

Detection at Scale
Panther Labs
The Detection at Scale Podcast is dedicated to helping security practitioners and their teams succeed at managing and responding to threats at a modern, cloud scale. Hosted by Jack Naglieri, Founder and CTO at Panther, every episode is focused on actionable takeaways to help you get ahead of the curve and prepare for the trends and technologies shaping the future.
Episodes
Mentioned books

Sep 24, 2024 • 19min
Grammarly’s Thijn Bukkems on Working Backwards from Response Strategies
Thijn Bukkems, Threat Hunting Lead at Grammarly, shares his expertise in building robust security intelligence programs. He emphasizes working backwards from response strategies to create effective threat detection mechanisms. Collaboration across teams is crucial to avoid silos and uncover valuable insights. Thijn discusses maximizing existing resources, enhancing security efficiency through adaptable tools, and the importance of internal threat modeling. He highlights the need to prioritize tasks and balance analytical research with practical solutions in the ever-evolving landscape of cybersecurity.

Sep 4, 2024 • 25min
CRED’s Saksham Tushar on Data Enrichment for Effective Threat Detection
Saksham Tushar, the Head of Security Operations & Threat Detection Engineering at CRED, dives into the intricacies of compliance in a fast-paced tech environment. He discusses how CRED streamlines complex compliance requirements and leverages automation to enhance threat detection. Saksham highlights the importance of verifying automated outcomes and using Python libraries for swift incident investigations. Additionally, he emphasizes the need for contextual understanding of security incidents and the integration of threat intelligence to create a robust security operations framework.

Aug 20, 2024 • 41min
Netflix’s Dan Cao and Brex’s Josh Liburdi on Balancing Big Platforms and Bespoke Tools
Dan Cao is the Engineering Manager of Security Incident and Response at Netflix, and Josh Liburdi is a Staff Security Engineer at Brex. They dive into the shift toward developer-centric security operations and the challenge of balancing big platforms with bespoke tools. The importance of critical thinking and foundational skills in cybersecurity is emphasized. They share strategies for building resilient security teams through effective mentorship and culture, highlighting the need for adaptability in our ever-evolving tech landscape.

Aug 6, 2024 • 24min
ThoughtSpot’s Alessio Faiella on Building Forward-Looking Security Programs
Alessio Faiella, the Director of Security Engineering & Security Operations at ThoughtSpot, shares his expertise on building forward-looking security initiatives. He emphasizes the importance of understanding product nuances and user behavior in security strategy. Alessio discusses how AI enhances detection and response, offering real-time recommendations during incidents. He highlights the need for detailed playbooks to optimize resource allocation and covers the balance between automation and human oversight to strengthen security operations.

4 snips
Jul 23, 2024 • 25min
Sprinklr’s Roger Allen on Preventing Team Burnout in Cybersecurity
Roger Allen, Senior Director and Global Head of Detection and Response at Sprinklr, delves into the complexities of cybersecurity. He emphasizes the importance of understanding adversaries' tactics to enhance detection capabilities. Roger discusses integrating adversary simulations to strengthen security measures and improve response strategies. He addresses team burnout through balanced workloads and meaningful discussions. With actionable insights on data management and alert prioritization, he provides a roadmap for building resilient security operations.

Jul 9, 2024 • 21min
WP Engine’s Christopher Watkins on Cost-Effective Threat Hunting Strategies
Christopher Watkins from WP Engine shares insights on efficient logging with native tools and API gateways. Strategies for cost-effective threat hunting and optimizing queries. Importance of mental well-being in cybersecurity. Tips on data management across cloud services.

Jun 25, 2024 • 28min
Elastic’s Darren LaCasse on Cutting Alert Volumes in Half By Automating Responses
In this episode of Detection at Scale, Jack Naglieri chats with Darren LaCasse, Director of Threat Intelligence, Incident Response, & Threat Detection at Elastic. Darren offers insights into the innovative project around detection as code, shedding light on the methodologies Elastic employs to enhance security operations.
Darren touches on the challenges of managing massive amounts of data, the importance of prioritization in security tasks, and how automation has revolutionized their response strategies. He also shares practical advice on conducting gap analyses to focus on what truly matters.
Topics discussed:
The importance of prioritizing security tasks to focus on critical business-impacting elements, ensuring a resilient security framework.
Strategies for handling and analyzing large volumes of security data to maintain effective monitoring and response capabilities.
How automation has halved alert volumes, freeing analysts from repetitive tasks and enhancing overall productivity.
Conducting regular gap analyses and attack path discussions to visualize vulnerabilities and direct security efforts effectively.
The role of tagging and context-aware responses in streamlining security operations and making analysts' lives easier.
Prioritizing security efforts based on the criticality of vendors and data, focusing first on restricted and critical vendors.
The importance of conducting at least annual reviews to reassess and improve security controls and monitoring strategies.
Using metrics to measure the effectiveness of security measures and guide continuous improvement efforts.
Resources Mentioned:
Darren LaCasse on LinkedIn
Elastic Security Solution website

5 snips
Jun 11, 2024 • 44min
Check Point’s Daniel Wiley on Balancing Technology and Human Analytics in Cybersecurity
Daniel Wiley, Head of Threat Management at Check Point, discusses the highs and lows of cybersecurity startups, effective incident response strategies for SMBs, and the integration of machine analytics and human expertise in managing large amounts of cybersecurity data.

May 28, 2024 • 19min
Inductive Automation’s Jason Waits on Building Scalable Security Programs Through Automation
Jason Waits, CISO at Inductive Automation, discusses the role of SCADA systems in security, challenges in building scalable security programs with automation, and the impact of IT-OT convergence. He emphasizes the importance of automation in security operations, ML, and AI for efficient data analysis to enhance detection capabilities.

May 21, 2024 • 24min
Panther’s Jack Naglieri on Navigating the New Role of Detection Engineering in Cybersecurity (Special Episode)
In our recent special Hot Ones-style episode of Detection at Scale, Panther CEO Will Lowe and Founder & CTO Jack Naglieri sit down to taste hot sauces and talk hot topics in the field of cybersecurity. Jack shares his evolution from security professionals to founders, emphasizing the importance of experience and understanding attacker profiles.
Jack also gives his insights on the foundational skills to becoming a detection engineer, including building detection engineering functions and having war room experience. He also discusses the evolving role of AI in the security field, such as its usefulness in generating code for detection programs.
Topics discussed:
Jack’s transition from practitioner to company founder, emphasizing the importance of saying yes to opportunities and keeping an open mind.
Building detection engineering functions with a focus on understanding what needs to be detected and why.
The significance of measurement in detection engineering and the importance of a growth mindset for continuous improvement.
The importance of understanding the experiences of security practitioners and software engineers.
The role of war room experience in understanding attacker profiles and the importance of incident response strategies to prepare for a role as a detection engineer.
The importance of sharing knowledge and experiences within the cybersecurity community.
Resources Mentioned: Jack Naglieri’s Substack


