In brief

A non-technical survey of the security tool line-up — antivirus, DLP, EDR/XDR, SIEM, SOAR, SOC, DFIR — all on the same pattern: what it is, who needs it, the nuances, what is lost without it. The speaker calls it a "little talk… to warm up your brains": the 33 pages of technical detail were set aside. There are two selection criteria — reasonableness and maturity, and the refrain is "count, count, don't be lazy". The talk is not a product presentation, but it has no technical content either.

Key points

Tools, artifacts, technologies

No specific laws, articles or agencies were named: only "basic levels of compliance with various requirements" and "if you're under regulators, you need it, there's no way around it"; personal data — as an example for DLP. Supply chain: regulations "between the two companies" — "these days that's not rare". A big company needs digital evidence for the legal arena; law enforcement — only as readers of DFIR reports.

Questions from the audience

The speaker's position

What he considers right is counting — the scale, the licenses, the people, the time, the lost profit — and coordinating deployments with the departments; what he considers wrong is buying on advertising and on fear. Formally he was "really angry" at Boroshchuk's post, but in substance he agrees with it and ends on that same thesis. He admits the limitations himself: he calls the figures subjective, and answers the counter-argument about hardening with "Alas". The tone is a light lecture, not a sales pitch.

Quotes