In brief

What to do when EDR, antivirus and firewalling have not worked: an organizational talk for CISOs/CIOs/CTOs and security managers. The main point — a security incident is not an IT failure: first kick the attacker out, then fix things. To take away — the emergency actions, the stages from the SANS guide and free recommendations published together with Cyberdom. There is no product pitch; the talk continues Nikita Vyugin's.

Key points

Tools, artifacts, technologies

Questions from the audience

One question (no microphone, recorded in fragments, the name is not given): which is there more of — cases where the encryption has already happened, or cases where the attack was spotted while it was still being prepared? The answer: the question should be put to those who get called in to do DFIR; there is "survivorship bias" — the businesses that did not recover "don't come to these conferences"; prepare in advance. There were no other questions.

The speaker's position

He treats the order "kick out → clean up → recover" as not open to discussion; he rejects the ransom on technical, banking and legal grounds. He argues not with people but with the typical IT approach: he found no complete public recommendations and wrote his own. He acknowledges the limits himself: DFIR lasts days even when you have prepared, the remote format requires hands on site, and the 72 hours for the report are not the same as the duration of the investigation. The tone — a practical lecture with sarcasm, with nothing to sell.

Quotes