lecture recording on 14 November 2024 at 11.24.04 AM

Introduction

  • Lily Rodriguez: Senior Solution Engineer at Splunk.

  • Enrique Tranko: Regional Sales Manager for state and local government accounts.

  • Agenda overview: Discuss the state of the SLED sector, Splunk's Unified Security and Observability platform, and Business Analytics.

Crisis in the SLED Sector

  • Definition of crisis: Intense difficulty, trouble, and danger.

  • Increase in layoffs and impact of COVID-19 on workforce expertise.

  • Loss of long-term knowledge due to retirements without adequate documentation.

  • Shift in employee responsibilities with fewer staff and more onus.

  • Increase in security threats during this period, leading to a heightened state of danger.

Challenges

  • Difficulty in managing workloads with reduced staffing levels.

  • Need for better cybersecurity due to vulnerability from decreased personnel.

  • Increase in cyber attacks taking advantage of understaffed environments.

  • Importance of acknowledging the crisis to drive necessary changes.

Solutions Overview

  • 3 P's Approach: Product, Process, People.

    • Improve operational efficiency and reduce response times.

    • Enhance alert resolutions with enriched data.

    • Automate mundane tasks to allow focus on critical processes.

  • Leverage shared threat intelligence across agencies.

  • Automate phishing and malware responses to reduce investigation times significantly.

Splunk Unified Security and Observability Platform

  • Centralized data repository for integrated security and observability.

  • Contextualization of collected data through applications and dashboards.

  • Enterprise Security features with numerous detections based on established frameworks.

  • Importance of comprehensive inventory management and compliance awareness with asset and risk intelligence.

Key Features of Splunk Solutions

  • Splunk Attack Analyzer: Analyze malware and phishing impacts within a controlled environment.

  • Splunk SOAR: Automation for rapid response to events and incidents with numerous workflows.

  • User Behavior Analytics: Monitor internal user actions to detect anomalies and potential threats.

  • Risk Based Alerting: Prioritize risk detection to manage threats effectively.

Analytical Capabilities with Splunk

  • Data can be analyzed from various perspectives for different use cases (Marketing, DevOps, IT Operations).

  • Ability to mix and match data sources for comprehensive dashboards.

  • Showcase of examples: Medical billing fraud dashboard, executive summary, and security policy metrics.

Conclusion

  • By redefining products, processes, and embracing effective partnerships, organizations can better manage performance amid the crisis.

  • Importance of visualizing data collectively for improved decision-making and threat awareness.