Yes We Can Get In. Now What?

No ratings

Presented at InfoSecurityEurope 2019 by

The results of a red-team test (or breach) can be a thunderclap under a clear blue sky. The recommendations might look idealistic and expensive. Management might be upset, employees discouraged. Attackers will always get in, but there is no need for fatalism. The talk focuses on what to prioritise and how to think like an attacker.Learning Outcomes:How to treat and prioritise the results from a breach or red-team test.How to limit attack surface.How to deal with the required change in company culture.How to raise the cost of attack for the attacker.How to force the attacker to make mistakes that can be detected using the right detection strategy.