In brief
A non-technical survey of the security tool line-up — antivirus, DLP, EDR/XDR, SIEM, SOAR, SOC, DFIR — all on the same pattern: what it is, who needs it, the nuances, what is lost without it. The speaker calls it a "little talk… to warm up your brains": the 33 pages of technical detail were set aside. There are two selection criteria — reasonableness and maturity, and the refrain is "count, count, don't be lazy". The talk is not a product presentation, but it has no technical content either.
Key points
- He dropped 33 pages of technical detail after Dmitry Boroshchuk's post about maturity in information security; he counts himself among security marketers.
- There are two criteria: reasonableness — consulting all the departments, not just the business; maturity — it "isn't the ability and willingness to buy any tools for millions upon millions", but an understanding of why and how.
- Antivirus — "the most, most, most basic level"; false positives, the BYOD hole, quarantine gets in the way of an investigation; without it "90% of simple threats won't be blocked right away".
- DLP — needed even on 15 machines when there is personal data and a "tyrant of a boss"; the effect is "up to 30% of data leaks", not the "90–100 in the marketing brochures".
- EDR — an agent: processes, the network, scripts; XDR — plus email and clouds; spending grows with scale — "count, count, don't be lazy".
- SIEM — "an alarm system": it does not respond by itself, it is "not SOAR, not some kind of artificial intelligence"; "garbage in, garbage out"; 6,000 machines for 6 IT specialists.
- SOAR — "whatever playbooks you write, that's what it'll follow"; only "through negotiations… between all the departments"; a bad playbook — "business goes down".
- SOC — an organizational unit: people, infrastructure, TI feeds; expensive, 24/7, burnout, a staff shortage.
- DFIR "doesn't protect anything", "in probably 90 percent of cases works retrospectively"; with three incidents a year your own team is not needed; the reports "are read by law enforcement as well".
- The conclusion: "Don't fall for bare advertising", count the lost profit too; "security has probably never been better", but without proper configuration — "maybe even go bankrupt".
Tools, artifacts, technologies
- Covered: antivirus (unconditionally needed), DLP (the advertised "90–100%" are criticized), EDR/XDR (expensive), SIEM, SOAR, SOC, DFIR — there is a "myriad" of tools: vendor ones, open-source ones, scripts people "knock together for themselves".
- A cheat sheet — a slide summarizing the systems and the stages; Dmitry Boroshchuk's Telegram channel — the reason for the talk.
- MK Enterprise — so in the moderator's joke; in the question from the audience the same product is Mobile Criminalist Corporate.
- From the Q&A: Nextcloud/ownCloud as a budget "controlled environment" instead of DLP, an access control system, 2FA, backup checking, hardening, the Golden Rules book.
Legal and organizational context
No specific laws, articles or agencies were named: only "basic levels of compliance with various requirements" and "if you're under regulators, you need it, there's no way around it"; personal data — as an example for DLP. Supply chain: regulations "between the two companies" — "these days that's not rare". A big company needs digital evidence for the legal arena; law enforcement — only as readers of DFIR reports.
Questions from the audience
- Question 1 (by the context — the moderator, "Nik, look"): what he laid out comes to "those same 5–10 million" that small business does not have — so what should the less rich do? And right away: "How much does hardening cost?" → Answer: four main areas — user identification (passwords/2FA), perimeter control, backups with checking, control of users inside the perimeter; for a company of "about 100 people… revenue around 200 million" — Nextcloud/ownCloud instead of DLP, otherwise forensics after the fact.
- In the same exchange: the pentester Sasha Dmitriev recommended the Golden Rules book, but out of 200 pentests exactly one such company turned up, "only half a percent". The counter-argument: "Hardening costs nothing" apart from the specialist's time; to the question about guaranteeing the basic measures — "Alas".
- Attribution is not guaranteed: there are no speaker labels, the lines are run together inside the paragraphs, the split is inferred from the logic of the dialogue; under the reverse attribution the "four main areas" are the moderator's words.
- Question 2 ("Igor Evgenievich", as the moderator addressed him): they have been deploying Mobile Criminalist Corporate for "maybe three years now", nobody has dropped it, but "the inflow of new clients is lower"; "the Kaspersky representative" before that "was actively trading in fear" — is it not time to start "putting pressure on those who make the decisions"? → Answer: scaring people is "bad form", which is exactly why the talk "went from highly technical to… fairly light and surface-level"; someone who bought out of fear will not renew the license.
The speaker's position
What he considers right is counting — the scale, the licenses, the people, the time, the lost profit — and coordinating deployments with the departments; what he considers wrong is buying on advertising and on fear. Formally he was "really angry" at Boroshchuk's post, but in substance he agrees with it and ends on that same thesis. He admits the limitations himself: he calls the figures subjective, and answers the counter-argument about hardening with "Alas". The tone is a light lecture, not a sales pitch.
Quotes
- "…maturity isn't the ability and willingness to buy any tools for millions upon millions…"
- "The figure I believe most is that up to 30% of data leaks are cut… Some say 90–100 in the marketing brochures…"
- "It's not SOAR, not some kind of artificial intelligence. It's simply this: SIEM screams, and the IT guy cries."
- "…you'll just earn yourself a headache, spend a pile of money, get disillusioned with life, and maybe even go bankrupt."
- "That is, from a business-ethics standpoint, scaring people is not good."