This session is for members.

Subscribe or log in to watch every GoSec session.

Subscribe Log in

This recording is not available yet.

Incident Response That Moves at Attack Speed

GoSec 2026Panel39 minEnglish
Download resources

About this session

Sabine Lainer of GoSecure, joined on stage by two Magnet Forensics colleagues, argues that incident response is routinely undermined by premature network isolation: EDR-triggered containment cuts the very connectivity investigators need to pull memory dumps, logs and disk images, forcing slow physical shipment of laptops and servers and losing volatile evidence along the way. She calls for a pre-built quarantine network and an emergency firewall configuration that leaves a narrow, controlled path for forensic tooling, plus a dormant acquisition agent deployed on every endpoint before an incident happens so investigators can pull targeted evidence in hours instead of weeks. The second half covers insider threat and HR cases, now roughly a fifth of the team's caseload: a standing agent lets investigators covertly pull daily snapshots from a suspect's laptop without tipping them off, producing defensible evidence while avoiding the cost of confiscating a device and finding nothing. A closing Q&A covers agent lifecycle management and multi-tenant data isolation on the SaaS platform.

Last year’s conversation distinguished between proactive preparedness and reactive readiness. highlighting why having plans alone is not enough. This year, we take the next step: what it truly means to be ready.

Network Isolation Breaks Traditional Acquisition Paths
Modern EDR solutions can isolate compromised endpoints within seconds, but that same isolation can prevent investigators from accessing the systems they need to examine. This session explores the tension between containment and evidence collection and discusses practical approaches to maintaining investigative capability during active incidents.

From Suspicion to Insight: Rapid Endpoint Acquisition for Early Triage
Not every alert warrants a full incident response effort, but every alert deserves context. Learn how endpoint acquisition agents can provide immediate access to key forensic artifacts, enabling analysts to quickly assess risk, validate suspicions, and make better escalation decisions long before a formal incident is declared.

Key takeaways

  • Do not let an EDR fully isolate a compromised endpoint by default; build a runbook that leaves a narrow, controlled path for forensic acquisition before you contain.
  • Stand up a quarantine network ahead of time so isolated endpoints can be moved there instead of powered down, preserving memory and logs.
  • Deploy a dormant forensic acquisition agent across the fleet as part of the golden image so evidence can be pulled in hours, not the days or weeks that shipping a device takes.
  • For insider threat and HR cases, use a covert, always-on agent to pull periodic snapshots instead of confiscating the laptop; it avoids tipping off the suspect and reduces wrongful-suspension exposure.
  • Ask any SaaS forensic vendor how tenants are logically isolated on the shared platform before you commit.

Speakers

Sabine Lainer
Sabine Lainer
Director IR Services, GRC Senior Advisor · GoSecure
Sabine Lainer is the Senior Advisor at GoSecure, bringing a wealth of knowledge and experience in security and privacy. She holds degrees from the University of Applied Science in Furtwangen, Germany; Brunel University in London, UK; the University… Read moreRead less

Sabine Lainer is the Senior Advisor at GoSecure, bringing a wealth of knowledge and experience in security and privacy. She holds degrees from the University of Applied Science in Furtwangen, Germany; Brunel University in London, UK; the University of South Australia; McGill University; Concordia University; and the University of Alberta. Sabine is passionate about security, privacy, learning, and teaching. She was awarded an innovative teaching prize in 1997 and was nominated for the Women in IT Award – Security Champion in the UK in 2016. Having lived and worked in nine countries, Sabine is now a proud permanent resident of Canada. Outside of her professional life, Sabine enjoys running, cycling, hiking, paddle boarding, and indulging in science fiction and fantasy stories through various media. A dedicated Star Trek fan, she takes great pride in living in the birthplace of William Shatner.

Lynita Hinsch
Lynita Hinsch
Platform Consultant · Magnet Forensics
Lynita Hinsch is a United States Air Force veteran and digital forensics professional with extensive experience spanning military, federal law enforcement, Fortune 100 enterprise security, and the private sector. She specializes in digital… Read moreRead less

Lynita Hinsch is a United States Air Force veteran and digital forensics professional with extensive experience spanning military, federal law enforcement, Fortune 100 enterprise security, and the private sector. She specializes in digital forensics, incident response, eDiscovery, and helping organizations modernize investigative workflows through automation and emerging technologies. Today, she works with private sector organizations around the world to improve the speed, scalability, and defensibility of digital investigations using Magnet Forensics elite platform solutions.

Andrew Oprea
Andrew Oprea
Enterprise Account Executive · Magnet Forensics
My name is Andrew Oprea. I am the Magnet Forensics Enterprise Account Executive based in Waterloo, Canada – supporting Canada. I come from a background inf SaaS sales specializing in Digital Forensics and Incident Response (DFIR), supporting SMB to… Read moreRead less

My name is Andrew Oprea. I am the Magnet Forensics Enterprise Account Executive based in Waterloo, Canada – supporting Canada. I come from a background inf SaaS sales specializing in Digital Forensics and Incident Response (DFIR), supporting SMB to Enterprise F100 organizations onboard tooling for forensic investigations.

Resources

Photos

Tags

More from GoSec 2026

Also from Sabine Lainer

On the same topic