Anton on Security

article thumbnail

RSA 2025: AI’s Promise vs. Security’s Past — A Reality Check”

Anton on Security

RSA 2025: AIs Promise vs. Securitys PastA RealityCheck Ah, RSA. That yearly theater (Carnival? Circus? Orgy? Got any better synonyms, Gemini?) of 44,000 people vaguely (hi salespeople!) related to cybersecurity where the air is thick with buzzwords and the vendor halls echo with promises of a massive revolutioneveryyear. Gemini imagines RSA 2025 (verytame!

article thumbnail

Anton’s Security Blog Quarterly Q1 2025

Anton on Security

Amazingly, Medium has fixed the stats so my blog/podcast quarterly is back to life. As before , this covers both Anton on Security and my posts from Google Cloud blog , and our Cloud Security Podcast ( subscribe ). Dall-E security bloggingimage Top 10 posts with the most lifetime views (excluding paper announcement blogs, Medium postsonly): Security Correlation Then and Now: A Sad Truth AboutSIEM Can We Have Detection asCode?

Insiders

Sign Up for our Newsletter

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

article thumbnail

The Return of the Baby ASO: Why SOCs Still Suck?

Anton on Security

Flickering screens, a sickly, yellow glow. Humming servers, a constant, low thrum of digital malaise. Alerts screamed into the void, a cacophony of meaningless noise, lost in the echoing expanse of our digital tomb. Playbooks, relics of a forgotten war, their pages yellowed and brittle, offered no solace, only a hollow echo of outdated procedures. We were digital ghosts, sorting through the digital detritus of a network that had long since abandoned us.

article thumbnail

A Fair Weather SOC: 5 Signs It’s Time to Panic (and Fix It!)

Anton on Security

A fair-weather SOC by MetaAI Do you have a fair-weather friend? Ortwo? Fair weather friend (viaGoogle) OK, do you also have a fair-weather SOC? This train of thought was inspired by reading pilot forums about how some training approaches lead to fair weather pilots who perform well in all cases except real emergencies. Anyhow, let me stop with this because this is not my area; it only triggered the ideation process forme.

article thumbnail

15+ Years of Loading Threat Intel into SIEM: Why Does This Still Suck?

Anton on Security

Unfortunately, I am old enough to remember how SIEM was done before the arrival of threat intelligence feeds. We had to write broad behavioral (well, behavioral-ish, if I am totally honest) rules without relying on any precise knowledge of attacker infrastructure and details of their operations ( IF event_type=exploit FOLLOWED BY event_type=config_change ON the same machine THENalert ).

article thumbnail

Cross-post: Office of the CISO 2024 Year in Review: AI Trust and Security

Anton on Security

[written together with Marina Kaganovich , Executive Trust Lead, Office of the CISO @ Google Cloud; originally postedhere ] In 2024, we shared our insights on how to approach generative AI securely by exploring the fundamentals of this innovative technology, delving into key security terms, and examining the essential policies needed for AI governance.

CISO 100
article thumbnail

A Brief Guide for Dealing with ‘Humanless SOC’ Idiots

Anton on Security

image by Meta.AI lampooning humanless SOC My former colleagues have written several serious pieces of research about why a SOC without humans will never happen ( Predict 2025: There Will Never Be an Autonomous SOC , The Autonomous SOC Is A Pipe Dream , Stop Trying To Take Humans Out Of Security Operations ). But I wanted to write a funny companion to this called How to Talk to Idiots Who Believe in Humanless SOC.