Session
Compliant and Compromised: Mapping the Gap Between Your Audit and Your Attacker
A clean audit and a successful breach are not contradictions; across NIS2, DORA, NIST, or CIS, they are frequently the same fiscal quarter at the same organization. This talk shows exactly where the paperwork and the adversary disagree, using evidence from environments where I both produce the compliance artifacts and run the defensive operations they describe.
We work through three control patterns that pass assessment while leaving attack paths open: account management that misses the stale service accounts enabling lateral movement, logging that meets retention requirements while nobody triages it, and configuration baselines that were true exactly once. Each is mapped to the ATT&CK techniques it fails to stop, and one gets a live demonstration: the control passes evidence collection on screen, then fails an atomic validation test sixty seconds later.
The back half is the fix: a threat-informed validation program a small team can run, with test cadence, evidence standards an adversary would respect, and the framing that keeps your auditors as allies. Attendees leave with the control-to-technique mapping and a starter test plan, regardless of which regulation is generating their paperwork.
Amanda Kollmorgan
Deputy State IT Director, WI Department of Military Affairs
Fond du Lac, Wisconsin, United States
Links
Please note that Sessionize is not responsible for the accuracy or validity of the data provided by speakers. If you suspect this profile to be fake or spam, please let us know.
Jump to top