Big Data Lake Talk

An updated deck for my talk on Big Data in Cybersecurity can be downloaded here.

Cybersecurity operations (SECOPS) requires a team with a broad skill set, including security frameworks, various security technologies, legal expertise, criminal investigation, forensics, and risk management. However, most organizations struggle to hire personnel with all these skills at the necessary staffing levels. Outsourcing SECOPS to MSSPs or other approaches also face challenges, such as risk management, lack of organizational context, and diverse security control configurations. Sharing information is further complicated by large volumes of data and regulatory restrictions. The topics covered will include: (1) Collecting incident data forensically, (2) Creating standardized units of work, (3) Securely synchronizing data, (4) Shipping sanitized data to address risk concerns, (5) Securely executing SOAR playbooks and remote data searches, and (6) Sharing workloads between consolidated and remote SOCs.

 

About the Author

Charles Herring

Charles Herring

Co-founder & Chairman, WitFoo

I started WitFoo in 2016 to make information and operations shareable across the craft of cybersecurity — between companies, law enforcement, national security and insurers, who mostly cannot see what each other sees. Before that I was at Lancope and Cisco, and I began in 2002 as Network Security Officer for the Naval Postgraduate School.

I lead research and development on a platform that ingests trillions of messages a day across hundreds of clusters. It is sold as Conductor, Reporter and Analytics, licensed flat per appliance with unlimited data — because a team charged by the gigabyte ends up making coverage decisions on a spreadsheet, months before the incident that needed the logs they dropped.

Everything here is mine, not the company's, and it wanders. Corrections are genuinely welcome — I would rather be right than consistent.

A note on how this was written: I use artificial intelligence tools to help me research, check facts, and edit these posts. The ideas, the arguments, and any mistakes are mine. I read the sources, I check the claims, and I take full responsibility for what I publish here. The views are my own and the writing is my intellectual property.