Video: Operationalizing Incident Response: Compliance-Ready Tabletop Exercises with an AEV Platform | Duration: 2851s | Summary: Operationalizing Incident Response: Compliance-Ready Tabletop Exercises with an AEV Platform | Chapters: Welcome and Introduction (0s), Welcome and Introductions (17.012s), Integrating Cybersecurity Exercises (297.112s), Integrating Security Exercises (396.55699999999996s), Assessing Regulatory Compliance (1016.377s), Standardizing Crisis Simulations (1111.257s), Board-Level Resilience Reporting (1422.0220000000002s), Organizational Cyber Resilience (1535.2620000000002s), Operationalizing Threat Intelligence (1656.342s), Automated Threat Simulation (1798.672s), Third-Party Resilience Testing (2000.217s), Supply Chain Intelligence (2119.342s), Testing Legacy Systems (2261.332s), Concluding Thoughts and Recap (2512.9320000000002s)
Transcript for "Operationalizing Incident Response: Compliance-Ready Tabletop Exercises with an AEV Platform": So alright. Enough of that. Let's get into the fun stuff. Let's get into our session. So here, I am joined by my teammates Nina Sharma from product marketing and Steven Barr, solutions engineering. So I'll pass it over to you guys to, introduce yourselves. Thank you, Adam, and a very warm welcome to everyone. My name is Nina Sharma, and I'm the head of product and customer marketing team here at Filigran. I've been a strategic marketer, all my professional life, and I've been in cybersecurity for about twelve, thirteen years now, which means that I have learned a lot of buzzwords and acronyms. I've been using those two and just adding AI power to it these days. Jokes apart, a big big part of my job and something which I immensely enjoy doing is, tracking market trends and customer insights and how it shapes or rather how should it shape security solution space. I've had a front row seat to a lot of change. It's actually very interesting how everything seems to be related to AI today, but, you would know that it's actually not new. When I started my cybersecurity journey, AI was everywhere even at that time. Not Gen AI or LLM, but machine learning, behavioral analytics. Right? So this is what gave rise to newer categories like EDR, MDR, this next generation SIEM systems, or so. And now we are seeing another shift with the AI driven automation, talk about autonomous security, you know, AI driven SOC or SecOps. But, we we never had, I would say, an issue with technology in cybersecurity. It has been one of the heaviest invested solution spaces. Right? But I think the big question is, whether we are able to connect the dots properly or not, whether we have access to right data. We have loads of data again, but whether we are able to extract the relevant high priority intel that's specific to our business, business and risk landscape. So lot of cybersecurity, has been driven by regulation and compliance. Take example of incident response. Like, incident response plans have been, treated, as a compliance checkbox exercise, something you write, file away, and hope you never need. But, should that really be the primary purpose, or can we turn them into a real advantage in a lever to actually improve our security posture? Because that's kind of the ultimate goal and objective. Right? What what what are the vendor tools available, that, you know, today that you could experiment with? What are the shifts that we are seeing around tabletop exercises, crisis management exercises? That that's really what I'm looking to explore today with my colleagues, Steven and Adam here. We've decided to keep it, very light on slides, but focus more on conversation and discussion, sharing market and customer insights from what we are seeing, from the field today. So please keep your questions coming. You know, chat with us, challenge us, disagree with us if you like, and together, hopefully, we'll make it a worthwhile session an hour for you. Awesome. Over to you, Steven Bar. Yeah. I mean, Neena has a brilliant background. So, yeah, I'll keep mine short and sweet. But, again, Steven Bar Barr. I'm with, Filigran, and I'm the senior solutions engineer here. And, I have a unique perspective on the technical side with working with different clients and, you know, helping support and helping them understand, a lot of the value when it comes to cyber threat intelligence, even specifically with tips, source, and deep and dark web threat intelligence, but also on the, adversarial side. Right? How we can start to understand the the, tracking and monitoring of different threats and understanding what that looks like in a more realistic way, and not in in an imaginative way. So, with that being said, you know, I am so happy to be here, to meet everyone. And, again, yes, please do ask questions if you do have any questions. And to be transparent, today is more of discussion. If there are anything you'd like to see when it comes to the actual platform, we would love to show you. So if you would like to schedule a demo, we'd be happy to do that and do an actual demonstration and try to make it more along the lines of what your, institution looks like. So, thank you. Thank you again. I'll pass it back to you, Adam. Awesome. Thank you, guys. Again, super excited about this session. Let's start off with the reality that we're all facing. Cyber threats are not slowing down. They're faster, they're more disruptive, and they hit you where it hurts organizations the most, which is the ability to keep the business running effectively. Obviously, the question is no longer can we stop every single attack anymore. It's more of like how do we respond, when the inevitable happens and how quickly can we recover. Tabletop exercises have, been a cornerstone of incident response planning, but the problem is historically been scaling them across teams and geographies is usually a challenge. You know, they're manual, they're inconsistent, and they're hard to measure. But it doesn't have to be that way. So today, we're gonna explore how adversarial exposure validation platforms like OpenAEV, enable teams to combine technical breach and attack simulation, with realistic tabletop exercises to validate both defenses and decision making. And, also how this integrated approach transforms compliance from, you know, merely being a checkbox, into a real capability and makes resilience a measurable continuous practice. So with that being said, let's dive into some questions that we got for, Neena and Steven. So first off, you know, we've seen some framework frameworks like FFIEC, and FYDFS in the financial sector, for example, push for both technical testing and government, level exercises. Neena, question for you. In practice, how can organizations bring red team simulations and tabletop drills together so that they're not two completely separate worlds? Sure. So, you know, with my, product map marketing hat on, I would say that red team simulations and tabletop grills were never meant to be two separate worlds. Both are fundamentally about the same thing, understanding risk. So Red Team's, exercises focus on what can go wrong by simulating real world attacks to expose weaknesses and controls, configurations, and workflows. Tabletop exercises, on the other hand side, focus on what happens when something does get wrong, how teams respond, how executives make decisions, how do we communicate that with the customers. Right, so, not only with the external world, with your internal employee base, also, and bring bring all of that together. So, yeah, because of how most cybersecurity tools and processes have evolved, what has happened is that breach and attack simulations, typically are owned by highly technical security teams, while crisis management and tabletop exercises are run by risk, compliance, or business continuity functions. But this split creates operational silos, inconsistent view of risk, and lost opportunities for learning. And and this is where this whole evolution of, breach and attack simulation, BAS tools to, adversary, adversarial exposure validation tools, AAV tool, this is what it's allowing, to do to bridge, some of this gap to provide our customers the ability to conduct both of these with one single platform and reduce the friction between teams. Of course, it means less friction between security risk, executive stakeholders. You can bring all that insight together and, you know, develop a holistic understanding of what your true exposure looks like and a repeatable way to move from, you know, can we be breached to are we ready when we are. As a result, security then becomes more measurable, responses become more coordinated, and investments decision become easier. So that that's that's what we we are bringing to the table here, and I would let, you know, now ask Steven to provide bit more color around that. Yeah. I mean, absolutely, to echo that. Right? The practical way to meet whether it's the regulations or even just your internal standards. Right? Because in The US, we don't really have that, the regulations like you might see in The UK or even Australia. But internal standards, we we need to stop treating the the red team and your tabletop really as two separate compliance check boxes. And, really, instead, use a platform whether it's OpenAV or something like that as a common backbone, for, you know, your single threat led, single threat led, exercises that are gonna produce both your your technical and your governance evidence. So in practice, what that looks like is you're gonna start with, let's say, OpenAV. You're gonna design a, realistic scenario mapped to, let's say, minor attack and your actual business services. An example we can use is like, an attacker targeting your wiring platform or even online banking. And I know I'm using finance as, as an example today, but it it then orchestrates really the technical side. It's gonna drive the red team style simulations. It's gonna, look at some of the breach and attack steps. It's gonna collect hard data on what your SOC and your controls are actually detecting, and it's gonna look at how long it took and what potential business impact there was. And this is giving you that factual attack timeline rather than a a hypothetical story. Right? You can then use that same scenario as a script for your governance level tabletop. Instead of saying, okay. Let's imagine an attacker is in our payment environment. You can say, well, our AAV exercise last week showed, an attacker obtained these privileges at 09:00. We detected them at, let's say, 10:45, and and they had these paths to these systems. And around that real time line, you walk executives, maybe your risk, your compliance, legal communication. You walk them through those decisions that they really care about. Right? They care about, like, the service shutdowns, what is the customer market communications, what's happening in the back end. And those results, into what we call, like, a AAV AAV driven scenario that's gonna generate really two kinds of artifacts that regulators or even your teams wanna see. That's gonna be the measurable controlled effectiveness, the the response, of those metrics from maybe a technical simulation, and then the documented governance side. Right? The necessary escalations, the the decision making from the tabletop. And I think, personally, I think that's how institutions can really blend the red team and tabletop into a a single threat led program that's gonna really satisfy both the technical and the procedural testings in a way that's really, of course, defensible but repeatable. And that's that's what we wanna hone in on repeatability. Awesome. No. Thank you both. You know, regulators want proof. Right? Clear evidence of testing, measurable outcomes, and remediation that actually closes gaps. Neena, in your opinion, what does audit ready resilience testing look like on a day to day basis? And then how do you make sure that your improvements actually stick? You're on mute, Neena. Yeah. Sorry about that. I would like to, flip this question. So why are we actually discussing it today? Why do we think regulators want proof of testing and measurable outcomes? Let's just try to understand this premise. Ultimate goal here is resilience. Right? Cyber resilience resiliency of a business or organization. I I tend to use an analogy. So here in The UK, we almost always have a signposting of speed cameras on the road. And why is that? Because the goal is not to catch people speeding and give them tickets. Right? I mean, of course, some some some local councils do do that because of funding challenges, but it is really to enforce people to slow down. Right? So so that something bad doesn't happen. Similarly, if you're able to continuously assess and validate your security controls, remediate the gaps, you're essentially improving the security posture over time. Right? So it it it in its simplicity, that's what it really is. And in OpenAED, which is our AED platform, you have time based reporting and ability to customize reporting dashboards to not only comply with the regulations, but also monitor and measure trends. You can schedule recurring simulations, see how a particular tool like your EDRs detect incoming attacks more efficiently over time. I would say it's kind of a win win situation, from both sides for the customers. Yeah. I that that I mean, the analogy in and of itself, it makes a lot of sense. Right? And I think audit ready resilience testing looks a lot less like a an annual fire drill, let's say. Right? It's a lot more like a continuous instrumental process. Right? So you're not just running pen tests. You're you're designing those repeatable scenarios in AAV, and then they're they're mapped to those critical businesses that we've talked about. Right? It could be your MITRE attack techniques, the the specific expectation and frameworks that are out there. And each exercise, whether it's going to be that technical simulation or or your governance level tabletops, it's going to be, defined upfront. Right? You have your clear objectives, what you can control, what you can process or or the decisions that we're testing for. You have your, measurable success criteria. Right? Maybe detection time, escalation time, decision points, data at risk, and, of course, the explicit owners on the business and technology side. Right? It's important because during any of those exercise, the platform is gonna give you that structured evidence. It's going to, have the time stamps for every inject. It's gonna record who did what and when. We're capturing the the SOC control responses, the the logs that, executive decisions and communications in that tabletop stream. So, really, from that, you you produce those artifacts auditors and regulators care about. Right? The attack timeline, the detection response metrics we've been talking about. And the second half of that really of being audit ready, to me is making sure the improvements are actually sticking. Right? And, again, AAV or a platform that's leveraging this is going to be having that repeatability that matters. Right? Every finding is logged as an action with a specific owner. It's gonna have those those specific due dates, and all those actions are gonna be tied back to that original scenario. So when you're finishing or or when remediation is done, you don't just, like, close a ticket. You rerun that same scenario. You're you're comparing those metrics over time as you build a library of different scenarios with a before and after. And I think that evidence really shows a a sort of closed loop. Right? It's your testings, then to your findings, your remediation, and then retest so we have an improved outcome. And for a regulator, I believe that's what good looks like. Now it's not just that we ran a a red team or tabletop last year. It's more that, hey. We can open a platform and show a living, breathing catalog of threat led exercises that have quantified results. They have the remediation items, and you can subsequently have more reruns to prove that those gaps are genuinely closed and they stay closed. Awesome. No. That's, that's amazing. Before we before we keep on going, I do wanna open up a poll. Actually, pardon me as I pull this up. It's gonna be here on the right hand side of your screen. But one thing that we would love to know from the audience is how would you rate your organization's current understanding and mapping of tabletop exercises with regulatory, requirements? You know, we'd love to see what you guys have to say. This is obviously gonna pop up, on the screen as you answer. Right now I'm seeing, we have a couple of answers that are we don't really map tabletop exercises to regulatory requirements yet. Hopefully, you know, you find this session helpful, and there's a lot of, you know, actions and steps to take afterwards. But yes. And we have defined mapping but it's not fully up to date. We're getting a little bit across the board, but pretty much for every answer on here, we would love if everything was extremely well documented, regularly updated mapping and everything. But hopefully, what we talk about as we progress through this session will be helpful. So thank you everyone for answering. I'm gonna close that. Another question, for Neena again. Cyber resilience is mission critical, obviously. How do you realistically test the readiness of, you know, the legal, communications, and leadership teams alongside SOC analysts and make sure that those results are meaningful? Sure. So I think we've been kind of, touching on it already in our previous questions, and establishing that just testing your security tools is no longer sufficient. Right? So organizations need to be able to assess, tools, processes, people. So, again, kind of do that, incident response planning holistically from all three angles. This is exactly, what, you know, the federal, regulations or regional ones like NYDFS are pushing for as well. You know, part of the reasons why, crisis simulation exercises have been run, like, more on an annual basis, more as in one of isolated exercises, is also because it's been a tedious manual process. Right? So details and spreadsheets, inability to bring people together in a room, and and more importantly, no standardization. So if we take example of financial services organizations with, you know, global operations, and regional offices, regional sites, this can become very complicated and result in inconsistent response. I'll just quickly take an example here. This is a Swiss client of ours, so federal department of foreign affairs. They've been using open AV, platform. And with that, they managed to standardize operational readiness across 170 global sites, including investors and consulates. So this is, you know, I think this is one of the key benefits that we are seeing from, AEB, tools now, especially around how do we make it, this process standardized, and build repeatable kind of tabletop scenarios in open AAV, so they can run across different units and departments. And because, this is, it generates lot of data, lot of data for training purposes also for process improvement, for next iteration of the exercise. So in this sense, we're not running, like, one monolithic annual exercise, but building continuous testing and learning, program. And this is something that, a kind of model I would say everybody, should follow. And now with, tools like OpenAV, we we have the technology available where we are able to, you know, create workflows, automate, use AI, for building scenarios, and be able to really kind of, speed up the whole process, but also standardize it as well. Steven, Yeah. I you like. to add something here? Yeah. Yeah. Absolutely. Thank you, Neena. Sorry about that. I absolutely I mean, one of the biggest things is, like, siloed teams and and to make it realistic is by putting everyone on the field for the same game. Right? It's not it's not running those separate drills for each team. You you need something concrete, and those are those threat led scenarios. Like, I like to use examples of saying, like, a a payment system outage tied to maybe a ransomware attack. Right? The platform can either really orchestrate or even import the technical side of those in incidents. So that could be the the alert the alerts at the Soxhall, the timeline of those different compromises, what, you know, what systems and data were at risk. But, essentially, you you need to have a factual story instead of the hypothetical ones that you tend to see. Right? What we saw sometimes in polls is people don't have that, realistic story. Right? And on top of that, AAV then drives those, parallel injects for both your, you know, your legal, your communication, and, I mean, even your leadership. And you're you're in real time watching how quickly those functions are are plugging into the same incident. You know, when legal's pulled in, you know, how long is it taking for that shape, take shape to to have those decisions made or the notifications of those, how comms are are coordinated with your SOC and and leadership. Right. Who actually has the authority to approve those statements? And really, those results become a lot more meaningful because, AAV is recording the whole thing and, who, you know, who was involved when, what decisions were made, how long those handoffs took, was there confusion even or even, you know, conflict that might have appeared. And I think that gives you those hard metrics in a single timeline that you can replay maybe in a in a joint debrief, or even just turn into those remediate remediation act actions. So, I mean, again, it's the retest that I keep honing back onto. It's, like, maybe six months later, you run into a retest in with that same scenario. And that's where you can actually prove, that the results are sticking, and that's very important for, regulators and leaders alike. Awesome. On the, you know, board level accountability is now front and center. Question for you, Steven. How do you make resilience results clear and actionable for senior leadership, but without drowning them in technical detail? Yeah. So, I mean, at at the board level, the conversation really has to shift shift from, tools and TTPs to more, business services, you know, the impact and the trend lines. Obviously, that's exactly what we're here talking about today with OpenAV, but, you know, we build each AV exercise around the the critical business service the board already cares about. Right? Those high value payment systems, maybe, online channels. It's not really about the EDR coverage or, you know, what TTP or t, you know, one five blah blah blah. Right? The platform is there to to translate the technical run into a more simple set of metrics, you know, of service and whether the obligations were met inside the required windows. Obviously, technical jargon like minor tap mapping, the the log telemetry, all that sit underneath. And, what the board is actually gonna see is, okay, against something severe but plausible, towards our payments attack, we're detecting this in twenty minutes where, we've got it contained in seventy five, and we've had decision makers engage in, thirty, forty minutes. Right? And because of how OpenAV operates and it stores those scenarios and results over time, you can actually show those trends and just not any noise. And that really turns resilience reporting, into a more strategic dashboard even that, they can act on. Right? Do they do they decide to accept that residual risk, or do we fund the next step? Right? I think rather than a dense packet of technical detail, that they really just don't care or want to interpret themselves. I think that's pretty important. That's a great point. And I mean, you know, cyber resilience is, it really is a team game. So many people are involved. And I think another, poll that I wanna open up here, is for the audience is when you hear that Perm Cyber Resiliency in your organization, what do you feel is the biggest gap right now for you? You know, is it do you need better security tools? Do you need a clearer strategy and better leadership support? You know, investing in employee awareness and training. We'd love to hear from the audience on that. And again, this is on the right hand side of your screen. You'll see a poll button, where you can choose your, answer and submit. I'm seeing that we are fairly resilient and our main need is continuous improvement. That's great to see. Need a clear strategy and better leadership support, better security tools, kinda like all across the board for, for this one again. Yeah. And and, to that, I would just, say this is a real requirement. Right? So this kind of really resonates with the different, plan conversations that we have today and and, where kind of, customer demands are coming from, but exactly what needs to happen and how it really needs to trickle down from top down, right from looking as we've been discussing, looking at your incidence response plans, what what do they involve? Are you doing, tabletop exercises? But are you connecting them with any other kind of simulation programs you have built today? And are you actually looking out for exploring different tools to be able to, do that? But it it it is kind of a collective, exercise. It is the responsibility of this doesn't really kind of, lies with one single team, but this is, you know, this goes across team and that that's what we would like to highlight. Completely. agree. Yes. You have do you have many options of of awareness of of setting up, notifiers. Obviously, the more people in the tool, the better. And, of course, you're getting the engagement, which is crucial. Right? You need, I mean, one of the highlights here is we need to invest in employees' awareness and training. Of course, that's huge and that's super important when we're trying to to alert those who may be, you know, out of out of the know of what's currently going on. And and, obviously, the solution has has ways to, notify and and start to not silo teams, of course. Awesome. Now thank you guys. And, again, it's so nice to hear from the audience what, what you guys are dealing with. So moving along, we hear a lot about severe but plausible scenarios. How do you make sure that your exercises reflect real threats based on current intel rather than just generic drills that don't actually move the needle? Neena, what do you think? Yeah. I would say this question, really connects it with our mission, our DNA, right, which is, operationalizing threat intelligence, making it actionable. You know, this is how we we, started Filigran started our open source threat intelligence. Our, threat intelligence platform, Open CTI, allows to gather, process, enrich threat intelligence from all different sources, internal, external, open source, commercial feeds. You just kind of, bring it all together. But the, objective here is to it as per your business, your cyber risk. You you got to filter it by country, region, industry vertical, threat actors most active in your landscape. So customize it as per your requirement and then prioritize it to take action on what's relevant for you. And this is then what OpenAV carries forward to be able to then actually test your security stack against these prioritized threats. And in an automated way, like I said previously, also, backed by AI capabilities as well in each step of your threat management life cycle. So then it gives you, you know, two advantages. One is speed. When you find a high priority exploit, validate your security posture there and then. And, like I said, you can automate the whole workflow. So that gives you much, much, much faster speed and, detection and response, capabilities. Second is scale. You're not limited by the number of scenarios or execution of it. So this whole combination of Open CTI and OpenAV gives that real power in your hands And, you know, all the technical for all the technical details, I'm going to pass it over to you, Steven. Yeah. No. I mean, the reality is we we're not using generic drills. Right? We wanna start from intelligence as you were talking about, Neena. It's it's not imagination. We we we're not sitting in a room and we're not inventing, you know, ransomware hits the bank. That's a vague storyline. We we're really pulling from, you know, current CTI. That could be, you know, which ransomware families are actually hitting our sector. Another example is like, you know, what initial access vectors are they using, or even your own open CTI platform if you guys are using something like that today. And the data says, you know, a lot about that. And with open a AV, the the intel becomes, really the template for that exercise. You select the real actor or even the campaign profile. It's, you know, map, it's TTPs to MITRE. You're binding those specific business services to what would, you know, most realistically impact you or your organization, your your payments, your your training online banking, whatever it might be today. Right? Whatever your institution has risk. And, AV really lets you play that threat through end to end. But really on the technical side, you can start to orchestrate, simulations or red team actions that are mirroring those live TTPs. So, even on the governance side, you you can spin up a corresponding tabletop and have it stream, like, a time to that same timeline. So the output isn't you know, we survived maybe a a hypotheticals crisis. It's more against the, you know, against this specific actor with, you know, the these techniques that they might be using, in this business service, and here's actually how we might have performed. Right? And the other half of that, again, is being able to rerun these again. I know that keeps coming right back down to repeatability. And that's because, you know, scenarios in OpenAV are built from those different intel objects. Right? The threat actors, the techniques, the exposed assets. And you do have that customization that Neena was talking about to update those different threat pictures, the the shifts in that, and then being able to rerun that exact scenario after maybe you've updated some of the controls or those different playbooks, that also gives you that before and after evidence of, you know, what's specifically going on currently with the threat. And has it gone from severe plausible to severe, but we've contained it? And, again, it's crucial for boards and regulators, to see that information because I think it's far more convincing than saying, yeah. We we ran a drill last year. Obviously, they wanna make sure in the time and money and efforts that they're investing, they wanna make sure it's got a return on investment, and that's where I believe that shows. Awesome. Thank you. Repeatability is the, is the word of the day. Yeah. So another question, you know, big topic is third party and supply chain dependencies. So many regulations require testing ICT third party dependencies. Third party risk is obviously huge, you know, cloud providers, MSSPs, vendors. How do you bake those dependencies into resilience exercises so that you're not blindsided when something upstream fails? Yeah. I can answer that first. I I would say you bake the third parties into the exercises. Right? You treat them as, like, a a one of your main elements. And it's not a footnote. Right? It's exactly what we wanna achieve with the OpenAV platform. In in OpenAV, we can start by modeling those critical services. Maybe the way, how they're doing it, in The UK, for Dora Neena or even the NYDFS as you mentioned would like to see it. So it's not just our SOC or our data center saw something. It's more of payment services that depend on maybe an x cloud provider or or y network or or your, you know, z MSSP for detection response. I think those, dependencies are explicitly represented in in the scenario. So we have the ability to, like, design those exercise. We don't just simulate an internal incident. We introduce maybe a a third party failure. And of course, at the right moment, this could be your cloud region starts degrading or, I don't know, your MSSP SOC misses. I mean, there could be a number of different things. Right? But because the whole exercise is captured, with the time stamps, decisions, the communication flows, you end up with that solid evidence, that you've tested third party resilience. Right? You're no longer really relying, heavily on a third party to manage incidents before they really impact your institution. You have control over that. You're muted, Neena, as well. Yeah. I tend to do that. I was saying, there is a broader point about sharing here. Steven, like, how you, described about openly we can take that third party and supply chain dependencies into consideration. And even before that, right, for threat intelligence, I would ask this question. So do you share it today with your supply chain? You know, if not with everyone, then at least, you know, with your tier one suppliers or vice versa, are you asking your cloud providers, your managed security providers to share that threat intel from their side? It it it it really kind of comes down to this third party ecosystem mapping and being able to on an execution level, being able to model that both in open CTI, so you or your you know, threat intel platform, as well as, your AV tool like OpenAV. But, you know, being able to link it to real campaigns, threat actors, TTPs that target cloud and, managed security providers, it it it it should really help you pick realistic high value, scenarios. For example, you know, abuse of IDP takeover. So OpenAV definitely turns these scenarios into structured exercises and automated checks, as Steven Bar was mentioning. But my point is more around this, again, community sharing and having that really, you know, one on one mapping with all your supply chain, entities in there doing that third party, building that third party ecosystem and, having checks and balances that there is this good amount of threat intel that is flowing in and out of, your systems. So together, you know, again, what we are, referring to is to be able to move towards this intelligence driven, evidence back kind of view of third party resilience that then you can show to, leadership and regulators. Awesome. Thank you guys. Again, we're running, getting later in the session. I do have one more question for, you know, Neena and Steven, then we're gonna go to q and a. So, again, if you have any questions for them, please leave them in the q and a tab on the right hand side of your screen. Last question for you guys. Not every organization can deploy agents everywhere, especially with legacy systems. How do you still run meaningful tests without adding complexity or, you know, breaking things? Yeah. So this is about a very specific capability. Right? And the way we have developed, OpenAV, it provides that flexibility to customers to not having to deploy, a new agent, on end point, rather use your existing, EDR agents, for example, to execute simulations. Again, Steven can provide you much more detail on than, than I I I can. But this this means, you know, less overload on already resource constrained endpoints, smoother ex employee experience, which is also one of the key criterias for any kind of new security investment, and and much faster time to value. Currently, we have integrations with CrowdStrike and Tanium as EDRs, and there are more on the way. We also do provide a hybrid approach. So it's it's all, the, summary point is here is in flexibility, total flexibility for the customers to go about it as per their Yeah. I. mean, that's extremely well said. I mean, reality is we you know, you don't need agents everywhere to run any meaningful test, really. It's it's it's a lot of the critical legacy environments that it's, I think that's really the the wrong starting point. Right? The way we can approach open AAV is really to focus on more of the behaviors and signals and, not too much on, you know, what endpoints can we instrument. And I think there's three three major things we can focus on here. Right? First, we can design open AAV scenarios around maybe, what an attacker would cause rather than maybe a specific what would, that specific agent do. Usually, we can look at, unusual, authentication patterns, maybe odd payment flows if we're in the finance or maybe data being ex exfiltrated. Right? There's a number of different things we can look at. And as we emulate those at the the network application, and or even the the user level, right, we're checking those existing logs and controls, you're you're testing whether your SOC, your SIM, and and even your processes react appropriately without dropping any new binaries, onto maybe some more fragile systems. The second piece to this, we can take more of a a layered view of coverage where maybe you're running more invasive injects, Right? From your more modern workstations, maybe your your cloud work workloads. And and for your legacy systems, you maybe switch to low impact injects. Right? Your your log replays, synthetic alerts even. And the platform is gonna, really orchestrate the whole thing end to end and capture how the detection and escalation and and, of course, the decision making plays out across, across your entire institution. Right? And the last thing really is because AV is scenario driven rather than agent driven, you are able to really prove the value to auditors and the board without really touching every box. You show that, okay. We've exercised the critical business service. We've, validated the monitoring and response chain. And then, of course, expanded the technical depth of where it's, you know, safe and feasible. And, really, that's that's how you keep tests realistic. You keep them meaningful, especially in a, you know, financial environment full of legacy tech. We can we see a lot of the times. And it does add it doesn't really add that unnecessary complexity to it. So the the again, those are the three major takeaways I would I would take from that. Awesome. Yeah. Thank you, guys. Again, I think this has been a great session, a lot of great discussion points. I do have one more. You guys are gonna be sick of polls by the end of this. I do have one more poll that we would like to ask the audience here is, based on our discussion today, like, how do you foresee better standardization and scaling of table tabletop exercises with AEV tools like OpenAEV? Again, leave it in the poll section on the right hand side of your screen. We would, we we would love to hear from you. Awesome to see. They're starting to roll in. I expect significant improvement. I expect moderate improvement. Well, I also want to take this opportunity to, you know, again, echo that we would love to have, some questions from the audience on this. So if you have any questions for Neena and Steven, please ask away. I know that they love questions. At least when I asked them, they haven't gotten too upset at me yet. So, ask away. And Neena and Steven, just like any any, you know, blasting thoughts, before we wrap things up today as well. Yeah. I mean, I I would say, hopefully, the biggest takeaway here is that being able to quantify the risk in a way that can translate back to leadership or the regulators is is going to be a key differentiator to any organization who has a product like AUV. Right? It doesn't necessarily have to be ours, but you're going to be able to have more control over the unknown, and you're going to be able to relay that, to them in a much easier manner. So, again, if if you can take anything away from this, it's no longer about running just one exercise. It's about being able to continuously test, and that doesn't fall on one person. That's a team effort. And a solution like open CTI, solution like open AV focuses on that and make sure that everyone is all hands and they're all on the same level playing field. So that's what I would add. These are all great points. Thank you for that, Steven. And I would just say that, you know, this is a very, fast evolving space actually that we are talking about AAV or exposure management. We, talked about continuous improvement. So this is this is all directly related to what Gartner, describes as, continuous threat exposure management or CTEM, which is not a tool in itself. It's a framework. Right? It's it's a, again, cybersecurity strategy. But moving the shift towards proactive security and being able to, as we said right at the beginning, being able to utilize your tools, but, you know, extracting the right data, connecting the dots, and then, validating that your tools are operating as expected. And then they are, you know, able to kind of detect and respond in the way that they are, the in the, as per the expectation or their overall purpose. And now, as opposed to breach and attack simulation, which, was, you know, one of kind of static x static static exercises. We are moving with AEB tools towards this space where, it gives you capability to be able to, conduct these exercises on a more continuous basis, but also feed the right intel, to it to create the right kind of, simulations on an ongoing basis. So there there's lots that we try to cover today, and there's a lot more, I would say, for the audience to read and educate themselves about, and we are always happy to help. Of course. And, I mean, I know that today's, session was, again, largely discussion based, conversational, didn't show much of the platform itself. In the docs tab, again, we have some valuable resources if you would like to read more about OpenAEV, or just like any of these topics. There's some relevant resources in there. If you wanna, you know, look into our website, there's an OpenAEV link there as well, as well as if you would like to get a demo directly on open a e v, you can find all of that there. People are being shy. There's not too many questions coming in, but I think that that means we answered all of them with our great presentation today. So on that note, I know we're running a little bit low on time. On behalf of myself, and the entire team at Filigran here, I'd like to thank you all for taking the time out of your day to attend the session. We really hope you enjoyed it. One of the things I'm doing right now as well is there's a survey that should be popping up on your screen. We'd love to hear your feedback on this session as well as any topics that you may like to hear, from us, present on in the future. Any feedback is greatly appreciated. We wanna put out what you guys wanna hear from us. So anything, any feedback will help us improve our webinar program and, produce the most relevant sessions for you all in the future. Again, fill that out if you can, but, thank you all again for joining us. I hope you have a great rest of your Thursday, and, we will see you at our next webinar. Thank you all. Thank you. Thank you. Thank you, everyone.