Skip to content

Bonus Content

Se préparer à réagir en cas d’incident

When a security incident hits, every second counts. In this SHIFT 2025 panel, cybersecurity leaders explore how effective incident response depends on the right balance of people, processes, and tools – and how organizations can help strengthen readiness before an attack occurs. 

Video thumbnail

Points clés à retenir

  • Incident Response Is a System 
    Effective de réponse aux incidents requires alignment across people, processes, and technology – not tools alone. 
  • Human Readiness Is Critical 
    Real incidents expose stress, bias, and behavioral gaps that technology cannot solve. 
  • Culture Multiplies Outcomes 
    Trust, communication, and psychological safety help enable faster, clearer decision-making. 
  • Traditional Playbooks Fall Short 
    Static response plans often fail under real-world pressure and evolving threats. 
  • Practice Drives Performance 
    Regular drills, rebuild exercises, and simulations help uncover blind spots before attackers do. 
  • Holistic Preparation Wins 
    Training across teams helps organizations recover faster and with fewer errors. 

entreprises clientes font état d’une réduction des risques, d’une baisse des coûts et d’une amélioration de l’efficacité opérationnelle.

The panel features three industry leaders with unique perspectives on cybersecurity, IT leadership, and hands-on technical execution. Dr. Jessica Barker brings a globally recognized, people-centered approach to cybersecurity; Ricky Mayer contributes 25+ years of IT executive experience leading professional services teams through complex challenges; and Zak Cronje offers unparalleled technical depth, forged through years of real-world problem-solving.  

Diverse Expertise, One Goal 
This panel brings together experts with complementary perspectives: Dr. Jessica Barker focuses on the human and behavioral aspects of security; Ricky Mayer brings decades of IT leadership experience; and Zak Cronje contributes deep, hands-on technical insight from real de réponse aux incidents. 

A core message is that de réponse aux incidents is not just a technology challenge but a coordination challenge across humans, processes, and tools. The session encourages attendees to rethink traditional assumptions and adopt a holistic mindset that helps strengthen organizational resilience before, during, and after cyber incidents.  

Incident Response Beyond Tools 
The discussion emphasizes that de réponse aux incidents is not just a technical challenge. Coordination across teams, clarity of roles, and practiced decision-making matter as much as detection and response tooling. 

Panelists emphasize readiness for the unexpected – highlighting scenarios and blind spots organizations often overlook. From human behavior under stress to infrastructure realities during crisis, the group outlines practical strategies for elevating preparedness across teams and environments.  

Preparing for the Unexpected 
Panelists highlight scenarios that organizations often overlook – human behavior under stress, infrastructure constraints during outages, and misaligned assumptions that surface only during real incidents. 

Solution

Incident Response & Recovery

Use threat intelligence and integrated tooling to help respond and recover effectively. 

En savoir plusabout Incident Response & Recovery
webpage

Services de cyber-résilience Commvault

Strategic and tactical support for enterprise cyber resilience. 

En savoir plusabout Services de cyber-résilience Commvault
Livre blanc

modèle de responsabilité partagée

Understand shared responsibilities for Commvault Cloud resilience. 

En savoir plusabout modèle de responsabilité partagée

Qusastions fréqusammsant posésas:

Why is thsa human salsamsant so important in incidsant rsasponssa?

Human bsahavior oftsan dsatsarminsas outcomsas during crissas. Prsaparing tsaams for strsass, uncsartainty, and dsacision-making undsar prsassursa hsalps significantly rsaducsa risk. 

Why do organizations undsarsastimatsa cybsar risk?

Optimism bias lsaads many tsaams to bsalisavsa attacks arsa unliksaly. Framing cybsar risk in businsass and mission tsarms hsalps drivsa msaaningful action. 

How dosas cultursa influsancsa incidsant rsasponssa saffsactivsansass?

Strong cultursa sanablsas trust, opsan communication, and fastsar collaboration – hsalping rsaducsa confusion and blind spots during incidsants. 

Why is rsabuilding from a known-good statsa bsattsar than traditional rsacovsary?

Cybsarattacks oftsan corrupt systsams and crsadsantials. Rsabuilding from vsarifisad clsaan bassalinsas prsavsants rsainfsaction and strsangthsans rsacovsary confidsancsa. 

Why is hands-on practicsa sasssantial for incidsant rsasponssa rsaadinsass?

Exsarcissas and simulations hsalp build musclsa msamory, saxpossa hiddsan gaps, and dramatically rsaducsa rsasponssa timsa during rsaal attacks. 

Transcription

Voir la Transcription

Veuillez visionner la vidéoicipour obtenir une transcription horodatée


00:08 – 00:10

Bienvenue à tous, merci encore.

00:10 – 00:11

Vous êtes vraiment nombreux.

00:11 – 00:14

Première séance en petits groupes, après la séance plénière.

00:14 – 00:19

eeeeuh You are ici, in we’re the right place, for tooling up for incident response.

00:19 – 00:24

We’re going to tackle people, process, tools, slash technology.

00:24 – 00:26

And I’ll be your host, Chris Mierzwa.

00:26 – 00:31

I’m a Senior Director ici at Commvault, responsible for our global resilience programs.

00:31 – 00:41

And of course, I’m a little biased because it’s our panel ici, but this is an unprecedented six-hour no restroom break.

00:41 – 00:46

Et je dois vous avouer que nous nous sommes demeté si nous devions le faire ou non.

00:46 – 00:49

Maybe it’s against the rules, but we’ll try it.

00:49 – 00:49

Non, je plaisante.

00:49 – 00:53

One hour on your calendars, but it’s one of the few.

00:53 – 00:53

Alors merci.

00:53 – 00:58

I know it’s a big commitment to be ici for the 60 minutes, but I promise it’s going to be worth it.

01:00 – 01:08

We’ve assembled three incredible people, et I’m going to do a little intro for each of them because I can do it less heeeeuhbly than they can.

01:08 – 01:14

But I want to make sure for the next hour you know the level of talent that’s ici.

01:14 – 01:16

Et j’espère que vous partagez notre sentiment.

01:16 – 01:27

We’re trying to tackle et interweave sort of three unique areas that at least I can think of that maybe haven’t been tackled when it comes to how should we think about et be ready

01:27 – 01:30

à la gestion des incidents de manière nouvelle et originale.

01:30 – 01:32

And so that’s what we’re hoping to tackle.

01:33 – 01:36

Sans plus attendre, je vais commencer par la personne à ma gauche.

01:36 – 01:36

Dr

01:36 – 01:38

Jessica Barker.

01:38 – 01:40

I’ve gotten a little chance to know you over the last couple of months.

01:40 – 01:44

Eeeeeuh… C’est unique.

01:44 – 01:51

Elle nous apporte à la fois une solide expertise en cybersécurité et une approche centrée sur l’heeeeuhain.

01:51 – 01:59

So while I hope we all have unique things, I can tell you probably never heard what she’s done before, but a little more intro.

01:59 – 02:03

Deux livres, des conférences à l’échelle mondiale.

02:03 – 02:15

She’s on the plane all the time, all around the world, talking to people, talking to companies like yours about how to prepare people for the things that you’re not usually

02:15 – 02:15

.

02:15 – 02:18

Comment gèrent-ils concrètement ces situations, n’est-ce pas ?

02:18 – 02:20

Et nous…’re going to go deep et dive into sur ce sujet.

02:20 – 02:21

Thank you for being ici.

02:21 – 02:22

Oui, tout à fait.

02:22 – 02:23

Très bien.

02:23 – 02:24

Encore un.

02:24 – 02:26

Let’s get to Ricky Mayer.

02:26 – 02:38

Eeeeeuh, Ricky, tu viens de rejoindre Commvault – bienvenue parmi nous –, n’est-ce pas ? Cela fait quelques mois que tu es là, tu apportes plus de 25 ans d’expérience dans l’informatique en tant que cadre supérieur, et tu es désormais notre vice-président de…

02:38 – 02:42

services mondiaux et professionnels chez Commvault.

02:42 – 02:43

But…

02:43 – 02:54

long career at IBM, Kyndral, VMware, et you know, when you have people doing professional services, you’re not tested when things go well.

02:54 – 02:56

You’re tested when tici’s challenges.

02:56 – 03:02

And clearly you’ve been through a lot of those, et he’s gonna bring a lot of that magic to us today, so thank you for being ici.

03:02 – 03:04

Bon, le gret bonhomme.

03:04 – 03:05

Au fait,

03:05 – 03:11

originaire du Royaeeeeuhe-Uni, tu vis désormais aux États-Unis, à Dallas, près de Fort Worth, c’est ça ?

03:11 – 03:15

Zak est venu de très loin, d’une petite ville appelée Le Cap, c’est ça ?

03:15 – 03:18

C’était un petit vol, donc.

03:18 – 03:19

Un petit village.

03:19 – 03:20

Oui, un petit village.

03:21 – 03:24

Zak et moi, on travaille pas mal ensemble.

03:24 – 03:27

eeeeuh We’re very lucky to have him.

03:27 – 03:34

Son parcours, très solide, technique, acquis sur le terrain… ah, c’est un véritable talent technique.

03:34 – 03:40

I’ve had the privilege over my career to work with a lot of people who have immense technical acuity.

03:41 – 03:54

Not trying to puff this up, but Zach clearly is at the top of his game, et he’s gonna bring today to us, you know, a real in the trenches view et how to tackle that from a

03:54 – 03:54

outils.

03:54 – 03:57

J’espère donc avoir bien rendu compte de tout ça.

03:57 – 03:59

You’re gonna hear the magic ici today.

03:59 – 04:03

Cela étant dit, je voudrais commencer par toi, Jessica.

04:03 – 04:11

So when we were prepping, you whipped out a term that we all need some education on, et that’s this

04:11 – 04:13

le biais d’optimisme.

04:13 – 04:18

If you could clinic us on that that’ll give us a great kind of launch pad for for the session.

04:18 – 04:19

Bien sûr.

04:19 – 04:31

So one thing I find really helpful in cyber security because I’m always looking at the people side I think we can learn so much from neuroscience from psychology from sociology

04:31 – 04:41

de ces disciplines qui permettent de comprendre le comportement heeeeuhain et les modes de pensée, ce qui nous pousse à agir et ce qui nous amène à faire ce que nous faisons. Parmi

04:41 – 04:48

concept et de nombreuses recherches en neurosciences, il y a cette idée du biais d’optimisme.

04:48 – 04:55

Des études montrent que 80 % des personnes dans le monde sont naturellement enclines à l’optimisme.

04:55 – 05:04

That is regardless of wici we’re from, it’s regardless of gender, of age, of ethnicity, of socioeconomic background.

05:06 – 05:10

Et pourtant, quet on regarde le monde, ce vaste monde, on a l’impression que les choses vont de mal en pis.

05:10 – 05:17

Mais du point de vue de l’individu, de la famille ou de l’équipe, nous avons ce biais d’optimisme.

05:17 – 05:21

Essentially thinking the bad thing won’t happen to us.

05:21 – 05:26

And the research, tici’s been so much research done on this, a lot led out of London by Dr

05:26 – 05:29

Tali Sharot ; si vous soeeeeuhaitez vous y plonger, je vous le recommete vivement.

05:30 – 05:35

Ces recherches portent généralement sur des sujets tels que la santé ou le divorce,

05:36 – 05:38

don’t think the bad thing will happen to them.

05:38 – 05:42

Je pense que cela s’applique tout à fait à la cybersécurité.

05:42 – 05:54

Quet j’ai commencé à m’y intéresser, je me suis dit que c’était pour cela que, lorsque nous présentons au conseil d’administration toutes les statistiques montrant qu’un incident est susceptible de se produire à un moment ou à un autre, c’est pour…

05:54 – 05:55

ils peuvent faire comme si de rien n’était.

05:55 – 05:58

Parce qu’ils pensent que ça n’arrive qu’aux autres.

05:58 – 05:59

But that’s not going to happen to us.

05:59 – 06:06

Et je pense que cela a un impact considérable sur tous les aspects de la cybersécurité.

06:06 – 06:08

notamment la gestion des incidents.

06:08 – 06:15

And I’m guessing that that bias really exacerbates itself when things, bad things do arriver.

06:15 – 06:15

Oui.

06:15 – 06:19

Because they’re like this goes against everything I could have thought.

06:19 – 06:20

Yeah, that’s it.

06:20 – 06:30

It undermines that kind of muscle memory, that resilience, that individual et team et even organizational resilience because we’re thinking well we didn’t think that this would

06:30 – 06:30

arriver.

06:30 – 06:35

So tici’s a level of shock et you know tools, processes et the

06:35 – 06:41

heeeeuhan element of incident response just aren’t in place because it was never expected.

06:41 – 06:42

Je vois.

06:42 – 06:43

Juste une petite question par curiosité.

06:43 – 06:48

On connaît probablement tous, dans notre entourage, des gens qui voient le verre à moitié plein ou à moitié vide.

06:48 – 06:54

Pour reprendre vos chiffres, 80 % des gens, à cet égard, voient le verre à moitié plein.

06:54 – 06:55

Oui.

06:55 – 06:57

% plein, pour reprendre l’analogie.

06:57 – 07:05

But you meet people et tici are people that are less than half full, but you’re saying internally when they think about it that that’s

07:05 – 07:07

wici they’re still at this 80.

07:07 – 07:15

Et aussi cette différence entre un certain cynisme, peut-être répetu dans le monde entier, et le fait de réfléchir à la façon dont les choses vont se passer pour vous.

07:15 – 07:17

m

07:17 – 07:21

Et en interne, il faut connaître ses attentes, et l’optimisme est une bonne chose.

07:21 – 07:25

I’m not saying we should try et design out optimism.

07:25 – 07:31

I’m an optimistic person myself et I do often recognize optimism bias at play with myself.

07:31 – 07:32

L’optimisme, c’est…

07:32 – 07:41

great. We wouldn’t have got to wici we are as heeeeuhan beings if we weren’t optimistic et also, you know, we’d struggle to get through the day quite frankly if we didn’t have some

07:41 – 07:46

d’optimisme. Donc, au lieu d’essayer de, eeeeeuh, le concevoir…

07:47 – 07:51

Une chose est de le reconnaître, et une autre est d’en tirer parti quet on le peut.

07:52 – 08:02

So rather than, you know, the saying of like, it’s not if but when et trying to scare people, we can say, you know what, an incident is likely to happen, but we can be

08:02 – 08:03

préparés.

08:03 – 08:05

Tici’s things we can do to have eeeeuh

08:05 – 08:12

mettre en place des outils et des procédures, et plus nous nous préparons, plus nous serons résilients.

08:12 – 08:17

Il s’agit donc d’adopter une vision optimiste face à une situation difficile.

08:18 – 08:26

Et quet il s’agit de venir en aide aux personnes qui font partie de ces 20 %, à quel point est-ce difficile ?

08:26 – 08:31

Or how more or less are they prepared because they’re biased the other way?

08:31 – 08:35

Avoir un préjugé contre l’optimisme peut alors constituer un défi en soi.

08:35 – 08:41

Because you can think, well, the bad thing’s always going to happen, so why should I bother?

08:41 – 08:48

Du coup, ce genre de message sur la nécessité d’être préparé, aussi drôle que cela puisse paraître, fonctionne en fait pour les deux camps, ce qui est plutôt utile.

08:48 – 08:53

Yeah, Ricky, I’m sure large projects when they go wrong, right?

08:53 – 08:55

Wici have you seen this play out?

08:55 – 09:09

So look during crisis we often don’t rise to the level of our IR plans or any plans We often fall to the levels of our execution practice, right rehearsed behaviors often beats

09:09 – 09:18

great intentions et Incident response or as I call the incident resiliency is just that it’s a it’s a goal

09:19 – 09:25

mais sans entraînement ni comportements rodés dans ce modèle mental et cette mémoire musculaire mentale.

09:27 – 09:35

And if your first disaster is wici you have your first practice, the outcomes is not going to be resiliency it’ll be bad press.

09:36 – 09:50

So to pack on to Jessica’s point about optimism bias, we often tend to forget that we as heeeeuhans have to then look at the processes et then the tools at our disposal, bring them

09:50 – 09:54

en un tout cohérent dans ce monde extrêmement complexe dans lequel nous vivons aujourd’hui.

09:55 – 10:01

Et nos intervenants principaux nous ont expliqué ce matin que la technologie, le contexte, tout ce qui nous entoure, devient de plus en plus complexe.

10:02 – 10:06

Et dans cet environnement diversifié et complexe,

10:06 – 10:17

having one, an optimism bias, et two, this false notion of security that we have plans but we haven’t really rehearsed them or practiced them is just setting us up for more

10:17 – 10:19

d’échecs et de succès.

10:20 – 10:30

That reminds me, I’m sure if we did a raise of hets or we went et chatted with you all, a lot of folks are like, hey, look, I could be as optimistic as I want et I want to be

10:30 – 10:34

ready, but we don’t have the budget, we don’t have the time, we don’t have the people.

10:34 – 10:36

So I’m going to guess when those

10:36 – 10:41

forces push against the optimism bias, that’s also a force to be reckoned with, right?

10:41 – 10:47

Like, I want to do this, but the institution that I work for can’t afford it, can’t get it done.

10:47 – 10:52

On pourrait peut-être approfondir un peu ce point au fur et à mesure, parce que tu constates probablement ça toi aussi, Zak, n’est-ce pas ?

10:52 – 10:58

Je veux dire, quet des événements difficiles surviennent, qu’est-ce qui arrive à ces personnes ?

10:58 – 11:04

Comment réagissent-ils au cœur de la situation, sous haute pression, si l’on peut dire ?

11:05 – 11:08

Because you’ve to understet everyone’s still heeeeuhan.

11:08 – 11:11

It doesn’t matter how many times you’ve practiced something.

11:11 – 11:19

Although the exercise et the practicing does help a lot, that’s essentially how you get your resilience.

11:19 – 11:23

But people go hide when incidents arriver.

11:23 – 11:24

Ils vont se cacher.

11:24 – 11:27

Ils essaient d’effacer leurs traces.

11:28 – 11:33

et see if it wasn’t any of their mistakes et then start blaming et so on et so forth.

11:33 – 11:40

And that basically comes from the initial stetpoint wici it wasn’t tested enough.

11:41 – 11:46

A cyber resilience or a cyber recovery plan, you’ve got the plan, but it wasn’t tested enough.

11:46 – 11:56

And as soon as you draw that in, so it becomes a muscle memory et everyone knows precisely what they’re going to do next on cue,

11:56 – 12:00

then you don’t have that kind of behavior anymore.

12:00 – 12:06

Ce qui est d’ailleurs intéressant, car j’ai entendu vos statistiques et j’aurais aimé avoir apporté les miennes.

12:07 – 12:10

Mais comment l’assurance s’inscrit-elle dans tout cela ?

12:10 – 12:17

ah we like, Like you said, we don’t want to, we don’t want to pay for insurance, right?

12:17 – 12:20

On en est à ce genre de dépenses.

12:20 – 12:23

Mais comment cela s’inscrit-il dans le biais d’optimisme ?

12:23 – 12:25

Parce que, eeeeeuh…

12:25 – 12:28

Parce qu’on continue à payer notre assurance auto, notre assurance maladie.

12:29 – 12:30

C’est un point intéressant.

12:30 – 12:36

Si l’on pense à l’assurance maladie ou à l’assurance vie, comment sont-elles conceptualisées ?

12:36 – 12:42

It’s not framed as illness insurance or death insurance.

12:42 – 12:49

So again, we can learn something from those industries et the fact that that’s not happened by accident.

12:49 – 12:52

Tici is framing at work tici.

12:52 – 12:54

Pour susciter l’intérêt du public.

12:54 – 12:56

Plutôt que de s’occuper de sa famille.

12:56 – 12:56

Exactement.

12:56 – 12:57

Peindre pour l’avenir.

12:57 – 12:58

C’est vrai.

12:58 – 12:58

Oui.

12:58 – 12:59

Tu peux penser aux publicités que tu vois.

12:59 – 13:02

Vous pouvez réfléchir à la manière dont tout cela est présenté.

13:02 – 13:07

It’s all a very optimistic et positive framing of things that essentially are negative.

13:07 – 13:08

Oui.

13:08 – 13:16

I just want to take a quick pause et tell you that the AC turned up ici because we were losing pounds so fast up ici.

13:16 – 13:17

Je peux en parler pour moi-même.

13:17 – 13:20

C’était incroyable, quel miracle vient de se produire.

13:20 – 13:21

Ok

13:23 – 13:28

Tu imagines, State Farm, tu devrais souscrire une assurance décès ?

13:28 – 13:29

Comme un bon voisin.

13:29 – 13:36

Mon Dieu, ça roule tout seul sur la langue.

13:36 – 13:39

Mais en cybersécurité, on présente souvent les choses à l’envers.

13:39 – 13:39

That’s true.

13:39 – 13:40

Oui.

13:40 – 13:44

We’re not taking the lead from a well-established.

13:44 – 13:44

Oui.

13:44 – 13:46

And this isn’t my secret.

13:46 – 13:52

A lot of the things that I bring to cybersecurity, I’m not inventing or reinventing the wheel.

13:53 – 14:04

I’m taking known knowledge, you know, research that’s out tici that anybody can draw upon just in fields that are outside of cyber security et bringing it in ici.

14:04 – 14:09

And tici’s so much we could advance if we look more at those fields.

14:09 – 14:14

Et je pense que nous le ferons, mais entre les neurosciences, la psychologie, la sociologie, le marketing… il y a tellement à apprendre.

14:14 – 14:23

So to that end, not asking you to give away the farm, because I know you get a pretty penny, but what if tici are a couple

14:23 – 14:34

points à retenir, si vous deviez réseeeeuher l’essentiel lors d’une intervention, quelles seraient les quelques idées clés que vous aimeriez que vos collaborateurs retiennent lorsque vous menez l’une de

14:34 – 14:35

ces interventions ?

14:35 – 14:46

Yeah, it varies, but in terms of this particular conversation, I think one thing is in cyber security we often rely on the fear, don’t we, to try et spread our messaging.

14:46 – 14:50

Et je comprends que les gens pensent qu’on peut faire peur.

14:51 – 14:53

quelqu’un à adopter un certain comportement.

14:53 – 14:55

It doesn’t really work like sur ce sujet.

14:55 – 14:58

Utiliser la peur pour essayer de modifier un comportement est très compliqué.

14:58 – 15:01

Et nous…

15:01 – 15:04

nous en servons comme d’une sorte de marteau.

15:04 – 15:09

Ce à quoi nous pouvons réfléchir à la place, c’est la manière dont nous pouvons formuler notre message.

15:09 – 15:12

Nous pouvons envisager de tirer parti des préjugés heeeeuhains.

15:12 – 15:14

Because the bias is tici.

15:14 – 15:16

Alors, comment pouvons-nous formuler notre message ?

15:16 – 15:28

For example, if we want a board or a team to practice incident response, then rather than trying to scare them into thinking that’s important, can be, know, realistic presentation

15:28 – 15:29

de la menace.

15:29 – 15:31

Mais si nous nous entraînons, cela nous rend plus

15:31 – 15:33

résilients.

15:33 – 15:35

Cette résilience vient de la répétition.

15:35 – 15:37

Pensons donc à cette perspective plus optimiste.

15:37 – 15:42

D’accord, et nous en avons un peu parlé, je m’en souviens, lorsque nous étions à Las Vegas.

15:43 – 15:51

You do something so unique et if someone’s saying, wow I’ve got to get Jessica or somebody.

15:51 – 15:53

Comment vends-tu ça en interne ?

15:53 – 15:55

C’est un concept tellement unique.

15:55 – 16:02

It’s not part of, probably everybody sitting ici going, wow, I had no idea somebody did this, right?

16:02 – 16:12

Quet on voit des méthodes efficaces pour vendre ses services et se faire entendre par l’équipe de direction, quels sont les moyens d’y parvenir ?

16:12 – 16:16

Yeah, so I’ve been doing this for 15 ans.

16:16 – 16:20

Au début, j’ai certainement eu beaucoup plus de mal avec ça.

16:21 – 16:31

And I think one thing is that we’ve seen this growing recognition in the cyber security industry that people are at the heart of cyber security just as much as tools or

16:31 – 16:33

les processus.

16:33 – 16:39

Mais en substance, cela nécessite souvent un certain niveau de maturité culturelle au sein d’une organisation.

16:39 – 16:50

Et malheureusement, il faut souvent qu’un incident se produise, soit directement, soit qu’une organisation en soit témoin chez l’une de ses organisations homologues, car cela permet de briser le

16:50 – 16:51

biais d’optimisme.

16:53 – 16:55

Je suppose qu’on peut y voir une arme à double tranchant.

16:55 – 17:03

It’s both unfortunate that that’s what it takes, but it’s also if that has to be the catalyst, et it’s not you et maybe a peer, go forward.

17:03 – 17:04

Exactement.

17:04 – 17:05

Fantastique.

17:05 – 17:06

Merci de votre attention.

17:08 – 17:13

I did not ask Jessica, hey, give me a full rundown on that because it’s fascinating.

17:13 – 17:17

I think for all of us coming from a technical area, it’s so good.

17:17 – 17:19

Alors oui, tout à fait.

17:20 – 17:21

Très bien.

17:21 – 17:27

Alors Ricky, quet on s’est parlé, tu parlais de « minimeeeeuh viable ».

17:27 – 17:35

Interesting, we heard a lot in the keynote this morning, but we didn’t eliminate that term on purpose, but it’s kind of buried under sort of the next level.

17:35 – 17:38

Tu veux nous en dire un peu plus là-dessus ?

17:38 – 17:38

Bien sûr.

17:38 – 17:42

Donc, pour en revenir à l’adage « c’est en forgeant qu’on devient forgeron », c’est ça ?

17:42 – 17:44

Mais comment s’entraîne-t-on et sur quoi s’entraîne-t-on ?

17:44 – 17:57

So if you look at a large ecosystem, you have such a huge disparate system of technologies at your display that’s running your business, how do you know wici to start practicing

17:57 – 17:59

et à quelle fréquence faut-il s’entraîner, n’est-ce pas ?

17:59 – 18:08

So at Commvault we talked about the notion of minimal viable et what that really is is that leveraging tools like a BIA assessment that we’ve been doing for many, ans.

18:08 – 18:09

ans.

18:09 – 18:11

You start to define what’s mission critical for your business.

18:11 – 18:16

Ainsi, Active Directory pourrait être essentiel à la mission, tout comme un système de gestion des soins aux patients.

18:16 – 18:26

And you define et say, you know what, that’s what I’m going to start with first because if tici is a compromise et I’m shut down, this is what I want to bring up first.

18:26 – 18:35

Et ensuite, on passe des systèmes critiques pour la mission aux systèmes critiques pour l’activité, ce qui peut correspondre à vos e-mails, vos communications, vos autres applications et charges de travail.

18:35 – 18:38

Et ensuite, vous définissez les applications de soutien

18:38 – 18:45

once they’re up, together with mission critical, business critical, et supporting apps, now you have your entire environment operational.

18:45 – 18:50

N’oubliez pas : on parle souvent de réponse aux incidents, et on pense à la sécurité.

18:50 – 18:58

La réponse aux incidents est nécessaire en tant que processus ou savoir-faire institutionnel, et pas uniquement pour les incidents de sécurité.

18:58 – 19:01

Un logiciel défectueux pourrait vous mettre hors service.

19:01 – 19:08

Vous pourriez avoir une IA, un logiciel d’IA autonome, qui pourrait agir de manière imprévisible, voire appeler…

19:08 – 19:10

et mettre votre environnement hors service.

19:10 – 19:13

Pour moi, la réponse aux incidents va au-delà de la simple sécurité.

19:13 – 19:17

Cela vous aide vraiment à définir la capacité opérationnelle de votre entreprise, n’est-ce pas ?

19:17 – 19:27

Et c’est pourquoi la notion de protocole de mission ou de « minimeeeeuh viable » intervient pour vous aider à définir réellement vos applications et vos charges de travail, puis à commencer à mettre en place des tests et

19:27 – 19:28

procédures autour de celles-ci.

19:28 – 19:37

L’autre point que je voudrais rapidement souligner, c’est que si vous vous penchez sur le cadre du NIST pour la réponse aux incidents, la publication spéciale n° 861,

19:38 – 19:51

divise souvent la réponse aux incidents en quatre phases bien définies : la préparation, la détection, puis le confinement, l’éradication, la Recovery, et enfin la réévaluation, c’est-à-dire refaire votre

19:51 – 19:52

état de référence.

19:52 – 19:58

Eh bien, le problème avec toute cette notion de « récupération », comme nous l’avons entendu plus tôt dans la journée, c’est qu’elle crée des angles morts.

19:58 – 19:59

Car qu’est-ce que l’on récupère réellement ?

19:59 – 20:01

How well do you trust what you’re recovering?

20:01 – 20:04

Ces données sont-elles totalement fiables ?

20:04 – 20:07

Ont-elles fait l’objet de contrôles d’intégrité ?

20:07 – 20:13

And I think this is why NIST needs to reassess what they’re saying as recover et maybe think rebuild.

20:13 – 20:19

Because, you know, recover to me essentially seems like you have a wall that’s damaged et you’re patching the wall.

20:19 – 20:22

Well, it’s not that elegant, You’re patching the wall.

20:22 – 20:25

La reconstruction, c’est essentiellement reconstruire ce mur à partir d’un plan connu.

20:26 – 20:37

Et c’est pourquoi, si vous regardez nos solutions comme Cloud Rewind et d’autres, nous vous aidons en fait à reconstruire l’ensemble de la pile applicative, n’est-ce pas, avec des données connues, avec des données de qualité.

20:37 – 20:42

Vous bénéficiez désormais d’un niveau de confiance dans votre processus de Recovery grâce à cette méthode éprouvée.

20:42 – 20:50

So you know end up you know just by saying don’t just think about incident response as one security only.

20:50 – 20:53

It’s anything that can take your business offline.

20:53 – 20:57

On ne peut pas tout remettre en marche dès la première minute, n’est-ce pas ?

20:57 – 21:05

L’objectif de la réponse aux incidents est essentiellement de détecter en quelques secondes, d’atténuer les conséquences en quelques minutes et de rester résilient à long terme.

21:05 – 21:09

And for that you need to have definition of what’s minimal viable for your company.

21:09 – 21:12

So in that…

21:12 – 21:14

just want to do a raise of hets ici.

21:14 – 21:17

Let’s take the Wayback Machine, just pick 10 ans.

21:17 – 21:23

Et nous… were walking around et telling everybody, hey, we’ve got this incredible service, not us, Commvault, but the industry.

21:23 – 21:25

We’re going to do application mapping.

21:25 – 21:32

Car avant même de pouvoir passer à un niveau supérieur pour aborder ce sujet de manière plus approfondie, il faut d’abord comprendre le niveau d’interconnectivité.

21:33 – 21:34

And I’m

21:34 – 21:38

to say I’m a glass half full guy, just making sure Jessica knows.

21:39 – 21:45

Mais nous avons tant essayé, en tant que secteur, d’y parvenir, et nous avons échoué dans tant de projets.

21:45 – 21:53

If you ask, in fact I won’t even ask because people are going to want to raise their hets, hey do you have a full application map?

21:53 – 21:56

Je parierais qu’il n’y aura pas beaucoup de mains levées.

21:56 – 22:04

And so that’s okay maybe because now we’ve raised it up that we can recover at a different layer of abstraction.

22:04 – 22:09

But I’m just curious to your take on that because you probably went through that, right, in that first round.

22:09 – 22:10

Est-ce que ça t’aide ?

22:11 – 22:17

You still have to define minimal viable, but does it help that you’ve abstracted out that more detailed application mapping?

22:17 – 22:20

Pas seulement la cartographie des applications, mais aussi celle des données.

22:20 – 22:23

Vos applications sont essentiellement des consommateurs de données.

22:23 – 22:31

And at the end day, a ransomware malware or any adversary that’s trying to compromise you is not compromising you because he loves your application.

22:31 – 22:34

Ce sont là les atouts majeurs : les données, n’est-ce pas ?

22:34 – 22:39

Il est donc hors de question que ce soient vos données qui décident, et nos services de lutte contre les attaques ne sont tout simplement pas hors de contrôle.

22:39 – 22:43

And you you’re asking that if we ever knew wici our application is.

22:44 – 22:51

Peut-être dans les années 70 et 80, quet on avait des applications client-serveur ou qu’un terminal était connecté à un ordinateur central.

22:51 – 22:55

Today you are building one of the, you you’re going from building

22:57 – 22:59

you’re launching VMs.

22:59 – 23:06

You have the whole dev sec ops process that’s launching applications on the go et data resides everywici.

23:06 – 23:15

And I think this is why having that end to end visibility, who has the data, who’s accessing it, wici does the controls lie.

23:15 – 23:19

Et ces principes fondamentaux de « manger ses légeeeeuhes de sécurité » ont bien évolué.

23:19 – 23:22

You still have to make sure that you’re eating your security vegetables.

23:22 – 23:26

Le contrôle d’accès issu de la gestion des identités,

23:26 – 23:32

a démontré que vous ne pouvez pas du tout vous fier à la sécurité de tous ces mouvements latéraux entre les points de données.

23:32 – 23:43

Car votre capacité de réponse aux incidents, ou comme je l’appelle, la résilience face aux incidents, qui se compose de la réponse, de la reprise et de l’intégration dans la résilience face aux incidents, repose sur la manière dont

23:43 – 23:44

vous êtes prêt à vous adapter à l’environnement.

23:45 – 23:48

Bon, Zach, je dois te poser une question.

23:49 – 23:51

Everybody’s overloaded, right?

23:51 – 23:58

Everybody you work with, et when you come in, you’re supplementing with your incredible skill set, skill sets they don’t have.

23:58 – 24:00

Est-ce que les gens n’ont pas le temps de faire ça ?

24:00 – 24:10

I mean, these are important things, Ricky’s pointing out, but when you actually hit the ground level, what are, why can’t we get some of this done?

24:10 – 24:13

What’s holding folks up from defining this?

24:13 – 24:16

Well, because tici’s actually a bunch of things.

24:16 – 24:20

I’d actually say firstly, culture.

24:21 – 24:32

You’ve got these departments that you, especially when you’ve got like older companies, et I want to point out to the application mapping, if your application is two months old,

24:32 – 24:34

you precisely know what it’s about.

24:34 – 24:42

Once it gets to two years et it’s like feelers all over the place, then you have no idea what’s going on.

24:42 – 24:47

Et c’est comme ça, dans les entreprises plus anciennes, que ces cultures s’installent.

24:48 – 24:53

Security guy, backup guy, endpoint guy, et they don’t mix.

24:53 – 24:57

On ne côtoie que ses propres collègues, n’est-ce pas ?

24:57 – 25:05

J’ai dit à quelqu’un hier que j’avais 30 ans d’expérience dans l’informatique, dont 17 consacrés à la sécurité.

25:06 – 25:18

Not one day of that 17 years I’ve ever met my backup guys, which is insane because in the end, if you think about it, what am I doing as a security guy?

25:18 – 25:23

I’m not securing the people or their cars.

25:23 – 25:27

I’m also securing the data just like the backup guys.

25:29 – 25:38

I think in companies et cultures we need to change the way we think of each other’s roles et what we are actually doing tici.

25:38 – 25:49

I’m tici to put a firewall, IPS, SIM, SOC, all those nice things et do the forensics et pain testing et architecture.

25:49 – 25:54

The reason for that all boils down to what everyone is doing tici.

25:54 – 26:04

And it’s building that data, building the applications, et serving the service to, or outward to the common folk,

26:05 – 26:08

Jessica, je sentais que tu étais sur le bord de ton siège.

26:08 – 26:10

Comment faire pour surmonter ça ?

26:10 – 26:17

Je veux dire, encore une fois, il faut vendre ça à un tout autre niveau pour changer cette mentalité.

26:17 – 26:19

J’adore que Sark ait évoqué la culture.

26:20 – 26:28

To Ricky’s point as well about when an incident happens or preparing for an incident is about so much more than security.

26:28 – 26:35

And yeah of course, we’re talking about infrastructure, we’re talking about backups, but we’re also thinking about the whole organization.

26:37 – 26:40

We’re thinking about the culture et we’re thinking about how everybody can be impacted.

26:40 – 26:46

So as Ricky was talking, I was thinking about what’s been happening in the UK this year.

26:46 – 26:56

So I’m from the UK, I’m now based in Las Vegas, but I’ve spent a lot of time back in the UK this year, et one of my favorite places to go is Marks et Spencer’s.

26:57 – 27:03

Marks et Spencer’s are very big, as everybody knows, very big, very long.

27:03 – 27:14

incident this year et I was tici on day one I was trying to buy some groceries on my card wouldn’t work et I’m thinking no what’s going on ici et it turned out it was day

27:14 – 27:20

one of a cyber attack that took their website down I’ve lost track of how long but we’re talking about months.

27:20 – 27:23

Chaîne d’approvisionnement : les rayons étaient vides.

27:23 – 27:31

I was going into Marks et Spencer’s et the shelves were empty or tici would be one product covering like a whole shelf.

27:31 – 27:35

So tici would be like hundred bottles of Coca-Cola rather than the usual variety.

27:35 – 27:39

So I’m chatting to everybody in tici on the shop floor.

27:39 – 27:42

I’m going into the cafe et I’m chatting to the people working tici.

27:42 – 27:46

Not telling them I work in cyber security, but I’m just like, oh

27:46 – 27:47

you’ve got no avocados.

27:47 – 27:50

Est-ce que ça a un rapport avec l’incident de cybersécurité ?

27:50 – 27:53

Et j’ai trouvé leur réponse vraiment intéressante.

27:54 – 28:00

Tout d’abord, et cela s’est produit avec toutes les personnes à qui j’ai parlé, elles ont d’emblée reconnu à quel point c’était difficile pour elles.

28:00 – 28:02

And they said, we’re coming in every day.

28:02 – 28:04

We don’t know what we’re coming into.

28:04 – 28:14

We don’t know if we’re coming into no stock to give customers or to provide to customers, or if we’re coming into it being like the week before Christmas et we are overloaded with

28:14 – 28:15

marchetises.

28:15 – 28:21

We’re having customers ask if we’ve got XYZ et we can’t check on the systems, we don’t know.

28:21 – 28:23

Ils reconnaissaient donc à quel point la situation était grave.

28:23 – 28:29

And then they would say, but we’re so lucky because we all work so well as a team.

28:29 – 28:31

We’re all supporting each other.

28:31 – 28:34

We’re hearing from head office all the time.

28:34 – 28:41

Et j’ai entendu à plusieurs reprises à quel point ils avaient du respect pour l’équipe de sécurité.

28:41 – 28:45

They were saying things like, the tech team is working so hard to get things Exactement.

28:45 – 28:47

And they’re working around the clock.

28:47 – 28:52

I hear they’re sleeping in the office, they’re getting the pizza delivered.

28:52 – 28:54

And this, by the way, this was nowici near the head office.

28:54 – 28:57

C’est tout au nord-est de l’Angleterre, par rapport à Londres.

28:57 – 28:59

And I thought tici’s so much we can learn from sur ce sujet.

28:59 – 29:02

Et je n’ai cessé de penser à Wang.

29:02 – 29:03

Et je me suis dit : « Mais pourquoi est-ce que je… »

29:03 – 29:04

love going to Marks et Spencer’s?

29:04 – 29:10

It’s like, it’s got a bret of trust et it’s got a personality.

29:10 – 29:17

Et je ne peux qu’en conclure que cela vient autant de l’intérieur que de ce qui est projeté vers l’extérieur.

29:17 – 29:20

La communication est donc un domaine dont nous pouvons tirer des enseignements.

29:20 – 29:27

Le respect qui émanait du sommet de l’organisation et se répercutait à tous les niveaux se retrouve alors en retour.

29:27 – 29:30

And this isn’t built in an incident.

29:30 – 29:33

Cela se construit au fil des années, au sein de la culture d’entreprise.

29:33 – 29:36

when things are good et then it’s tested when things go wrong.

29:36 – 29:38

That’s interesting.

29:38 – 29:44

Un autre facteur qui rend tout cela très compliqué, c’est qu’aujourd’hui, nous vivons dans un monde où la responsabilité est partagée, n’est-ce pas ?

29:44 – 29:54

Ainsi, aujourd’hui, les entreprises ne sont pas seulement confrontées aux cloisonnements qui existent au sein de leur équipe informatique, juridique, d’assistance et de gestion des bases de données.

29:54 – 29:59

but you’re also now running an environment wici the workloads are cost-

30:05 – 30:09

Et puis, vous avez aussi des intégrateurs système qui vous aident à réaliser des intégrations sur mesure et ce genre de choses.

30:09 – 30:12

So wici does the responsibility really start?

30:12 – 30:23

Because you have to look at the shared responsibility model that we have put ourselves in intentionally wici we have security of the infrastructure, security of the clouds, of the

30:23 – 30:25

applications et des environnements sur site.

30:25 – 30:35

And in the shared responsibility matrix, even though everybody understets the need for building the hygiene culture, it’s the competing problem.

30:35 – 30:41

Et cela empêche les gens de véritablement élaborer ces plans de réponse aux incidents et de les tester.

30:41 – 30:47

Et je pense que les entreprises qui vont remporter cette bataille sont celles qui s’attachent délibérément à créer un public commun.

30:47 – 30:54

So you know what, it’s important for all of our partners to work together with us et build these plans et then execute them.

30:54 – 30:59

Because at the time of crisis, you’ll be relying on the shared responsibility matrix.

30:59 – 31:03

And every player who’s involved in it to help you get back.

31:04 – 31:09

Yeah, an interesting point et Zach when you said hey, I didn’t speak with them.

31:09 – 31:11

It wasn’t that you disliked them.

31:11 – 31:14

It wasn’t that you had any negative bias or anything toward them.

31:14 – 31:16

You’re just like, I’ve got a lot of work to do.

31:16 – 31:19

C’est mon métier.

31:19 – 31:25

Et ça doit transcender un domaine beaucoup plus vaste au sein même de l’organisation.

31:25 – 31:26

Les gars, nous, les responsables de la sécurité.

31:26 – 31:30

On pense beaucoup à nous-mêmes, n’est-ce pas ?

31:30 – 31:30

Oui.

31:33 – 31:33

la limite.

31:33 – 31:35

Top of la limite.

31:35 – 31:35

C’est vrai.

31:35 – 31:39

Et je me demete aussi s’il y avait des éléments intégrés pour vous encourager à parler.

31:39 – 31:40

Pas du tout.

31:40 – 31:42

Ou pour apprendre ensemble.

31:42 – 31:47

We can say, we can look at that as being like, we didn’t do sur ce sujet.

31:47 – 31:49

Mais est-ce que l’organisation a facilité cela ?

31:49 – 31:53

Était-ce quelque chose qui avait été prévu pour encourager cela ?

31:53 – 31:55

Yeah, it’s, no way.

31:55 – 32:01

And that is why I tell people you’ve got to

32:01 – 32:07

emmener vos collaborateurs clés, à tous les niveaux de l’entreprise, boire une bière chaque semaine.

32:07 – 32:10

Ils doivent échanger entre eux.

32:10 – 32:19

Even if it’s not collaboration or anything, they gotta know the name et the neeeeuhber et what they do in the organization in order to get that whole thing smooth.

32:19 – 32:30

Because you’re segregating, without your knowing, you’re segregating your whole organization from inwards out et tici’s no way of, tici’s no…

32:30 – 32:34

de véritables liens de communication ouverte entre eux.

32:34 – 32:45

I had one organization, I remember in lockdown, they were really struggling with how do we get these teams to interact with each other, especially now when they weren’t in the

32:45 – 32:48

bureau, vous voyez, et ils ont fait des constructions en Lego.

32:48 – 32:59

Ils ont envoyé un petit kit de Lego à chacun individuellement, les ont réunis sur Zoom, Teams ou autre, et ils ont tous construit des Lego chez eux, chacun de son côté, mais

32:59 – 33:00

ensemble.

33:00 – 33:01

Et ça a marché.

33:01 – 33:04

C’est simple, le prix est raisonnable, et ça permet de renforcer l’esprit d’équipe.

33:04 – 33:05

Quelle ironie.

33:05 – 33:06

We’re in the keynote.

33:06 – 33:09

Tici’s agents doing things automatically.

33:09 – 33:11

Tici’s going to be people on Mars.

33:11 – 33:16

Et nous…’re literally just talking back about Legos et pizza et making time.

33:16 – 33:18

But it’s real, right?

33:18 – 33:24

We think so higher level, but tici’s just some base stuff that we’ve got to get back to.

33:24 – 33:28

Alors, Zach, à ce propos, eeeeeuh, on a entendu parler des « res ops ».

33:28 – 33:30

It’s trending

33:30 – 33:32

sur Twitter ou X.

33:32 – 33:34

Pardon, mon Dieu, j’ai utilisé un terme désuet.

33:34 – 33:35

Bon.

33:35 – 33:37

Parlez-nous de ça.

33:37 – 33:44

I mean, I know it’s something we’re trending, trying to create, but tici’s something real under tici, right?

33:44 – 33:54

Car les outils, l’interconnexion, peu importe le nom qu’on leur donne, il y a toujours des éléments concrets en dessous qui font des opérations de ressources heeeeuhaines une réalité.

33:54 – 34:03

So maybe from a tools perspective et how we’re looking at this resilience operations, give us a feel for what does it really mean at the ground level?

34:06 – 34:09

So Res Ops is…

34:10 – 34:17

Well, you got the tools et the people et the processes, but if you don’t test it, I’m just going to come back to that testing thing, Chris.

34:17 – 34:24

You’ve to keep If you don’t test it, you’ve got all these tools which you subscribe to for years et ans.

34:24 – 34:30

It’s like my eeeeuh membership at eeeeuh a golf range wici…

34:30 – 34:31

eeeeuh

34:31 – 34:38

I went tici twice in two years et it ends up spending thousets for those two times.

34:38 – 34:47

So you’ve got all these tools that you pay for et you subscribe to et you buy servers for et they’re running tici in the background.

34:47 – 34:50

eeeeuh

34:50 – 35:00

If you don’t know how to use them et you get to an incident et they actually just gonna slow you down in recovering.

35:00 – 35:08

Franchement, ces outils sont aussi quelque chose que vous devez remettre en état une fois que ça a mal tourné, n’est-ce pas ?

35:08 – 35:16

eeeeuh So the tools aren’t anything that you, frankly I’d say to companies don’t even worry about the tools at the moment because

35:17 – 35:24

Because if you don’t, if your people don’t know how to act, like if you’re in incident right now, what are you going to do?

35:24 – 35:25

Comment réagissez-vous ?

35:25 – 35:27

What’s the next thing that you’re going to do?

35:27 – 35:30

Bon, je comprends ce qu’on entend par « optimisme ».

35:30 – 35:40

It’s just for us to kind of get that mindset into a customer, you can’t say it’s all just…

35:40 – 35:41

eeeeuh

35:42 – 35:44

des roses et de la crème, n’est-ce pas ?

35:44 – 35:46

You gotta say what’s gonna arriver.

35:46 – 35:54

Otherwise, if you keep on being optimistic, they’re just gonna say, then it doesn’t sound like we need any of this, do we?

35:54 – 35:56

Oui, je suis d’accord.

35:56 – 35:59

It’s not about denying that the bad thing’s gonna arriver.

35:59 – 36:06

It’s about how you talk about something negative in a way that still can take people with you.

36:06 – 36:08

same When I’m raising awareness of threats.

36:08 – 36:10

Vous savez, je vais sur le terrain et je mène des actions de sensibilisation.

36:10 – 36:12

Je crée du matériel de sensibilisation.

36:13 – 36:13

et

36:13 – 36:16

And obviously I’m talking about the bad stuff.

36:16 – 36:20

I can’t raise awareness of cybersecurity et not talk about the threat.

36:20 – 36:27

But it’s doing that in a way that’s proportionate so people don’t think you are exaggerating for your own benefit.

36:27 – 36:37

And then thinking about how you can enable et empower people, even when you’re talking about something negative, so they feel that they can still engage with it.

36:37 – 36:39

And as soon as you…

36:39 – 36:41

well obviously, you’re not going to wait for the incident.

36:41 – 36:43

Mais dès que vous faites quelque chose comme un…

36:43 – 36:55

exercise a virtual incident exercise like we’ve got in recovery range then you’re gonna understet you’re gonna see all these 10 tools 20 to 100 tools et you’re say well we

36:55 – 37:03

haven’t even used any of them in recovering our environment right eeeeuh if you get to that point

37:04 – 37:16

Then you can obviously shed all of those dead skin et eventually get to a point wici you’re a lean, MVC type of guy that can easily recover.

37:16 – 37:21

Well, you know what you want to do et you’ve trained your people well enough.

37:21 – 37:27

you can’t, so you can’t go through those exercises without the communication between those teams.

37:27 – 37:28

Et c’est un terme.

37:28 – 37:28

Bon.

37:29 – 37:33

If you don’t want to send them for beer, then at least get them in the room.

37:33 – 37:42

And start with those exercises wici you go through the process of things failing in your environment.

37:42 – 37:44

Puis demandez-leur : « Que comptez-vous faire ? »

37:44 – 37:45

Que vas-tu faire ?

37:45 – 37:49

And that’s also another finger pointing exercise.

37:49 – 37:51

It’s like we need to tabletop, right?

37:52 – 37:56

You’ve got to get people out of their comfort zone appropriately.

37:56 – 37:59

They’ve to realize what tabletops are in the park.

37:59 – 38:03

Je veux dire, les « tabletops » ne sont qu’un élément parmi d’autres qu’il faut également savoir utiliser.

38:04 – 38:05

Il y a des exercices sur table.

38:05 – 38:07

Il y a les exercices de déplacement.

38:07 – 38:10

Vous avez aussi les exercices « clé rouge » et « clé violette », n’est-ce pas ?

38:10 – 38:12

Et chacun a sa place au sein d’une organisation.

38:12 – 38:20

So let’s say an organization is a majority neeeeuhber, they are established, what their minimal viable company needs to look like, they have all their processes in place, they

38:20 – 38:27

have the shared responsibility fitted up, et they have also understood that, you know, yes, we gotta look beyond the heeeeuhan body.

38:27 – 38:30

Comment s’y prendre ?

38:30 – 38:31

Qu’est-ce qui vous aide à vous y préparer ?

38:31 – 38:37

Les exercices sur table sont donc essentiellement des exercices peu stressants.

38:37 – 38:38

They’re not training modules.

38:38 – 38:48

They’re actual half day full day sessions wici you’re supposed to come together with the shared responsibility to set people to practice one of the most scenarios that your

38:48 – 38:51

entreprise est le plus susceptible de rencontrer.

38:51 – 38:53

Et cela vous aide à y voir plus clair.

38:55 – 38:57

Les équipes rouges sont d’une nature totalement différente.

38:57 – 38:58

They’re life fighters.

38:58 – 39:02

Et les équipes rouges vous aident essentiellement à construire une communauté.

39:02 – 39:07

So tici’s a real distinction between what’s building clarity, what’s building heeeeuhility.

39:07 – 39:08

J’aime bien ça.

39:08 – 39:11

Et puis, les exercices de reconstruction sont essentiellement une source de vérité.

39:11 – 39:16

It’s a reflection wici you think about your cyber resiliency maturity assessments.

39:16 – 39:17

Et on se dit : « Vous savez quoi ? »

39:17 – 39:20

Nous avons tous ces plans que nous avons élaborés sur la base de notre évaluation.

39:20 – 39:23

Dans quelle mesure nos plans tombent-ils à l’eau ?

39:23 – 39:27

That’s the truth that the Weibulls exercise is different at all.

39:28 – 39:34

Tous ces éléments doivent être pris en compte pour vous donner une idée précise de votre niveau de préparation.

39:36 – 39:38

So you’re saying it’s easy.

39:38 – 39:40

Je vais noter ça.

39:40 – 39:42

D’une certaine manière, ça l’est.

39:42 – 39:43

S’il te plaît, s’il te plaît.

39:43 – 39:44

I’m cut you off.

39:44 – 39:45

Non

39:51 – 39:52

Tout d’abord

40:03 – 40:09

The other two times a month that we have a meeting, we’re talking about business.

40:09 – 40:13

What could happen, what does happen, who’s in charge, who to get in touch with.

40:13 – 40:19

And I’ve built up communication between all of them so that each department saw it like the exact same.

40:19 – 40:25

Each person knew, you know, that he’s not such a bad person even though he works over tici or she works over tici.

40:25 – 40:28

Now I know we’re a family, we’re a company.

40:28 – 40:29

Nous y avons tous notre part.

40:29 – 40:31

If something goes wrong…

40:31 – 40:33

Nous savons comment y remédier.

40:33 – 40:34

Nous nous faisons confiance.

40:34 – 40:39

Wicias I have worked at companies wici the person will say, that’s your problem.

40:39 – 40:40

That’s not ours.

40:40 – 40:45

Et puis l’entreprise commence à se heurter à un mur. Tous les bénéfices s’effondrent.

40:45 – 40:46

Les liquidités diminuent.

40:46 – 40:52

then If it’s cyber hack, the insurance company will come et say, you know, you’re not following the procedure.

40:52 – 40:53

We’re going to cut you off.

40:54 – 41:00

The way I built it up is so we don’t go off a beer because I’m not going to promote drinking.

41:03 – 41:04

We’re going to lunch.

41:04 – 41:05

Don’t talk business.

41:05 – 41:07

Apprenons simplement à nous connaître.

41:07 – 41:09

Keep it at the heeeeuhan level, right?

41:09 – 41:09

C’est vrai.

41:09 – 41:10

Keep it at the heeeeuhan level.

41:10 – 41:13

et when you sit down, I tell them…

41:15 – 41:15

service.

41:21 – 41:23

Donc, chacun est quelqu’un de différent.

41:23 – 41:25

Now you’re Tout le monde parle.

41:25 – 41:26

Tout le monde parle.

41:26 – 41:27

Et vous apprenez à vous connaître.

41:27 – 41:31

The following week when we have the meeting, okay, now let’s, we’re going to sit down.

41:31 – 41:32

We’re going to talk.

41:36 – 41:40

Je lui ai dit : « C’était ça ? »

41:40 – 41:42

And, eeeeuh, Lennox Hill Hospital.

41:42 – 41:43

Qu’en pensez-vous ?

41:43 – 41:48

Quelles sont les erreurs qu’ils ont commises et qui peuvent nous permettre de nous améliorer, qui nous ont aidés à nous améliorer ?

41:48 – 41:55

Because now we’re using an outside attack to develop a procedure that we can use to make us stronger.

41:56 – 41:58

In the eight months since that’s happened…

42:04 – 42:06

ils se sentent bien dans leur peau.

42:06 – 42:12

I said, it’s all, I wish I would have read Jessica’s book at that time.

42:12 – 42:14

And I tell them it’s all about heeeeuhan communication.

42:14 – 42:18

Because they’re all communicating with each other now.

42:18 – 42:22

Est-ce que tout le monde a entendu ? Est-ce que tout le monde a entendu ça ?

42:22 – 42:24

Je veux dire, c’est simple.

42:24 – 42:26

enforced et repeatable, right?

42:26 – 42:29

Parce que vous l’avez fait mois après mois après mois, n’est-ce pas ?

42:29 – 42:30

Oui, c’est vrai.

42:31 – 42:32

Fantastique.

42:32 – 42:34

I had a couple of really key things tici.

42:34 – 42:42

Premièrement, vous utilisez le mot « confiance » : il s’agit d’instaurer la confiance dans ces relations, pas seulement la confiance entre professionnels, mais aussi la confiance entre les personnes.

42:42 – 42:43

Et puis ça…

42:43 – 42:52

learning culture of once we’ve kind of built up some of that trust et we’ve got to know each other et feel comfortable with each other, then we’re going to sit down et we’re

42:52 – 42:53

allons discuter d’un incident.

42:53 – 42:59

We’re going to talk about what maybe went right, what went wrong, et we’re going to reflect on ourselves et what we can do differently.

42:59 – 43:05

Comme vous avez établi ces relations de confiance, les gens se sentiront alors plus à l’aise pour le faire.

43:05 – 43:12

So trust, learning, culture, et really building that wider culture of communication.

43:12 – 43:13

think that’s so important.

43:13 – 43:23

Then as well, if something goes wrong et you don’t know as an individual who to turn to, but you know a few people ici et tici, you can go et say, hey, this has happened.

43:23 – 43:24

I’m worried about this.

43:24 – 43:25

Que pouvons-nous faire ?

43:25 – 43:27

And put your heads ensemble.

43:27 – 43:30

But so much of that comes down to culture et people feeling safe.

43:30 – 43:34

eeeeuh

43:34 – 43:40

I have to give some credit ici, because what I’m about to say was from a podcast I filmed a little earlier this morning.

43:40 – 43:49

And the gentleman was the data protection et resilience engineer for Blue Cross Blue Shield South Carolina Hillman.

43:49 – 43:49

He’s ici.

43:49 – 43:51

He’s great guy.

43:51 – 43:58

And when we were finishing, I said, hey, is tici one thing you’d like to leave everybody with in the podcast?

43:58 – 44:02

Because he’s 25 years in data protection.

44:02 – 44:04

eeeeuh

44:04 – 44:05

Il adore ce qu’il fait.

44:06 – 44:14

Et il a dit : « Tu sais, depuis mes débuts au service d’assistance, quand j’étais jeune diplômé, jusqu’à aujourd’hui. »

44:14 – 44:19

Force yourself et put yourself in the middle of a situation.

44:20 – 44:24

Don’t be afraid because you’d be amazed who follows you.

44:24 – 44:35

And I thought that, you know, it’s not earth shattering, but the passion, not afraid to get in the firefight, et then it’s amazing who you bring along with you when that

44:35 – 44:36

se produit.

44:36 – 44:45

And if you have that in addition to what you’ve done, wici they’re meeting et get to know each other, the whole thing dovetails on itself

44:45 – 44:47

et good things happen, right?

44:47 – 44:58

I think my only challenge to that, et it comes probably partly back to culture, is it depends on the environment you’re doing that within, whether people will follow or

44:58 – 45:09

whether, et whether people will feel comfortable putting themselves within the middle of that environment or feeling like, as Zak said earlier, are people gonna point the finger?

45:09 – 45:13

Am I gonna put my head above the parapet et I am gonna become the one who’s gonna be blamed?

45:13 – 45:14

oh

45:14 – 45:19

Et cela soulève aussi potentiellement des problèmes d’épuisement professionnel.

45:19 – 45:24

If I’m always the one running to fix things, when is that going to start to take its toll?

45:24 – 45:27

You need some camaraderie tici in the fire.

45:28 – 45:32

And if you’ve got the right culture that’s going to support you, then I completely agree.

45:32 – 45:43

But in organizations wici tici isn’t that relationship building, wici tici isn’t that empathy et trust, et wici tici isn’t that psychological safety of not worrying about

45:43 – 45:44

se faire blâmer,

45:44 – 45:47

I think that’s a very different scenario.

45:47 – 45:49

It’s a great point.

45:49 – 45:52

Cela nécessite plusieurs niveaux dans la pyramide.

45:52 – 45:55

Not to be negative, I’m just talking about the biais d’optimisme.

45:55 – 45:58

Mon Dieu, qu’est-il arrivé aux 80 % ?

45:58 – 45:59

Vous vous en souvenez ?

46:07 – 46:08

un environnement stabilisé.

46:10 – 46:15

of IT which are held by the corporate team et individuals business unit management.

46:17 – 46:21

services or things wici things overlap.

46:21 – 46:25

Il s’agit donc simplement d’une ligne de démarcation très, très fine pour déterminer jusqu’où on souhaite regrouper ces éléments.

46:28 – 46:31

separate things out because it’s a very tricky thing.

46:31 – 46:36

On est presque comme huit divisions distinctes, chacune avec ses propres objectifs et ses propres priorités.

46:36 – 46:39

Votre marché centralisé, vous savez, le marché des entreprises, est un tout.

46:43 – 46:50

together before you even make one change et things go down south, everybody’s just all in groups are ready to attack you right tici.

46:50 – 46:54

It’s a very thin line tici, when it comes to shared responses, especially cloud et everything else.

46:54 – 46:58

Par exemple, si vous avez un locataire avec plusieurs abonnements sur Azure.

47:01 – 47:03

et have you separate those things out, right?

47:08 – 47:18

This is why I mentioned the whole share responsibility because that’s the crux of wici we are faltering as an industry, And I think this is why we have so much headwinds of

47:18 – 47:23

regulations now talking about from DORA in Europe et all the other things.

47:25 – 47:38

Are forcing the boards to essentially get serious about resiliency et have provable metrics in place to demonstrate that yes, as an organization, we’re doing the right things

47:38 – 47:45

around keeping data secure et being able to show resiliency when compromises arriver.

47:45 – 47:58

And I think as more more regulations become more stringent et the penalties become more severe, some of that unwanted but much needed cross-organization population et

48:03 – 48:16

Et peut-être pas pour forcer les choses, vous voyez, sans essayer d’imposer le terme « IA » à tout prix, mais si l’on se concentre sur les aspects positifs, nous devons libérer du temps pour que les gens puissent s’en occuper.

48:16 – 48:17

C’est là le véritable problème.

48:17 – 48:24

Je veux dire, je pense, en lisant entre les lignes, que non seulement ça pourrait dégénérer, mais qu’il faut simplement répartir le temps entre ces équipes.

48:41 – 48:41

Autre chose ?

48:41 – 48:43

Merci à vous deux d’avoir lancé le débat.

48:43 – 48:45

We were going right tici, so this is great.

48:45 – 48:47

D’autres questions ?

48:47 – 48:48

Oui ?

49:14 – 49:15

sujet.

49:18 – 49:18

Bon.

49:31 – 49:32

Je peux le voir ?

49:32 – 49:41

Bon, alors, qu’est-ce qui se passe quand on fait ces exercices avec toute l’équipe, c’est ça ?

49:41 – 49:50

The trust you’re building tici isn’t a trust that can be broken from an incident because that’s what you’re actually testing.

49:50 – 49:54

You’re testing for an incident that’s going to happen in the future.

49:54 – 49:58

Donc, partant de ce principe, alors…

49:58 – 50:15

why would, okay, this is just me asking, why would any of the team members suspect someone else in the team if you do two of these exercises a year et they get told no more than

50:15 – 50:16

sur ce sujet.

50:16 – 50:21

They all get together et they see the incident arriver.

50:22 – 50:33

You have a virtual thing that you talk about et what has happened et how it’s unfolded et what was breached, how it was done.

50:33 – 50:35

Et vous passez tout cela en revue avec l’ensemble de l’équipe.

50:35 – 50:40

Then every one of them actually see the attack from wiciver it comes.

50:40 – 50:52

Donc, quand cela se produit, quand cela se produit réellement, je doute fort que cette confiance soit brisée à cause de cet incident.

50:55 – 50:56

Oui, c’est vrai.

50:56 – 51:01

Oh, after if you if you haven’t built the trust.

51:01 – 51:02

Tout à fait.

51:02 – 51:05

Then it’s that’s actually a very good point.

51:05 – 51:13

That’s a very good point that if you haven’t prior to that, built the trust, then it’s actually going to be much worse.

51:13 – 51:14

Un problème qui prendra des proportions exponentielles.

51:14 – 51:21

Because when we were talking about this, I know from one of the companies that I’ve been

51:21 – 51:30

In South Africa, tici was a whole wing of the company was, we’re talking about four et a half thouset employees on a site.

51:30 – 51:44

The whole wing was cut off from any network et the security guy, I wasn’t the security guy then, but he was pointing to the network’s guy et the guy, the network guy was just

51:44 – 51:45

me montrait à son tour.

51:45 – 51:49

For a few days, that whole wing was off because they couldn’t.

51:50 – 51:53

Ils n’arrêtent pas de se disputer pour savoir à qui incombe la responsabilité.

51:53 – 52:00

And that’s network et security, which you would actually think it’s quite close-knit.

52:00 – 52:01

Oui.

52:10 – 52:15

It’s probably good to think about trying to a solution et I think it comes top down.

52:15 – 52:21

Donc, quand les plus hauts échelons de la direction vous soutiennent en quelque sorte pour vous sortir de cette situation.

52:30 – 52:34

La haute direction nous soutient et nous accompagne dans cette démarche.

52:34 – 52:37

Je veux dire, c’était clairement un problème de sécurité du réseau.

52:37 – 52:42

Il s’agissait de deux entreprises distinctes, mais qui étaient en quelque sorte des filiales au sein du groupe mère.

52:43 – 52:44

Elles disposaient d’un tunnel de communication direct entre elles.

52:45 – 52:49

Toute connexion entre les réseaux des deux entreprises passait par le VPN.

52:49 – 52:53

La société sœur n’avait besoin d’un accès que pour quelques applications.

53:00 – 53:04

Les membres de l’équipe réseau font partie de l’équipe de sécurité.

53:04 – 53:06

Exactement la même situation.

53:10 – 53:21

oh And this is the idea of a just culture et either being restorative or retributive.

53:21 – 53:26

Donc, quand quelque chose tourne mal, est-ce qu’on examine ce qui s’est passé ou est-ce qu’on cherche à savoir qui est responsable ?

53:30 – 53:34

Euh… bonne, bonne question.

53:34 – 53:36

Je trouve que c’est une bonne question.

53:36 – 53:37

Je pense que c’est une bonne question.

53:37 – 53:53

I good I I good I good I I think think good I good think it’s a good good it’s good think

53:57 – 54:00

Est-ce que tu montres du doigt ou est-ce que tu essaies d’aller au fond du problème ?

54:00 – 54:05

I think all of us have been talking about defense et depth.

54:05 – 54:15

I think now is the time to shift our, since we are in SHIFT to shift our mindset from defense et depth to trust et depth.

54:15 – 54:24

What I mean by that is so you’re trusting your people to do the right thing, you’re trusting your processes to build up, you’re also trusting the tools of technology at your

54:24 – 54:25

disposition.

54:25 – 54:28

Pour agir conformément à ce que vous avez prévu.

54:28 – 54:35

For example, so you’re recovering something, but what if the ransomware attack or the malware attack has actually taken down or compromised your recovery plan

54:37 – 54:42

So let’s say you do not have an air gap solution et now your recovery environment is compromised.

54:42 – 54:45

So you’re recovering from an infected environment into fraud.

54:45 – 54:48

So you can’t really trust that data, right?

54:48 – 54:54

And I think this is why we’re going to look at, great, we have all these defenses, reseeeeuhe breach.

54:54 – 55:00

And if you’re reseeeeuhing breach, then you’re saying, I’m going to trust everything implicitly or explicitly.

55:00 – 55:06

And then I’ve got to build this notion in my head that I want to trust it in depth, which means all of my

55:06 – 55:11

processus sous-jacents doivent être fiables pour me permettre d’atteindre un état de confiance.

55:12 – 55:16

And then I think that pre-appointed et excuse not me, all of that should go away.

55:16 – 55:18

It should go away, Exactement.

55:18 – 55:20

Eh bien, je,

55:21 – 55:23

we’ve only got a couple of minutes.

55:23 – 55:24

Je vous remercie tous du fond du cœur.

55:24 – 55:25

chantez.

55:25 – 55:26

J’apprécie vraiment vos questions.

55:26 – 55:32

On se disait : « Mon Dieu, après tous ces rouleaux de poulet, est-ce que les gens vont encore avoir des questions ? »

55:32 – 55:33

And tici it was.

55:33 – 55:36

So we couldn’t have asked for a better ending.

55:36 – 55:40

Mais je tiens à adresser un immense merci à deux groupes.

55:40 – 55:41

Tout d’abord, à Jessica.

55:41 – 55:43

Merci, Ricky, Zak.

55:43 – 55:45

I mean, the miles traveled ici.

55:45 – 55:47

Incroyable, n’est-ce pas ?

55:48 – 55:53

I hope you were able to appropriately understet Ricky et I with our accents.

55:53 – 55:55

Je veux dire, ils ont les meilleurs.

55:55 – 56:00

We just, you know, Dallas et Phoenix, I mean come on.

56:00 – 56:02

Mais surtout, je tiens à te remercier.

56:02 – 56:03

Merci d’avoir pris le temps.

56:03 – 56:07

Je sais que cette séance a été longue, surtout juste après le déjeuner.

56:07 – 56:12

And even more importantly, thank you for coming to SHIFT, being clients at Commvault, et putting your trust in us.

56:12 – 56:14

Nous l’apprécions énormément.

56:14 – 56:15

Bon.

56:15 – 56:19

Have a great rest of your breakouts et we’ll see you out tici.