April Wright -Digital Separation: Reclaiming your data, post-relationship and using risk-based OPSEC

Опубликовано: 29 Июль 2026
на канале: BSides Boston
84
5

One of the key notions of “Zero Trust” is that trust should not be taken for granted. We are obligated to continually authenticate, validate and protect enterprise entities - including users and organization assets - regardless of the location of those entities.

Threat intelligence approaches within a perimeter-driven environment focus on detecting the threat that’s within, while “Zero Trust” leads us to focus on all organization entities regardless of their location and the risk they represent.

As such, I believe that threat intelligence in a “Zero Trust” environment should be re-shaped into a dynamic signal-based indicator of threats that are associated with organization entities. These signal-based indicators should be data-driven, and empowered by a variety of data sources.

In this presentation I will present a data-driven approach and a set of algorithms that utilize data sources to create threat vectors such as: device posture, user traffic and behavioral profiling, and continuous threat detection. All of this data will be combined into a dynamic signal representing real-world risk representing the associated trust level to network entities, leading to policy driven actions that can reduce risk without implications on usability.