AI in Security Operations Centres: What We’ve Learnt so Far

No ratings

Presented at InfoSecurityEurope 2019 by

Is it time for the traditional multi-tiered SOC to end? Get beyond the InfoSec buzzwords in this practitioner-lead session in which we'll we share our insights and learning from live deployments of AI within Security Operations Centres. Time and knowledge are key factors that can make the difference between a contained incident and a full blow breach or successful attack. We’ll discuss how AI is empowering analyst teams to handle unpatched and zero-day vulnerabilities, to detect and respond to advanced attackers, and work at a previously unattainable speed and efficacy.Learning Outcomes:Evaluate your SOC's security maturityHear how to build and enable purple teamsIdentify SOC automation opportunities (and where not to automate)Learn techniques that will reduce attacker dwell time