it-sa 2019 - Germany on alert at Europe’s leading trade fair for IT security

Security Matthias Maier

A record-breaking number of 15.000 visitors make it-sa one of the largest get-togethers of the IT security community in Europe. The large amount of visitors, reveal a trend and need for enhancing cyber security strategies and capabilities across Germany. Many organizations are at a turning point in their cybersecurity journey - starting to establish their own, dedicated security know-how.

The Splunk Team and many partners had been on-site of course! Here are a few of my personal highlights.

Splunk at it-sa 2019

MITRE ATT&CK

The times when only big companies invested in cyber defence capabilities beyond Firewalls and Endpoint Protection is over. Every big or small security team is establishing a detect and response strategy beyond prevention and along the full kill chain.

Dr. Sebastian Schmerl, Cyber Defence Manager at ComputaCenter shared how they are using MITRE ATT&CK for Cyber Defence Maturity Assessments which enables organizations to allow the identification and prioritization of security investments.

Sebastian Schmerl, Computacenter

Each day of the conference, Angelo and me presented on stage, making 15-minute-pitches on MITRE ATT&CK, what it is and how it can be used with Splunk.

Splunk MITRE ATT&CK presentation

Operational Technology (OT) Security - Protecting the Shopfloor

Our partners Airbus and ComputaCenter showcased how they use Splunk to bring their know-how to the production lines within manufacturing plants. Computacenter showcased PDEX to collect PROFINET Data from Siemens Industrial Control Systems as an example.

Airbus showcased a cyber attack against a manufacturing line and how to detect and investigate it early with Splunk before it is too late.

Airbus at it-sa 2019

Managed SIEM & Managed SOC

At Splunk we help organizations build, operate, modernise and mature their Security Operations Center. However, not every organization can afford their own team of security analysts. To allow hybrid operating models or fully outsourced operating models, Splunk was present at many exhibition booths from our partners offering Managed Security Services powered by Splunk Technology.

Our partners at it-sa: magellan netzwerke GmbH, SVA GmbH, NTT Security, SecureLink, NetDescribe, Airbus Cybersecurity, Computacenter and doIT Solutions

Cheers,

Matthias

Related Articles

Supercharge Cybersecurity Investigations with Splunk and Graphistry: A Powerful Combination for Interactive Graph Exploration
Security
3 Minute Read

Supercharge Cybersecurity Investigations with Splunk and Graphistry: A Powerful Combination for Interactive Graph Exploration

In this blog post, we'll dive deeper into how combining Splunk and Graphistry can help you unlock new capabilities for your cybersecurity investigations and gain better resilience for your organization.
From Prompt to Payload: LAMEHUG’s LLM-Driven Cyber Intrusion
Security
10 Minute Read

From Prompt to Payload: LAMEHUG’s LLM-Driven Cyber Intrusion

The Splunk Threat Research Team analyzes the LAMEHUG malware, examining its tactics and techniques to provide insights that can help SOC analysts and blue teamers identify and respond.
Key Threat Hunting Deliverables with PEAK
Security
4 Minute Read

Key Threat Hunting Deliverables with PEAK

When most people think of threat hunting, they think of uncovering unknown threats – but that is only one of many (better) reasons to show value with threat hunting.