Hi [[ session.user.profile.firstName ]]

2017 Cybersecurity Threat Insights Report for Leaders

In our "2017 Cybersecurity Threat Insights Report for Leaders" report, we shared several key findings and observations from our client engagements and about the security industry. This webcast covers our findings and observations but will also provide you with clear direction on where you need to focus your resources to evoke positive action in your security program.

During this webcast one of our lead Counter Threat Unit™ researchers, Chris Yule, who helped develop the report, gives his perspective, observations and guidance through responses to a series of questions led by our Product Marketing Director, David Puzas.

You Will Learn About:
• Our observations from our engagements and findings
• How you need to rethink core security processes and operations
• Whether the current nature and behaviors of the threat are evolving or staying constant
• What the common attack vectors are and how to protect your organization against the fundamentals of cyber-attacks
• How to focus your resources from a tactical and strategic perspective
Recorded Feb 23 2017 63 mins
Your place is confirmed,
we'll send you email reminders
Presented by
Chris Yule, David Puzas
Presentation preview: 2017 Cybersecurity Threat Insights Report for Leaders

Network with like-minded attendees

  • [[ session.user.profile.displayName ]]
    Add a photo
    • [[ session.user.profile.displayName ]]
    • [[ session.user.profile.jobTitle ]]
    • [[ session.user.profile.companyName ]]
    • [[ userProfileTemplateHelper.getLocation(session.user.profile) ]]
  • [[ card.displayName ]]
    • [[ card.displayName ]]
    • [[ card.jobTitle ]]
    • [[ card.companyName ]]
    • [[ userProfileTemplateHelper.getLocation(card) ]]
  • Channel
  • Channel profile
  • Modernizing SecOps With Software-Driven Detection and Investigation Recorded: Aug 4 2020 72 mins
    Matt DeMatteo, Sr. Principal Engineer, Secureworks
    The security landscape is more complex than ever. Cybersecurity professionals are challenged by threat detection and response. As organizations confront resource constraints, how can they stay ahead of unknown and emerging cyber threats?

    What you will learn:
    -How cloud-native software is transforming security
    -Understand how data science and machine learning principles best apply to security
    -See a demo of how Red Cloak TDR can be used to detect and investigate a real-world attack scenario
  • Top 8 Cybersecurity Incident Response Plan Failures Recorded: Jul 7 2020 56 mins
    Rob Lelewski, Senior Incident Response Consultant – Secureworks
    Each year, Secureworks performs hundreds of proactive incident response exercises and emergency response engagements for a variety of industries, globally. During these engagements, consistent Cybersecurity Incident Response Plan failures are observed, regardless of their maturity level or industry vertical.

    Listen to this webcast where Rob Lelewski, Senior Incident Response Consultant, will highlight and discuss the common organizational shortcomings observed by Secureworks, which hinder organizations’ abilities to respond to security incidents.

    What You Will Learn:

    -- Top organizational deficiencies in responding to incidents.
    -- Impact of organizational deficiencies on the incident response process.
    -- Recommendations on fixing deficiencies.
  • Making Sense of MITRE ATT&CK Evaluations to Address Your Cybersecurity Needs Recorded: Jun 30 2020 56 mins
    Paul DiOrio, Lee Lawson, Patrick Donegan
    The MITRE ATT&CK Framework is a common industry language of threat actor tactics and techniques based on real-world observations. MITRE regularly conducts product evaluations to provide independent transparency on the capabilities of security products to defend against known cyber adversary attacks.

    This webcast explains how MITRE evaluations use their ATT&CK Framework to simulate attack scenarios that security vendors must then detect as quickly as possible. You’ll also hear about our results and perspective as a recent participant. Security teams can leverage the results of these evaluations to assess the array of vendor options against a common standard, think about key visibility points within their environment, and review their own detection coverage and security strategies.

    Watch this presentation to learn:

    •The detection categories the MITRE evaluation uses – and what an endpoint product needs to do
    •How our cloud-based Red Cloak™ Threat Detection and Response application delivered accurate, early detections of attacks
    •How to use MITRE ATT&CK evaluation results to inform your security decisions
  • Lessons from the Field: How Are Skilled Testers Infiltrating? Recorded: Jun 23 2020 59 mins
    Nate Drier, Senior Consultant, Secureworks and Jared McLaren, Senior Consultant, Secureworks
    Many organizations perform regular annual or bi-annual testing to identify network vulnerabilities, gaps in their controls and satisfy industry compliance requirements. Examining results and lessons learned can be limited. However, wouldn’t it be nice to see what tactics and techniques some of the most skilled testers out there are utilizing across all industries, all levels of maturity and to serve a variety of different objectives?

    Join this webcast for an opportunity to see how good guys simulate the bad guys and gain valuable insights. In this webcast you will hear from some of Secureworks’ most skilled testers, Nate Drier and Jared McLaren, as they talk about lessons learned from some of their most challenging engagements and the trends they are seeing with clients and their defense practices.

    Key topics covered include:

    •Examples of real-world engagements
    •Tactics and techniques commonly used to achieve their objectives
    •Trends and weaknesses seen in defenses
    •Insights and lessons learned
  • What Buyers Need to Know Before Investing in Managed Detection & Response (MDR) Recorded: Jun 16 2020 31 mins
    Joakim Lialias, Secureworks and Craig Robinson, IDC
    Managed Detection and Response is a rapidly emerging security solution seeing increased demand in the marketplace. But what are the trends driving MDR services and what do buyers need to know when evaluating a security vendor? This webcast helps to make sense of the noisy market and shares IDC’s unbiased views and data points.

    Explore and learn more about the trends shaping the dynamic MDR market. Discussion topics include:

    •7 overarching trends in cybersecurity
    •How digital transformation is causing an exponential jump in complexity
    •What is driving the need for MDR Services?
    •What are CISOs looking for in managed security service providers (MSSP)?
    •What is the market definition of MDR?
    •What 5 things should an organization look for when choosing an MDR provider?
    •Which advanced detection and analytic techniques are most important to security leaders – machine learning, AI, big data, behavioral analytics, threat hunting, or others?
    •Where is the market headed and where are we today?
  • Creating the SOC of the Future Recorded: Jun 11 2020 43 mins
    Wendy Thomas, Chief Product Officer, Secureworks and Jon R. Ramsey, Chief Technical Officer, Secureworks
    The Security Operation Center or SOC has historically played the important role as the ‘command and control’ hub for an organization’s cybersecurity efforts. However, the reactive SOC of yester-year cannot keep up with today’s advanced adversaries and is failing to keep organizations safe from unknown cyber threats. This must change.

    What you will learn:

    -How the global security community is coming together to define the SOC of the Future requirements.

    -How Human-Machine intelligence, Artificial Intelligence and Advance Analytic Software give organizations an enduring advantage over the adversary.

    -Emerging analytics tools, real world use cases and software-driven solutions that are transforming the way security teams detect, investigate, and respond to unknown threats across endpoints, networks, and the cloud.
  • Creating the SOC of the Future Recorded: Jun 9 2020 43 mins
    Wendy Thomas, Chief Product Officer, Secureworks and Jon R. Ramsey, Chief Technical Officer, Secureworks
    The Security Operation Center or SOC has historically played the important role as the ‘command and control’ hub for an organization’s cybersecurity efforts. However, the reactive SOC of yester-year cannot keep up with today’s advanced adversaries and is failing to keep organizations safe from unknown cyber threats. This must change.

    What you will learn:

    -How the global security community is coming together to define the SOC of the Future requirements.

    -How Human-Machine intelligence, Artificial Intelligence and Advance Analytic Software give organizations an enduring advantage over the adversary.

    -Emerging analytics tools, real world use cases and software-driven solutions that are transforming the way security teams detect, investigate, and respond to unknown threats across endpoints, networks, and the cloud.
  • How to Breach Security 101: Lessons from the Field Recorded: Oct 15 2019 59 mins
    Nate Drier, Senior Consultant, and Jared McLaren, Senior Consultant
    Gain insights from the good guys simulating the bad guys.

    Many organizations perform regular annual or bi-annual testing to identify network vulnerabilities, gaps in their controls and satisfy industry compliance requirements. Examining results and lessons learned can be limited. However, wouldn’t it be nice to see what tactics and techniques some of the most skilled testers out there are utilizing across all industries, all levels of maturity and to serve a variety of different objectives?

    Join this webcast for an opportunity to see how good guys simulate the bad guys and gain valuable insights. In this webcast you will hear from some of Secureworks’ most skilled testers, Nate Drier and Jared McLaren, as they talk about lessons learned from some of their most challenging engagements and the trends they are seeing with clients and their defense practices.
  • Introducing Red Cloak™ Threat Detection & Response Recorded: Aug 6 2019 58 mins
    John H. Collins, CISSP - Director, Solution Engineering SaaS Security Applications
    For more than 20 years, you’ve known the world-leading threat intelligence and industry-recognized services from Secureworks. Now, it’s time you know Red Cloak Threat Detection and Response, and hear directly from our experts.

    Red Cloak Threat Detection and Response is a cloud-based security analytics application that transforms the way your security team detects, investigates and responds to threats across your endpoints, network and cloud. Built by a team of data scientists and engineers with experience solving big data cybersecurity challenges for intelligence agencies, Red Cloak TDR enables you to detect advanced threats, trust your alerts, streamline and collaborate on investigations and automate the right action.
  • The Transformative Effect of Data Science and Machine Learning Recorded: Jun 26 2019 60 mins
    Tim Vidas - Senior Distinguished Engineer, Nash Borges PhD, Sr Director of Engineering and Data Science
    The combination of big data and machine learning is making it possible for defenders with limited resources and expertise to detect and respond to unknown threats faster than ever before. In an industry forever locked in an adversarial battle with increasingly sophisticated actors, Tim Vidas, Distinguished Senior Engineer, and Nash Borges PhD, Sr Director of Engineering and Data Science at Secureworks explain how the power of machine learning combined with human intelligence have become fundamental to defending the digital economy.
  • Improving Incident Response Outcomes Recorded: Feb 21 2019 61 mins
    Matthew Webster, Senior Security Researcher, Secureworks Counter Threat Unit
    All too often companies are learning the hard way — during an incident — how they could have been better prepared to stop the threat or reduce the damage. Join us for a one hour webcast, hosted by SC Magazine, featuring the key findings of Secureworks newly-released Incident Response Insights Report 2018: Risks, Remedies, and Best Practices for Defending Against Cyber Threats.

    Webcast takeaways will include:
    - Threat and attack trends identified by responders in 2017.
    - Lessons learned by organizations in a wide variety of incident response (IR) scenarios.
    - Key recommendations for IR planning, practices and capabilities that improve security defenses and mitigate business risk.
    - Live Q&A with experts from our Counter Threat Unit™ (CTU) and Incident Response team.

    In 2017, Secureworks’ team of incident responders helped hundreds of organizations navigate through complex and high-risk security incidents. Now the top insights from those collective engagements will be shared by speakers from the Secureworks Counter Threat Unit and Incident Response practice.

    This program offers the support you need to prepare better for emerging threats, understand how you might be vulnerable, and respond more effectively when an incident does occur. Program content is appropriate for cybersecurity leaders, incident responders, CIOs, CTOs, and executives with responsibility for enterprise risk management.
  • Cyber Global Warming: Real Life Malscape Insights Recorded: Feb 14 2019 49 mins
    Andy Norton, Director, Threat Intelligence, Lastline and Michael Rico, Senior Intrusion Analyst, Secureworks
    Layered security has been the mantra for many years, but this methodology leaves gaps the adversary can leverage to compromise your organization. Applying high fidelity cyber acumen with innovative Behavioral Intelligence technology can help increase your cybersecurity resilience. With this combination of advanced technology and human expertise you can better identify and remediate malicious web and email activity to improve your security program and close gaps.

    What You Will Learn:

    - The factors leading to Cyber Global Warming and how you can avoid the pitfalls
    - Global threat trends identified via Lastline’s behavioral intelligence
    - How to measure your cyber resilience
    - Why structured investigations help you get more value from your security tools
    - How a managed network sandbox with Secureworks expertise helped an organization identify a real life attack
  • State of Cybercrime Report 2018: Key Findings Recorded: Jan 15 2019 57 mins
    Alex Tilley, Secureworks Senior Security Researcher
    From July 2017 through June 2018, Secureworks Counter Threat Unit® (CTU®) researchers analyzed incident response outcomes and conducted original research to gain insight into threat activity and behavior across 4,400 companies. Their findings, which include new data about who is conducting what types of attacks and why, will be shared in person by CTU experts on this webcast.

    We’ll examine a small subset of professional criminal actors responsible for the bulk of cybercrime-related damage worldwide and explain: how they’re leveraging the underground hacker economy, why they can’t be seen by researchers and law enforcement who monitor the dark web, and how we know their tools and techniques are as sophisticated, targeted and insidious as most nation-state actors.

    You’ll also learn how constant “background noise” from low-level criminality is impacting businesses around the world and see latest cost of stolen goods, hacking tools, and hacking services on the underground marketplace.

    Additionally, get insight on these key findings from the report:

    - Ransomware is now more sophisticated than ever. Secureworks’ CTU researchers observed no less than 257 new and distinct ransomware families in 12 months
    - Cryptocurrency mining remains an extremely popular way for criminals to monetize access to infected computers. In 2017, at least one in three organizations experienced cryptocurrency mining activity on their network.
    - Criminal gangs have combined advanced social engineering and network intrusion techniques with POS malware to generate millions of dollars of revenue through stolen payment card data. According to the FBI, business email compromise and business email spoofing alone have now generated $12B in financial losses since October 2013.
  • How the Counter Threat Unit™ Sets Secureworks Consulting Services Apart Recorded: Jan 25 2018 57 mins
    Panel of Secureworks Information Security Strategic and Technical Consultants
    As the scope for security skill and expertise demanded of organizations extends, CISOs are increasingly turning to security consulting partners for strategic guidance and technical and advisory expertise.

    There are a broad range of organizations in today’s market offering security consultancy services based on best practices and standard frameworks. Partnering with one of these firms can provide your organization with the technical expertise to improve network visibility and gain a clearer understanding of your vulnerabilities, provide the strategic and practical guidance that helps you prioritize and build out programs that enable business objectives, as well as advise on how to effectively engage with the C-suite.

    What truly sets Secureworks’ information security consulting services apart is how we utilize our Counter Threat Unit™ and knowledge garnered from thousands of client engagements to ensure you are being consulted on the latest industry trends and threats. This way, the outcome is based on real-world scenarios that matter to your organization.

    Join consultants across our technical and strategic practices as they share lessons learned from their most challenging engagements and the value that real-time threat intelligence has brought to those engagements.

    Key topics discussed include:

    • Examples of real-world engagements where the CTU™ and Consulting Practice improved the outcomes for clients
    • Tools consultants use to ensure that your outcome is based on real-world scenarios and threats that matter to your organization
    • Lessons learned from our most strategic and complex engagements
  • 4 Reasons Next-Generation Antivirus Should Be Your Next Managed Service Recorded: Sep 26 2017 53 mins
    John Collins, SecureWorks Counter Threat Unit Principal Architect | Mike Viscuso, Carbon Black CTO
    There seems to be no shortage of threats these days with attackers constantly innovating and combining different techniques with classic malware. New ransomware variants, targeted espionage campaigns, and attacks that don’t use malware at all are just a few threats that put your organization at risk. As each new attack generates global headlines, it can feel a bit overwhelming.

    It’s increasingly clear that the signature-based approach of traditional antivirus (AV) can no longer provide the protection needed to keep attackers off your endpoints. Join John Collins, SecureWorks Counter Threat Unit Principal Architect and Mike Viscuso, Carbon Black CTO, as they discuss how managed Next-Generation Antivirus (NGAV) goes beyond malware prevention to ensure that organizations of all sizes stay out of the security headlines and one step ahead of emerging cyber threats.

    You will learn:
    • What are the indicators that I need NGAV?
    • How do I know when it is time to make the move from traditional AV to NGAV?
    • Why is managed NGAV better able to address Ransomware, PowerShell and WMI threats?
    • What managed NGAV can do for you
  • Windows Management Instrumentation Threats: Good Tools Gone Bad Recorded: Sep 12 2017 46 mins
    Lee Lawson, Special Operation Resercher, SecureWorks Counter Threat Unit
    Windows Management Instrumentation (WMI) is a Microsoft Windows administrative tool that has access to all system resources, making it powerful for both legitimate and illegitimate use. Via WMI you can do things like execute, delete and copy files; change registry values; and identify what security products are installed to aid in bypassing them.

    The malicious use of WMI and other legitimate tools continues to grow and was identified as a top trend in a recent SecureWorks Threat Intelligence Executive Report. Like PowerShell, WMI is often used to create file-less attacks that are difficult to identify and stop with technology alone. This makes WMI the perfect tool for threat actors to use as camouflage while acting inside your organization.

    Join us to learn:
    • Why WMI is so risky
    • Tips to identify malicious use of WMI
    • How threat actors hide their tracks and how you can unmask them
    • WMI threats identified by SecureWorks researchers
    • How you can avoid becoming a victim to this growing threat vector
  • Executive Cyber Protection Recorded: Aug 29 2017 48 mins
    Chris Bullock, SecureWorks Managing Principal
    In a world where physical attack vectors are no longer the preferred way to attack a person of notoriety or a chief executive sta¬tus individual, the need for cyber executive protection to enhance existing cybersecurity programs and traditional executive protection has become greater than ever. With expanded use of information sharing through social media and use of technologies such as home automation, Executive’s habits, families and close personnel staff are being monitored, targeted and shared via the dark web for a number of reasons such as disruption of business, personal or brand embarrassment and financial gain just to name a few.

    In this webcast, Chris Bullock, SecureWorks Managing Principal, will cover a new approach to mitigating risk to this emerging threat that encompasses:

    • Analyzing ten domains of risk to an Executive, their family and close staff
    • How to assess potential risk and exposure to the brand or reputational damage
    • Guidance on which specific risk factors to monitor regularly to ensure preparedness
    • How to implement the most effective and appropriate safeguards
  • Three Key Principles for Managing Cloud Security Risk Recorded: Aug 1 2017 62 mins
    Hadi Hosn, Head of Security Strategy and GRC Consulting, EMEA
    Whether you like it or not, the security industry is being cloudified.
    As IT moves into the Cloud, security must follow, and with IT losing its grip on the endpoint, Cloud is the only Security option. In addition, the Internet of Things continues to scale upwards, and Cloud computing will be its data repository, application engine, provisioning system and Security platform.

    Join Hadi Hosn, Head of Security Strategy & GRC Consulting in EMEA, as he explains why cloud security is so important, and provides guidance on key considerations when building out a cloud security program.

    In this webcast you will learn:
    • 3 key principles for managing cloud security risk
    • 5 common misconceptions and how to avoid them
    • The 5 fundamental cloud security controls you should implement
  • The Value of Time in Threat Detection and Incident Response Recorded: Jul 26 2017 42 mins
    Derek Brink, VP and Research Fellow (Aberdeen Group) | John Collins, CTU Special Operations Manager (SecureWorks)
    The stakes for enterprise investments in threat detection and incident response capabilities are getting higher, as evidenced by empirical data from successful cyber attacks detected and remediated by SecureWorks, a Dell Technologies company.

    The sheer growth and complexity of the technical threat landscape and vulnerability landscape means that merely keeping up is no longer enough. In cyber security, time is currently working in favor of the attackers — and time is the strategic advantage that the defenders need to regain.

    Join Derek Brink, vice president and research fellow for Aberdeen Group, and John Collins, Operations Manager for the SecureWorks Counter Threat Unit Special Operations Team and Advisory Systems Engineer for threat intelligence services , to gain fact-based insights into:

    • Real use cases where time to detect has impacted the business outcome
    • Trends in threat actors and motivations – and how this affects your strategies for protection, detection, and response
    • Quantifying the value and ROI of faster detection and response – for both attacks on availability (e.g., unplanned downtime or slowdown), and attacks on confidentiality (e.g., a data breach)
    • The increasingly important role played by third party threat detection and incident response, in this rapidly evolving context
  • Analysis Paralysis: Billions of Logs to Incidents That Matter Recorded: Jul 19 2017 52 mins
    Tony Merritt, SecureWorks Managing Principal
    Most enterprise organizations have set up a security model that includes a first layer of security event management, responsible for capturing of logs, notification, filtering and some level of correlation. However, with the escalating number of users and logs from more and more devices, making sense of the noise and translating them into incidents that matter can be a daunting task.

    In this webcast, Tony Merritt, SecureWorks Managing Principal, will cover how to leverage logs and tactics to integrate the proper incident response. Topics covered include:

    • Sensing: The challenge of ever increasing in-bound noise and priorities
    • Improving Sensing: What logs and events matter? How do you ensure you have visibility?
    • Sense Making: Not all logs are created equal. The importance of correlation, business context, rules and use cases to determine if the incident matters.
    • Decisions Making: An event has passed a threshold of incident viability. How do you connect logs and tactics into actionable response?
Information Secuirty Thought Leadership
SecureWorks is a global provider of intelligence-driven information security solutions exclusively focused on protecting its clients from cyberattacks. SecureWorks’ solutions enable organizations to fortify their cyber defenses to prevent security breaches, detect malicious activity in real time, prioritize and respond rapidly to security breaches and predict emerging threats.

Embed in website or blog

Successfully added emails: 0
Remove all
  • Title: 2017 Cybersecurity Threat Insights Report for Leaders
  • Live at: Feb 23 2017 7:05 pm
  • Presented by: Chris Yule, David Puzas
  • From:
Your email has been sent.
or close