From my Gartner Blog – The new (old) SIEM papers are out!

As Anton already mentioned here and here, our update of the big SIEM paper was turned into two new papers:
How to Architect and Deploy a SIEM SolutionSIEM is expected to remain a mainstay of security monitoring, but many organizations are challenged wi… Continue reading From my Gartner Blog – The new (old) SIEM papers are out!

From my Gartner Blog – Endpoint Has Won, Why Bother With NTA?

One of my favorite blog posts from Anton is the one about the “SOC nuclear triad”. As he describes, SOCs should use logs, endpoint and network data on their threat detection and response efforts. But we also know that organizations don&#821… Continue reading From my Gartner Blog – Endpoint Has Won, Why Bother With NTA?

From my Gartner Blog – Gartner Security and Risk Management Summit Brazil – 2018

The Gartner Security Summit Brazil is fast approaching and I’m happy to be part of it again. This time it’s even more special, for many reasons.
This is my first year as the chairman of the conference. It’s very rewarding to be w… Continue reading From my Gartner Blog – Gartner Security and Risk Management Summit Brazil – 2018

From my Gartner Blog – Threat Simulation Open Source Projects

It’s crazy how many (free!) OSS projects are popping up for threat and attack simulation! We are working on research about Breach and Attack Simulation (BAS) tools, and we’ll certainly mention these projects, buy I thought it would be valua… Continue reading From my Gartner Blog – Threat Simulation Open Source Projects

From my Gartner Blog – Big data And AI Craziness Is Ruining Security Innovation

I don’t care if you use Hadoop or grep+Perl scripts. If you can demonstrate enough performance to do what you claim you can do, that’s what matters to me from a backend point of view. Now, can you show me that your tool does what it should … Continue reading From my Gartner Blog – Big data And AI Craziness Is Ruining Security Innovation

From my Gartner Blog – It’s Not (Only) That The Basics Are Hard…

While working on our research for testing security practices, and also about BAS tools, I’ve noticed that a common question about adding more testing is “why not putting some real effort in doing the basics instead of yet another security t… Continue reading From my Gartner Blog – It’s Not (Only) That The Basics Are Hard…

From my Gartner Blog – BAS and Red Teams Will Kill The Pentest

With our research on testing security methods and Breach and Attack Simulation tools (BAS), we ended up with an interesting discussion about the role of the pentest. I think we can risk saying that pentesting, as it is today, will cease to exist (I&#82… Continue reading From my Gartner Blog – BAS and Red Teams Will Kill The Pentest

From my Gartner Blog – The “working with an MSSP” Tome Is Here

As Anton just posted, the new version of the famous “How to Work With an MSSP to Improve Security” has just been published. I’m very happy to become a co-author (together with Anton and Mike Wonham) on this document, as it is usually … Continue reading From my Gartner Blog – The “working with an MSSP” Tome Is Here