Artwork for podcast Security by Default
When a Simple Breach Became a Crisis: Lessons We Learned | Lukas Hlavicka
Episode 3914th September 2026 • Security by Default • Joseph Carson
00:00:00 00:32:15

Share Episode

Shownotes

I discuss with Lukas Hlavicka how ordinary security incidents can escalate into full-blown crises when organizations lack preparation, reliable backups, and secure deployment pipelines. We share stark war stories, from backups that were never actually taken to compromised software deployment systems and a ransomware attack that exposed six months of bank fraud. Lukas draws on over a decade of incident response experience, including leadership of a national CSIRT and work in the private sector. We describe common failure points: unknown assets and third‑party links, intertwined IT and OT systems, missing evidence, unclear roles for decision and containment, and compromised CI/CD. We stress clear, practical steps: maintain offline incident plans and backups, map assets and dependencies, secure and monitor deployment pipelines, and practice response with defined authorities. This episode targets any organization that thinks “it won’t happen to us” and seeks concrete lessons to prevent incidents from becoming crises.

Takeaways:

  • I learned that many incidents become crises because organizations do not know what assets they own or how they connect to third parties.
  • We must keep offline backups and verify that backups are actually taken and restorable before incidents occur.
  • I saw attackers abuse cloud managed security products and deployment pipelines to gain full network access quickly.
  • We found that unclear roles and slow approval processes delay containment and allow the attacker to spread further.
  • I observed that organizations often destroy evidence or change systems in ways that hinder forensic investigations.
  • We recommend practicing incident response, keeping plans offline, and retaining institutional memory to avoid repeating past mistakes.
  • I noted cases where ransomware accidentally revealed long running fraud and showed the need to follow financial trails in investigations.
  • We must monitor CI/CD and software supply chains continuously because compromise there can implant persistent backdoors.

Transcripts

Speaker A:

Hello everyone.

Speaker A:

Welcome back to another episode of the Security By Default podcast.

Speaker A:

I'm the host of the show, Joe Carson, chief security evangelist at Segura, based here in Tallinn, Estonia and joining you with another awesome guest and another fantastic, very interesting topic.

Speaker A:

Always bringing interesting ideas around, how to get clarity out of the chaos in the world that we live in and really allow you to learn and help you on your career or journey that wherever it may lead you in the cybersecurity world.

Speaker A:

So I'm joined by a guest that has a very, a very, very experienced background.

Speaker A:

So Lukas, welcome to the Security by Default podcast.

Speaker A:

Since it's your first time on the show, can you give the audience a bit of a background about how did you get into the industry, what you've been doing and what you're doing today.

Speaker A:

So if you can give us your origin story.

Speaker B:

Thank you.

Speaker B:

First, I would like to thank you for privilege to be in here.

Speaker B:

So I would like to say hi to audience.

Speaker B:

I started in cybersecurity in:

Speaker B:

I started as the system engineer, then incident responder and was head of analytical department.

Speaker B:

And I finished in:

Speaker B:

In:

Speaker B:

And then we came and created our own cybersecurity company in Slovakia east where I am currently serving as cto.

Speaker B:

We are focusing especially on the incident, risk response, forensic, basically let's say special cyber operations and also helping our client to basically solve their problems in cybersecurity world.

Speaker A:

Fantastic.

Speaker A:

That's really interesting.

Speaker A:

For me it's one of the fun areas.

Speaker A:

It is one of the most stressful areas in our industry, working in incident response because you're always looking at a lot of the victims, helping them, looking through the incidents.

Speaker A:

And sometimes in those situations you're faced with hard choices.

Speaker A:

And I think in recent years through the increase of things like ransomware and the geopolitical situation we're in and DDoS attacks, it really means that all organizations have to have a plan.

Speaker A:

They have to have, you know, practice.

Speaker A:

They need to know what they're doing.

Speaker A:

And this topic of course has taken some of the interesting scenarios is that when things go wrong, what choices you make can lead from a simple incident that can go to completely disaster and crisis situation.

Speaker A:

So take me through what's some of the first things, you know, when organizations, you know, first experience an incident, what's some of the common things that they start off with?

Speaker A:

What's the common kind of like simple mistakes that already can it start the snowball effect rolling.

Speaker B:

Basically there are quite a lot of areas I like my job because there is quite a lot of the.

Speaker B:

The dopamine and adrenaline and this kind of stuff.

Speaker B:

When the incident started usually there is a lot of suspects incident happen.

Speaker B:

And basically the.

Speaker B:

The cases where we are involved usually is the basically most serious incidents from the ransomware, sabotage, exfiltrated data or sometimes even the life of the people which are connected to the.

Speaker B:

To the.

Speaker B:

To the.

Speaker B:

To the devices are at stake.

Speaker B:

And the mistakes which really creates the crisis is usually the bad steps which was done before the incidents that the organization was not prepared from the.

Speaker B:

We have for example even nowadays we run the incidents in the organization which is not defensible.

Speaker B:

Basically we solve the incidents, we clear the attacker.

Speaker B:

But because of there is very specific type of the organization.

Speaker B:

We just created the infrastructure and cannot be shut down.

Speaker B:

And the organization is not defensible.

Speaker B:

We basically need to play a little bit whack a mole with the attacker.

Speaker B:

Because we removed the attacker from one side.

Speaker B:

We deleted.

Speaker B:

And so.

Speaker B:

And we said we found that we have new.

Speaker B:

We have actually all.

Speaker B:

We found new connections to the external networks which is quite old.

Speaker B:

But it was one of the supplier which was.

Speaker B:

Which is not even the organization not exist for six years or seven years.

Speaker B:

But the connection is still there and the public IP and the services is publicly available still.

Speaker B:

So we have another vector which we need to discuss and to contain and eradicate and recover to the.

Speaker B:

To the again to the production.

Speaker B:

So basically the most common cases is that there are missing that the organization is not defensible.

Speaker B:

So the organization doesn't even know what they have how they are interconnected with their third party.

Speaker B:

Especially in the multi organization multi data center is everything from the New York through the Frankfurt through the capsicum store through the.

Speaker B:

Through the Hong Kong and basically everywhere we doesn't know how we are connected with the third parties.

Speaker B:

We doesn't know what we have.

Speaker B:

And basically it's something happened.

Speaker B:

This is most challenging parts.

Speaker B:

There are actually way how to do that.

Speaker B:

But we can.

Speaker B:

We can maybe speak about it later.

Speaker B:

Then there are also possibilities that basically where we have especially the integration with IT and OT systems.

Speaker B:

And there is not possible to distinguish between security and safety networks.

Speaker B:

For example, we have cases few months ago where basically the safety network was interconnected with the standard IT network.

Speaker B:

And so we cannot basically disable the connection because basically the same connection which actually was used for the connection between the Organization and their supplier was used for actually the connection of the safety systems of the chemical factory.

Speaker B:

Which basically if you would disconnect it you doesn't know if it will going to basically blow up.

Speaker B:

So this was actually funny.

Speaker B:

So interconnection IT and OT network especially the safety networks.

Speaker B:

There is also the missing the evidences.

Speaker B:

Sometimes you doesn't even have access to the part of your own infrastructure.

Speaker B:

For example, we found a way where the.

Speaker B:

Where the attacker was able to compromise part of the infrastructure.

Speaker B:

It was a multinational retail company.

Speaker B:

And basically what was happening is that the organization not anymore had access to their own switches, routers and firewalls because it was managed long time ago by the some kind of third party vendor.

Speaker B:

And some of these devices was not passed to the new vendors.

Speaker B:

So nobody has access to those.

Speaker B:

So that was quite funny actually that we needed to do offensive parts of our engagement that we get to the specific firewalls.

Speaker B:

So we.

Speaker B:

So we was able to basically help the client to defend their infrastructure.

Speaker B:

That there is also the undefined roles that okay, we are buying this kind of software as a service and but who is managing it this kind of stuff.

Speaker B:

There is also a lot of parts that okay, this is.

Speaker B:

This is this is we paying this kind of part of the infrastructure.

Speaker B:

Storage as a service, containers as a service or anything as a service.

Speaker B:

But we doesn't know who really actually is able to help us with that because we do it with the cloud service broker which basically provide us with service.

Speaker B:

But when we needed okay, but we have problem then there was three or four days until we get to the people who actually was able to do something about it.

Speaker B:

So this is kind of the.

Speaker B:

When the.

Speaker B:

When the crisis it's happening.

Speaker B:

And also if you doesn't have precisely know what your crown jewels actually are.

Speaker B:

And if you had it basically backup for example.

Speaker B:

Very interesting story happened few actually it's already months ago where basically the organization didn't know if they.

Speaker B:

If they have backups and say okay, but our vendor was told us that we have backups.

Speaker B:

So we come to the vendor and we need the backups to.

Speaker B:

To recover your organization.

Speaker B:

The organization.

Speaker B:

And they said but we was never asked to do the backups.

Speaker B:

And I say we.

Speaker B:

We send the.

Speaker B:

We send the proposal.

Speaker B:

But it was never approved.

Speaker B:

So the backups was never done.

Speaker B:

And the organization was thinking that okay backups and we have it in daily basis.

Speaker B:

So you doesn't have backup.

Speaker B:

So we need to start the negotiation with the attacker and make sure that what kind of we can we can recover what kind of.

Speaker B:

If we need to basically pay the RAM until we find the the until we receive the the or if we receive the recovery the decryption key.

Speaker B:

So this is something which basically if there would be standard processes, if there would be communications organization know what have.

Speaker B:

How dare they have it.

Speaker B:

They would be able to basically have the incident would be very easier to solve.

Speaker B:

But usually why the incidents became the crisis is that the preparation is not enough.

Speaker B:

Basically they sometimes have very expensive tools, for example EDRs, XDRs, AI based and you know, Palm, but nobody use it or they are in default state.

Speaker B:

For example.

Speaker B:

In some of the cases I even found that basically the security product itself was actually way how attacker was introduced into the infrastructure.

Speaker B:

Because well, we bought these new shiny firewalls and so on.

Speaker B:

And we say okay, you can integrate it with with our cloud solution and so on.

Speaker B:

And you can everything managed from the cloud.

Speaker B:

Great.

Speaker B:

But then basically attacker came because why they would use two factor authentication to the network as a service, right?

Speaker B:

So the attacker came, they actually find the password because the administrator used same password on some website which was compromised.

Speaker B:

And then actually attacker just do the credential stuffing connect it to the to the network to the network as a service.

Speaker B:

And he connected his own machine as part of the network in the server side of the network.

Speaker B:

And the solution was actually very good to that.

Speaker B:

So it allowed the attacker to connect directly to the same network as was domain controllers.

Speaker B:

So he was able to connect there.

Speaker B:

So basically some incident really quickly escalated to crisis which needed to be done.

Speaker B:

Then in a lot of cases, even when this is not happening, the organization usually has quite a lot of problems in the reward that they doesn't know who can authorize.

Speaker B:

For example disconnected part of the network.

Speaker B:

And basically it happened in the actually same the factory where they ask okay, we need to disconnect this part of network.

Speaker B:

Because this is how the attacker is spreading through your infrastructure.

Speaker B:

And they say okay, we need to find out who is able to approve it.

Speaker B:

And while we were looking who is able to approve it, we waited hours.

Speaker B:

So we said okay, we do this kind of firewall rules, this kind of containment measures and so on.

Speaker B:

But basically there was infected about 20 another servers which needn't to be infected if we would have possibility to do what it was possible to do.

Speaker B:

But we was told do not touch it.

Speaker B:

We are not allowed to touch it because that is responsible.

Speaker B:

We doesn't know who our sister company in another state.

Speaker B:

So this kind of stuff is quite a lot of problematic Also we see in quite a lot of cases where the.

Speaker B:

When the.

Speaker B:

When the administrator starting to do the incident response, then they.

Speaker B:

They destroy the evidence.

Speaker B:

Sometimes not willingly, sometimes even willingly because they okay, I did something wrong, I destroy evidence.

Speaker B:

So nobody can see that.

Speaker B:

But we see that you destroy the evidence, right?

Speaker B:

And also we also quite lot of see that.

Speaker B:

Basically when the incident is start happening, for example, we see the attacker is lurking in the environment.

Speaker B:

He is trying starting to exfiltrate.

Speaker B:

Then we basically tipping of the attacker.

Speaker B:

He doesn't know what actually was done, but we disable his account and so on and say okay, execute order 66 and wipe the backups and start encrypting.

Speaker B:

This is when the real incidents start to become the crisis.

Speaker B:

And also there is quite a lot of problems in the cases of the solving of the incident.

Speaker B:

Especially if there is multinational companies involved.

Speaker B:

Then basically there is information sending right and left and these information are usually not either correct or basically is what I think I will send us information and basically it will happen.

Speaker B:

If you know, if you remember a ping of the deck.

Speaker B:

Basically you send so much information that it will kill basically the recipient because basically he doesn't know what to do.

Speaker B:

Or actually even the Smurf attack is actually applicable here because you receive the information of from every every site and you doesn't know what to do.

Speaker B:

Another part of very interesting why the incident become crisis because you have for example you find the infection on the some of the server.

Speaker B:

Let's say on the web server or publicly facing server or anything like that and what is actually happening the server is compromised and you say okay, I clear it.

Speaker B:

I do not know how the organization how the attacker got there, but I but I reimagined and I'm happy and basically I could if I investigate it by the attacker or how the attacker got actually there on the server then I would be able to find that okay, that attacker basically had privileged accounts or something like that or exploit vulnerability which I didn't know it was present there.

Speaker B:

And basically if I only recover or even if I basically solve the initial.

Speaker B:

This initial vector and I doesn't know how it actually got there really what was the first point of attack then?

Speaker B:

Basically I'm allowing the attacker come back.

Speaker B:

And when the attacker come back usually I say okay, I will prepare.

Speaker B:

And this is this kind of cases which I'm very unhappy about because basically this is the incident which could be.

Speaker B:

Could be avoided.

Speaker B:

We had the cases actually in the June where the organization it was actually the second it was actually the second incident because basically we was performing incident response there a year ago and what was actually happening was that basically we was monitoring the endpoints and we saw that basically the software management solution deployed anomalous system and it deployed actually malware immediately.

Speaker B:

We stopped basically the spreading and basically block and so on.

Speaker B:

But we found out that attacker actually was able to compromise the software deployment toolkit which was basically.

Speaker B:

And created new profiles.

Speaker B:

So anybody who basically connect there was downloading a new package and install malware in the system and say okay, and how it was good because this was, this should be internal tour.

Speaker A:

I've seen, I've seen, yeah I've seen those, those scenarios a few times.

Speaker A:

One of.

Speaker A:

One of my favorite ones was there was a telco that had an initial incident and what they decided to do was let's go to the backup.

Speaker A:

They restored a backup and within two weeks later the incident reoccurred again because they actually had backed up the actually the infection.

Speaker A:

So, so the infection was in their backups.

Speaker A:

They just never sanitized them before recovery and never said let's.

Speaker A:

When was the initial access?

Speaker A:

When was the initial incident happening?

Speaker A:

They just went to that recovery scenario, got the business, got everything running and then of course the reinfection was introduced because the backups actually had the infection contained in it.

Speaker A:

And I you mentioned about the.

Speaker A:

I remember a similar scenario doing.

Speaker A:

It was a.

Speaker A:

There was a Windows 7, Windows 10 upgrade.

Speaker A:

This has come back quite a while.

Speaker A:

And during that upgrade process there was a massive new software deployment rollout that was about to happen.

Speaker A:

And what the attackers had done was they had embedded their piece of malware into the software deployment.

Speaker A:

So you know, the organization during this upgrade was going to deploy the malware for the attacker themselves.

Speaker A:

So sometimes, I mean they are very creative.

Speaker A:

Yeah they try to, you know, embed themselves into the existing organization's workflows.

Speaker A:

So absolutely it's it so and some of those lessons, you know, you hope that organizations make it more visible from, from the lessons learned and that's what I love about this particular topic is that as long as we get, you know, enough knowledge out there that these, you know, similar mistakes and, and, and incidents that you know, could have been avoided can, can get to the knowledge of others any other.

Speaker A:

I mean what else from.

Speaker A:

From the software deployment?

Speaker A:

One that's always.

Speaker A:

It's very creative when the attackers get into your software supply chain.

Speaker B:

Actually I even better because you know, nowadays it's infrastructure as a code and my most beloved part, how the attacker got there when you Compromise CI CD pipeline and basically you add a repository where basically every time you add a new version you add basically backdoor.

Speaker B:

And usually this is not kind of the stuff where you have some kind of ransomware or this kind of stuff.

Speaker B:

Usually this is the stuff where basically you have the backdoor and attacker go there, receive the information and live there.

Speaker B:

And when you analyze it and you see there is even the years there, it's actually okay.

Speaker B:

And you say okay, this is a very funny story and I will 100% told it in the next podcast which I, which I will be in.

Speaker B:

So that is very, actually that's unfortunately.

Speaker B:

And what we see that even when the people, when the organization will learn that they shouldn't do this, they do the same mistake six, six months later.

Speaker B:

Usually as you know that organization has six months long memory against the bad stuff.

Speaker B:

Then usually they say oh, it was not so bad, it could be we survived.

Speaker B:

So let's, let's spare some money, let's lower the budget and then the incident will happen again and again and again.

Speaker B:

Basically I was thinking same as you, that if we put enough information to the public they will learn, they will try to learn from the mistakes of the other, other organization.

Speaker B:

But unfortunately what I found out is that even if the organization will the experience, lived experience of the mistake, they are able to forget it about year, year and a half later because when we do the, for example all these or this kind of stuff year and a half again they are on the same level as was before the incident.

Speaker A:

Yeah, yeah, I've seen, I've seen those scenarios happen more than I wish, you know, they would occur is that they quickly become victims again.

Speaker A:

And a lot of sometimes is that they see the cause as the IT and security team so they rotate the people but they didn't change the culture and, and the investment into IT as well.

Speaker A:

One thing I've seen also quite often I don't know if you've seen is during incidents as well, two scenarios.

Speaker A:

One is the instant response plan was also encrypted with a ransomware.

Speaker A:

So yeah, so, so, so, so their ability to respond is also like okay, we don't have an offline copy and we don't know what to do because, because our instant response plan itself has been encrypted.

Speaker A:

Always funny scenarios.

Speaker A:

I mean it is crisis and it's painful when it does happen, but when you think about it, you know, it is iron.

Speaker A:

And then another situation as well is that when you, when you start the incident, you're doing the forensics evidence gathering.

Speaker A:

A lot of times you find that, you know, you're dealing with an attacker who's launched a campaign, but you'll always find multiple evidence of maybe other multiple attackers who just, you know, we're in the environment but just decided, you know, that then wasn't the right time.

Speaker A:

Or they may have not had enough privilege to do as damage as they want.

Speaker A:

And they were waiting to do that lateral move or elevation.

Speaker A:

So sometimes you do find, you know, multiple attackers in the same environment.

Speaker A:

It's just one was more malicious than another.

Speaker B:

Actually I have one one story where the attacker, the organization was actually saved by ransomware actor.

Speaker B:

You say how it is possible the organization, it was actually the small bank.

Speaker B:

It was connected to the SWIFT system and this kind of stuff.

Speaker B:

And basically they was hit by ransomware, became where there was hit by ransomware and started to solving the incident and so on.

Speaker B:

And in the forensic we found out that the attacker was there six months before and slowly steal the money and move it away to the.

Speaker B:

To the other accounts.

Speaker B:

And if the attacker would.

Speaker B:

And actually the attacker was very, very smart in a way that basically they have very basic controlling of the money.

Speaker B:

And there.

Speaker B:

So he changed the.

Speaker B:

So the summaries was correct and nobody checked anything else but summaries.

Speaker B:

It was very small bank in Africa.

Speaker B:

Then the ransomware actor hit and basically this attacker was basically quick away because it was encrypted also the system which he used for stolen the money.

Speaker B:

So it's actually very funny story.

Speaker B:

It's not funny for them, but it was very funny for me to be honest.

Speaker A:

That's an interesting.

Speaker A:

It reminds me of that one incident that I worked on a few years ago was all very similar, but this was.

Speaker A:

There was two incidents.

Speaker A:

One was where the attackers had, you know, deployed a ransomware, brought the business to a complete standstill.

Speaker A:

And during the forensics investigation, which was permitted to go back five years of logs found two years prior, one of the employees had stalled a crypto mining within the business and had been actually using the server resources for actually doing crypto mining.

Speaker A:

And the energy costs alone, because the CPUs of course are running it, you know, over over loaded the CPUs and the energy costs alone ran into the tens of thousands of euros, which was like, okay, so sometimes you find if that incident didn't occur, would they have found that employee who was abusing their resources?

Speaker A:

Probably not.

Speaker A:

Another interesting one, this goes back into.

Speaker A:

, around:

Speaker A:

So it's supposed to wanna cry, not pet you.

Speaker B:

Yeah.

Speaker A:

And this was in.

Speaker A:

In Ukraine.

Speaker A:

They were doing basically they were overloaded with cases.

Speaker A:

So the cases they couldn't handle this huge case load that they had.

Speaker A:

And they were giving financial support to victims of ransomware.

Speaker A:

So these organizations who had ransomware, they were getting financial support to recover.

Speaker A:

And one particular organization actually because they were trying to hide fraud had deployed the ransomware to themselves.

Speaker A:

Which is, which is very creative when you think about it.

Speaker A:

Because at the same time there are hiding, you know, they're destroying evidence of the fraud and, and also getting financial support to recover.

Speaker A:

Very creative.

Speaker A:

But unfortunately they did.

Speaker A:

They didn't get fully away with it because of the case reviews.

Speaker A:

I was able to.

Speaker A:

To lead it.

Speaker A:

You know, it didn't follow the typical attack path because you can see, you know, it was spreading from within rather than from an initial external point.

Speaker A:

So there's always interesting cases especially you know the work you've done for.

Speaker A:

For the cert because you know you do get a lot of insights over the years from some of the.

Speaker A:

Some of the most high profile cases as well.

Speaker B:

Well, that was.

Speaker B:

That was the time where when I was on a governmental C17 there started ransomwares and this kind of stuff.

Speaker B:

But most of the.

Speaker B:

Most of the attacks was that somebody compromised something steal data and so on.

Speaker B:

And one.

Speaker B:

One actually story was that on the.

Speaker B:

One of the servers what it was utilized for spreading basically the.

Speaker B:

It was small city or small village.

Speaker B:

Basically they have one web server where they showed how much you need to pay for the dog and this kind of stuff.

Speaker B:

And basically somebody compromised their server and utilized the machine as there was MP3 storage.

Speaker B:

So basically and they found the incident in that way that they received quite a big bill for electricity because nobody actually was going to the web server of the small village.

Speaker B:

But when you know you sharing the new MP3s, I don't know Shakira or something like that.

Speaker B:

Everybody dumbled is it so and they say okay, why we have so much electricity bill?

Speaker B:

And they found that they have compromised web server.

Speaker B:

That was actually very very funny funny story when I started and or even better they started then business email compromise incidents and there was.

Speaker B:

There was this village chief which basically received the email that he need to access and so on.

Speaker B:

So he pay all money which they have on the.

Speaker B:

On the budget in the fall reach to the some account.

Speaker B:

And then that was about a March or something and nine months they doesn't have even sent in the.

Speaker B:

In the.

Speaker B:

In the budget because they.

Speaker B:

They send everything to somewhere else to the.

Speaker A:

To the wrong account.

Speaker A:

I've seen, I've seen that with.

Speaker A:

There was a ship company, shipping company which was basically had docked and was doing the fueling process and for ship, you know, cargo ship, the fuel quite, quite expensive.

Speaker A:

So it was, and I think it was like something like €200,000 or whatever, or whatever, whatever currency.

Speaker A:

And when they, they got the invoice, they paid the invoice for the fuel and but it's actually been business email compromised.

Speaker A:

They'd actually already compromised the systems, had sent the invoice out before it was actually meant to be sent, had changed the accounting information.

Speaker A:

So the next day later they got the, the real true invoice and they're going hey, hold on, we have already paid it.

Speaker A:

What are you sending another invoice for?

Speaker A:

And ultimately they end up finding that yeah, the, the organization was actually doing the invoicing for the fuel had been compromised and all their invoices accounting had been changed and, and the attackers knew how to kind of, you know, their processing and timing as well.

Speaker A:

So Casey, you know it's, it's, it's important I think sometimes in our industry following the money is one, one way of motive.

Speaker A:

And we talked earlier about, you know, we even look back at Cliff Stoles, Cuckoo's Egg which was a 75 cent accounting error which led to entire, you know, basically cross costs the Atlantic Ocean investigation into why the 75 cents was missing.

Speaker A:

So sometimes money can tell us a lot of things about, you know, some, something happening.

Speaker A:

en remember back on the early:

Speaker A:

It was an expensive, expensive experiment but with an interesting motivation.

Speaker A:

So.

Speaker A:

Yeah, so, so question you know, in this, you know, we're always moving, you know, fast.

Speaker A:

This industry changes a lot.

Speaker A:

You know, we've got lots of technology trends, we've got lots of attacks are getting creative, they're advancing social engineering is, is, is accelerating.

Speaker A:

How do you, how do you what, what way do you stay up to date, you know, especially in the role that you're in dealing with a lot of incidents.

Speaker A:

And how do you step to date?

Speaker A:

And also what, what thing would you recommend, you know, any of the audience who wants to prevent their organization from becoming a victim and not going into a crisis.

Speaker A:

What would be, what would be your recommendation as well?

Speaker B:

First of course this podcast.

Speaker A:

Absolutely.

Speaker A:

It is a source, a source of knowledge and entertainment for the world.

Speaker B:

But there is also the very good conferences which is also very cheap or very free.

Speaker B:

For example, one of the best of them is BET defcon.

Speaker B:

It's my most favorite conference.

Speaker B:

I actually get bought a few few books.

Speaker B:

One is the Mizardry:

Speaker A:

Yep, two two awesome books and absolutely from my favorite publishers which is the no Start yes no Start press yes.

Speaker B:

No Start pledge rulers.

Speaker B:

So and of course the.

Speaker B:

Of course we each time for example look for the new time of the incidents.

Speaker B:

We have also our own research which basically one of their.

Speaker B:

One of their job is basically to provide us with the links with the new kind of ideas and how to basically enable us to be ready for new kinds of attacks.

Speaker B:

Especially here in AI Basically the attacks actually quite faster and quite.

Speaker B:

Nowadays even the less prepared and less knowledgeable or sophisticated attackers actually can create the attack or perform the attack on the highest level.

Speaker B:

And we actually see even the agent which was on the one of the pivot point and there was the instructions that until compromise do this loop actually Very very very funny.

Speaker B:

So the Learn, learn and learn.

Speaker B:

Actually there is very good source.

Speaker B:

I don't know if you know Cyber.

Speaker A:

Yep, yep, I do Cyber.

Speaker A:

Absolutely.

Speaker A:

I was formerly one of their instructors and mentors there.

Speaker A:

Actually this, this podcast came out of Cyber eventually so good.

Speaker A:

Cybri was the company that we.

Speaker A:

We started the original podcast which was a long time ago and this came out of that.

Speaker B:

That Source Vee Co. Has quite few of subscription of there.

Speaker B:

So yeah, especially the young juniors can.

Speaker B:

Can.

Speaker B:

Can work and play.

Speaker A:

Absolutely.

Speaker A:

It's.

Speaker A:

It's been fascinating chatting with you.

Speaker A:

Many thanks for coming on and sharing your insights and you know the, the lessons learned and hopefully the audience will you know take away.

Speaker A:

You know they're.

Speaker A:

I'll.

Speaker A:

I'll kind of create some summary in the takeaways in the show notes and also put the links for the.

Speaker A:

For the books that you shared as well.

Speaker A:

But yeah, I mean it's important to know, you know what we can learn from past incidents, from past scenarios from organizations who've been down, you know the path of being a victim and how the recovery and the post kind of mortem scenarios.

Speaker A:

It's really important.

Speaker A:

So many thanks for coming on and sharing your story and thank you.

Speaker A:

It's a pleasure having you on.

Speaker A:

So for the audience.

Speaker B:

Thank you.

Speaker A:

What's Lucas, if anyone wants to follow up with you or you know, connect with you, what's the best way to.

Speaker A:

If they do have follow up questions, what's the best way to contact you,.

Speaker B:

Please drop me an [email protected] or basically write me on LinkedIn.

Speaker B:

I would be very happy to answer any of your questions and hopefully I will not meet any of the audience in the incidence cases.

Speaker B:

But remember the incidence is also dead.

Speaker B:

You will meet him sooner or later and better be sooner than later.

Speaker A:

Yes, and prepared.

Speaker A:

And you know, have the practice and always have an offline copy of your instant response.

Speaker B:

Exactly.

Speaker A:

This is one takeaway so and we'll definitely make sure to include all of those in the show notes as well.

Speaker A:

So Lucas, many thanks for being on the show.

Speaker A:

So for everyone out there, this is the Security by Default podcast.

Speaker A:

Bringing you information, knowledge, lessons learned and hopefully is something that will help you make your organization safer, make your social sphere, your family better protected and stay safe and secure out there.

Speaker A:

So tune in every two weeks for new episodes.

Speaker A:

This is Security by Default podcast.

Speaker A:

I'm the host Joe Carson.

Speaker A:

Stay safe.

Speaker A:

Take care until next time.

Speaker A:

Thank you.

Speaker B:

May the fourth video Goodbye.

Links

Chapters

Video

More from YouTube