Skip to main content
Alfredo Nash

Alfredo Nash

Cybersecurity professional; Principal Information Security Analyst at American Red Cross; Co-Founder/CEO of Cyber Coffee Hour Podcast

Jul 14, 2026

2:47
But Alfredo, what's your thoughts on it?
2:49
Uh, this is a little close to home, right? So last, to your point, right, when the, the FTEs and full-timers, the gov...
2:54
big .gov folks start get... letting go, they hire contractors, the hundred-pound brains that fill up the 20%, right, that you mentioned, 80/20, right? Fortunately, looking at Krebs' piece, you know, they couldn't alert that contractor on the incident and the response plan, which is horrifying, to your point.
3:10
The second thing, Krebs' piece goes and says, "Well, as we're alerting the contractor to this potential exposure, it's of keys in AWS GovCloud." That hit home, that hit home to the heart, man.
3:21
That's the bread and butter, right? Like, that's supposed to be the incident response plan.
3:25
That's supposed to be automated.
3:26
It's auto remediation, and, and then the, the brain compounds, right? There's, there's tasks that we have to complete in a certain time and fashion to knock out an incident or alert Amazon, right? There's the hint, right? The contractor, if you can't get a con-contact to the contractor, right, contact and contract, right? You can't get the incident response plan if, even if it's absent, 'cause Amazon has one, right? And then the keys to the castle that go out, y-your, you're pretty much too late from your SOC catching the logs afterwards, right? So reading the, reading the room, reading the incident in itself, it's, it's, it's a little heartbreaking.

28 MINS LATER

32:11
I remember.

We value your privacy

We use cookies to understand how you use our platform and to improve your experience. Click “Accept All” to consent, or “Decline non-essential” to opt out of non-essential cookies. Read our Privacy Policy.