
Now that attackers are leveraging AI, automation is essential for defenders. How will the use of AI change security operations, such as anomaly detection, alert prioritization, and automatic response through SOAR? We will explain realistic defense strategies in which humans and AI work together. |Colorkrew Security

Cyber risk is not an IT problem, but a management risk. Against the backdrop of increasing damage, the spread of RaaS, and tightening regulations, why is security an "investment" now? We will explain the concept of risk and step-by-step investment design that management should understand. |Colorkrew Security

To prevent lateral movement after intrusion, it is essential to have a multi-layered defense of privilege management, network isolation, and behavior detection. Based on the concept of Assume Breach, we will explain practical measures that can be used in common with Azure, AWS, and GCP. |Colorkrew Security

Explains the design of using Azure's Entra PIM, AWS's IAM Identity Center, and GCP's conditional IAM to make cloud permissions "limited". This is a practical guide to how to prevent privilege bloat and attack surface expansion. |Colorkrew Security

Almost all breaches of AWS are access key leakage, excessive authority, IAM, and S3 misdisclosure. Continuous monitoring combined with CloudTrail and GuardDuty provides a checklist of practices to efficiently close common entry points. |Colorkrew Security

GCP security incidents are mainly caused by service account key leakage, IAM overprivileges, and lack of audit logs. Learn IAM design best practices and practical steps to enable Cloud Audit Logs in a checklist format. |Colorkrew Security

We will explain the four paths of Secrets leakage, such as API key miscommit to Git repositories and CI/CD log leaks, and the creation of a practical mechanism to protect them through three layers: prevention, detection, and rotation. |Colorkrew Security

Explain the causes of SOC fatigue due to too many alerts and five practical points for operational design to prevent the risk of missing incidents and personalization. Learn how to build a sustainable SOC with automation, prioritization design, and knowledge standardization. |Colorkrew Security

"Safe because I authenticated with an API key" is a misconception. We will explain five threats that lurk after authentication, such as BOLA, insufficient rate limiting, input verification omissions, excessive information responses, and lack of audit logs, as well as implementation points for an unbreakable design. |Colorkrew Security

Explains the pitfall of security operation, "I take logs but don't notice the attack". From the perspective of an infrastructure engineer, we will introduce five steps to transform logs from mere storage objects into "defensive weapons" using correlation analysis and automatic detection. |Colorkrew Security
![[Latest in 2026] EU AI Act and Japan's Regulatory Response|5 Measures Security Personnel Should Take](https://ckmediastgstr.blob.core.windows.net/uploads/post_105_00_c8fd936043.jpg)
A thorough explanation of the risks unique to AI and measures against the Japanese AI Act, which will come into effect in 2025, and the EU AI Act, which will take effect in 2026. From building governance using Microsoft Purview and Defender to monitoring operations by SOC, we have summarized the practical points that security personnel should work on now. |Colorkrew Security

Experts will explain the setting conditions and "three principles" to ensure that serious incidents are not overlooked regarding automatic closing of alerts, which is an issue in SOC operations. The secrets of safe automation design, such as the importance of Severity limited and logging and weekly reviews to prevent accidents, are now available. Dramatically improve your own operations. |Colorkrew Security