Learning from chaos, cloud and scale: Netflix SIRT

No ratings

Presented at FirstConferenceKualaLumpur 2018 by

The Netflix Security Intelligence and Response Team (SIRT) has grown out of the unique Netflix culture and technology stacks and taken a non-traditional approach. We seek to make SIRT central to our learning security organization while buying down risk across a broad range of known and unknown threats. To achieve this we are leveraging concepts from chaos engineering to introduce continuous testing for security controls and detections spawned out of the post incident review process. Post-detection we are investing in modern forensic and response tools that can scale in the public cloud and leverage immutable deployments in production. On the corporate side we are developing best practices for IR in a fully SaaS environment, and rethinking our approach to network and endpoint security monitoring with identity as the new perimeter. This allows us to grow our response capabilities through engineering and new approaches as opposed to large multi-tiered SOCs with linear staffing requirements. We believe this approach can enable even modestly resourced security teams to have significant impact through their IR programs, and would like to share some of our thoughts for discussion.