Skip to main content
Right of Boom

Our Speakers

An Uncompromising Roster of Experts.
Our speakers bring unfiltered, tactical insights forged in the crucible of real-world incident response.

Back to all speakers
Andrew Scott

Andrew Scott

FIeld CISO

Todyl

Sessions

Why attack surface reduction still comes first, how UEBA is returning to prominence as a critical context layer, and how speed from signal to containment changes the outcome.

  • AI has collapsed the cost of a sophisticated attack. Reconnaissance, phishing, exploit development, and extortion now run in parallel instead of in sequence, letting one attacker probe network, endpoint, identity, and cloud simultaneously and pivot the instant a path closes. Small and mid-market organizations are now targeted with the same sophistication once reserved for the enterprise.

  • No single control survives that pace, but security layers do. Zero-trust network access and modern endpoint controls shrink the attack surface, unified telemetry across endpoint, network, identity, and cloud closes the visibility gaps between them, and AI-assisted detection compresses time to contain. Identity is the layer under the most pressure: when a stolen session token satisfies MFA, there is no malware to find and no failed login to alert on.

  • UEBA needs to be built for the multi-tenant reality MSPs actually operate in. Scoring normalized deviation, each user against their own baseline and then against a peer cohort of comparable roles and org sizes, means detection sharpened in one client environment strengthens every other, without commingling tenant data. Weighting signals by attack-stage coverage and mutual agreement surfaces the intrusion hiding in moderate anomalies and suppresses the loud outlier that isn't one: faster triage, fewer false positives, one SOC covering dozens of heterogeneous environments.

What you’ll walk away with:

  • A clear read on why AI-powered attacks hit SMBs like enterprises, and why speed, not sophistication, is now the gap.

  • A layered security model you can defend to a board, an underwriter, or an auditor, with identity as the layer that decides whether the rest holds.

  • A practical standard for evaluating UEBA as an MSP: knowing what “faster and more accurate” actually require across dozens of heterogeneous tenants.