mnemonic security podcast

The Speed of Threat

mnemonic

Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.

0:00 | 40:06

The speed of threat: Threat intelligence and detection engineering in the age of AI

How can security teams shorten the time from identifying a cyber threat to having detection code live in production?

In this episode of the mnemonic security podcast, Robby is joined by Nick Maeckelberghe, Co-Founder and Managing Director at the offensive security research lab and services company Crimson7, and welcomes Jeff Schiemann back to the podcast, now a Board Advisor at Crimson7. 

Nick and Jeff discuss how security teams can shorten the OODA loop, the time it takes to observe, orient, decide and act on a threat, with the ambition of going from understanding what an attacker is doing to having detection code live in production in a matter of hours.

They explore what it takes to keep pace with attackers as new tools and techniques emerge, and how cyber threat intelligence (CTI) and detection engineering can work together to identify and stop threats at different stages of an attack campaign. They also discuss how LLMs and other forms of AI are changing cybersecurity on both sides of the equation, as attackers move faster and defenders look for ways to analyse threats and turn what they learn into detections at the same speed.

The conversation also turns to some future-gazing: the rise of neoclouds, the concept of "headless security services" increasingly delivered by AI, and a potential shift from identity as the attack surface to trust as the attack surface. They discuss what these developments could mean for the security industry, and how customers will distinguish between good and average security vendors as AI takes on more of the work.

Send us Fan Mail

People on this episode