THANK YOU FOR SUBSCRIBING
The problem with feeding every log from every system into your organization’s SIEM isit gets every log from every system, creating a virtual tsunami of data. However, data itself is useless; it needs to be turned into information, which is then consumed to become knowledge. With hundreds of thousands of data points flooding your correlation engine, how can we InfoSecprofessionals filter out the chaff and get to the wheat? It seems obvious, but aggregation, correlation, and alerting tools need tuning to get the most out of them. Too many organizations implement an SIEM, turn on every rule they can find, and wait for alerts with the mindset of ‘not wanting to miss anything.’This approachalmost always leads to data overload, burning out teams and hunting down useless incidents. First, not all data is created equal and worthy of examination, even if automated. Some are useless and should be thrown out like yesterday’s takeout container. But since usefulnessis in the eye of the beholder, every security operations team will need to identify what should be kept or dropped based on their needs, concerns, and experience. This is a seemingly simple statement but experienced Ops and Admin folks have nightmares at the thought of trying to wade through the data stream and pull out nuggets of gold.Many organizations have taken the ‘keep everything, just in case’ model, but if we look in the records management space, we can see keeping everything forever will ultimately lead to far more problems than spending time establishing rules and policies around filtering and retention. "Taking IoCs and organization-specific needs into consideration will help to round out your alerting and logging implementation." Only keeping what is useful has a direct impact on your IT budget as well, especially if you’re using a SaaS SIEM like MS Sentinel or a SIEM charging on an events-per-second model. Every byte of data aggregated has a dollar value, which can add up quickly, leaving you to explain to your CFO why you need a bigger budget or have cost overruns. A great place to start isidentifying legal or regulatory requirements around alerting. If you’re a PCI-regulated entity, PCI DSS has clear requirements around monitoring and retaining logs, both online and near. Ensuring compliance should also highlight other data elements in your logs that serve no value being ingested and can be tuned out. Next, lookat your critical systems and your “Crown Jewels." Are the logs coming out of those systems telling you what you need to know? Some systems are chatty, and some are almost mute. Again, limit log ingestion to only relevant data points and move on. Duplicate data feeds are typically a problem as well. For example, there may be two or more feeds sending DNS data to the SIEM; a host-based web filtermight send it, as well as perimeter firewalls.Decide on a ‘system of record’ and push data from there. The host-based web filter might be a good choice since it also captures traffic regardless of location.
Managing cybersecurity vulnerabilities is a continuous race against time. Data from the renowned vulnerability database, Exploit Database, reveals that the number of reported vulnerabilities has increased by more than 140 per cent between 2015 and 2019. During the same period, the time taken to exploit a known vulnerability has been reduced from being several months to almost immediately. This drastic decrease in patching time has resulted in a situation where IT departments are faced with not having enough resources to identify and remediate critical vulnerabilities while managing day-to-day business operations. eSentire, the global leader in managed detection and response (MDR), keeps organizations safe from such constantly evolving cyber attacks that technology alone cannot prevent. The company’s ‘Risk Advisory and Managed Prevention’ offering continuously identifies blind spots, puts the capabilities in use to build a strategy around cyber risk for predicting and preventing threats. Alongside, eSentire’s esNETWORK captures and analyzes all network traffic to support real-time detection and response to both known and unknown cyber threats. esNETWORK’s threat intelligence, black-listing, and IPS/IDS functionality detect and block known threats. Its advanced behaviour based anomaly detection alerts and assists eSentire security operations centre (SOC) analysts in hunting down, investigating and containing attacks that have bypassed all other security controls. To eliminate blind spots, the company also brought forth Carbon Black powered esENDPOINT for providing continuous next-gen endpoint detection and response capabilities to assist eSentire SOC analysts in threat mitigation. The final piece of eSentire’s offering is esLOG+, a co-managed SIEM solution designed to extract meaningful and actionable intelligence from on-premises and cloud assets that accelerates targeted threat hunting and rapid response empowering our SOC analysts to stop attackers before they can become business disrupting. A case in point for the company is its recent partnership with a top investment management firm.
The scope of cybersecurity has expanded beyond IT, now influencing corporate survival by shaping financial resilience, operational integrity and public trust. Adding the latest cybersecurity solutions and measures seems like the best step forward, but the reality is more counterintuitive. Many businesses find themselves overwhelmed by the constant noise of false alarms, which inadvertently makes real threats even harder to detect. Shield53, a managed security services provider (MSSP), lowers the noise and provides an effective solution to over 50 clients. This trusted ally enables businesses to safeguard their data, strengthen their security posture and operate with confidence. The goal is to help clients always stay ahead of bad actors. “After building an MSSP from the ground up, I’ve learned exactly how threat actors operate and more importantly, how to stay ahead of them. Our mission isn’t just to provide security; it’s to embed a strategy, validate it with technical assessments, and deliver 24/7 monitoring to catch threats and risks before they escalate,” says Chris Stewart, CEO. Guided by this mission, Shield53 employs a multi-layered defense approach that integrates cybersecurity strategy development, continuous security monitoring, incident response, vulnerability assessments, and simulated threat detection exercises. The vanguard of its approach is built around Attack Shield, a world-class enterprise security solution. Designed to monitor and secure organizations, the solution continuously scans for vulnerabilities to ensure that businesses follow industry-standard security practices. The software’s proactive stance is strengthened by a 24/7 security operations center (SOC), which offers real-time monitoring, threat detection and automated incident response to mitigate cyber threats as they emerge. The SOC leverages AI, machine learning, and user behavior analytics to cut alert noise by 90 percent, ensuring businesses focus only on real threats and risks.
Genetec is a global leader in physical security and operational intelligence. The company develops open-platform software, hardware, and cloud-based services that integrate video surveillance, access control, automatic license plate recognition (ALPR), communications, and analytics into a single, cohesive ecosystem. This integrated approach enables organizations to respond swiftly, make informed decisions, and strengthen overall resilience. Security Center: The Heart of Unified Operations At the heart of Genetec’s portfolio is Security Center, its flagship platform that breaks down the barriers of traditional siloed systems. By consolidating multiple security operations into a unified interface, the platform enhances situational awareness, streamlines workflows, and empowers proactive risk mitigation. Operators can manage access events, review video feeds, analyze ALPR data, and coordinate communications seamlessly—supported by intuitive, map-based visualization tools. Genetec’s commitment to openness and adaptability is evident in its flexible architecture, which facilitates seamless integration with third-party systems. This ensures long-term scalability and compatibility for organizations of all sizes, from single-site businesses to multinational entities and public safety agencies. The company’s focus extends beyond technological capability to encompass privacy, cybersecurity, and ethical responsibility. Built on privacy-by-design principles, Genetec’s solutions incorporate advanced encryption, multi-layered authorization, and secure authentication—ensuring compliance with international regulations and reinforcing public trust.
Cameron Yardy, Director of Cyber Security, First West Credit Union
Michael Laing, Director of Cyber Security, Rogers Communications
Ron Kaine, Product Director, Enterprise Frand Management, Central 1
Marian Serna, Director, Privacy and Data Security, Skyline Group of Companies
Jason Blumenauer, Vice President Head of Security, First Student
Milad Shaheen, Vice President of Engineering, CIRCOR Aerospace & Defense
Adam Evans, Senior Vice President & CISO, Royal Bank of Canada (RBC)
Canadian businesses and government institutions have experienced a surge in cyber threats, including ransomware, phishing, and data breaches. As the country advances digitally, the need for cybersecurity defense services.
In an ever-evolving digital landscape, organizations are prioritizing cybersecurity like never before. The increasing sophistication of cyber threats has spurred enterprises to adopt advanced cybersecurity strategies and solutions. However, while the intent is strong, the journey towards implementing these trends is fraught with challenges.
A National Effort: How Canada Is Rethinking Cybersecurity
The Canadian Centre for Cyber Security is leading this evolution, promoting coordinated defence strategies across critical infrastructure sectors. At the same time, public and private partnerships are growing stronger. Banks, telecommunications providers, and energy companies are working closely with government agencies to detect and neutralize threats before they escalate. Real-time collaboration and threat intelligence platforms are central to this new model.
Emerging technologies are also changing the game. Artificial intelligence now scans for anomalies across vast data sets, flagging potential breaches in milliseconds. At the same time, quantum-safe encryption is being explored to prepare for future threats posed by quantum computing. These tools are designed to make systems fundamentally harder to compromise.
Education is another critical pillar. As cyber-attacks increasingly target individuals through phishing, scams, and misinformation, digital literacy has become a form of national defence. Initiatives like Get Cyber Safe are helping Canadians understand how to protect themselves, their data, and their communities.
Canada’s approach is human-centred. It recognizes that cyber threats do more than endanger data. They disrupt lives, erode trust, and challenge democracy. In response, the country is building a more secure digital landscape grounded in transparency, collaboration, and preparedness.
In this edition, we spotlight insights from Erin Flett, Vice President of Cyber and Professional Liability at Chubb [NYSE: CB], on evolving risk landscapes, and Peter Kim, Director of Cybersecurity at Orgill, who shares insights on building operational resilience in a complex threat environment.