Episode Details

Back to Episodes
The End of Reactive Security

The End of Reactive Security

Published 2 weeks ago
Description

You already had the threat intel. The IP was on your blocklist, the file hash was known bad. So why did your MDR only raise an alert instead of blocking it? Lieuwe Jan Koning, Co-founder & CTO at ON2IT, and colleague Nicholai Piagentini, Technical Enablement Engineer at ON2IT, make the case for preemptive cybersecurity: the shift from detect-and-clean-up to block-first, and what it means for the future of MDR.


Timestamps:

  • (00:00) - Preemptive cybersecurity: what it means for MDR
  • (00:59) - Why detect-and-clean-up is not enough (the leaking tap)
  • (01:42) - You knew the threat: block first
  • (03:34) - Fusing the SOC and operations teams
  • (05:57) - Speed, seconds, and AI versus AI
  • (08:15) - Data freedom and vendor lock-in
  • (10:33) - Dynamic policy without breaking change control

Key Topics Covered:

  • Preemptive cybersecurity as the Gartner-flagged direction, and why MDR has to move past detect-and-respond
  • Turning known indicators of compromise into automated blocks at the endpoint, network, and cloud
  • Collapsing the SOC and operational teams so detection and enforcement act as one
  • Sub-second response, AI-driven attacks, and why MTTD and MTTR need to converge
  • Data freedom and data sovereignty, and avoiding vendor cloud lock-in

Related ON2IT Content & Referenced Resources:

Threat Talks website: https://threat-talks.com/
ON2IT (Zero Trust as a Service): https://on2it.net/
AMS-IX: https://www.ams-ix.net/ams 

Listen Now

Love PodBriefly?

If you like Podbriefly.com, please consider donating to support the ongoing development.

Support Us