Breach Coach et préparation aux incidents, un guide pour s’y retrouver
Download resourcesAbout this session
Laurent Desaulniers, VP at GoSecure, gives a practical talk in French on preparing for and responding to incidents, arguing the worst time to figure out how you handle one is during it. He distinguishes an incident (the technical work: acquisition, analysis, recovery) from a crisis (lawyers, HR, PR and management, the 'our people'), and recommends two separate tables so managers manage and technicians work, with a designated incident lead empowered to override even a CEO. He walks the phases: pre-incident preparation (roles, break-glass authority to call police or the cyber-insurer, out-of-band channels), investigation (assets, timeline, impact, legal exposure, and distinguishing a vulnerability like Log4Shell from an incident), documentation so hypotheses do not become facts, prioritising return to a healthy state over attribution, the delicate case of not half-evicting an active intruder, and the post-mortem as the real moment of leverage. He covers cyber-insurance mechanics, the breach coach (a lawyer whose involvement makes findings privileged) and approved-vendor lists, and warns that reporting minor incidents can burn limited claims. Four real-case exercises engage the audience, and he ends on incident simulations and a Q&A on alert fatigue, ransom-payment ethics and how far back to investigate.
Le pire moment de considérer la gouvernance et la gestion d'incidents est... pendant un incident. À ce moment, les tensions sont hautes et l'impact d'une erreur est important. Ainsi, cette présentation présente les différents concepts liés à préparation et réponse aux incidents, à la cyberassurance, à la simulation d'incident, à la gestion de crise et présente les principaux cadriciels de réponses aux incidents
Key takeaways
- Invest in pre-incident preparation: a break-glass list saying who may declare an incident, call the police or notify the cyber-insurer, and pre-agreed out-of-band channels for when email is compromised.
- Split incident from crisis: run a technical table and a management table with a designated incident lead who intercepts management requests so responders can keep working.
- Make return to a healthy, available state the priority over attribution, and document actions and hypotheses so unverified guesses do not harden into 'facts' at the management table.
- Do not partially evict an active intruder; map every access path and command-and-control channel first, or you tip off the attacker and they simply return.
- Test the plan with table-top simulations including the crisis side, and always run a post-mortem, it is the moment of leverage to fix what was deprioritised before the incident.
Speakers

Laurent Desaulniers le directeur des services d’intrusions chez GoSecure. Il possède plus de 15 ans d’expérience en sécurité offensive et simulation d’attaques. En plus de son expérience en intrusion, M. Desaulniers a eu la chance d’enseigner à… Read moreRead less
Laurent Desaulniers le directeur des services d’intrusions chez GoSecure. Il possède plus de 15 ans d’expérience en sécurité offensive et simulation d’attaques. En plus de son expérience en intrusion, M. Desaulniers a eu la chance d’enseigner à l’ÉTS, aux HEC ainsi qu’à l’école polytechnique de Montréal. Laurent a été conférencier à travers le monde, présentant à plusieurs conférences tel que RSA, Red Team Summit, NorthSec, NCFTA, CQSI, Hackfest et plusieurs autres. Dans ses passe-temps, M. Desaulniers s’intéresse aux techniques de crochetage, à la magie et au pickpocketing.

