In manufacturing environments, every minute of downtime can impact production, revenue, and customer commitments.

Yet when a cyber incident occurs, many organizations struggle to quickly understand what actually happened - especially when data is distributed across endpoints, plants, and remote locations.

This session will walk through a realistic incident scenario, highlighting where typical approaches break down and how teams can respond more effectively under pressure.

What you'll learn

  • How manufacturing organizations can reduce investigation time during active incidents
  • Where visibility is typically lost across endpoints, cloud, and distributed environments
  • How to quickly determine scope, impact, and affected systems
  • Real-world scenarios including:
    • ransomware
    • insider risk
    • suspicious activity
  • How to improve collaboration between security, IT, and investigation teams

During the session, we will work through a practical investigation workflow, including:

MFCvent_WhyAttend1

Remote acquisition and triage of endpoint data

MFCvent_WhyAttend2

Rapid evidence collection during an active incident

MFCvent_WhyAttend3

Connecting artifacts across systems to understand impact

MFCvent_WhyAttend4

Building a defensible investigation - from collection to reporting

This is a small, interactive session designed for discussion and exchange—so we can share approaches and challenges across organizations.

As places are limited, we recommend securing your spot early.

Countdown to the Lunch & Learn

See you in 53 days 20 hours 25 minutes
  • 53
    Days
  • 20
    Hours
  • 25
    Minutes