Jul 13, 2017 · 20m · mad

Graph Theory and Cybersecurity Data // Liz Maida, Uplevel Security (FirstMark's Data Driven)

Liz Maida · 16m spoken Matt Turck · 27s spoken
0:00 / 0:00
▶ Watch on YouTube →

gold bands on the timeline = statements, start to end. Hover to read, click to jump. CC turns on captions

At FirstMark's DataDrivenNYC event, Uplevel Security Founder and CEO Liz Maida outlines the severe data overload and operational friction facing enterprise cybersecurity teams, advocating for graph data structures and automated correlation to transform threat analysis.

How this conversation actually went

Every chapter scored 0–10 on four independent dynamics. Hover any point for the reasoning behind the score. Matt holds 2.3% of the talking time here. How this is scored →

Matt as informed peer 0.5 Guest teaching 5.0 Guest disagreement 1.3 Matt pushing back 0.3
05100:0010:0020:000:13–2:53 · Matt as informed peer 0/10 The Cybersecurity Data Dilemma Liz Maida presents a solo keynote on cybersecurity data overload, explaining how security vendors generate excessive disconnected alerts. The host does not speak in this segment, resulting in zero scores for host metrics.2:53–5:49 · Matt as informed peer 0/10 Limitations of SIEMs and Raw Log Querying Maida details the operational friction of traditional SIEMs and raw log queries, noting analysts spend 16 hours on single email investigations. This segment continues as a presentation monologue without host participation.5:49–14:40 · Matt as informed peer 0/10 Process Playbooks vs. True Intelligence Maida presents graph data structures as the optimal technical architecture to correlate cyber threats over time without fragile manual playbooks. The segment remains a monologue, keeping host scores at zero.14:40–20:24 · Matt as informed peer 2/10 Uplevel Security History and Analyst Pain Matt Turck opens Q&A with general background questions before audience members ask about tech stacks and enterprise security hygiene. Maida patiently explains hybrid database architectures and human factors without any conversational hostility.0:13–2:53 · Guest teaching 4/10 The Cybersecurity Data Dilemma Liz Maida presents a solo keynote on cybersecurity data overload, explaining how security vendors generate excessive disconnected alerts. The host does not speak in this segment, resulting in zero scores for host metrics.2:53–5:49 · Guest teaching 5/10 Limitations of SIEMs and Raw Log Querying Maida details the operational friction of traditional SIEMs and raw log queries, noting analysts spend 16 hours on single email investigations. This segment continues as a presentation monologue without host participation.5:49–14:40 · Guest teaching 6/10 Process Playbooks vs. True Intelligence Maida presents graph data structures as the optimal technical architecture to correlate cyber threats over time without fragile manual playbooks. The segment remains a monologue, keeping host scores at zero.14:40–20:24 · Guest teaching 5/10 Uplevel Security History and Analyst Pain Matt Turck opens Q&A with general background questions before audience members ask about tech stacks and enterprise security hygiene. Maida patiently explains hybrid database architectures and human factors without any conversational hostility.0:13–2:53 · Guest disagreement 1/10 The Cybersecurity Data Dilemma Liz Maida presents a solo keynote on cybersecurity data overload, explaining how security vendors generate excessive disconnected alerts. The host does not speak in this segment, resulting in zero scores for host metrics.2:53–5:49 · Guest disagreement 1/10 Limitations of SIEMs and Raw Log Querying Maida details the operational friction of traditional SIEMs and raw log queries, noting analysts spend 16 hours on single email investigations. This segment continues as a presentation monologue without host participation.5:49–14:40 · Guest disagreement 1/10 Process Playbooks vs. True Intelligence Maida presents graph data structures as the optimal technical architecture to correlate cyber threats over time without fragile manual playbooks. The segment remains a monologue, keeping host scores at zero.14:40–20:24 · Guest disagreement 2/10 Uplevel Security History and Analyst Pain Matt Turck opens Q&A with general background questions before audience members ask about tech stacks and enterprise security hygiene. Maida patiently explains hybrid database architectures and human factors without any conversational hostility.0:13–2:53 · Matt pushing back 0/10 The Cybersecurity Data Dilemma Liz Maida presents a solo keynote on cybersecurity data overload, explaining how security vendors generate excessive disconnected alerts. The host does not speak in this segment, resulting in zero scores for host metrics.2:53–5:49 · Matt pushing back 0/10 Limitations of SIEMs and Raw Log Querying Maida details the operational friction of traditional SIEMs and raw log queries, noting analysts spend 16 hours on single email investigations. This segment continues as a presentation monologue without host participation.5:49–14:40 · Matt pushing back 0/10 Process Playbooks vs. True Intelligence Maida presents graph data structures as the optimal technical architecture to correlate cyber threats over time without fragile manual playbooks. The segment remains a monologue, keeping host scores at zero.14:40–20:24 · Matt pushing back 1/10 Uplevel Security History and Analyst Pain Matt Turck opens Q&A with general background questions before audience members ask about tech stacks and enterprise security hygiene. Maida patiently explains hybrid database architectures and human factors without any conversational hostility.

speaking balance: gold is Matt, purple is the guest (3 minute bins)

0:00 · Matt 0% · guest 100%0:00 · Matt 0% · guest 100%3:00 · Matt 0% · guest 100%3:00 · Matt 0% · guest 100%6:00 · Matt 0% · guest 100%6:00 · Matt 0% · guest 100%9:00 · Matt 0% · guest 100%9:00 · Matt 0% · guest 100%12:00 · Matt 4% · guest 96%12:00 · Matt 4% · guest 96%15:00 · Matt 12.2% · guest 87.8%15:00 · Matt 12.2% · guest 87.8%18:00 · Matt 0.9% · guest 99.1%18:00 · Matt 0.9% · guest 99.1%
Sharpest disagreement ▶ 19:20 Rebuffing simplified security risk views

Maida gently reframes an audience member's premise that breaches stem purely from unpatched software, pointing out organizational trade-offs and human social engineering realities.

Hardest push from Matt ▶ 14:45 Transitioning to audience Q&A

Matt Turck steps in at the conclusion of Maida's presentation slides to redirect focus toward company history and founding timeline.

Biggest teaching moment ▶ 16:30 Explaining graph database architectural limits

Maida educates the inquirer on why graph databases require secondary search index databases to handle metadata queries and count operations effectively.

Matt holds his own ▶ 14:45 Directing discussion to founding background

Matt Turck guides the session from technical lecture into operational background by asking Maida specific questions about Uplevel Security's origin.

the scores for every segment, with the reasoning behind each
ChapterTopicMatt as informed peerGuest teachingGuest disagreementMatt pushing backWhy
The Cybersecurity Data Dilemma 0410 Liz Maida presents a solo keynote on cybersecurity data overload, explaining how security vendors generate excessive disconnected alerts. The host does not speak in this segment, resulting in zero scores for host metrics.
Limitations of SIEMs and Raw Log Querying 0510 Maida details the operational friction of traditional SIEMs and raw log queries, noting analysts spend 16 hours on single email investigations. This segment continues as a presentation monologue without host participation.
Process Playbooks vs. True Intelligence 0610 Maida presents graph data structures as the optimal technical architecture to correlate cyber threats over time without fragile manual playbooks. The segment remains a monologue, keeping host scores at zero.
Uplevel Security History and Analyst Pain 2521 Matt Turck opens Q&A with general background questions before audience members ask about tech stacks and enterprise security hygiene. Maida patiently explains hybrid database architectures and human factors without any conversational hostility.

Statements from this episode (8)

Assertion Supported
Liz Maida: Akamai operates 230,000 servers processing petabytes of daily data
“Akamai, for those who don't know, actually has over 230,000 servers deployed in over 1600 networks around the world. So when we were talking about data processing, we were talking the order of petabytes on a daily basis.”
Liz Maida Jul 13, 2017 ▶ 0:48
Assertion Partly supported
Maida: The average large organization uses over 40 cybersecurity vendors
“So, on average, the average large organization has over 40 security vendors between their network analysis and things that are installed on their endpoints, and all of those security devices are actually generating alerts.”
Liz Maida Jul 13, 2017 ▶ 2:37
Assertion Not checkable as stated
Maida: Over 90% of enterprise cybersecurity data goes completely unused
“There's far too much data, and actually the majority of it, you know, greater than 90%, Isn't actually used at all.”
Liz Maida Jul 13, 2017 ▶ 3:41
Assertion Not checkable as stated
Maida: Security teams average 16 hours investigating potentially malicious emails
“On average it can take them 16 hours to investigate a potentially malicious email.”
Liz Maida Jul 13, 2017 ▶ 5:44
Insight
Maida: Playbook automation speeds up alerts without improving threat intelligence
“That's not actually solving the underlying problem, right? You might be processing alerts faster, but you're not getting any smarter or learning more about the attacks that you've seen.”
Liz Maida Jul 13, 2017 ▶ 6:43
Insight
Liz Maida: Cybersecurity is an ideal use case for graph data structures
“Cybersecurity in many ways is almost the absolute ideal use case for a graph data structure.”
Liz Maida Jul 13, 2017 ▶ 9:09
Assertion Not checkable as stated
Maida: Cybersecurity analysts waste significant time on manual copy-paste queries
“The gap in the technology that they have today means that that's not how they're actually spending a lot of their time. Like a lot of their time is actually copying and pasting things to see if they're on a known bad list or running who is queries and the like…”
Liz Maida Jul 13, 2017 ▶ 15:52
Insight
Maida: Graph databases excel at relationships but struggle with metadata and counts
“While the graph databases are really efficient and really good at storing the relationships between the various entities, they are not as good at doing things like storing additional metadata or quickly retrieving counts and the like.”
Liz Maida Jul 13, 2017 ▶ 16:40
Made with StarZero

Turn any episode into a week of clips.

This entire site, over 400 conversations transcribed, diarized, checked and made playable, runs on the StarZero media pipeline. Drop in your own episode and the podcast clipper finds the moments worth sharing, cuts them, captions them, and reframes them for every feed.