Point's focus on maintaining high operational margins and its impact on the business's success and sustainability.