This session is for members.

Subscribe or log in to watch every GoSec session.

Subscribe Log in

This recording is not available yet.

Breach Coach et préparation aux incidents, un guide pour s’y retrouver

Download resources

About this session

Laurent Desaulniers, VP at GoSecure, gives a practical talk in French on preparing for and responding to incidents, arguing the worst time to figure out how you handle one is during it. He distinguishes an incident (the technical work: acquisition, analysis, recovery) from a crisis (lawyers, HR, PR and management, the 'our people'), and recommends two separate tables so managers manage and technicians work, with a designated incident lead empowered to override even a CEO. He walks the phases: pre-incident preparation (roles, break-glass authority to call police or the cyber-insurer, out-of-band channels), investigation (assets, timeline, impact, legal exposure, and distinguishing a vulnerability like Log4Shell from an incident), documentation so hypotheses do not become facts, prioritising return to a healthy state over attribution, the delicate case of not half-evicting an active intruder, and the post-mortem as the real moment of leverage. He covers cyber-insurance mechanics, the breach coach (a lawyer whose involvement makes findings privileged) and approved-vendor lists, and warns that reporting minor incidents can burn limited claims. Four real-case exercises engage the audience, and he ends on incident simulations and a Q&A on alert fatigue, ransom-payment ethics and how far back to investigate.

Le pire moment de considérer la gouvernance et la gestion d'incidents est... pendant un incident. À ce moment, les tensions sont hautes et l'impact d'une erreur est important. Ainsi, cette présentation présente les différents concepts liés à préparation et réponse aux incidents, à la cyberassurance, à la simulation d'incident, à la gestion de crise et présente les principaux cadriciels de réponses aux incidents

Key takeaways

  • Invest in pre-incident preparation: a break-glass list saying who may declare an incident, call the police or notify the cyber-insurer, and pre-agreed out-of-band channels for when email is compromised.
  • Split incident from crisis: run a technical table and a management table with a designated incident lead who intercepts management requests so responders can keep working.
  • Make return to a healthy, available state the priority over attribution, and document actions and hypotheses so unverified guesses do not harden into 'facts' at the management table.
  • Do not partially evict an active intruder; map every access path and command-and-control channel first, or you tip off the attacker and they simply return.
  • Test the plan with table-top simulations including the crisis side, and always run a post-mortem, it is the moment of leverage to fix what was deprioritised before the incident.

Speakers

Laurent Desaulniers
Laurent Desaulniers
VP Breach Detect Response Services · GoSecure
Laurent Desaulniers le directeur des services d’intrusions chez GoSecure. Il possède plus de 15 ans d’expérience en sécurité offensive et simulation d’attaques. En plus de son expérience en intrusion, M. Desaulniers a eu la chance d’enseigner à… Read moreRead less

Laurent Desaulniers le directeur des services d’intrusions chez GoSecure. Il possède plus de 15 ans d’expérience en sécurité offensive et simulation d’attaques. En plus de son expérience en intrusion, M. Desaulniers a eu la chance d’enseigner à l’ÉTS, aux HEC ainsi qu’à l’école polytechnique de Montréal. Laurent a été conférencier à travers le monde, présentant à plusieurs conférences tel que RSA, Red Team Summit, NorthSec, NCFTA, CQSI, Hackfest et plusieurs autres. Dans ses passe-temps, M. Desaulniers s’intéresse aux techniques de crochetage, à la magie et au pickpocketing.

Resources

Tags

More from GoSec 2022

Also from Laurent Desaulniers

On the same topic

This site is registered on wpml.org as a development site. Switch to a production site key to remove this banner.