Lessons and Observations from Incident Response and MDR teams
Download resourcesAbout this session
Daniel Wiley, who leads threat management and incident response at Check Point, opens the conference with a hard look at why so many organisations fail at day-to-day security operations. Drawing on thousands of incident response and managed detection cases, he argues that many companies only think they have a SOC when in reality it is one overloaded analyst reacting to crisis after crisis without a plan, a budget or management authority. He walks through recurring failures: repeating the same breach because remediation advice was ignored, treating cyber insurance as a get-out-of-jail card and losing control of the response, buying tools expecting a magic bullet, and blaming individuals instead of building a team. His prescription is cultural more than technical: get executive buy-in for a long-term commitment, break down silos, build an incident response capability before the crisis, run tabletop exercises, and protect the health of the people doing the work. He closes on security as a team sport across vendors, partners and government.
Key takeaways
- Judge whether you really have a SOC by whether it proactively finds threats; if every event is a crisis, you have crisis management, not security operations.
- Do not treat cyber insurance as an incident response plan: paying a ransom can hand control to the insurer and expose you to sanctioned-entity and act-of-war clauses.
- Map your network and secure management buy-in, budget and authority before trying to build a SOC; without them, walk away.
- Actually implement the remediation controls after an incident, because lessons are repeated until they are learned.
- Protect the people: security operators face real burnout and health risks, so build a team culture instead of depending on one overloaded analyst.


