We're thrilled to share insights from our Co-founder and CTO, ???? ???? Guy Barnhart-Magen, who recently delivered an impactful talk at the T2 Infosec Conference. His presentation delved into some of the most pressing challenges and innovations within the cybersecurity landscape. Check out Guy's post to gain valuable perspectives and stay updated with the latest trends in the field. #Profero #Cybersecurity #T2Infosec #Innovation #Leadership
A few days ago, a talk I gave at t2 infosec conference last year surfaced online. Many thanks to the organizers for letting me share my day-to-day experience as a professional incident responder and explain why I think that, by and large, IR is utterly broken. It's an hour-long talk (link in the first response), so I'll try to give you just the bulleted version: * Resources gap - Large organizations have the budget, and they can go to large IR companies and get help when they need it. Demand and supply. But small companies - SMBs and SMEs - have tight budgets, therefore almost no one to turn to (And sure enough, they are in need more and more often). * Expertise gap - Most of the time IR is done by consultants. They are usually not very technical, and they sell IR alongside PT services, compliance services, and more. But almost no one specializes in IR. * Time frame problem - In IR there are bottlenecks everywhere. It usually takes between 12 to 36 hours to engage a company if they don't have a pre-existing arrangement with an IR provider. Then, it usually takes between 1 to 3 days to actually get access to the systems (!). All in all, a successful incident takes weeks to months just to start the remediation phase (Graph attached). Slow response to incidents is a real problem. * Incentives gap - One of the most important aspects that shapes this market is that consultants (like lawyers) bill by the hour, so they are incentivized to stretch out engagements for as long as possible while bleeding the customer. It is a predatory practice. The title of my talk was "Closing the Gap." Profero was established 5 years ago (birthday approaching) with all of those gaps in mind. We are solving those gaps with a recurring SaaS business model, a preemptive readiness approach, and ongoing assessments. It is like having all the fire extinguishing equipment in place, knowing the firefighters by name, and running joint drills. This has proved itself numerous times as a healthy approach to prevent cyber incidents in the first place or dramatically reduce the mean time to recover. Most importantly, it gives our customers peace of mind.