Monthly Archives: February 2020

March, 2020 Chapter Meeting

Our March chapter meeting is on Wednesday, March 4, 2020 at 5:45PM. Please RSVP if you plan on attending!

Open Source SIEM

Abstract: The Gordon Food Server Enterprise Information Security team chose to adopt an open source approach to security monitoring. After analysis, we decided to implement an Elastic Stack environment in preference over a commercial SIEM. This talk will discuss where we started, what we were looking to accomplish, why we chose the Elastic Stack. We will discuss adoption, budget, resource requirements, lessons learned to implement the solution and where we are taking our implementation in the future.

Speaker Biography: Paul Dumbleton is the Enterprise Information Security Team Manager at Gordon Food Service

Schedule
5:45-6:00PM Networking, dinner
6:00-7:15PM Presentation
7:15-7:45PM Q&A

Location Information
Metro Health IT Facility
985 Gezon Parkway (across from Target loading dock)
Wyoming, MI, 49519

Map

February, 2020 Chapter Meeting

Our November chapter meeting is on Wednesday, February 5, 2020 at 5:45PM. Please RSVP if you plan on attending!

Is poor cyber hygiene crippling your security program?

Abstract: Don’t expect a whole lot from your expensive new security tools unless you first master the basics. Time and again in 2019, responders and security analysts saw threat actors exploit basic security gaps to circumvent expensive security stacks. Join Marcelle Lee and Allison Wikoff, both Senior Security Researchers from Secureworks’ Counter Threat Unit™ Research team for an overview of the cyber threat landscape. Topics covered will include: Lessons learned from Secureworks incident response practice, eCrime threat landscape, and targeted threat landscape (with a focus on Iran)

The new Secureworks Incident Response Insights Report 2019 shows how organizations are undermining their security programs by leaving gaps in security fundamentals that gift easy opportunities to threat actors. As a result, the adversaries gravitated toward known successful tactics and needed only moderate evolution to achieve success. Use of native tools and other living off the land techniques helped them evade detection. Frustratingly, many of the gaps our team saw can be effectively addressed with measures like multi-factor authentication.

The report examines the methods threat actors used to gain access and provides advice on prioritizing your efforts to protect against present day threats. You’ll also learn the 5 most common misconceptions our incident response team hear from organizations with large blind spots.

Speaker Biography: Marcelle Lee and Allison Wikoff, both Senior Security Researchers from Secureworks’ Counter Threat Unit™ Research team

Schedule
5:45-6:00PM Networking, dinner
6:00-7:15PM Presentation
7:15-7:45PM Q&A

Location Information
Metro Health IT Facility
985 Gezon Parkway (across from Target loading dock)
Wyoming, MI, 49519

Map