7 hours ago · 10 min read2084 words · Tech · hide · 0 comments

An analyst finds a serious problem. They can explain what happened, how it happened, and why the activity is technically dangerous.Then someone asks whether the affected system can be shut down.Does it support a revenue-generating service? Who owns it? Which customers will lose access? Does the incident need to involve identity, infrastructure, legal, fraud, or a cloud team? Who can approve containment, and what should happen if that person is unavailable?The analyst may know the threat and still have no idea what to do next.That was the most useful challenge in Mari Galloway’s BrightTALK session, Preparing Security Analysts for the Reality of Modern Security Operations. We spend a great deal of time preparing analysts to recognize malicious activity. We spend much less time teaching them how their organization makes a difficult decision once the activity is found.Technical training matters. Certifications can establish a foundation, labs can teach a tool, and capture-the-flag…

No comments yet. Log in to reply on the Fediverse. Comments will appear here.