Maxime Lamothe-Brassard, Co-Founder of LimaCharlie, discusses modern SecOps, evolution of EDR, tailoring security solutions, bridging on-prem and cloud security with Leemich Ali, querying language in Lima Charlie product, and highlights of an innovative cybersecurity conference.
Read more
AI Summary
AI Chapters
Episode notes
auto_awesome
Podcast summary created with Snipd AI
Quick takeaways
Modern SecOps combines security and operations teams for organization protection.
LimaCharlie offers flexible cloud SecOps solutions for MSSPs, enterprises, and startups.
Sleeper Mode and querying language enhance incident response and data analysis in LimaCharlie platform.
Deep dives
Maxim Lamath-Brusard's Journey to Founding Lima-Charlie and the Need for Modern Security Operations
Maxim Lamath-Brusard, co-founder of Lima-Charlie, shared his journey to founding the project, emphasizing the need for modern security operations. Initially working in security at the Canadian Intelligent Service, CrowdStrike, and Google, his experience highlighted a lack of tailored solutions for larger organizations like Google. This gap led him to launch Lima-Charlie, originally an open source EDR project, which later evolved into a cloud SecOps platform.
Understanding the Evolution of Endpoint Detection Response (EDR) and Lima-Charlie's Cloud Provider Approach
EDR, focusing on visibility and response, has evolved in the industry, merging with aspects of traditional antivirus solutions. Lima-Charlie positions itself as a cloud provider for cybersecurity capabilities, akin to how AWS offers EC2. By prioritizing the flexibility to customize and assemble security capabilities, Lima-Charlie diverges from the promise-based vendor model, emphasizing capability over product.
User Profiles and Adoption of Lima-Charlie's SecOps Cloud Platform
Lima-Charlie caters to diverse user profiles, including managed security service providers (MSSPs), enterprises, and startups. MSSPs benefit from the ease of deployment and scalability, while tech-forward enterprises appreciate the capability-centric approach. Lima-Charlie also supports startups in rapidly bringing security products to market through a pay-as-you-go model, akin to the agility offered by AWS for startups.
The Innovative Sleeper Mode Feature and Lima-Charlie's Cost-Effective Approach
Lima-Charlie's introduction of Sleeper Mode, a feature that allows agents to remain active but cost-effective, revolutionizes incident response and proactive security measures. By offering a cost-efficient pre-deployment option, Lima-Charlie enhances response times during security incidents. The cost-effective model aligns with Lima-Charlie's commitment to providing value-driven solutions while maintaining competitive pricing.
Lima-Charlie's Querying Language Initiative and its Impact on User Experience
Lima-Charlie's introduction of a querying language in 2021 aimed to streamline data analysis and enhance user experience. Built on an existing automation engine, the querying language enables users to extract actionable insights from security event data efficiently. The language's integration with the automation engine simplifies rule creation and fosters a seamless transition between manual queries and automated security responses.
Security Operations, or SecOps, refers to the collaboration between security and operations teams to secure an organization’s systems, applications, and data.
Maxime Lamothe-Brassard is a Co-Founder of LimaCharlie which is a cloud SecOps platform. He has a background in security and has previously worked at the Canadian Intelligence service, Crowdstrike, Google, and Google X. He joins the podcast to talk about modern security operations.
Gregor Vand is a security-focused technologist, and is the founder and CTO of Mailpass. Previously, Gregor was a CTO across cybersecurity, cyber insurance and general software engineering companies. He has been based in Asia Pacific for almost a decade and can be found via his profile at vand.hk.