Battle-Tested Incident Recovery: Lessons from the Front Lines @FIRSTdotorg
Battle-Tested Incident Recovery: Lessons from the Front Lines  @FIRSTdotorg
Uploaded August 2026 | Updated September 2026, 1 hour ago
Jack Hughes (Unit 42 by Palo Alto Networks, GB)

With 86% of attacks resulting in business impact, there is no one‑size‑fits‑all path to recovery. This session moves beyond theory to present battle‑tested strategies derived from Unit 42’s front‑line experience. We will dissect the critical decision‑making process between Brownfield recovery (remediating the existing estate) and Greenfield recovery (building fresh), helping you determine the right approach for your specific crisis.

Central to this approach is the Sheep Dipping methodology, a rigorous process to sanitise and verify assets. We will demonstrate how to apply this technique to secure your Minimum Viable Business, ensuring that whether you repair or rebuild, you emerge from the incident resilient and response‑ready.

---

Bringing over a decade of experience leading world-class incident response teams, Jack Hughes has had a front-row seat to the ever-evolving landscape of cyber threats. His passion lies in transforming that experience into actionable strategies that empower organisations to not only withstand attacks but emerge stronger.

His expertise spans the full spectrum of incident response, from dissecting malware to orchestrating global investigations involving forensic experts, legal teams, and crisis communication specialists. He thrives on building and leading high-performing teams, fostering a collaborative environment where technical excellence meets strategic thinking.
Battle-Tested Incident Recovery: Lessons from the Front LinesThe AI Assistant’s Betrayal: One-Click for AI to Turn into the Perfect InsiderBoosting Vulnerability Intelligence: How Accurate CWE Mappings Transform ML Model PerformanceCan a General-Purpose LLM Do Tier-1 Triage?Improving Security Across Nations with FIRST: Esmeralda Kazia, FIRST MemberThe Weaponization Gap: What 20 Million KEV Detections Reveal About Edge RemediationAztronomy: Establishing the Foundation of Attack Path Analysis in AzureImproving Security Across Nations with FIRST: Derek Manky, FIRST CORE Founding PartnerCVE/FIRST VulnCon 2026 & Annual CNA Summit Recap VideoFighting Back Without Hacking Back: Why “Risk Management” Isn’t Enough In The Era of Cyber WarThreat From The Inside: Investigate eBPF MalwareThree Musketeers: CVE, CSAF, and VEX
FIRST |

Battle-Tested Incident Recovery: Lessons from the Front Lines

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER