Prémisses, Principes et Présentation Panégyrique du Modèle Unifié de Cyberdéfense
Download resourcesAbout this session
A Mandiant (Google Cloud) principal consultant presents a unified cyberdefense model built from lessons learned advising clients and from Google's own internal SOC, which was rebuilt from scratch after a 2009 nation-state breach. He opens with ten enduring 'plagues' of cyber defense (talent market failure, tool sprawl, alert fatigue, weak business alignment, reactive posture) as motivation, then walks four pillars: unifying data pipelines (logs, threat intelligence, detection, response) so a weak link degrades the whole chain, choosing between deterministic hyper-automation and decision-making agentic automation by use case rather than hype, continuous validation (validation-in-depth paired with detection-in-depth, informed by capability abstraction and breach-attack-simulation tooling), and Google's own CDCR (Continuous Detection Continuous Response) framework, which merges detection and response into one team and targets a 40/40/20 split between operations, engineering and improvement instead of the industry-typical 90 percent spent purely on operations. He closes on burnout statistics (75 percent of security teams lost staff to stress in the past year, half of practitioners want to leave, CISO tenure averages 18-24 months) as the human argument for the model.
Description et exploration du nouveau modèle de cyberdéfense unifié : sa genèse, sa motivation, ses axiomes, son opérationnalisation et le futur du modèle. Cette session couvrira la description du modèle mais également les enjeux d'opérationnalisation et des leçons provenant de multiples RETEX sur les 3 dernières années.
Key takeaways
- Audit each stage of your security data pipeline (log source, coverage, ingestion, storage) separately; a single weak stage degrades the value of the whole pipeline no matter how much you invest elsewhere.
- Decide deliberately between log-first (maximize coverage, better for high-compliance sectors) and detection-first (ingest only what a detection requires) rather than defaulting to one extreme.
- Reserve deterministic hyper-automation for well-understood, bounded playbooks like emergency containment or phishing triage, and save agentic automation for tasks that benefit from a new analytical layer, such as hunting or modeling.
- Merge detection-content authors and incident responders into one team per ecosystem; splitting them removes the incentive to write detections that actually make response easier.
- Track and budget for the operations/engineering/improvement time split of your analysts (industry norm is roughly 90 percent operations); moving toward something closer to Google's 40/40/20 reduces burnout and raises the return on cyberdefense investment.
Speakers

Thomas is an experienced cyberstrategy advisor & service lead, he regularly performs strategic & technical assessments of cyber programs across all industry verticals, with speciality for large companies in N. America & EMEA. His background is in… Read moreRead less
Thomas is an experienced cyberstrategy advisor & service lead, he regularly performs strategic & technical assessments of cyber programs across all industry verticals, with speciality for large companies in N. America & EMEA. His background is in SOC engineering, incident response, and cyberstrategy.
