Brian Contos
Field CISO, Mitiga
San Francisco, California, United States
Actions
With two IPOs and nine acquisitions, Brian has contributed to the development and scale of several of the most influential cybersecurity companies globally. He brings more than 30 years of experience across the security sector as an entrepreneur, board advisor, investor, and author. Brian began his career with the Defense Information Systems Agency (DISA) and later at Bell Labs, before moving into the private sector to build and scale security startups. He has held leadership roles in companies that achieved significant liquidity events, including ArcSight, Imperva, McAfee, Cylance, and Mandiant. He has worked in more than 60 countries across six continents, advising enterprises and governments on cyber risk, adversary operations, and defensive strategy. Brian is the author of Enemy at the Water Cooler and co-author of Physical & Logical Security Convergence with William Crowell, former Deputy Director of the NSA. He was featured in the cyberwar documentary 5 Eyes alongside General Michael Hayden, former Director of the CIA. Brian is a contributor to Forbes and regularly speaks at industry conferences including Black Hat and RSA.
Area of Expertise
Topics
Hack The Cloud: Attackers Love Blind Spots, Break Their Hearts
Malicious actors, on an unholy crusade, have discovered that a lack of visibility across Cloud, SaaS, and Identity, combined with legacy controls that provide limited cloud detection and response capabilities, grants them a nefarious advantage. This lack of visibility, detection, and response in cloud environments allows malicious actors to operate with an elevated ability to breach organizations, evade detection, and maintain persistence.
As businesses transition to the cloud, critical assets, sensitive data, and an increasing array of interconnected SaaS applications have followed. This shift attracts malicious actors eager to exploit any visibility gaps, such as those caused by the segmentation of environments across workloads and SaaS. While such segmentation is a beneficial security best practice for incident prevention, it also provides a stealthy refuge for attackers. In essence, your SecOps team is operating within a landscape fraught with invisible threats.
This presentation will explore real-life stories from the trenches, drawn from years of cloud-based incident response. Various hacks will be explored to illustrate how breaches occur, what happens following a breach, and why organizations are struggling to detect and respond.
Finally, we will cover mitigation strategies such as proactively preparing for a breach, discovering malicious activity, and responding. Malicious actors are counting on your passivity, your blind spots, and your inability to effectively detect and respond to attacks in the cloud. Break their hearts!
Attendee Takeaways
• Understand how malicious actors exploit cloud visibility gaps.
• Explore demonstrations that illustrate breach techniques.
• Learn about real-life incidents detailing breach methods and detection challenges.
• Leave with mitigation strategies.
Please note that Sessionize is not responsible for the accuracy or validity of the data provided by speakers. If you suspect this profile to be fake or spam, please let us know.
Jump to top