Beyond the Alert
David Groveman [https://www.linkedin.com/in/david-g-120a2341/], Director of Cyber Services, Incident Response at AmTrust [https://amtrustfinancial.com/] has been inside hundreds of ransomware incidents, and the patterns he describes are not what most security teams are preparing for. The first 60 minutes of an attack are less about technical response and almost entirely about psychology: talking boards off ledges, managing the instinct to wait it out, and watching organizations that expressed full confidence in their MSP discover, in real time, where that trust was misplaced. David breaks down how ransom payment decisions actually get made from the carrier side: the interplay between business continuity, reputational exposure, council teams defining market-specific harm, and the moral conviction of a CEO who simply refuses to pay regardless of the business case. About half of cases end in payment, and the factors that tip it are rarely what organizations anticipate. He also covers why unknown threat actors are harder to work with than established ransomware groups, what investigative shortcuts consistently leave organizations exposed months later, and why he never saw a case go more smoothly when the carrier was notified late. Topics Discussed: * Managing the psychological reality of the first 60 minutes of a ransomware attack across organizations of all sizes * How third-party MSP trust erodes during incident response as culpability and inaction come into focus * Carrier-side decision framework for ransom payment covering business continuity, reputational exposure, and moral conviction * Why unknown independent threat actors are less predictable and harder to negotiate with than established ransomware groups * Behavioral patterns of established ransomware groups including demand amounts, price reduction timelines, and operating like a business * What investigative shortcuts leave organizations vulnerable to re-entry months after initial incident response concludes * The role of OSINT and cross-industry intelligence sharing in building threat actor pattern recognition over time * Why carrier notification timing consistently affects incident outcomes and how to communicate security risk to executives Listen to more episodes: Apple [https://podcasts.apple.com/us/podcast/beyond-the-alert/id1825166903] Spotify [https://open.spotify.com/show/49amXAmCaEyniDZ6HtD7nB?si=6416f87f6f174f4e] YouTube [https://youtube.com/playlist?list=PLkBbuaz1Cy9R6UaLtrOl31URWguaGd8So&feature=shared]
18 episodios
Comentarios
0Sé la primera persona en comentar
¡Regístrate ahora y forma parte de la comunidad de Beyond the Alert!