Beyond the Breach: Proactive Defense in the Age of Advanced Threats

QCon London 2024

Session

Beyond the Breach: Proactive Defense in the Age of Advanced Threats

Wednesday Apr 10 / 01:35PM BST, Mountbatten (6th Fl.)

Abstract

This talk will cover some of the most advanced attacks that are in the public domain, mostly attributed in public by commercial organizations.  This talk will give a whirlwind tour of some of the high end of threat activity to set out a context of changing cybersecurity landscape.

The second part will talk about what controls we apply in Government that help defend against the most advanced attacks.  The spoiler warning here is that most of these are not actually really fancy advanced and complex stuff, it's the things that people already know they should do, but are hard to do.

I'll cover a few different things, such as requiring MFA for everyone, reducing your administrative accounts, securing your endpoints effectively, along with a bonus tip around defending your CI systems.

You'll walk away from this talk with a better appreciation of why security matters, and some of the simple but hard things that you should be doing in your enterprise and application system stacks to ensure that you are a hard target.

76% senior dev or higher
1:11 speaker ratio
60+ practitioners

QCon London 2024 is a three day conference for senior software engineers, architects and team leads. An international program committee of working engineers selects every session. Patterns and practices, not products and pitches.

Share

From the same track

Wednesday 10 April

10:35 Mountbatten (6th Fl.) Session zero trust A Zero Trust Future for Applications: Practical Implementation and Pitfalls Ashish Rajan CISO @Kaizenteq Ltd, Host of "Cloud Security Podcast", and SANS Trainer for Cloud Security, 13+ Years Experience in the CyberSecurity Industry 11:45 Windsor (5th Fl.) Session Ethical AI Trends in InfoSec: Data Minimisation, Autoclassification, and Ethical AI Rachael Greaves CEO & Co-Founder @Castlepoint Systems, Australia's Most Outstanding Woman in IT Security, RegTech Female Entrepreneur of the Year, Women in Fintech Powerlist, Top 100 Innovator, CISM, CISA, CDPSE, & CIP 13:35 Mountbatten (6th Fl.) Session Beyond the Breach: Proactive Defense in the Age of Advanced Threats Michael Brunton-Spall Deputy Director Cyber Policy and Solutions @Cabinet Office 14:45 Mountbatten (6th Fl.) Session Poetry4Shellz – Avoiding Limerick Based Exploitation and Safely Using AI in Your Apps Rich Smith 15:55 Mountbatten (6th Fl.) Session From Anti-Patterns to Best Practices: A Practical Guide to DevSecOps Automation and Security Spyros Gasteratos Founder @smithy.security