Preparation: The Less Shiny Side of Incident Response - Joe Gross - ESW #360
May 3, 2024
auto_awesome
Expert Joe Gross emphasizes the importance of preparing for cyber incidents, breaking down tasks required for incident response. Discussion includes RSA news overload, Verizon's DBIR, and Mandiant’s M-Trends. Insights on incident response foundations, threat detection, and engaging training scenarios. Exploring investments in cybersecurity technologies and financial dynamics in tech industries. Unique discussions on DM funding, ARK browser features, and Nord Security's product launch. Cloud security enhancement with AWS resource tagging and insight into cybersecurity trends and cloud threat models.
Regular training and tabletop exercises are crucial for effective incident response planning.
Island's success demonstrates market acceptance of secure browsing solutions in cybersecurity.
Establishing AI marketing ethics policy is essential for ethical AI-driven marketing strategies.
Deep dives
Greylog Discusses Incident Response Preparedness and Security Trends
Incident response expert Joe Gross shares valuable insights on the importance of consistent training and tabletop exercises for effective IR planning. He emphasizes the need for organizations to structure tabletop scenarios realistically and involve key stakeholders such as legal and PR teams. Gross highlights the significance of practicing incident response regularly, advising quarterly full-day exercises for mature teams and more frequent sessions for beginners. He underscores the importance of augmenting IR staff to prevent burnout during prolonged incidents and emphasizes the value of feeding, resting, and rotating team members for optimal performance.
Island's recent $175 million Series D funding, valuing the firm at $3 billion, reflects the growing market for secure browsing solutions. Contrary to initial skepticism on secure browsers, the success of Island demonstrates market acceptance and clear value proposition in the cybersecurity landscape. With a competitive edge after Talon's acquisition by Palo Alto Networks, Island is poised to address emerging threats like unauthorized data sharing through corporate end-users. Backed by Sequoia and Co2, the company's funding signifies confidence in its growth potential despite a crowded security market.
AI Ethics Policy in Marketing
The podcast episode highlighted the importance of establishing an AI marketing ethics policy to ensure ethical practices in marketing strategies involving artificial intelligence.
Accelerating Incident Response with Generative AI
The blog discussed how generative AI can accelerate incident response processes and enhance security incident analysis using innovative approaches and technology.
Vulnerability Exploitation Trends
The podcast explored the significant increase in vulnerability exploitation rates, indicating a shifting focus towards exploiting vulnerabilities over social engineering techniques in cyber attacks.
Universal Cloud Threat Model
Rich Mogul and Chris Ferris introduced a new cloud threat model to address the unique security challenges in cloud environments, offering insights into comprehensive cloud threat assessment and response strategies.
It's the most boring part of incident response. Skip it at your peril, however. In this interview, we'll talk to Joe Gross about why preparing for incident response is so important. There's SO MUCH to do, we'll spend some time breaking down the different tasks you need to complete long before an incident occurs.
It's the week before RSA and the news is PACKED. Everyone is trying to get their RSA announcements out all at once. We've got announcements about funding, acquisitions, partnerships, new companies, new products, new features...
To make things MORE challenging, everyone is also putting out their big annual reports, like Verizon's DBIR and Mandiant's M-Trends!
Finally, we've got some great essays that are worth putting on your reading list, including a particularly fun take on the Verizon DBIR by Kelly Shortridge.