Pre-empting attacks - Relevance of red teaming in enterprises

HITB Cyber Week Dubai: Red Team Village

2020/11/18

AI Generated Summary

This panel discussion from HITB Cyber Week Dubai explores the relevance of red teaming in enterprises, covering why it’s important, how to get budget approval, common pitfalls, and how to resolve conflicts between red and blue teams.

Panelists

Key Topics Discussed

Why Red Teaming is Important for Enterprise:

Emmanuel’s Perspective:

Dr. Erdell’s Perspective:

Kiran’s Perspective:

Bryson’s Perspective:

How to Convince People Who Control the Purse:

Emmanuel’s Approach:

Dr. Erdell’s Approach:

Kiran’s Approach:

Bryson’s Approach:

Major Pitfalls in Red Teaming:

Emmanuel’s Perspective:

Dr. Erdell’s Perspective:

Kiran’s Perspective:

Bryson’s Perspective:

Resolving Conflicts Between Red and Blue Teams:

Emmanuel’s Perspective:

Dr. Erdell’s Perspective:

Kiran’s Perspective:

Bryson’s Perspective:

Key Insights:

Actionable Takeaways:

  1. Red teaming matters like military training - readiness, tactics, know enemy
  2. Best way to uncover unknown unknowns
  3. Translate to business language - dollars, not CVEs
  4. Three phases: recon, access, post access - business value increases down phases
  5. Purple teaming - collaborative culture, get results as go
  6. Scope matters - define activities and targets
  7. Repeatable testing key - validate posture maintained
  8. Resolve conflicts by focusing on business risk, not ego
  9. Leadership must set vision and expectation
  10. Don’t let ego take precedence - there are always threats don’t know about