Lessons Learned from the Fires of Response

Lauren Proehl

SAINTCON 2025 · Day 1 · Main Track 2

Overview

Lauren Proehl, Global Head of Detection Response at Marsh McLennan, delivered a candid and insightful presentation at SAINTCON, drawing upon her 11 years of experience in blue team operations, from a Security Operations Center (SOC) analyst to her current leadership role. Titled "Lessons Learned from the Fires of Response," her talk offered a "hot take" on the evolving landscape of cybersecurity incident response, emphasizing both the human and technical challenges faced by defenders. The presentation moved beyond conventional technical advice, delving into the critical importance of soft skills, organizational culture, and strategic thinking in an increasingly complex threat environment.

Watch on YouTube

Visual summary for Lessons Learned from the Fires of Response by Lauren Proehl
Visual summary for Lessons Learned from the Fires of Response by Lauren Proehl

Key moments

  1. 0:00 Introduction and speaker's background in blue team
  2. 1:20 Core philosophy: Every responder should be a SOC analyst
  3. 2:00 Lesson 1: AI as a friend for supercharging analysis
  4. 4:15 Lesson 1: AI as a foe, utilized by threat actors
  5. 6:00 Lesson 2: Make new friends and keep the old (networking)
  6. 6:35 Importance of making friends with legal and HR

Lessons Learned from the Fires of Response

Speakers: Lauren Proehl, Global Head of Detection Response, Marsh McLennan

Conference: SAINTCON

YouTube: https://www.youtube.com/watch?v=-XpgVwf7kOg

Overview

Lauren Proehl, Global Head of Detection Response at Marsh McLennan, delivered a candid and insightful presentation at SAINTCON, drawing upon her 11 years of experience in blue team operations, from a Security Operations Center (SOC) analyst to her current leadership role. Titled "Lessons Learned from the Fires of Response," her talk offered a "hot take" on the evolving landscape of cybersecurity incident response, emphasizing both the human and technical challenges faced by defenders. The presentation moved beyond conventional technical advice, delving into the critical importance of soft skills, organizational culture, and strategic thinking in an increasingly complex threat environment.

Proehl’s talk is particularly relevant for cybersecurity professionals at all career stages, from frontline SOC analysts to CISOs and security managers. It provides a holistic view of incident response, highlighting the often-overlooked aspects of regulatory compliance, mental well-being, and effective communication with business stakeholders. By sharing personal anecdotes and practical strategies, Proehl underscores the need for a resilient, adaptable, and intelligence-driven defense posture, stressing that success in cybersecurity is not merely about technology, but about people, processes, and continuous learning.

Background

▶ Watch: Introduction and speaker's background in blue team (0:00)

Proehl began her career as a SOC analyst, a foundational role that profoundly shaped her philosophy: "every responder a SOC analyst." She believes that all blue team functions—from threat intelligence (CTI) and threat hunting to detection engineering—ultimately exist to support frontline defenders. These analysts, often working at 3 AM, need robust tools, clear playbooks, and well-defined processes to quickly distinguish between genuine threats and false positives. This perspective forms the bedrock of her subsequent lessons, emphasizing the need for practical, actionable support for those in the trenches.

The talk implicitly acknowledges the relentless pace and high-stakes nature of incident response. The cybersecurity industry is characterized by a constant arms race, where adversaries are increasingly sophisticated and fast-moving, while defenders grapple with an overwhelming volume of alerts, ever-expanding attack surfaces, and mounting regulatory pressures. Proehl’s experiences reflect the journey of many security professionals who have witnessed the transformation of the threat landscape over the past decade, from a time when CTI was a luxury to today, where it's a necessity. Her emphasis on documentation, inter-departmental collaboration, and understanding business risk stems directly from the chaotic and often isolating "fires of response" that define a blue teamer's life.

Key Findings

▶ Watch: Lesson 1: AI as a friend for supercharging analysis (2:00)

Proehl's presentation distilled her extensive experience into several critical lessons, emphasizing both strategic and operational considerations for effective incident response:

  1. AI as a Dual-Edged Sword: While AI, particularly large language models like ChatGPT, can significantly augment an analyst's capabilities by providing quick context, identifying red flags, and suggesting next steps, it also serves as a potent tool for adversaries. Threat actors are already leveraging AI for nefarious purposes, from setting up command-and-control (C2) servers using cloud AI services (e.g., Anthropic's Claude) to lowering the barrier to entry for complex attacks by generating malicious code or attack instructions.
  2. The Indispensability of Human Connection: In a field often associated with solitary technical work, Proehl stressed the critical need for strong interpersonal relationships. Building rapport with help desk, executives, legal, HR, and finance teams before an incident occurs is paramount. These connections facilitate smoother incident resolution, provide necessary context, and ensure organizational alignment during crises.
  3. Documentation is Non-Negotiable: The adage "if it's not in a ticket, it didn't happen" highlights the importance of meticulous documentation. This includes regularly updated Incident Response Plans (IRP), concise playbooks, clearly defined roles and responsibilities, and documented exceptions. Effective documentation ensures replicability, aids in training new analysts, and provides an auditable trail for post-incident analysis and compliance.
  4. Regulatory Burden Outpaces Adversary Speed: Proehl presented a stark "hot take": regulators currently scare her more than adversaries. The exponential growth of data protection and cybersecurity regulations (e.g., GDPR, state-level breach notification laws, SEC lawsuits like those impacting SolarWinds CISOs) places immense pressure on organizations. Compliance timelines (e.g., 72-hour reporting) can divert critical resources from immediate containment efforts, forcing difficult prioritization choices that can have severe financial and reputational consequences. Emerging AI laws further complicate this landscape.
  5. Intelligence is No Longer Optional: With exploit times sometimes being "in the negatives" (i.e., exploited before public disclosure), Cyber Threat Intelligence (CTI) has transitioned from a specialized luxury to an absolute necessity. Organizations, regardless of size, must find ways to integrate intelligence to prioritize patching, understand adversary tactics (e.g., CrowdStrike's 51-second breakout time for e-crime actors), and proactively block low-hanging fruit.
  6. Burnout is Inevitable: Cybersecurity, particularly incident response, is a high-stress field with an alarmingly high rate of burnout (76% of professionals, according to a Sophos report). Proehl shared a personal story of developing a brain tumor at 26 due to extreme work hours, highlighting the severe physical and mental toll. Proactive and reactive support for teams, including regular breaks, recognition programs, and investment in growth opportunities, is crucial for retaining talent and maintaining team effectiveness.
  7. "Inappropriate Things" Are Always Present: Incident investigations frequently uncover disturbing or "inappropriate" content (e.g., Proehl's "butthole counter" during a malware investigation). This often-unspoken reality can be trauma-inducing for analysts, further contributing to burnout and underscoring the need for strong mental health support systems.
  8. Translate Security to Business Value: Leadership primarily cares about money. Security professionals must learn to articulate their work in terms of quantitative business risk, cost avoidance, and competitive advantage. Demonstrating return on investment through metrics and consistent communication (e.g., incident reports, after-action reviews, dashboards) is essential for securing budget and strategic alignment.
  9. Measure Impact, Not Just Volume: Over-reliance on simple metrics like "number of tickets closed" can lead to perverse incentives and a false sense of security. Instead, focus on metrics that reflect actual impact, such as Mean Time to Detect (MTTD), Mean Time to Respond (MTTR), Incident Caught at Execution (ICE) metrics (catching threats earlier in the kill chain), and rate of repeat incidents.

Technical Deep Dive

▶ Watch: Lesson 1: AI as a foe, utilized by threat actors (4:15)

Proehl dedicated a significant portion of her talk to a "lightning round" of critical technical considerations that defenders should be actively addressing in 2025. These points highlight common vulnerabilities and emerging attack vectors:

  • Microsoft Teams External Exposure: A prevalent issue is the external exposure of Microsoft Teams tenants, which Scattered Spider and other threat actors exploit to impersonate help desk staff and gain unauthorized access. Organizations must assess if external calling into Teams instances is truly necessary for client interactions or if separate, controlled tenants are required. Generally, Proehl recommends against broad external exposure.
  • Commercial VPN Authentication: Allowing users to authenticate from commercial VPNs (e.g., NordVPN, AstroVPN, Mullvad VPN) poses a significant risk. Nation-state actors, such as those from DPRK, frequently use these services to obfuscate their origin, making attribution and blocking difficult. Proehl strongly advises against allowing authentication from known commercial VPNs due to the high threat posed.
  • Cloud Control Plane Security: The security of cloud control planes (e.g., AWS, Azure, GCP management interfaces) remains a critical concern. As threat actors increasingly jump from cloud to cloud, an unsecured control plane provides an easy entry point. Proehl cited the F5 breach involving 45+ undisclosed vulnerabilities as a stark warning. Securing these planes requires specialized cloud expertise, often necessitating engagement with native cloud services or dedicated security vendors.
  • Patching Older Vulnerabilities: While the focus often shifts to the latest CVEs, attackers frequently exploit older, unpatched vulnerabilities. Proehl noted the resurgence of techniques like LNK files. Organizations must prioritize patching externally exposed Remote Code Execution (RCE) vulnerabilities, regardless of their age, as these are easily discoverable via tools like Shodan and provide low-hanging fruit for adversaries.
  • Insider Threat Monitoring: With uncertain economic times and threat actors offering money for internal access, insider threat programs are becoming non-negotiable. Proehl referenced Cisco insider threat instances and cases where incident responders ransomed their own companies. Implementing such programs requires careful consideration of labor laws and works councils, especially in global organizations. While EDRs offer some basic detections (e.g., impossible travel), dedicated solutions are increasingly necessary.
  • Blocking Known Bad Passwords: Simple, commonly used passwords like "welcome123" or "UtahJazz2025" remain a persistent threat. Microsoft's banned passwords list for Active Directory 2016 or newer is a useful tool. Beyond technology, a multi-pronged approach involving awareness training and constant monitoring is needed. Proehl also warned against storing secrets or temporary passwords in CRM, Zendesk, or Jira systems, as these are frequently compromised.
  • Open-Source Software Supply Chain: The complexity of the open-source software (OSS) supply chain presents a significant challenge. Proehl highlighted the Shy Halude npm worm incident, where hundreds of packages were weaponized before GitHub could intervene. The immediate recommendation is to inventory all open-source software in use and consider implementing trusted repositories (e.g., Artifactory). These repositories allow organizations to control approved versions, slow-roll updates, and scan for malicious code, mitigating the risk of developers pulling directly from public, potentially compromised package managers.

Demo / Proof of Concept

▶ Watch: Lesson 2: Make new friends and keep the old (networking) (6:00)

While the talk did not feature a traditional live demonstration of an exploit or a complex security tool, Lauren Proehl illustrated the practical application of AI in incident response. She presented a real-world example of using a free, non-logged-in ChatGPT session. Proehl took an Indicator of Compromise (IOC) from a DFIR Report and queried ChatGPT to determine if it was malicious or a false positive.

The AI promptly provided a detailed dissertation, confirming the IOC's malicious nature and explaining why it was malicious, highlighting critical red flags such as backing up to a local share or targeting NTDS. Furthermore, ChatGPT offered high-level next steps for investigation, including isolating the host, searching EDRs, and checking user context. Proehl used this example to demonstrate AI's potential to supercharge analysis for junior analysts, cut down investigation time, and potentially prevent unnecessary escalations at inconvenient hours. She clarified that while AI is excellent for pointing out red flags and guiding investigations, it should not be trusted to autonomously execute critical actions like quarantining a host or contacting a CEO.

Defensive Implications

▶ Watch: Importance of making friends with legal and HR (6:35)

The insights shared by Lauren Proehl offer a comprehensive framework for bolstering an organization's defensive posture, encompassing technology, process, and people:

  • Embrace AI Augmentation, but with Caution: Leverage AI tools like ChatGPT for initial alert analysis, context gathering, and generating investigative next steps. However, maintain human oversight for critical decisions and be acutely aware that adversaries are also using AI; implement appropriate monitoring for AI service usage within your environment.
  • Prioritize Human-Centric Security: Cultivate strong relationships across all departments (legal, HR, finance, help desk). These connections are invaluable for seamless incident response, legal compliance, and effective communication during a crisis. Foster a culture of collaboration, recognizing that security is a collective responsibility.
  • Implement Robust Documentation and Playbooks: Develop and regularly update comprehensive IRPs, clear and concise playbooks, and detailed roles and responsibilities. Document all exceptions and ensure that every action taken during an incident is recorded in ticketing systems to maintain an auditable trail and facilitate learning.
  • Strategic Regulatory Preparedness: Engage legal teams proactively to understand the ever-growing landscape of data protection and cybersecurity regulations. Develop clear processes for reporting and compliance that minimize disruption to active incident containment efforts.
  • Invest in Intelligence-Driven Security: Integrate CTI into all aspects of your security program. Use intelligence to prioritize vulnerability patching (especially for Kev-labeled CVEs), block known adversary infrastructure (e.g., Tor nodes, commercial VPNs like AstroVPN), and understand emerging threats. This proactive stance is crucial for slowing down fast-moving adversaries.
  • Combat Burnout Proactively: Foster a supportive work environment that acknowledges the inevitability of burnout. Encourage regular breaks, promote work-life balance, implement recognition programs, and invest in professional development opportunities. Managers should actively remove obstacles and advocate for resources that ease their team's burden.
  • Secure the Modern Attack Surface:
  • Microsoft Teams: Restrict external exposure of Teams tenants unless absolutely critical for business operations.
  • Commercial VPNs: Block authentication from known commercial VPN services to mitigate risks from nation-state actors.
  • Cloud Control Planes: Prioritize securing cloud management interfaces. Engage cloud security experts or leverage native cloud security services for robust configurations.
  • Vulnerability Management: Focus on patching externally exposed RCE vulnerabilities, regardless of their age, as these represent critical attack vectors.
  • Insider Threat: Develop and implement an insider threat program, working closely with legal counsel to navigate privacy and labor laws.
  • Password Hygiene: Implement Microsoft's banned passwords list and enforce strong password policies. Educate users and prevent the storage of secrets in non-secure systems.
  • Open-Source Supply Chain: Inventory all open-source software, implement trusted repositories (e.g., Artifactory), and establish processes for vetting and managing third-party dependencies to prevent supply chain attacks.
  • Communicate Security Value to Business Leaders: Translate technical security work into quantifiable business terms (e.g., risk reduction, cost avoidance). Use dashboards with clear metrics (MTTD, MTTR, ICE, cost per incident), incident reports, and after-action reviews to demonstrate impact and justify resource allocation. Avoid vanity metrics that don't reflect true security posture.

Key Takeaways

  • AI is a powerful augment for SOC analysts but also a potent tool for adversaries. Leverage it for analysis, but maintain human oversight and be aware of its misuse by threat actors.
  • Effective incident response hinges on strong inter-departmental relationships and meticulous documentation. Build connections before crises and ensure every action is recorded for accountability and learning.
  • The regulatory burden is a growing challenge that demands strategic planning and legal collaboration. Prioritize compliance without sacrificing critical containment efforts during an active incident.
  • Cyber Threat Intelligence (CTI) is no longer optional; it's essential for proactive defense. Invest in intelligence to understand, prioritize, and mitigate threats before they impact your organization.
  • Burnout is a serious, inevitable issue in cybersecurity. Leaders must prioritize team well-being through supportive cultures, recognition, and investment in growth opportunities.
  • Translate security efforts into business value for leadership. Use clear metrics and consistent communication to demonstrate risk reduction and justify security investments.

About the Speaker(s)

Lauren Proehl is the Global Head of Detection Response at Marsh McLennan, a leading professional services firm. With 11 years of experience exclusively in blue team operations, she has progressed from a SOC analyst role, through lead analyst positions at managed detection and response (MDR) firms, to her current global leadership position.

Proehl is a strong advocate for foundational SOC skills, believing that "every responder a SOC analyst." Beyond her corporate responsibilities, she is deeply involved in the cybersecurity community, contributing to organizations like Besides KC, Seccon, and co-founding the Thor Collective. She also serves on the board of directors for the Urban Trail Company, a local Kansas City trail maintenance organization, reflecting her passion for escaping computers by running long distances in nature. Her career journey highlights a blend of deep technical expertise, leadership acumen, and a profound understanding of the human element in cybersecurity.

All talks from SAINTCON 2025