The presentation discusses the importance of intelligence-driven defense in cybersecurity and how it can be implemented in cloud-native infrastructure using automation and orchestration tools.
- Intelligence-driven defense involves knowing the enemy and their tactics to break the kill chain
- Attack is an open-source framework that provides a taxonomy of tactics and techniques used by attackers
- SOAR (Security Orchestration Automation Response) is a platform that enables organizations to collect data about security threats and respond to security events with little or no human assistance
- Cloud-native platforms offer advanced capabilities and automation tools that can be leveraged for incident response
- GitOps can provide an audit trail and a deterministic, reproducible way of working
- An operator can be used to automate response actions based on security events