[FR] Conference given in French
You've invested in a SIEM, an EDR, and perhaps even a managed SOC. On paper, you're protected. But one uncomfortable question deserves to be asked: have these defenses ever been tested against a real attack? In the vast majority of organizations, the answer is no—and the first real-world validation happens on the day of the incident, when it's already too late.
This talk proposes a shift in mindset: stop assuming your detection capabilities work, and start proving that they do. We will explore how adversary emulation and purple teaming can objectively measure detection coverage, identify blind spots before they are exploited, and transform cybersecurity spending into demonstrated effectiveness rather than a sense of security.
You'll leave with the right questions to ask your SOC team or security provider, practical metrics to measure and manage your detection capability, and a compelling business case for making defense validation a routine practice rather than an exception.