logo
episode-header-image
Apr 2024
45m 49s

Essential Strategies to master Incident ...

Cloud Security Podcast Team
About this episode

How do you build a Robust Detection Framework? Ashish spoke to Andrew Tabona, SVP of Cyber Threat Management and Incident Response at a Fortune 500 company about challenging the conventional wisdom of applying on-premise incident response plans to cloud environments. They speak about the critical metrics of mean time to detect, respond, and recover, and why mastering the fundamentals is key to effective cloud security.

The conversation also covers practical strategies for building a detection framework, the importance of a balanced approach to log ingestion, and the nuanced differences in incident response between cloud and traditional on-premise environments.


Guest Socials: ⁠⁠⁠Andrew Tabona

Podcast Twitter ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠@CloudSecPod⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠ ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠

If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our other Cloud Security Social Channels:

- ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠Cloud Security Podcast- Youtube⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠

- ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠Cloud Security Newsletter ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠

⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠Cloud Security BootCamp


Questions asked:

(00:00) Introduction

(03:20) A bit about Andrew Tabona

(04:26) What is Threat Detection and Response?

(06:14) Why incident response is different in Cloud?

(09:18) Benefits of doing Incident Response in Cloud?

(10:29) Is CSPM your incident response tool?

(12:33) Where to start with Detection in Cloud?

(16:35) Getting buy in from other teams for threat detection

(20:15) Should you build or buy a cybersecurity solution?

(22:34) Responding to incidents in a Cloud Context

(26:01) Containing incidents in a Cloud Context

(28:34) What kind of access do IR teams need?

(30:36) Balancing the signal to noise ratio

(32:10) Where to start with Threat Detection and Response

(34:37) Challenges an organisation might face

(35:58) Threat Detection and Response in MultiCloud

(37:52) Showing ROI of Cybersecurity to the business

(38:57) Where to learn about IR and Threat Detection?

(41:09) Fun Section

(44:14) Where you can connect with Andrew

Up next
Nov 18
How to Build Trust in an AI SOC for Regulated Environments
<p>How do you establish trust in an AI SOC, especially in a regulated environment? <a href="https://www.linkedin.com/in/grant-oviatt-882111a0/" target="_blank" rel="noopener noreferer">Grant Oviatt</a>, Head of SOC at P<a href="https://www.prophetsecurity.ai/" target="_blank" rel ... Show More
42m 15s
Nov 11
Threat Modeling the AI Agent: Architecture, Threats & Monitoring
Are we underestimating how the agentic world is impacting cybersecurity? We spoke to Mohan Kumar, who did production security at Box for a deep dive into the threats of true autonomous AI agents.The conversation moves beyond simple LLM applications (like chatbots) to the new worl ... Show More
47m 20s
Nov 4
AI is already breaking the Silos Between AppSec & CloudSec
The silos between Application Security and Cloud Security are officially breaking down, and AI is the primary catalyst. In this episode, Tejas Dakve, Senior Manager, Application Security, Bloomberg Industry Group and Aditya Patel, VP of Cybersecurity Architecture discuss how the ... Show More
1h 11m
Recommended Episodes
Jul 2022
Secure Cloud Migrations
<p>Bryan Woodworth (Solutions Strategist @Aviatrix) talks about the evolution of Cloud migrations, security best practices, and how to organize for migration success. </p><p><b>SHOW: 631</b></p><p><b>CLOUD NEWS OF THE WEEK - </b><a href='http://bit.ly/cloudcast-cnotw'>http://bit. ... Show More
39m 56s
Nov 2023
Improved Security thru Attack Path Analysis
<p>Tim Miller (@broadcaststorm, Technical Marketing Engineer, Outshift by @Cisco) talks about new ways to approach the overwhelming security challenges created by cloud-native apps and multi-cloud. </p><p><b>SHOW: 767<br/><br/>CLOUD NEWS OF THE WEEK - </b><a href='http://bit.ly/c ... Show More
36m 49s
Jun 2019
The so-called cloud and what it means for cyber security
What is the cloud? Is it secure? How safe is your information when it’s in the cloud? Reformed Hacker Bastien Treptel and Chief Cyber Risk Officer Fergus Brooks talk with David Kaplan from Amazon Web Services about the reliability of cloud security and what the benefits and pitfa ... Show More
20m 25s
Dec 2023
From Cloud to Cloud-native to COVID
<p>How did the modern cloud evolve from the earliest days of AWS to today’s AI boom? What roles did open source, mobile apps, microservices and the sharing economy play?</p><p><b>SHOW: 776</b></p><p><b>CLOUD NEWS OF THE WEEK - </b><a href='http://bit.ly/cloudcast-cnotw'>http://bi ... Show More
49m 6s
Dec 2023
2023 End of Year Mailbag
<p>Aaron and Brian answer mailbag questions from the community about the future of open source, future of VMware, the Big 3 Clouds and how AI will impact the next era of cloud.</p><p><b>SHOW: 780</b></p><p><b>CLOUD NEWS OF THE WEEK -</b> <a href='http://bit.ly/cloudcast-cnotw'>ht ... Show More
43m 37s
Feb 2022
Cloud Cost Intelligence
<p>Erik Peterson (@silvexis, Founder/CTO/CISO @CloudZeroInc) talks about how Cloud Cost Mgmt has matured, the importance of business context for cloud costs, and best practices for managing SaaS costs. </p><p><b>SHOW: 592</b></p><p><b>CLOUD NEWS OF THE WEEK -</b> <a href='http:// ... Show More
36m 26s
Mar 2023
3 Trends Shaping the Madness of March
<p>March comes in like a lion, but goes out like a lamb. Let’s explore 3 storylines that might have long-ranging implications for cloud. </p><p><b>SHOW: 703</b></p><p><b>CLOUD NEWS OF THE WEEK - </b><a href='http://bit.ly/cloudcast-cnotw'>http://bit.ly/cloudcast-cnotw</a></p><p>< ... Show More
28m 27s
Jun 2022
Cloudflare Outage Analysis - Jun 21 2022
<p>In this episode we go through the cloud flare outage blog. &nbsp;https://blog.cloudflare.com/cloudflare-outage-on-june-21-2022/ Fundamentals of Networking for Effective Backends udemy course (link redirects to udemy with coupon) https://network.husseinnasser.com</p> 
25m 3s
Feb 2024
Cloud News of the Month
<p>Welcome to the inaugural Cloud News of the Month. Aaron and Brian talk about the biggest tech stories from January 2024.</p><p><b>SHOW: 793</b></p><p><b>CLOUD NEWS OF THE WEEK - </b><a href='http://bit.ly/cloudcast-cnotw'><b>http://bit.ly/cloudcast-cnotw</b></a></p><p><b>NEW T ... Show More
48m 8s
Sep 2023
Ransomware and materiality. MetaStealer hits businesses. Two looks at cloud risks. His Highness, the Large Language Model.
The MGM Resorts incident is now believed to be ransomware, and how does that inform our view of Materiality of a cyber incident? MetaStealer targets businesses. Cloud access with stolen credentials. The cloud as an expansive attack surface. Johannes Ullrich from SANS describes ma ... Show More
25m 39s