This discussion emphasizes the importance of prioritizing understanding and proactive measures over relying solely on tools in addressing cybersecurity challenges. It underscores the necessity of comprehending potential attacks specific to an organization's architecture and attack surface before implementing solutions.
Here is the verbatim discussion:
Find okay fundamentals are still important you must understand the problem what type of attacks given your architecture given the tax service the architecture what type of attacks could potentially happen What would it look like on your network what would see it can you see it only then would you understand the problem after you understand the problem then you can go looking for tools right that could see it make the tools then sit your environment and not the other way around which is how it ends up happening when you just buy things and it's slap it on right to understand that solution the tools become secondary you begin to realize that open source does a really good job instead they have a tendency to buy products or servic to solve the problem so understand the the the you know the attacks we might see against the user how we would detect that let's just slap ADR on there let's not understand attacks against the network and how we might protected and respond let's just slap.
Comments