Jb cinderella of-cyber-v1.2

8
BLUE TEAMS – The Cinderella of Cyber Security? --James Burns (@Unstable_Alpha)

Transcript of Jb cinderella of-cyber-v1.2

Page 1: Jb cinderella of-cyber-v1.2

BLUE TEAMS – The Cinderella of Cyber Security?

--James Burns (@Unstable_Alpha)

Page 2: Jb cinderella of-cyber-v1.2

2

A Confession...

Page 3: Jb cinderella of-cyber-v1.2

3

So Why the “Cinderella“ Thing?

A motivated, mature blue team can speed the development of staff and add significant value to an organisation, yet defensive cyber continues to be under-represented in the wider community.

Page 4: Jb cinderella of-cyber-v1.2

4

Under-Represented

SIEM's will never look as cool as Metasploit

Being successful means admitting to (perceived) failures

Blue-teaming done right is not news-worthy

Page 5: Jb cinderella of-cyber-v1.2

5

Adding Value

Data from blue teams feeds into intel, malware, red teams

Blue teams have a greater emotional investment

Not just looking for the known vulnerabilities

Page 6: Jb cinderella of-cyber-v1.2

6

Speeding Staff Development

Defensive skills have never had more offensive relevance

Blue teams form an incubator into all other areas of cyber

Teams that share info and work together upskill faster

Page 7: Jb cinderella of-cyber-v1.2

7

So Why the “Cinderella“ Thing?

A motivated, mature blue team can speed the development of staff and add significant value to an organisation, yet defensive cyber continues to be under-represented in the wider community.

Page 8: Jb cinderella of-cyber-v1.2

8

Who Was This Guy?

James Burns Security Consultant with IRM. Previously a Security Analyst for Selex ES

All views have been my own