All Events and Webinars

Building an Effective Security Strategy | Gavan Egan & Raluca Saceanu on Cyber Resilience

Cross Industry
Leadership and Resilience
Identity and Access
April 15, 2026
Building an effective cybersecurity strategy requires visibility, resilience, and the ability to adapt to constantly evolving threats. In this final ZeroDayCon Conversations session, Gavan Egan and Raluca Saceanu discuss the key cybersecurity priorities organisations should focus on in 2026 while also previewing major themes from ZeroDayCon.

In-House Specialists

Gavan Egan

Chief Revenue Officer

Raluca Saceanu

Chief Executive Officer

External Speakers

No external speakers for this session.

Key Strategic Takeaways

What are the core pillars of an effective cybersecurity strategy?

There are five key pillars: proactive security (hardened environments, patch management, network segmentation), identity and human layer governance, operational threat intelligence, operational resilience and incident testing, and ensuring your security strategy drives your technology choices rather than the other way around. AI is also rapidly becoming a critical sixth consideration.

Why is user awareness training no longer enough to combat phishing and social engineering?

AI has dramatically improved attack quality. Threat actors now craft grammatically perfect, contextually aware, and highly targeted communications, including convincing voice and video impersonations. Technical controls like MFA, conditional access policies, and zero trust principles are now essential complements to any awareness program.

How does MDR support an organization's security strategy?

MDR bridges the gap between what a security strategy says on paper and what actually happens when something fires at 2am. It provides round-the-clock expertise across hundreds of environments, enabling fast detection and containment, and delivers the evidence-based reporting needed for board-level confidence.

How should organizations measure cybersecurity effectiveness?

Key metrics include mean time to respond, mean time to contain, MFA coverage across privileged accounts, and vulnerability patching speed by severity. These are far more meaningful indicators than simply counting the number of security tools deployed.

Why is operational resilience about more than backup and disaster recovery?

True resilience requires mapping critical dependencies, understanding which systems or third parties would threaten operations if disrupted, and regularly testing incident response with the right people in the room, including senior leadership. Organizations that handle major incidents well are typically those that have practiced, not those with the most sophisticated technology.

What are the core pillars of an effective cybersecurity strategy?
Why is user awareness training no longer enough to combat phishing and social engineering?
  • 0:00 Introduction
  • 1:12 Why cyber security strategy is now business critical
  • 2:48 What defines an effective security strategy
  • 4:02 Importance of proactive security and reducing blast radius
  • 5:18 Identity threats and governance challenges
  • 6:56 AI-driven phishing and social engineering attacks
  • 8:42 Why user awareness training is no longer enough
  • 9:50 Zero trust, MFA, and limiting attacker movement
  • 10:42 Making threat intelligence operational
  • 12:02 Operational resilience and testing incident response
  • 13:42 Why technology should not dictate security strategy
  • 15:04 Visibility gaps and security tool complexity
  • 16:07 AI as the new frontier in cyber security
  • 17:18 How MDR supports operational resilience
  • 18:36 Why organizations need experienced MDR partners
  • 19:42 Measuring the effectiveness of a security strategy
  • 20:22 Tabletop exercises and executive preparedness
  • 20:50 Final thoughts and closing remarks
Watch More
Security Operations

How Threat Actors Are Using AI

In this discussion, Adrian McDonald is joined by Arron Thundercliffe from Google to explore how attackers are using AI today. They discuss AI-enabled phishing, reconnaissance, and impersonation, along with the practical detection, threat intelligence, and response strategies organisations should prioritise.

Building a Winning Cybersecurity Strategy

In this discussion, Gavan Egan is joined by Ben Lovley from Splunk to explore how security leaders should evolve their strategy for the AI era. They cover the importance of visibility, resilience, effective incident response, and measuring security outcomes rather than focusing solely on tools.

How Organisations Can Adopt AI Without Creating Unnecessary Risk

AI is changing the way organisations operate, but it’s also introducing new security, compliance, and governance challenges. In this discussion, Aaron Smith explores how organisations can adopt AI without creating unnecessary risk.

Ready to scale your security and compliance operations?

We protect your on-premise/cloud/OT environments - 24x7x365