À PROPOS DE CET ÉPISODE
Today’s incident response ain’t your grandfather’s IR. But the psychology surrounding it hasn’t changed an iota. This is precisely what Sam Rehman, EPAM’s Chief Information Security Officer and SVP, and Tab Bradshaw, Chief Operating Officer at Redpoint Cybersecurity, are talking about on this #SecurityByDesign conversation.
“It really comes down to the preparation piece,” says Bradshaw. It’s about being well prepared and asking: “How often do you prepare in your organization, at a technical level, at an executive level, to handle some sort of incident?”
Rehman agrees and says that he has clients wondering, “OK, so when am I done?” The perception is that being IR-ready is enough, he says. “That's not the case. It's a muscle. It's emotion. It's how you work. It's how you react to it.”
There are benefits to knowing the proper way to react. “A well-handled breach really builds credibility,” says Bradshaw, adding that the word “reasonable” is omnipresent in IR documentation. He says: “Reasonableness is not just about having a mitigation strategy.” It’s also about, say, practicing tabletop exercises. Regularly. So that when you’re asked about doing regular tabletop sessions, the answer is, as Bradshaw puts it: “Yes, we did it every quarter for the past five years. We feel like we're in a pretty good spot that if something happens, might not be perfect, but we think we have good preparation, consistent preparation, consistent practice, to your point, to respond to the incident when it does occur.”
Rehman says that security people are “used to having that sudden sense of violent impulse and urgency coming to us,” but what about the business leaders and everyone else in the organization? He asks Bradshaw about IR communication: “How do you guide the team through it, especially when everybody's thinking about, ‘Oh, am I gonna be on the news?’”
Of the thousands of breaches Bradshaw and his team have responded to, for “a third, maybe half” of them, there is “some internal chaos at the client—and it's not because anybody's doing a bad thing.”
“It really comes down to what I call C-squared,” says Bradshaw, which is shorthand for “communication and coordination. Someone has to be the quarterback.”
Bradshaw says the chaos is about “a lack of preparation and testing.” A tabletop exercise needs to be a live fire exercise: “Doing it once a year is not good.” Too many organizations treat IR as a checklist, which is a mistake. He says: “It's a living, cross-functional discipline that evolves with the threat landscape externally, obviously, and also internally as people move.”
And so?
Get moving. Hit play and get ready.
Host: Lisa Kocian
Engineer: Kyp Pilalas
Producer: Ken Gordon
“It really comes down to the preparation piece,” says Bradshaw. It’s about being well prepared and asking: “How often do you prepare in your organization, at a technical level, at an executive level, to handle some sort of incident?”
Rehman agrees and says that he has clients wondering, “OK, so when am I done?” The perception is that being IR-ready is enough, he says. “That's not the case. It's a muscle. It's emotion. It's how you work. It's how you react to it.”
There are benefits to knowing the proper way to react. “A well-handled breach really builds credibility,” says Bradshaw, adding that the word “reasonable” is omnipresent in IR documentation. He says: “Reasonableness is not just about having a mitigation strategy.” It’s also about, say, practicing tabletop exercises. Regularly. So that when you’re asked about doing regular tabletop sessions, the answer is, as Bradshaw puts it: “Yes, we did it every quarter for the past five years. We feel like we're in a pretty good spot that if something happens, might not be perfect, but we think we have good preparation, consistent preparation, consistent practice, to your point, to respond to the incident when it does occur.”
Rehman says that security people are “used to having that sudden sense of violent impulse and urgency coming to us,” but what about the business leaders and everyone else in the organization? He asks Bradshaw about IR communication: “How do you guide the team through it, especially when everybody's thinking about, ‘Oh, am I gonna be on the news?’”
Of the thousands of breaches Bradshaw and his team have responded to, for “a third, maybe half” of them, there is “some internal chaos at the client—and it's not because anybody's doing a bad thing.”
“It really comes down to what I call C-squared,” says Bradshaw, which is shorthand for “communication and coordination. Someone has to be the quarterback.”
Bradshaw says the chaos is about “a lack of preparation and testing.” A tabletop exercise needs to be a live fire exercise: “Doing it once a year is not good.” Too many organizations treat IR as a checklist, which is a mistake. He says: “It's a living, cross-functional discipline that evolves with the threat landscape externally, obviously, and also internally as people move.”
And so?
Get moving. Hit play and get ready.
Host: Lisa Kocian
Engineer: Kyp Pilalas
Producer: Ken Gordon
Anglais
États-Unis
TRANSCRIPTION 🔗
Are you the producer of this podcast?
Add a podcast transcript
Need Audio-to-Text?
Transcribe with Listen411 in Just 60 Seconds
RECHERCHER LES ÉPISODES PASSÉS
Rechercher les épisodes précédents de The EPAM Continuum Podcast Network.
AUTRES ÉPISODES DANS CE PODCAST
How are CISOs holding up in the era of AI?
According to Tim Ramsay, Managing Director of Mandiant Client Advisory (now part of Google Cloud), and our guest on *Silo Busting*: “You have a number of parts of the organization that may be embracing AI without any involvement from central IT, and more…
What should we be focusing on? It’s an essential question for all of us… but for those in the cybersecurity game, it’s critical. Focusing on the wrong things here can be *costly.* Or so says Neatsun Ziv, Co-Founder and CEO of OX Security, in this *#CybersecurityByDesign* conversation with Sam Rehma…
“Can we use generative AI in a way that teaches us something that we might not have known otherwise, and in that learning… create something that actually has the potential to increase agency for all inside of the system?”
Good question, Angela Stockman! It is, in fact, one of many good questions t…
What does the phrase “aquatic corporate community” mean to you? A school of fish in business suits holding an underwater meeting around a table of coral? Well, for our guests on the latest episode of *The Resonance Test,* it’s all about plunging into a strategic social responsibility program called…
“If you want to know the future, look at the past.” While no one in their right mind would claim Einstein was giving any thought whatsoever to the future of the financial services industry, history would have once again proven him right if he had. Once upon a time, one’s choice of bank was based on…
Avertissement: Le podcast et les illustrations intégrés sur cette page proviennent de EPAM Continuum, qui est la propriété de son propriétaire et n'est ni affilié ni approuvé par Listen Notes, Inc.
MODIFIER
Merci de nous avoir aidé à tenir la base de données de podcasts à jour.