Cloud breaches are fast, noisy, and complex. This talk delivers a practitioner-focused cheatsheet for incident response and forensics in AWS, Azure, and GCP—highlighting where to look, what to collect, and how to act quickly. Whether you’re chasing logs in CloudTrail, unpacking GCP service accounts, or containing incidents in Azure, this session gives responders the critical triage knowledge needed to stay ahead of adversaries.
X-Force Principal Incident Response Consultant with 7 years of experience in Security Operations, specialising in Incident Response and Threat Intelligence. Extensive experience in the banking sector, having served as an Incident Responder, Detection Engineer, and Manager within a Global SOC. Successfully led and supported initiatives focused on building incident response capabilities, developing threat intelligence platforms, delivering technical training, and strengthening proactive security services. Holds industry-recognised certifications including GCTI, GCFA, and GCFR. Holds a Bachelor’s degree in Security Studies, is currently pursuing a Master’s in Cybersecurity, and is a Chevening Fellow (UK Defence Academy).