The first moments When visibility and artificial intelligence can compensate for the talent shortage.
Download resourcesAbout this session
This session, whose presenter is never named in the recording, opens on a ransom note and rewinds to the hours before it, arguing that the first 72 minutes of an intrusion decide the outcome while most companies take 208 days to notice. After a Cisco-produced dramatisation of a phishing operator and a look at extortion economics, ransomware-as-a-service and groups like Lapsus$, the speaker reviews why the old firewall-centric model fails: BYOD, personal Dropbox, teenagers on the home network, unscanned SSL and data nobody can locate. He then follows an attack minute by minute, from the double-click to memory-resident malware, persistence, privilege escalation, command-and-control, credential harvesting and lateral movement, naming the control that can stop each stage: signed USB policies, SmartScreen, macro blocking, EDR, LAPS, conditional access, SIEM. The talk closes with the case for AI-driven response and UEBA to compensate for scarce talent, a critique of 'best of breed' stacks nobody can master, and a survival kit: paper architecture, offline backups, a parallel war-room network, phishing drills and zero-trust hygiene.
During this session we will be exploring the following topics: How are the first minutes of a cyberattack critical to containing the breach? How to bridge the chasm between the 208 days before the discovery of the breach and one hour and 12 minutes (1h 12m), which is the average time for a response, to prevent an attack from becoming systemic? It is indeed one of the most beautiful scenarios for machine learning and automating reactions. We will demonstrate that the architecture based on the principle of "best-of-breed" has shaped our technological infrastructures, making us now more vulnerable. We will also share the vision of an architecture that will help overcome the talent shortage and allow you to obtain a deep commitment from your existing teams.
Key takeaways
- Block the entry points that cost nothing: disable macros and unsigned USB devices, keep SmartScreen on, and forbid VBS or PowerShell launched from email.
- Deploy EDR, LAPS and conditional access so memory-resident malware, local-admin reuse and stolen credentials are stopped before lateral movement.
- Remember that Azure AD conditional access applies after first-factor login; disable legacy protocols like POP and IMAP or password spraying still works.
- Keep a survival kit: printed architecture, an offline recovery checklist and contact list, immutable off-site backups and the media to reinstall recovery software.
- Consolidate the security stack so a small team can master and monitor it, and run recurring phishing drills until users report suspicious mail themselves.
Speakers

Passionné de technologie depuis plus de 25 ans, René-Sylvain a construit sa carrière sur des bases solides. Il est un fervent croyant des architectures technologiques robustes et sécuritaires, il s’inspire toujours du modèle d’affaires de ses… Read moreRead less
Passionné de technologie depuis plus de 25 ans, René-Sylvain a construit sa carrière sur des bases solides. Il est un fervent croyant des architectures technologiques robustes et sécuritaires, il s’inspire toujours du modèle d’affaires de ses clients. La cybersécurité étant au cœur de ses services et de sa réflexion, il est toujours à la quête de solutions viables et responsables. Lors de son parcours, il a été conseiller en architecture pour les grandes banques canadiennes, divers paliers gouvernementaux, l'aérospatial et les télécommunications. Il est maintenant, le fondateur et PDG d’Indominus, un groupe dédié à la cybersécurité, l’IA et l’infonuagique.
