Our Speakers
An Uncompromising Roster of Experts.
Our speakers bring unfiltered, tactical insights forged in the crucible of real-world incident response.

Andrew Scott
FIeld CISO
Todyl
Sessions
Thu Feb 04, 4:45 PM - 5:30 PM
Designing a user/tenant-aware security strategy for increasingly autonomous and AI-accelerated attacksWhy attack surface reduction still comes first, how UEBA is returning to prominence as a critical context layer, and how speed from signal to containment changes the outcome.
AI has collapsed the cost of a sophisticated attack. Reconnaissance, phishing, exploit development, and extortion now run in parallel instead of in sequence, letting one attacker probe network, endpoint, identity, and cloud simultaneously and pivot the instant a path closes. Small and mid-market organizations are now targeted with the same sophistication once reserved for the enterprise.
No single control survives that pace, but security layers do. Zero-trust network access and modern endpoint controls shrink the attack surface, unified telemetry across endpoint, network, identity, and cloud closes the visibility gaps between them, and AI-assisted detection compresses time to contain. Identity is the layer under the most pressure: when a stolen session token satisfies MFA, there is no malware to find and no failed login to alert on.
UEBA needs to be built for the multi-tenant reality MSPs actually operate in. Scoring normalized deviation, each user against their own baseline and then against a peer cohort of comparable roles and org sizes, means detection sharpened in one client environment strengthens every other, without commingling tenant data. Weighting signals by attack-stage coverage and mutual agreement surfaces the intrusion hiding in moderate anomalies and suppresses the loud outlier that isn't one: faster triage, fewer false positives, one SOC covering dozens of heterogeneous environments.
What you’ll walk away with:
A clear read on why AI-powered attacks hit SMBs like enterprises, and why speed, not sophistication, is now the gap.
A layered security model you can defend to a board, an underwriter, or an auditor, with identity as the layer that decides whether the rest holds.
A practical standard for evaluating UEBA as an MSP: knowing what “faster and more accurate” actually require across dozens of heterogeneous tenants.



