

Building an Incident Response Team for High-Growth Companies
Aug 22, 2024
In this discussion, Santiago, a Senior Security Engineer at Canva, shares insights on building incident response teams in high-growth companies. He explains how incident response differs in fast-paced versus established environments and the vital skills needed for effective management. Santiago also touches on the importance of communication, the dynamic between Red Teams and incident responders, and strategies for enhancing endpoint security. Additionally, he highlights the role of data visualization in security monitoring, emphasizing the need for effective dashboard design.
AI Snips
Chapters
Transcript
Episode notes
IR in Different Organizations
- Incident response (IR) varies between established and high-growth companies.
- Scale is a key differentiator, impacting tooling and process complexity.
Red Team vs. IR
- Red teams emulate attacker tactics to expose vulnerabilities.
- Incident responders investigate and contain real-world incidents and remediate vulnerabilities post-attack.
Cloud IR Challenges
- Cloud IR relies heavily on the provider's tools and infrastructure.
- Recreating attack paths can be challenging due to evidence limitations.