Truth in IT
    • Sign In
    • Register
        • Videos
        • Channels
        • Pages
        • Galleries
        • News
        • Events
        • All
Truth in IT Truth in IT
  • Data Management ▼
    • Converged Infrastructure
    • DevOps
    • Networking
    • Storage
    • Virtualization
  • Cybersecurity ▼
    • Application Security
    • Backup & Recovery
    • Data Security
    • Identity & Access Management (IAM)
    • Zero Trust
    • Compliance & GRC
    • Endpoint Security
  • Cloud ▼
    • Hybrid Cloud
    • Private Cloud
    • Public Cloud
  • Webinar Library
  • TiPs
  • DRAW

Beyond Prevention: Building a Resilient Security Plan

Huntress
07/24/2026
0 (0%)
Share
  • Comments
  • Download
  • Transcript
Report Like Favorite
  • Share/Embed
  • Email
Link
Embed

Transcript


So if you're going to be resilient, you need to be prepared for that when. Here's something nobody in security wants to admit. Everyone is vulnerable. I work in cybersecurity. I almost got phished. I work in cybersecurity, and this is the closest I've ever got to being phished. You're getting, you know, Amazon links or USPS delivery links. Maybe you're busy and you're just you happen to click the link and you almost enter your credentials. I got called by Google. These people had really done their homework. They want me to install TeamViewer, which I don't want to install TeamViewer. It all set all the sensors off. Hoping attackers don't get in isn't a plan, especially when they're using AI to move faster, scale bigger and operate with zero regulation. Nowadays, both the earliest adopter and the most aggressive adopter of AI is the adversary. AI is being used to obfuscate phishing emails, craft really legitimate looking phishing wars. And build out tools like the Evil Tokens infrastructure. Now they can feed lists of names and LinkedIn profiles through AI models and build out custom campaigns to target those individuals in a fraction of the time it would have taken them in the past. Attackers aren't hacking systems anymore. They're hacking humans. Prevention alone isn't a realistic strategy anymore. The unfortunate reality is the weaknesses that we see often exploited today are the weaknesses that were still there 20 years ago. It oftentimes is just a failure of the basics, a failure of the common controls being applied correctly. And that's where I believe it's more about education and informing partners around what the true risks are. That gap between knowing there's a problem and doing something about it starts with visibility. You have to understand what you have, how attackers are going to come at you and what normal even looks like in your environment. Understanding your attack surface, understanding how are attackers going to target and break into your organization. Understand what user activity is normal and what you're expecting to see. Having a plan in place of where are the backups? Are they off site, on site? What security products are in use? Having just an asset management system, knowing what is stood up and when it is stood up and having a catalog of that. The thing that's been most consistent to me as far as getting successful outcomes is controlling the surface of what you have to review. If you have a massive haystack and you're looking for a needle, you're really going to struggle. And it's just more likely you're going to miss the attack in the first place because you're responding to too many false alarms. A clean baseline gives you something to measure against. From there, it's all about putting the right detection tools in place, the ones that cut through the noise and get your team to the right outcomes faster. Most organizations don't get compromised because a user purposefully did something wrong. We're all busy. We all do a lot of things. It is crucial to make sure you're actually investing in your team with like security awareness training type materials so they understand the threats that they actually face. Pulling out an identity detection threat response tool allows you to very rapidly identify a potentially malicious login and disable that account automatically. The big thing I always tell people is, you know, there's a massive advantage to bringing an MDR partner in and that they have global visibility into millions and millions of endpoints. And when it comes to detection and response, I feel like if you really can't make the jump to a 24-7 team, it just makes a lot more sense to outsource that to some sort of MDR provider, somebody who can watch that for you. The difference between a bad day and a business ending disaster is how fast you react when things go sideways. The first piece of advice I'd give any organization with an internal IT team or an internal security team is to run a tabletop exercise. The last time you want to be running through your incident response plan is in the middle of an active incident. Do you have to understand and define and have agreement like, hey, when this happens, person A is going to do this, person B is going to do this, person C is going to do this. I'm going to use this tool. I'm going to use it this way. Identify who's involved in that process, who's doing the response, who is handling conversations with legal, any sort of press releases, things of that nature. It's going to make it much smoother and calmer for everybody when the breach happens, not if the breach happens. I can't recommend enough. Doing that in a dry run through a tabletop scenario is going to allow you to identify the gaps in your incident response plan, plug them and allow you to be more effective in the event of a true incident. If your security plan still starts and ends with keep the bad guys out, it's time for a new plan. Resilient teams assume the breach is coming, give their people the right tools and practice incident response before they actually need it. So if you're going to be resilient, you need to be prepared for that when and you need to know that when it comes, you're going to have to jump on it. You're going to have to have the incident response plan. But what makes things really effective is being able to have that monitoring. So when things happen, you have the resiliency and you can put into action what you've prepared for.

TL;DR

  • Prevention-only security is no longer viable; AI-powered attackers move faster and more precisely than most internal teams can counter, even targeting security professionals themselves.
  • Visibility is the foundation of resilience — organizations must understand their attack surface, catalog assets, and define what normal user behavior looks like before they can detect anomalies.
  • Identity threat detection tools and MDR providers offer critical advantages, including automatic account disabling on suspicious logins and 24/7 global endpoint monitoring that most teams cannot replicate in-house.
  • Tabletop exercises are essential — practicing incident response before a breach ensures roles are defined, tools are understood, and the team can act calmly and quickly when it matters most.

Summary

This Huntress thought leadership video challenges the assumption that prevention-first security is sufficient in today's threat landscape. Featuring candid commentary from Huntress team members — including one who nearly fell victim to a sophisticated phishing call — the video argues that every organization should operate under the assumption that a breach is inevitable. Attackers are now leveraging AI to craft hyper-personalized phishing campaigns from LinkedIn profiles, obfuscate malicious emails, and build infrastructure like Evil Tokens at a scale and speed that outpaces most internal security teams. The video outlines three pillars of a resilient security posture: establishing visibility through asset management and behavioral baselines, deploying detection tools that reduce noise and surface real threats quickly, and practicing incident response through tabletop exercises before an actual breach occurs. Identity threat detection tools that can automatically disable compromised accounts and MDR providers offering 24/7 global endpoint visibility are highlighted as practical force multipliers for teams that cannot staff around-the-clock coverage. The core message is direct — if your security plan still begins and ends with keeping attackers out, it is already obsolete.

Chapters

0:00 - The Inevitability of Breach
0:35 - AI-Powered Attacker Advantage
1:36 - Visibility and Baseline Controls
2:34 - Detection Tools and MDR
3:33 - Incident Response Readiness

Key Quotes

0:13 "I work in cybersecurity. I almost got phished."
0:45 "Nowadays, both the earliest adopter and the most aggressive adopter of AI is the adversary."
1:12 "Attackers aren't hacking systems anymore. They're hacking humans."
3:33 "The difference between a bad day and a business ending disaster is how fast you react when things go sideways."

FAQ

What is a tabletop exercise and why does Huntress recommend it?

A tabletop exercise is a simulated, discussion-based walkthrough of your incident response plan where team members rehearse their roles before a real breach occurs. Huntress recommends it because the worst time to figure out who does what is during an active incident — practicing in advance surfaces gaps in the plan and ensures everyone knows their responsibilities.

Why is prevention-only security no longer enough?

Attackers are using AI to scale phishing campaigns, obfuscate malicious content, and move faster than most internal teams can respond. Many exploited weaknesses today are the same basic control failures that existed 20 years ago, meaning the problem is not just sophistication — it is also execution. Detection, response, and resilience must complement prevention.

Categories:
  • » Webinar Library » Huntress
  • » Data Protection » Backup & Recovery
  • » Data Protection
Channels:
News:
Events:
Tags:
  • Threat Intelligence
  • Security Operations
  • MDR
  • Thought Leadership
  • Best Practices
  • Getting Started
  • Managed Detection and Response
  • AI-Powered Phishing
  • Incident Response Planning
  • Security Awareness Training
  • Identity Threat Detection
  • Cyber Resilience
Show more Show less

Browse videos

  • Related
  • Featured
  • By date
  • Most viewed
  • Top rated
  •  

              Video's comments: Beyond Prevention: Building a Resilient Security Plan

              Industry Events (Sponsor Hosted)

              • Oct
                13

                Transitioning from CJIS to FERPA: Essential Audit Evidence for Compliance

                10/13/202601:00 PM ET
                • Oct
                  15

                  Risk in Real Time Demo Series: Virtual Patching: Protection at the Speed of Exploitation

                  10/15/202611:00 AM ET
                  • Oct
                    20

                    Harnessing Data Governance for AI with Cyera and Snowflake

                    10/20/202611:00 AM ET
                    More events

                    Upcoming Webinar Calendar

                    • 10/13/2026
                      01:00 PM
                      10/13/2026
                      Transitioning from CJIS to FERPA: Essential Audit Evidence for Compliance
                      https://www.truthinit.com/index.php/channel/2159/transitioning-from-cjis-to-ferpa-essential-audit-evidence-for-compliance/
                    • 10/15/2026
                      11:00 AM
                      10/15/2026
                      Risk in Real Time Demo Series: Virtual Patching: Protection at the Speed of Exploitation
                      https://www.truthinit.com/index.php/channel/1372/risk-in-real-time-demo-series-the-autonomous-era-orchestrating-a-resilient-enterprise/
                    • 10/20/2026
                      11:00 AM
                      10/20/2026
                      Harnessing Data Governance for AI with Cyera and Snowflake
                      https://www.truthinit.com/index.php/channel/2137/harnessing-data-governance-for-ai-with-cyera-and-snowflake/
                    • 10/27/2026
                      01:00 PM
                      10/27/2026
                      The HUMAN Experience: Real-Time Insights into Page Intelligence
                      https://www.truthinit.com/index.php/channel/2139/the-human-experience-real-time-insights-into-page-intelligence/
                    • 11/04/2026
                      11:00 AM
                      11/04/2026
                      Leveraging CISA’s Zero Trust Maturity Model for an AI-Driven Landscape
                      https://www.truthinit.com/index.php/channel/2149/leveraging-cisas-zero-trust-maturity-model-for-an-ai-driven-landscape/
                    • 11/04/2026
                      11:00 AM
                      11/04/2026
                      Aligning Agentic Intent: Understanding Your Agents' Purpose vs. Their Actions
                      https://www.truthinit.com/index.php/channel/2158/aligning-agentic-intent-understanding-your-agents-purpose-vs-their-actions/
                    • 11/05/2026
                      01:00 PM
                      11/05/2026
                      HUMAN Dialogue: Redefining Authentic Trust in the Agentic Internet
                      https://www.truthinit.com/index.php/channel/2160/human-dialogue-redefining-authentic-trust-in-the-agentic-internet/
                    • 11/19/2026
                      01:00 PM
                      11/19/2026
                      360View: Govern, Secure & Recover Your Microsoft 365 Environment
                      https://www.truthinit.com/index.php/channel/2076/360view-govern-secure-recover-your-microsoft-365-environment/
                    Truth in IT
                    • Sponsor
                    • About Us
                    • Terms of Service
                    • Privacy Policy
                    • Contact Us
                    • Preference Management
                    Desktop version
                    Standard version