Detection at Scale

Chris Witter on Leading D&R Teams for Both Cloud and Enterprise at Spotify


Listen Later

In this episode, Jack chats with Christopher Witter (aka Witter), Engineering Manager, Detection & Response at Spotify and a founding member and former lead for Crowdstrike’s Falcon OverWatch managed hunting service. 

Witter has nearly two decades of experience in incident response and information security, holding leadership roles on computer security and incident response teams (CSIRT) with both a top five global bank and a top ten defense contractor. 

During this episode, Witter shares his behind the scenes experiences helping build the Falcon Overwatch Team at Crowdstrike, why it’s critical to measure queries in seconds, not minutes, his tips on running highly effective D&R teams at scale, and more! 

Topics discussed:

  • Witter’s experience as one of the first 100 people on the Falcon Overwatch Team at Crowdstrike 
  • Why the Overwatch team didn’t follow traditional SOC mentalities 
  • The various data sources Witter uses to improve accuracy and gather context 
  • How D&R is like going to court – telling the story around Who, What, Where, Why, How, to prove beyond a reasonable doubt that this incident happened
  • Why Witter measures in seconds, not minutes and why timescale is critical 
  • Why it could be a mistake to choose cybersecurity tools based on financial capability and budget and what criteria should be considered instead
  • Why Witter still believes in custom systems 
  • Witter’s rule of thumb that if a human does the same thing 10x manually, it should be automated  
  • Managing a remote D&R team and building psychological safety
  • Witter’s advice for how others can get involved in the D&R community 
  • His 3 pieces of advice to build a high-performing D&R team at scale, including a focus on ‘Jack of all trades’ people, avoiding distractions, and why it’s critical to capture everything to improve search. 
  • ...more
    View all episodesView all episodes
    Download on the App Store

    Detection at ScaleBy Panther Labs

    • 5
    • 5
    • 5
    • 5
    • 5

    5

    11 ratings


    More shows like Detection at Scale

    View all
    Security Now (Audio) by TWiT

    Security Now (Audio)

    1,966 Listeners

    Risky Business by Patrick Gray

    Risky Business

    360 Listeners

    SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast) by Johannes B. Ullrich

    SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

    628 Listeners

    Defensive Security Podcast - Malware, Hacking, Cyber Security & Infosec by Jerry Bell and Andrew Kalat

    Defensive Security Podcast - Malware, Hacking, Cyber Security & Infosec

    367 Listeners

    CyberWire Daily by N2K Networks

    CyberWire Daily

    1,015 Listeners

    Smashing Security by Graham Cluley & Carole Theriault

    Smashing Security

    314 Listeners

    Click Here by Recorded Future News

    Click Here

    392 Listeners

    Hacking Humans by N2K Networks

    Hacking Humans

    314 Listeners

    Defense in Depth by David Spark, Steve Zalewski, Geoff Belknap

    Defense in Depth

    78 Listeners

    Dwarkesh Podcast by Dwarkesh Patel

    Dwarkesh Podcast

    350 Listeners

    Cyber Security Headlines by CISO Series

    Cyber Security Headlines

    117 Listeners

    The Ezra Klein Show by New York Times Opinion

    The Ezra Klein Show

    15,007 Listeners

    Cloud Security Podcast by Google by Anton Chuvakin

    Cloud Security Podcast by Google

    40 Listeners

    Risky Bulletin by risky.biz

    Risky Bulletin

    33 Listeners

    No Priors: Artificial Intelligence | Technology | Startups by Conviction

    No Priors: Artificial Intelligence | Technology | Startups

    129 Listeners