Now that attackers are leveraging AI, automation is essential for defenders. How will the use of AI change security operations, such as anomaly detection, alert prioritization, and automatic response through SOAR? We will explain realistic defense strategies in which humans and AI work together. |Colorkrew Security
Cyber risk is not an IT problem, but a management risk. Against the backdrop of increasing damage, the spread of RaaS, and tightening regulations, why is security an "investment" now? We will explain the concept of risk and step-by-step investment design that management should understand. |Colorkrew Security
To prevent lateral movement after intrusion, it is essential to have a multi-layered defense of privilege management, network isolation, and behavior detection. Based on the concept of Assume Breach, we will explain practical measures that can be used in common with Azure, AWS, and GCP. |Colorkrew Security
Explain the causes of SOC fatigue due to too many alerts and five practical points for operational design to prevent the risk of missing incidents and personalization. Learn how to build a sustainable SOC with automation, prioritization design, and knowledge standardization. |Colorkrew Security
Explains the pitfall of security operation, "I take logs but don't notice the attack". From the perspective of an infrastructure engineer, we will introduce five steps to transform logs from mere storage objects into "defensive weapons" using correlation analysis and automatic detection. |Colorkrew Security
"Misconfiguration" is the most common cause of compromise in cloud environments. Learn about common pitfalls and risks, such as storage exposure settings and excessive permissions. From understanding the shared responsibility model to implementing defense-in-depth practices with CSPM and IaC, infrastructure engineers have summarized the essentials of secure cloud operations. |Colorkrew Security
Explains from the basics of EASM (External Attack Surface Management) to practical points for introduction and operation. Visibility into Public Assets and Continuous Risk Management for Pre-Intrusion Measures|Colorkrew Security
We will explain the basics of cyber threat intelligence (CTI), implementation procedures, and how to use it in SOC and SIEM. A practical guide to anticipating attacks and reducing risk for your organization. |Colorkrew Security
Based on the vulnerabilities and botnet risks hidden in IoT devices, we will explain the IoT security measures that organizations should implement. Easy-to-understand practical steps such as network isolation, access control, vulnerability management, and monitoring system|Colorkrew Security
Explaining identity management that is essential in the era of Zero Trust. Introducing practical procedures and operational points for SSO, MFA, terminal management, and dynamic access control|Colorkrew Security
Explains the types and risks of supply chain attacks and the defense measures that should be implemented throughout the organization from an expert's perspective. From Account Evaluation to Monitoring|Colorkrew Security
Systematically explains ransomware attack methods, damage risks, and multi-layered defense practices. Introducing a realistic defense model that includes EDR, SIEM, and backup strategies|Colorkrew Security