The cloud is where the data lives and where the processing happens, which means it is also where the attack happens. That changed what a SOC has to do, and most of the tooling has not caught up.
Brian Contos, Field CISO at Mitiga, put that to two people who have spent their careers on the problem from outside the vendor world:
• Bill Crowell — former Deputy Director of the NSA, later CEO of a public security company and an investor in the field
• Dr. Ulf Lindqvist — Senior Technical Director at SRI International, with a research background in intrusion detection and in securing critical infrastructure and space systems
What they get into:
• Why the architecture holds up and the configuration is where it comes apart
• Why forensics changed when you stopped being able to pull a drive, and how log depth varies by provider
• SaaS logging that arrives only with enterprise licensing, on a delay, and is kept for a week
• Ulf on detection being necessary and not sufficient, and on prevention that was never going to be perfect
• Bill on why an attacker who gets in does not have to act right away
• AI on both sides, from planting data that a scraping model will swallow to what happens when AI output is recycled as training data
Attackers may get in. With Zero-Impact Breach Prevention, they get nothing.
Let them come.
Catch the video playlist on YouTube or the Mitiga Mic webpage.
And subscribe for podcast episodes in your feed twice a month at Cybercrime Magazine.