
Sign up to save your podcasts
Or


Guest:
Angelika Rohrer, Sr. Technical Program Manager , Cyber Security Response at Alphabet
Topics:
Incident response (IR) is by definition "reactive", but ultimately incident prep determines your IR success. What are the broad areas where one needs to prepare?
You have created a new framework for measuring how ready you are for an incident, what is the approach you took to create it?
Why is continuous improvement crucial for effective incident response, especially in cloud environments? Can't you just make a playbook and use it?
How to overcome the desire to focus on the easy metrics and go to more valuable ones?
What do you think Google does best in this area?
Can you share examples of how the CI Framework could have helped prevent or mitigate a real-world cloud security incident?
How can other organizations practically implement the CI Framework to enhance their incident response capabilities after they read the paper?
Resources:
"How do you know you are "Ready to Respond"? paper
EP75 How We Scale Detection and Response at Google: Automation, Metrics, Toil
EP103 Security Incident Response and Public Cloud - Exploring with Mandiant
EP158 Ghostbusters for the Cloud: Who You Gonna Call for Cloud Forensics
EP98 How to Cloud IR or Why Attackers Become Cloud Native Faster?
By Anton Chuvakin4.8
3939 ratings
Guest:
Angelika Rohrer, Sr. Technical Program Manager , Cyber Security Response at Alphabet
Topics:
Incident response (IR) is by definition "reactive", but ultimately incident prep determines your IR success. What are the broad areas where one needs to prepare?
You have created a new framework for measuring how ready you are for an incident, what is the approach you took to create it?
Why is continuous improvement crucial for effective incident response, especially in cloud environments? Can't you just make a playbook and use it?
How to overcome the desire to focus on the easy metrics and go to more valuable ones?
What do you think Google does best in this area?
Can you share examples of how the CI Framework could have helped prevent or mitigate a real-world cloud security incident?
How can other organizations practically implement the CI Framework to enhance their incident response capabilities after they read the paper?
Resources:
"How do you know you are "Ready to Respond"? paper
EP75 How We Scale Detection and Response at Google: Automation, Metrics, Toil
EP103 Security Incident Response and Public Cloud - Exploring with Mandiant
EP158 Ghostbusters for the Cloud: Who You Gonna Call for Cloud Forensics
EP98 How to Cloud IR or Why Attackers Become Cloud Native Faster?

2,010 Listeners

373 Listeners

653 Listeners

1,024 Listeners

318 Listeners

418 Listeners

8,044 Listeners

181 Listeners

315 Listeners

189 Listeners

203 Listeners

74 Listeners

57 Listeners

139 Listeners

44 Listeners