Outnumbered, Not Outmatched: Smarter Cybersecurity by Following Compliance Frameworks
Paul Whittier (Principal Cybersecurity Advisor)
SAINTCON 2025 · Day 2 · Main Track 3
Overview
In an era where cyberattacks are a constant threat, Paul Whittier, a Principal Cybersecurity Advisor at Enable (formerly Ad Lumen), delivered a compelling talk at SAINTCON titled "Outnumbered, Not Outmatched: Smarter Cybersecurity by Following Compliance Frameworks." Whittier’s presentation underscored the critical importance of adopting comprehensive compliance frameworks, such as NIST, not merely as regulatory checkboxes, but as foundational blueprints for building resilient and multi-layered cybersecurity defenses. He argued that in a landscape where individual security products often fall short, a holistic, framework-driven approach provides the necessary depth and breadth to withstand sophisticated and persistent adversaries.

Key moments
- 0:00 Speaker introduction and company journey
- 2:00 Why compliance frameworks are essential for cybersecurity
- 3:50 Preparation matters: Haiti vs. Japan earthquake analogy
- 4:10 The Crown Jewels heist: Physical attack analogy for cyber
- 6:05 Monitoring matters: Shopping cart incident cybersecurity lesson
- 7:00 Quality monitoring and access to data are critical
Outnumbered, Not Outmatched: Smarter Cybersecurity by Following Compliance Frameworks
Speakers: Paul Whittier, Principal Cybersecurity Advisor, Enable
Conference: SAINTCON
YouTube: https://www.youtube.com/watch?v=xOhWQ7PWegk
Overview
In an era where cyberattacks are a constant threat, Paul Whittier, a Principal Cybersecurity Advisor at Enable (formerly Ad Lumen), delivered a compelling talk at SAINTCON titled "Outnumbered, Not Outmatched: Smarter Cybersecurity by Following Compliance Frameworks." Whittier’s presentation underscored the critical importance of adopting comprehensive compliance frameworks, such as NIST, not merely as regulatory checkboxes, but as foundational blueprints for building resilient and multi-layered cybersecurity defenses. He argued that in a landscape where individual security products often fall short, a holistic, framework-driven approach provides the necessary depth and breadth to withstand sophisticated and persistent adversaries.
The talk addressed a fundamental challenge in modern cybersecurity: the sheer volume and speed of attacks, coupled with the evolving sophistication of threat actors. Whittier, drawing on 25 years of experience and insights from Ad Lumen's 8,000-strong customer base, highlighted that successful breaches are rarely due to a single failure, but rather multiple gaps in an organization's security posture. By methodically implementing controls dictated by compliance frameworks, organizations can create robust layers of defense, significantly mitigating the risk of catastrophic cyber events and ransomware payments. His message resonates deeply with security professionals grappling with an ever-expanding attack surface and the urgent need for more effective, proactive defense strategies.
Background
▶ Watch: Speaker introduction and company journey (0:00)
The cybersecurity landscape has undergone a dramatic transformation over the past two decades, evolving from an environment where breaches were relatively rare occurrences to what Paul Whittier describes as a "pandemic" of cyberattacks. Drawing on his extensive career, which includes stints at Novell, SonicWall, and Sophos before joining Ad Lumen, Whittier noted the stark contrast between the past, where customer breaches were almost unheard of, and the present, where ransomware attacks occur every 20 seconds, inflicting an estimated $6 trillion in damages annually. This escalation underscores the inadequacy of traditional, siloed security solutions.
Whittier emphasized that the problem isn't necessarily a lack of good security tools – "CrowdStrike, Microsoft Defender, Sentinel One, Sophos – they're all good," he stated – but rather a reliance on single points of failure. Every security product, no matter how advanced, will miss something. Attackers have evolved to exploit these gaps, often by blending into the environment, much like the physical heist at the Louvre Museum he described, where thieves dressed as construction workers to appear legitimate. This analogy highlights the pervasive nature of social engineering and phishing, which even a former NSA hacking squadron commander (Tim Evans, an Ad Lumen co-founder) confirmed was their primary method of infiltration: "We fished them... We became the administrator... We stole stuff. They never knew it." The preparation phase of an attack, where adversaries meticulously case their targets, often takes far longer than the actual, rapid "smash and grab" execution. This necessitates a proactive, layered defense that can detect subtle anomalies and respond with unprecedented speed, a capability that compliance frameworks are designed to foster.
Key Findings
▶ Watch: Preparation matters: Haiti vs. Japan earthquake analogy (3:50)
Paul Whittier presented several critical findings based on Ad Lumen's extensive experience protecting 8,000 customers, including 800 financial institutions, which collectively provide a broad view of the current threat landscape:
- Compliance Frameworks as the Ultimate Defense: The central finding is that adherence to compliance frameworks, such as NIST, provides a robust, layered defense against cyberattacks. Instead of focusing on individual product strengths, frameworks guide organizations to implement a comprehensive suite of technologies, policies, and procedures, ensuring multiple layers of protection. This holistic approach is far more effective than relying on any single security solution.
- Overwhelming Attack Volume: The sheer scale of cyber threats is staggering. Across Ad Lumen's customer base in a single year, the platform generated 490,000 alerts, leading to 83,000 security escalations where suspicious activity required customer notification. More concerningly, there were 12,000 "breaches" – actual events requiring elevated SOC analyst intervention – highlighting the constant pressure on organizations.
- Primary Detection Vectors: Ad Lumen's data revealed the most effective detection methods:
- Ad Lumen's proprietary agent: This agent, deployed alongside existing EDR/AV solutions, was the number one detector of advanced threats, including behavior anomalies, malicious PowerShell executions, ransomware, and data exfiltration attempts.
- Customer's endpoint solutions: Traditional EDR or anti-virus products (e.g., Defender, CrowdStrike, Sentinel One, Sophos) were the second most common detection source.
- Cloud environments: Office 365 was highlighted as a significant attack vector, with 44% of all detections originating from cloud environments. This underscores the shift of "crown jewels" from on-premise data centers to the cloud.
- Identity: Monitoring user logins and activities across various platforms is crucial, as identity compromise is a primary attacker objective.
- The Need for Automated, Rapid Response: Human response times, even Ad Lumen's 15-minute SLO (Service Level Objective) for high-severity incidents, are often too slow for the rapid "smash and grab" nature of modern attacks. Attackers can compromise systems and exfiltrate or encrypt data in minutes. This necessitates automation via AI and Machine Learning to achieve sub-human response speeds.
- Cyber Insurance as a Practical "Mini-Framework": For organizations overwhelmed by comprehensive frameworks like NIST, Whittier suggested leveraging the requirements of cybersecurity insurance policies as a practical starting point. These policies often mandate essential controls such as endpoint protection, MDR (Managed Detection and Response), MFA (Multi-Factor Authentication), immutable backups, regular patching, and security awareness training. These form a pragmatic "mini-framework" for immediate implementation.
Technical Deep Dive
▶ Watch: The Crown Jewels heist: Physical attack analogy for cyber (4:10)
Paul Whittier delved into the technical architecture and capabilities that underpin Ad Lumen’s approach to cybersecurity, emphasizing how their platform aligns with a framework-driven strategy. The core of Ad Lumen's offering is a cloud-native SIM (Security Information and Event Management) built on a serverless architecture within AWS. This foundation enables rapid scalability and efficient processing of vast amounts of security telemetry from diverse systems.
A key differentiator for Ad Lumen is its agent-based detection. While customers may already have EDR (Endpoint Detection and Response) or traditional antivirus solutions like CrowdStrike or SentinelOne, Ad Lumen deploys its own agent on endpoints. This agent is designed to go beyond typical EDR capabilities by collecting additional logs and monitoring for behavior anomalies, specific PowerShell executions that indicate malicious activity, and signs of ransomware or data exfiltration. This dual-agent strategy ensures a deeper level of endpoint visibility and detection.
Beyond endpoints, Ad Lumen's platform prioritizes comprehensive log ingestion from cloud environments, specifically highlighting the high volume of attacks targeting Office 365. The platform connects via API to pull logs from these cloud services, providing crucial visibility into an organization’s increasingly cloud-centric "crown jewels." Furthermore, robust identity monitoring is integrated, tracking user logins, locations, and activities across the entire environment to detect compromised accounts or insider threats.
To combat the speed of modern cyberattacks, Ad Lumen heavily leverages automation and AI/Machine Learning. Their SOAR (Security Orchestration, Automation, and Response) capabilities enable automated responses such as system isolation, account disabling, and password resets. These automated actions are critical because, as Whittier noted, even a 15-minute human response time for critical incidents is often too slow for "smash and grab" attacks. AI and ML algorithms are employed for quicker detection, allowing human analysts to focus on more complex threat hunting rather than manual alert triage.
Whittier also positioned Ad Lumen within the broader Enable ecosystem, which offers a unique integrated approach:
- Manage (UEM - Unified Endpoint Management): Includes system management, patching, vulnerability scanning, and remote system access.
- Secure (Ad Lumen SIM/MDR): The core security platform discussed.
- Recover (Cove): A cloud-native backup solution, emphasizing immutable backups as a critical recovery mechanism against ransomware.
This "manage, secure, and recover" paradigm directly maps to the NIST Cybersecurity Framework functions: Identify, Protect, Detect, Respond, Recover, and Govern. Whittier stressed that while some aspects are product-driven, others require strong policies and procedures.
He further elaborated on the practical "mini-framework" derived from cybersecurity insurance requirements. These essential controls include:
- Endpoint Protection: Robust EDR/AV.
- MDR: Managed Detection and Response services.
- MFA: Multi-Factor Authentication across all critical systems.
- Immutable Backups: Ensuring backups cannot be modified or deleted by attackers.
- Patching: Consistent application of security updates, citing examples of major breaches (SonicWall, Palo Alto, Fortinet) due to unpatched vulnerabilities.
- Security Awareness Training: Educating users about phishing and other social engineering tactics.
- Business Controls: Broader organizational policies and procedures.
Ad Lumen's platform is designed for rapid deployment, claiming a fully managed MDR SIM can be operational in 60 to 90 minutes, including all SIM rules, parsing, and compliance reporting. This contrasts sharply with traditional SIM deployments that can take months or even a year. The platform also enriches data through UEBA (User and Entity Behavior Analytics), integrates threat intelligence, performs automated threat hunting, and utilizes honeypots and canary files to detect ransomware and data exfiltration. Unique compliance automation features analyze group policies, detect stealth accounts, and monitor privilege levels. Crucially, Ad Lumen offers a single-vendor solution encompassing the platform, detections, SOAR, and a dedicated SOC team, while remaining vendor-agnostic regarding customers' existing firewalls, cloud applications, or endpoint solutions.
Demo / Proof of Concept
▶ Watch: Monitoring matters: Shopping cart incident cybersecurity lesson (6:05)
While the talk did not feature a live technical demonstration, Paul Whittier highlighted the capabilities of the Ad Lumen platform and offered a demo to interested attendees. He specifically mentioned that during a Proof of Value (POV) engagement, Ad Lumen would "figure out what it is that you're missing and what you may be able to do to be able to prevent on top of that." This implies that a demo or POV would showcase the platform's ability to quickly identify gaps in an organization's existing security posture and demonstrate how Ad Lumen's comprehensive detection and response features could fill those voids. The emphasis on rapid deployment (60-90 minutes) suggests that a POV could quickly provide actionable insights into an organization's environment.
Defensive Implications
▶ Watch: Quality monitoring and access to data are critical (7:00)
The insights shared by Paul Whittier offer clear and actionable defensive implications for organizations grappling with the escalating threat landscape:
- Embrace Compliance Frameworks as a Strategic Imperative: Organizations should move beyond viewing compliance as a mere regulatory burden. Frameworks like NIST provide a structured, holistic approach to cybersecurity, ensuring that multiple layers of defense are implemented across people, processes, and technology. For those overwhelmed by comprehensive frameworks, starting with the practical requirements of cybersecurity insurance policies can serve as an effective "mini-framework."
- Prioritize Layered Security, Not Single Solutions: No single security product can guarantee protection. Defenders must adopt a multi-layered strategy, integrating EDR, MDR, SIM, MFA, immutable backups, and robust patching. Each layer acts as a tripwire or a barrier, increasing the difficulty for attackers to achieve their objectives.
- Invest Heavily in Monitoring and Visibility: The ability to detect subtle attacker behaviors is paramount. This requires comprehensive log collection from all critical sources – endpoints (via agents), cloud environments (especially Office 365), and identity systems. An effective SIM and MDR solution is crucial for correlating these logs, identifying anomalies, and reducing the signal-to-noise ratio of alerts.
- Automate Response to Achieve Sub-Human Speeds: Given the speed of modern "smash and grab" attacks, human response times are often insufficient. Organizations must implement SOAR capabilities, powered by AI and Machine Learning, to automate critical responses like system isolation, account disabling, and password resets. This reduces dwell time and limits the impact of breaches.
- Secure Cloud Environments and Identity as Top Priorities: With the shift of "crown jewels" to the cloud, Office 365 and other cloud platforms have become prime targets. Robust security configurations, continuous monitoring of cloud logs, and stringent identity and access management (including MFA for all users) are non-negotiable. Attackers frequently aim to become "the administrator," making identity protection critical.
- Reinforce Foundational Cyber Hygiene: Despite advanced threats, fundamental practices remain critical. Regular and timely patching of all systems, especially network devices and operating systems, is essential to close known vulnerabilities. Implementing truly immutable backups is the last line of defense against ransomware, ensuring recovery even if primary data is encrypted or destroyed.
- Empower Users Through Continuous Security Awareness Training: Phishing and social engineering remain the leading initial access vectors. Ongoing, engaging security awareness training is vital to educate employees about recognizing and reporting suspicious activity, effectively turning them into a human firewall.
Key Takeaways
- Compliance frameworks like NIST are essential blueprints for comprehensive, layered cybersecurity defenses, moving beyond single-product reliance.
- The volume and speed of cyberattacks necessitate rapid, automated responses; human response times, even 15 minutes, are often too slow for "smash and grab" attacks.
- Phishing and identity compromise remain the primary initial attack vectors, with adversaries aiming to blend into environments as legitimate users or administrators.
- Comprehensive monitoring, including agent-based detection, cloud log ingestion (especially Office 365), and identity tracking, is crucial for early detection of behavioral anomalies.
- Automation via AI, Machine Learning, and SOAR platforms is critical for achieving the necessary speed in detection and response, freeing human analysts for proactive threat hunting.
- A holistic approach integrating system management (patching, vulnerability scanning), robust security (SIM/MDR), and immutable cloud-native backups provides a resilient "manage, secure, and recover" posture.
About the Speaker(s)
Paul Whittier is a Principal Cybersecurity Advisor at Enable, a company that acquired Ad Lumen, where he previously served. With an impressive 25-year career in cybersecurity, Whittier has witnessed and adapted to the industry's constant evolution, including numerous acquisitions and technological shifts. He played a significant role in Ad Lumen's growth, seeing the company expand from 60 customers to over 8,000, establishing it as a major player in the SIM, SOC, and MDR space.
Whittier's extensive background includes experience at notable companies such as Novell, SonicWall, and Sophos. In his current role, he focuses on helping teams secure larger, more strategic deals, including a major statewide acquisition protecting all school districts in Utah (UEEN/UTN). His expertise is further enriched by working alongside X-NSA founders at Ad Lumen, such as Tim Evans (a former commander of a hacking squadron), from whom he gained valuable insights into real-world threat actor tactics, particularly the pervasive effectiveness of phishing. Whittier is a strong advocate for compliance frameworks, drawing on his experience securing over 800 financial institutions, an industry known for its rigorous adherence to security standards.