The cloud enables greater business agility and innovation – but also introduces unprecedented challenges for incident response teams.
Leveraging the cloud’s centralized control plane, attackers can now rapidly execute multi-step attack chains by programmatically discovering resources, escalating privileges, moving laterally, and encrypting and exfiltrating data. The richness of cloud services creates endless opportunities and multiple attack paths for adversaries, many of which are specific to each cloud provider.
For incident responders, modern multi-cloud infrastructures – AWS, Azure, GCP, and more – also bring increased complexity, massive scale, and accelerated rates of change, along with the need for new and specialized skills which are in short supply.
In this webinar, led by a senior security leader for a Fortune 500 financial services firm with operations in more than 40 countries, we’ll explore:
- Key differences and similarities between cloud and on-premises incident response.
- Why the scale and diversity of cloud services require new approaches to log ingestion, detection engineering, noise reduction, and investigation.
- The need to define playbooks and cross-functional processes that enable IR teams to quickly contain incidents and “stop the bleeding” before they cause major impact to your business.
- The forensic and investigation capabilities required to respond to cloud threats at speed.
- Why Cloud Security Posture Management (CSPM) alone is not enough.
- How to shift your SecOps team’s mindset and prepare them for threats in the cloud era.