EP248 Cloud IR Tabletop Wins: How to Stop Playing Security Theater and Start Practicing
Update: 2025-10-20
Description
Guest:
- Jibran Ilyas, Director for Incident Response at Google Cloud
Topics:
- What is this tabletop thing, please tell us about running a good security incident tabletop?
- Why are tabletops for incident response preparedness so amazingly effective yet rarely done well?
- This is cheap/easy/useful so why do so many fail to do it? Why are tabletops seen as kind of like elite pursuit?
- What’s your favorite Cloud-centric scenario for tabletop exercises? Ransomware? But there is little ransomware in the cloud, no?
- What are other good cloud tabletop scenarios?
Resources:
- EP60 Impersonating Service Accounts in GCP and Beyond: Cloud Security Is About IAM?
- EP179 Teamwork Under Stress: Expedition Behavior in Cybersecurity Incident Response
- EP222 From Post-IR Lessons to Proactive Security: Deconstructing Mandiant M-Trends
- EP177 Cloud Incident Confessions: Top 5 Mistakes Leading to Breaches from Mandiant
- EP158 Ghostbusters for the Cloud: Who You Gonna Call for Cloud Forensics
- EP98 How to Cloud IR or Why Attackers Become Cloud Native Faster?
Comments
In Channel