
M365.FM · 2026-07-02 · 1h 10m
Key moments - from our scoring
Substance score
58 / 100
Five dimensions, 20 points each
This episode reframes security from a traditional vulnerability management lens to an attacker-centric exposure management approach. Uros Babic walks through how modern adversaries chain vulnerabilities together to create exploitable attack paths - misconconfigurations, credential compromise, privilege escalation, and supply chain attacks - that defensive teams often miss when fixing issues in isolation. The conversation covers Microsoft Security Exposure Management's role in discovering assets, mapping attack surfaces, and identifying which exposures actually matter to critical tier-zero assets. Babic also discusses emerging challenges around AI agents in security contexts, explaining how tools like Security Copilot agents can escalate permissions unintentionally and why AI should be treated as a first-class identity requiring governance. The episode is valuable for security leaders, SOC teams, architects, and compliance officers trying to shift from alert-driven reactive defense to proactive risk-driven exposure management, integrating concepts like zero trust, Microsoft Defender for Cloud, Microsoft Sentinel, and continuous threat exposure management across hybrid and multi-cloud environments.
A vulnerability is an individual security weakness or misconfiguration, while an exposure is how attackers chain multiple vulnerabilities together to create an exploitable attack path - exposure management focuses on what attackers actually exploit, not just fixing every vulnerability.
It provides a unified view of assets across endpoints, cloud, identity, and applications with security context, enabling organizations to discover assets, identify attack paths, and prioritize exposure remediation based on which weaknesses actually threaten critical tier-zero assets.
AI agents inherit application and delegate permissions to APIs like Microsoft Graph, SharePoint, and Exchange at integration time; if not properly governed, they can access sensitive data and create data leakage scenarios similar to over-provisioned service accounts.
Zero trust reduces trust but doesn't eliminate exploitation risk; when combined with exposure management, it reveals where organizations remain exploitable and helps defend against attack paths that zero trust alone cannot prevent.
Security Copilot enables incident summarization, reverse engineering malicious scripts, impact analysis, automated remediation recommendations, and investigation triage - helping security teams respond faster without manual forensic workstation analysis.
Our reviewer’s read on each dimension, with quotes from the episode.
The episode contains substantial security concepts - attack surface management, exposure vs. vulnerability, zero trust, AI agents as first-class identities, and the shift from reactive to proactive security - but is severely hampered by poor audio transcription quality that obscures clarity. Many potentially valuable points are buried in garbled text, making it difficult to extract concrete takeaways. When passages are legible, they offer real substance; when they aren't, whole sections become noise.
exposure is actually how attacker actually chain goes issue together the key the key idea it is not about the fixing everything it is about fixing what attacker really exploit the first
the question is no longer do we trust this it's can attacker still get true and it is it is the right approach
Uros brings a genuinely fresh framing: thinking of security through the attacker's operational lens (MITRE ATT&CK tactics/techniques), connecting zero trust with exposure management, and treating AI agents as identity subjects needing privilege management. These are not mainstream talking points in most B2B security content. However, the execution is undermined by transcription quality and the guest occasionally retreats into familiar frameworks (defense-in-depth, layered security).
attacker don't think you know it they think in technique and might detect
zero trust reduce trust but for example in combination in expert management we can it can be show you where you still exposed if so if nothing is trusted it is real question becomes what is still exploitable
Uros Babic is a legitimate practitioner: Microsoft MVP, MCT, lead product engineer for Microsoft security, with 20+ years in cybersecurity including hands-on SOC operations, incident investigation, and real hybrid/cloud migrations. His credibility is clear from specific operational experience and current product responsibility. However, his accent and the poor transcription quality obscure some of his expertise, which diminishes the value delivery despite genuine seniority.
I am actually more than 20 years in cyber security start for my own premise I was actually system admin
I was also working as a cyber kind investigator
The episode struggles with specificity. While Uros names Microsoft tools (Defender, Sentinel, Security Copilot, Conditional Access), he rarely provides concrete data, metrics, timelines, or named attack examples. He references scenarios (misconfigured service account + device vulnerability + excessive permissions = path to domain admin) but doesn't ground them in real breaches, numbers, or case studies. Most claims remain at the conceptual level.
imagine some misconfiguration service account combined with device vulnerability and excessive permission individual that is not aren't critical but together they create path to domain admin
we have a lot of discussion about this topic the last one month we have a lot of AI agents now
Mirko (the host) attempts creative engagement - opening with a role-play scenario of being an attacker, rapid-fire questions, playful follow-ups - but the conversation rarely deepens into genuine pushback or challenge. Most questions are open-ended invitations for Uros to lecture; few press for specifics, disagreement, or clarification of vague points. The host's own accent and transcription issues further undermine dialogue quality. Some softball moments ('how did your journey begin') don't advance substance.
so i'm the checker so i try to bring you a little bit out of the concept so if you had an animal what name will you give him
congratulations you may make it me much harder than i expect but i am stubborn wrong
Computed from the transcript - who did the talking, and the words that came up most.
Traditional cybersecurity focuses on vulnerabilities, alerts, and dashboards. Attackers don't. They look for opportunities, weak identities, exposed cloud resources, excessive permissions, forgotten endpoints, and misconfigurations they can chain together into a successful attack. In this episode of the M365 FM Podcast, host Mirko Peters takes a unique approach by stepping into the role of the attacker while Microsoft Security MVP and Microsoft Certified Trainer Uros Babic defends a modern Microsoft environment using Microsoft Security Exposure Management, Microsoft Defender XDR, Microsoft Sentinel, Security Copilot, and Zero Trust principles. Instead of discussing security theory, this episode follows a realistic attack scenario from reconnaissance and phishing to privilege escalation, lateral movement, ransomware, and data exfiltration. Along the way, Uros explains how organizations can stop attackers before they reach critical assets by focusing on exposure rather than simply fixing vulnerabilities.
Transcribed and scored by The B2B Podcast Index.
Yeah, welcome back to another edition of the MC65FM podcast where we bring you conversations with MbP's, engineers, architects and community leaders shaping the future of Microsoft technology. Today, episodes, it's a little bit different. Usually, we interview expert today. I'm going to be the attacker by going to simple break into URO's Microsoft environment, gather intelligence, deal credentials, move through the network, reach the growing uwits and hopefully not get catched.
Yeah, thank you today's guest is a Microsoft leading security expert, URO's Babich, is a Microsoft security MbP, Microsoft certified trainer and lead product engineer for Microsoft security, deaf ops and a software-1 global center of excellence. We design enterprise SOC solutions using Microsoft Defender, Microsoft Sentinel security co-pilot, automation, Microsoft security, expose management. So today, if we can stop, if he can swap me with me, I succeed. URO's, are you ready?
Yeah, thank you, Mirko. Thank you for joining me on this session and looking forward to discuss a very important topic. Because today, I want you to forget how usually look like in our security because your inertia attacker don't see our environment the way you do. They don't see dashboard, severity, no, 100 open ticket.
They see opportunity. And that is very important, that is very challenge. They see some pet, interesting pet. And they see the fastest way to something very valuable.
And actually, the problem is for many organizations are still fixing vulnerability in isolation, while attacker actually try to change them together. And in this our co-versation, in this session, it is very important to going to think like what you mentioned, like attacker, and understand not just what is vulnerable, but what is actually exposed, publicly exposed. And that is exactly where Microsoft security has for sure management help us. And that is actually game changer because it is help to identify, to prioritize, to the break attack pet that's really major.
And that is the future for our modern stock. I love to say the future of a Celtic stock because we are the most AI now. But it's a center question how we protect our agent. And I love to say also what is the subject of elevation and etc.
That is interesting when many organizations like I don't know before 15 days we have a situation with some agent is Dini, some sub-engine is not properly secure security configure and by security policy. And we must prioritize because, a entropic disable for example, FABL and METUS, it is great example why we rely on external agent tools without governance is actually risky. And if my employee, your employee are using our many AI tools for example, your data is effectively subject of some policy outside of your organization include the regulatory decision you don't control.
And that is also the challenge and that is also the risk. In this central I love to amface something very important what we discuss under the beginning of our our conversation. We are facing with the challenge main cyber attack but into the cloud. The first actually your mansion is some kind of uncontrolled misconfiguration exploit.
An attacker take advantage of fully configured cloud service. What is publicly accessible like storage bucket like overage permission identity access manager role to gay are authorized are says to our sensitive data. The great example is credential that great example is account compromise because we are facing with a lot of fishing brute force attack. Credential staffing are used to hear cloud account after leaving to a lot many lots of movement without cloud environment without any control user nomination early face for attack and the challenges how we can stop in the fast way.
How we using to our tools in better efficient way because modern us were complying now include many many other challenge and clip cloud data. Pression with the third party clients partners for us to take with combination with data solution the next step is privilege installation. With data solution that is the great the margin but for a large input for many organization and for the money also for the reputation and actually we are facing also what is I so big challenge is the cloud base of the supply chain is also targeting but attacker compromise widely using some library or services to affect multiple organization and what a mission AI AI with the machine learning with the system exploit with the poison threatening data with the steel model.
I wait with many other challenge to use AI to generate the commencing fishing or some defake context and because cloud environments with the malware design it is a great example for Kubernetes for docker a container security under eyes often stealing some API key talk and secret and that is that is very usual that is very common attack perspective weak misconfiguration access control can lead for example to unauthorized access for many Azure as to simply in stroke past or policy and MFA I love to say past or less without any password using strong multifacare authentication with the fish persians mechanism it is it is a good start so I think before I take your organization I start with social engineering so yeah it was can you tell us a little bit about yourself and and how your journey begins into cyber security.
I am actually more than 20 years in cyber security start for my own premise I was actually system admin in Windows server environment and work with with a lot of on premise and who the two and lead to writing I remember 2016 and 2017 is migration actually from standard on premise and from on premise bare metal to cloud and actually my work is because the client often work in hybrid environment and move from the know but we also working for how environment but that is actually how I shift my knowledge my experience step by step in these 20 years and of course everything is changed shift and thinking and attack perspective and previous could be have other focus now we have more sophisticated focus how we can use the modern modern tool because you know we are facing with a lot of duct tape that data what means without any control in the cloud and the first question is before you define what is your sensitivity data do you know what is your sensitivity data how you protect your sensitive data in the cloud do you know how it looks like your data flow do you know what is managed and how you can manage your device or your device is under your control that is the first steps and yes very good exposure management give you a lot of opportunity but but in me must thinking very predicate and actually the great way is actually Microsoft security exposure management about why you love to discuss today how is shifting security from a reactive perspective to actually from reactive incident response to pro active risk reduction that is my focus and I love to continuously more the last five years to map my attack surface management and actually identify exposure across identity across endpoints across cloud across application and how I can prioritize my work and what is actually metric in that way that is crucial and that is that is a very good approach how we can do in our daily operation because also I love to mention I worked in day to day operation with the SOC team 24 hours critical asset critical resource incident other thing and what is the core message how we as for sure is not equal vulnerability we have vulnerability we have individual issue with common vulnerability as for score be the lot of misconfiguration what I mentioned before but exposure is actually how attacker actually chain goes issue together the key the key idea it is not about the fixing everything it is about fixing what attacker really exploit the first and that is that is a tricky and why that is why I love to am phasing I know no attack surface management the first thing I was thinking how discover attacker try to discover my asset from no from unknown and I have external option I have internal option that is also the case when you're conducting some internal or external pen test activity but exposure graph is very good option how you can identify security dependency method how show your weakness actually connecting into many attack path and the next step is how we can prioritize real risk and allow to make a question many time myself what is the fact aspect to domain admin or global admin for my critical assets and that is also attacker perspective show me I don't know show me top exposure affecting tier zero assets how I can help my analyst to reason faster and this is very important topic very important to point when we starting to work with this shift how well after say we have all so security operation center alert driven now manage sock modern sock thinking line attacker risk driven after attack no it is important proactive approach before attack and noise on overload how we can prioritize exposure management I love to to give you some real reward feeling how we work how we project our initiative with some practical scenario imagine some misconfiguration service account combined with device vulnerability and excessive permission individual that is not aren't critical but together they create path to domain admin extreme show management will be fine and purify that change that is good and this is actually answer how I shift myself from seco to DevOps for many automation in in the last in the last five years that is that is answer for a wish okay so I'm the checker so I try to bring you a little bit out of the concept so if you had an animal what name will you give him a name yeah with animal layer or something like that okay then I google now your your your birthday and I copy paste your email address from link that now I am in your your channel yeah yeah yeah yeah yeah correct very good yeah yeah let us a little bit short talk about the topic inside of risk what did you think how how big is this part actually of further the new checks the AI yes that is that is a good question the central question I actually have a lot of discussion about this topic the last one month we have a lot of AI agents now in two direction the first is a agent in security copilot for AI with some conditional access optimization agent to reveal your depping conditional access policy very good for security baseline in Microsoft 365 tenant show some security analyst is very interesting now you you have direct chat now with two security consul should unit to replace your for example to be good thank your security analyst not replace really because we must get you an interaction but for your vulnerability management for your security score for your custom very language or a lot of questions with primary discoloration a lot of questions from for for a later a moment pet that is very interesting point and the the central question yes is elevation privilege this agent I have a lot of discussion and explain a lot of during the session but I love to have phasing something why AI agent should be threat as the first class identity how we can simulate data leakage scenario for many company and that in entry protection how to enforce conditional access policy how to respond to agent incident from isolate anomaly because the central question is elevation but when use the many new interact with copilot agent on custom AI workflow the agent doesn't just answer question it act it call Microsoft graph it reads from share point but it query exchange it doesn't all the using delegate of application permission that we granted integration time and we forget that and we we we are facing with a lot of elevation of permission and the behavior is actually makes AI agent functionality equivalent to some I know well service principle manage identity in terms of access scope and this is exactly why Microsoft enter now that again the identity and the first class subject in identity plan all of us use the device and work load the center question is how we to protect to our sensitive information go outside when we have interaction of scope i vote great example is maybe data security poster management for AI on Microsoft review you can use in deal peak policy in combination the protection and detect some your sensitive data when you have but security joy journey is actually provide some very good framework in my opinion what we first identify with AI agent in Microsoft entry agent agent preview protect with hondesh initial access policy detect with identity protection in enter ID and security copilot respond with defender automatic access block and session termination using some conditional access or defender is the air capability and finally don't forget optimization continuous policy analysis get identification with and this is actually the six act and how we understand you are using very useful you often interacting with the pilot agent customer agent with share point online with the exchange line micro graph API and we have access the data access we have sensitive content access accessing file and folders critical outside and that is realistic data leakage scenario.
Miscofegration agent without any control orchestration layer it will be challenged in the next period of time we can use many protection mechanism but the central question how we use sound automation response to block to terminate tool login in scope for our automatic blocking via some policy when we have risk agent in in in in Fox and you can use many many very good good tool like defender for how depths like micro solution in many many additional capability in that way. Yeah, Microsoft have a topic I think in years they say zero trust zero trust zero trust for devices zero trust for users zero trust for applications how have zero trust change in the age of AI.
Yes, very good question and we have a lot of opportunity in that way. Yes, your mission very actually we can use some blend expert for management with the zero trust mindset instead to move step by step to change identity and point mis-confiduration permission into the path because for attacker perspective attacker don't care about your security model that is very interesting and they don't respect boundary they don't respect your your zero trust and they definitely don't follow your priority list because zero trust reduce trust but for example in combination in expert management we can it can be show you where you still exposed if so if nothing is trusted it is real question becomes what is still exploitable and connect zero trust with special management that is maturity angel and position you in in that way but zero trust in combination for for AI it will be it will be challenged surely with the identity AI when we when we have when we have the real scenario we when we have because because the trust is in age of again TKI a retinking security special for a for my opinion and the fixing special not just all it we are using angelic AI and especially the driven security in combination for our future modern stock and zero trust in in in conclusion is not enough you must use many other solution like special management but you implement zero trust model now with the AI but why is still exposed that is that is again TKI plus zero trust why attacker still actually win a how to stop in in in in in the either part and the I love to explore and thinking shift our focus how combines zero trust with micro security special management and again TKI all of us to finally shift from reacting to others to proactively breaking attacker pets for example before they ever use that is the modern stock and just zero trust limit access as per show management show where the attacker still win and that is a good approach for agent TKI agent TKI doesn't just detect threats they understand them it will be challenged and very good question so the question is no longer do we trust this it's can attacker still get true and it is it is the right approach breadball narrative into our our focus in the next period of time and thank you for this special um microsoft had had a lot of security tools I say Microsoft peer view your data security Microsoft in tune for device management Microsoft enter for identity Microsoft sent in it for yeah collecting detecting threats then they have uh not known I have forgotten for what was it and and and they have a defend or a lot of defenders but you're a specialist in Microsoft security expelers management is there's a true or what is it is a framework yeah that is that is good question uh how we can start with with special management uh that is combination your answer is combination uh this is I love to say more security solution provide for you unify view security posture across many organizations have all called the endpoint cloudless for I don't know my cellar that surface and security as for show management give you all asset information with security context and help you here to be proactive manage at a surface pro protect critical assets and explore and mitigate some special risk in digital state but actually now standard integration is with the defender for cloud because defender for cloud now is moving for a easier portal to defender portal uh not only for uh ager it is now be talking about multi-tenth and multi management across ager a a a a a a a a a a a a a a a a a a a a w s and gcp we are defend for cloud integration alongside traditional on premise single uh this unify approach graph expo show graph give you for example i don't know device your identity or cloud assets external atox surface management along with the gardener continuous threat expo show management in general to your answer is both this is some kind of framework but also provide for many many great opportunity great security tool uh and you can uh actually uh who is use this for example for my perspective security compliance having to improve your organization security post security operation guys uh need to visibility into data into your flow a workflow across uh many organization in order to detect in order to investigate in order to mitigate security threats the third category what you mentioned at the beginning of our organization very important topic is security architect architect is responsible to solving some issue in order of security poster management and our spisto i don't know chief security information officer uh with some decision makers who need inside into organization atox surface management they should manage being in order to address better understand security risk in organization the uh what is uh very important for our discussion to understand now vulnerability management is moving from traditional environment and point environment to uh expo show management and actually this is easy answer combination vulnerability with the risk management it is a great uh great and what can i do with this i can use unify view across many organizations with my asset ten points cloud environment external atox surface management managing investigation atox surface in order to visualize something i don't know uh analyze this manager uh and the other surface spending on premise and hybrid environments that is also very very important topic to to understand and i can discover i can say regard my critical asset i can manage the exposure tool to manage security exposure and mitigate many exposure risk and i can finally manage and investigate atox surface management with graph schema with a lot of another and the last topic what is important here for our discussion what you mentioned with the Sentinel but uh yes Sentinel is a cloud native security management system uh to connect uh many data sources but here we can uh with security as such management we can connect our data connector to integrate with the different security solution uh uh and data sources including external vendor rapid seven i will know cloud many other platform tenable callies uh uh a service now into single unify view uh esposh management graph and that is good that is fine and finally you can i will give you a deeper insight into security push for integrity data for various environment and external sources uh four years uh i think companies often think oh we have all these tools we pay Microsoft on the security and um yeah Microsoft they know and know and uh a lot of companies start to build their cyber security teams or have a partner for this topic but now it's i think a really new product it's the Microsoft security co-pilot uh and i think uh i got the sheep son of security expert and i paid in 60 uh european hour uh and now i can can get it four for six yes that is the interesting you know uh we are in areas security co-pilot and agente kai and actually uh you can use security co-pilot with uh as a core feature in your security quest for use some interesting use case uh many interesting for example you know i give you some great example wise from my perspective uh needed uh incident summarization it is better for you for your security alert to consist on actual online better connecting with your vulnerability uh basis uh data basis impact analysis ask the potential impact of security incidents at enable quicker response time uh reverse engineering you can put all your malicious scripts in security co-pilot to analyze this complex line script and translate into natural language with clear explanation uh of action without move to any digital forensic station you can use primarily binary first respondent forensic uh with security co-pilot and why the response step by step willens for incident response for example uh how you can automatically lock your account how you can automatically disable your account is your account for rest of the network uh the next steps for your recommendation for better uh security score everything including in right direction for triage for investigation for containment incident for a mediation critical part of your security management and this is very good uh and after that you have many uh agente kai with security co-pilot you can use uh 30-tellage's briefing agent to automatically create relevant and timely intelligence report you can use uh conditional access optimization to for your uh uh get insecurity policy uh uh fix for identity teams fishing three agent vulnerability remediation agent aint not all co-pilot in uh in preview in entra lot of lot of other challenge but that is that is good that is uh and yes provision capacity is uh very important to uh to know how you set your de-40 level and how to assign long permission how to use them with provision co-pilot capacity and the work with cost optimization phenopes it is great opportunity today uh especially for many security admin or security analysts in the cloud yeah um thank you this was really good good answer and let's a little bit talk about or uh or i have a question uh how is uh exposure different from uh value and urelities it's damn too old yeah that is very good question how is different uh you know our security esp- uh esp- uh esp- uh management offer uh that is important in the in-naster attacker can't destroy it to gain access to your data or how the rest of us and uh uh when you have insecure security api and point and growing necessity and microstracoolize that and uh give last very good program initiative for endpoint uh with good target score with uh cloud with your identity with your application uh and uh you have very top initiative here for uh found the re-beshma control zeal transfer nation this is male compromise is uh your mention very important topic busy small compromise is not for example classical fishing that is uh uh in in combination socio-engineering with many the middle attack and many other uh been in general it must be more and more proactive with critical asset protection to improve our scoring vulnerability management to uh to understand the score of history uh to devices special management distribution everything is related and uh uh when we know better our at the surface metric at the pet uh critical asset summary uh it will be definitely with this proactive approach uh uh uh i mentioned uh some critical pillar ranceover human operation ranceover is a challenge in in the last two two two years with the data filtration with this busy small compromise and we must shift uh uh you know uh it is very easy ask for your question lack of visibility lack of control uh not knowing where data is stored and who can uh he who has access uh two and can be risky but i can implement comprehensive monitoring and access management social care and hands visibility in this control and that is that is in in the summary there i approach uh how we can protect and how we actually shifting our thinking and the great question is how we can thinking like like that okay hope um there it's um i think our uh metra corp i think they have these um yeah and you see for e list uh that you think uh it's enough to handle cyber security um or have we have it there also a change yes very good approach we can map everything with uh my to protect framework we can use uh a bezel tactic technique it called on normal knowledge uh knowledge base of real world article behavior that is uh preposition uh pre-requisite and showing me how to actually operate step by step uh a key idea it doesn't focus on tool on malware but it focused on behavior and attack pattern meter attack framework is bej basically map of how I talk you think how I talk you move how I achieve the their goal inside your environment and uh that is the reason why I using many tactic uh in issuos kredeshwaks water movement as a iteration what is the attack try to achieve that is the the the the the first question and after that how I can use some technique like fishing pass the hash golden ticket stair skeleton key uh exploit vulnerability partial execution how would they achieve that and finally with a lot of sub technique in more detail uh with uh I don't know what a moment like SMV protocol RDP protocol a siltration with data transfer uh uh it shows how attacker progress across stage and I'm using in my approach attack attack uh a few metrics this is a very good approach and uh we have uh most important tactic uh I don't know our first is uh attacker getter info with reconnaissance uh execution initial access persistence and finally with privileges uh uh uh escalation for dash elaxes a lot of movement with the spread uh communication external with the command and control c2 server malissio server uh we have input we have damage we have ransom but and I love to conduct many red blue simulation uh maybe the wood uh uh to discuss for our another session some vocabulary detection engineering something like that to to for our resilience map sent in a rule with attack technique can't base behavior with the alerts uh attack show how attack will happen and finally if special management show you where they we will succeed and that is actually uh uh attacker don't think you know it they think in technique and might detect uh in in the conclusion it's very good blueprint of attack behavior yeah um uh I think a lot of executives are when they visit the cyber security team they they look at the dashboards and all this 80% and it's green and uh for the most are uh yeah is it uh then it's secure because it's green yeah um but how can an executive understand security posture without really called technical reports yes that is that is also uh you can control uh security score it is also important part what we don't mention uh with a single view of your data you're at the point with identity with data with application and to reveal yet uh and some identity some device some follow up location data cloud infrastructure um this type of consolidation enable a better proactive approach in risk management and inform you about decision making uh good for audit but uh uh uh uh you can also use in the many recommendation from Microsoft in your pro-pro-active approach for your device for your cloud from software to service application I don't know uh identity data with recommendation summary uh the center question is uh yes uncrasted uh but uh we must align in our defender uh class device manage device to onboard the now device to to be to be more secure uh your device and manage device uh without any control it will be great example of risk uh in today in uh very very sophisticated attack metric and uh we're facing with serious uh advanced threat uh uh groups uh and uh actually the lesson of although uh attacks to in the last uh uh one year tell us we must shifting definitely in in this in this uh in this way which metrics really are really important or which metrics or KPIs watch you every day yes uh actually uh metrics with the KPI how um for example diagram with attack with the exposure graph with attack pet how to map sentinel detection to attack pets uh red-blue demo using attack chain this uh this is would uh uh exercise management priority is attack reveals and micro-attact show your uh how attack remove but uh it doesn't tell which pet is the most dangerous this is wood combination to use some KPI approach and uh that is where aswoshu management comes in uh uh uh attack reminds them minds that and tell us uh tell us uh a lot of techniques to sub technique in in in that way uh uh but uh in in general uh this is this is uh uh um the biggest challenging modern soc is not like potato it is actually measuring the wrong things that is wood KPI uh the most stock track problem number of fellas number of incidents main time to respond time to fall number of close ticket the uh those are actually metric not security outcomes and you can close all at all day but it it will be still exposed and really what is the KPI too much noises KPI reward will you not quality uh no attack or context KPI don't reflect real attack pet everything is green but while attacker still have a pet full sense of security uh it is it is a lot of but uh traditional KPI we have out of volume but now i love to to discuss with you about exposure reduction real goals without the attack elimination with the modern KPI time to remediate critical exposure that is very good uh topic this is also business-imposed how we can cover a gem in in to meter meter attack framework with the texture quality how how i can identify a risk with tier zero exposure with the most critical real layer we can must use and what we discussed previously in agente here era that is a change in change the game but not processing more art but prioritize what is actually actually reduce with the the exposure management that is uh stop measuring activity start measuring exposure that is the message yeah okay um that's interesting if while you already know where i most like to attack but uh yeah it's time for plan B uh let's say my fishy game i worked uh what employee clicked uh what's now what's happened now?
Other episodes covering the same guests and topics, from across The B2B Podcast Index.