If attackers think in graphs, why can't we? presented at t2 2015

by Olleb ,

Summary : Microsofts John Lambert said "Defenders think in lists. Attackers think in graphs". If attackers can reason about a system using graphs, why can't we as defenders use the same methods to better protect ourselves?
This talk will present an alternative to checklist-based security by using a methodical approach to reasoning about the security of a system.
Instead of just telling you what you should be doing to defend yourselves, checklist style, this talk will give you the tools you need to actually figure out what controls are most relevant for your specific environment.
Practical information assurance advice such as "what to ask for in a security assessment report" will also be offered, which should be applicable even for those not yet willing to change their information security processes.
Along the way, we might have a few laughs at the expense of some "security experts". Because why not.
