Cybersecurity Evolution / Cost Reduction Paradox
Download resourcesAbout this session
Ajay Sood, then Rapid7's country manager for Canada, surveys the state of the industry through the lens of evolution. He starts with the 'follow the data' problem: organisations now create, collect, store and must destroy more data in more places than ever, largely in cloud services outside the old secure enclave, which raises cost, regulatory exposure and threat complexity. He then walks through five evolutions: infrastructure (from firewalled enclave to direct cloud access), attacks (from infrastructure to data to the individual), capitalisation (financial, intellectual, political, human), countermeasures (tools, hand-to-hand combat, then AI, IoT and inside-out threats) and regulation (PIPEDA, GDPR, US state laws, trial by social media). A section on the dark side of the cloud covers shadow IT, shadow data, correlated profiles and data residency. On resilience he argues breach is inevitable, that communication, containment and response matter more than any tool, and warns against destroying forensics by re-imaging virtual machines. COVID-era attacks on healthcare and APT29 illustrate the stakes. He closes with before-and-during-breach advice and the paradox of more threats, more regulation and fewer staff.
It is no secret that cybersecurity is an ever-evolving field, that attracts the brightest minds, both on offense and defense. In this session, Ajay will take us through the current state of the industry, what lead us here, and where we may be going.
Key takeaways
- Answer three questions before anything else: how would someone breach me, how would I know, and what does my worst-case scenario look like.
- Build the breach plan in advance: an IR plan, a committee with executives, a communication plan, cyber-insurance and vendor contacts, retainers and SLAs, all written down before the incident.
- Preserve forensics: do not re-spin a compromised VM from its image; Canadian breach-reporting obligations require a chain of evidence.
- Inventory your shadow data: cloud services, IoT and personal devices collect PII, health and location data you remain accountable for as custodian.
- Treat GRC as an ally and augment rather than replace your team, partnering with IR, managed-detection and legal firms where you lack the depth.
Speakers

As the Head of Security Sales for Canada at Google Cloud, Ajay K. Sood is a recognized leader in the cybersecurity industry with a career spanning over 25 years. He has a deep passion for building and growing innovative security companies, having… Read moreRead less
As the Head of Security Sales for Canada at Google Cloud, Ajay K. Sood is a recognized leader in the cybersecurity industry with a career spanning over 25 years. He has a deep passion for building and growing innovative security companies, having been an integral part of some of Canada's most successful cybersecurity practices. In his current role, Ajay is responsible for bringing Google's powerful security portfolio to the Canadian market. This includes overseeing the go-to-market strategy for both Mandiant's world-class threat intelligence and incident response services, as well as Google's cutting-edge cloud security products. His expertise lies in helping organizations navigate today's complex threat landscape and build resilient security programs. En français: En tant que responsable des ventes en sécurité pour le Canada chez Google Cloud, Ajay K. Sood est un leader reconnu dans le secteur de la cybersécurité, avec une carrière de plus de 25 ans. Il a une profonde passion pour la création et la croissance d'entreprises de sécurité novatrices, ayant été partie intégrante de certaines des entreprises de cybersécurité les plus prospères au Canada. Dans son rôle actuel, Ajay est chargé d'introduire le puissant portefeuille de sécurité de Google sur le marché canadien. Il supervise la stratégie de mise sur le marché des services de renseignement sur les menaces et de réponse aux incidents de Mandiant, ainsi que des produits de sécurité infonuagique de pointe de Google. Son expertise consiste à aider les entreprises à naviguer dans le paysage complexe des menaces d'aujourd'hui et à bâtir des programmes de sécurité résilients.
