Detection Engineering 101 : Establishing a Structured Approach to Detection Engineering @FIRSTdotorg
Detection Engineering 101 : Establishing a Structured Approach to Detection Engineering  @FIRSTdotorg
Uploaded August 2025 | Updated September 2026, 6 minutes ago
Tomohisa Ishikawa (Tokio Marine Holdings, JP)

Tomohisa is a Distinguished Cyber Security Architect at a global insurance company, bringing a wealth of expertise across diverse domains of cybersecurity. His professional experience spans global security strategy, security architecture, detection engineering, security operations, threat intelligence analysis, and digital forensics and incident response (DFIR). He has also been involved in red teaming and delivering security training. Tomohisa holds a Doctor of Engineering degree and a broad array of industry-recognized certifications, including CISSP, CSSLP, CCSP, CISA, CISM, CDPSE, and PMP.

Beyond his corporate responsibilities, Tomohisa has made significant contributions to the cybersecurity community. He has served as a speaker, a Cybersecurity Expert Advisor to the Ministry of Internal Affairs and Communications (MIC) in Japan, and a member of the national IT exam committee. He is also a translator and author. Tomohisa has spoken at international conferences such as SANSFIRE 2011 & 2012, DEFCON 24 SE Village, and FIRSTCON23, as well as numerous domestic conferences in Japan. As an author, he has written a book on threat intelligence in Japanese and translated seven security books published by O'Reilly Japan.
Detection Engineering (DE) is a vital aspect of modern cybersecurity operations, aimed at enhancing detection and response capabilities to address the ever-evolving threat landscape. This session presents a structured approach to DE, centered around the Detection and Response Development Lifecycle (DR-DLC) and supported by key frameworks and methodologies. These include the three techniques for improving detection capabilities, the HOPE framework, the VECTOR framework, the 3M+C framework, and three essential metrics (Time, Efficiency, and Coverage) for evaluating and managing an effective DE program. Together, these tools and processes enable a systematic approach to conducting DE and building a robust program.The key takeaway for attendees is a set of actionable strategies and thought toolbox to implement and refine DE practices. Participants will gain practical insights into structured processes and standardized methodologies, equipping them to enhance their organization's detection engineering capabilities effectively.
Detection Engineering 101 : Establishing a Structured Approach to Detection EngineeringThe CVE Program Quality Era: Strengthening Trust and Impact In Global Vulnerability DataFragile by Design: Large-Scale Evidence of Supply Chain RiskFriday Keynote Address - Network Security is a Team Sport, so How Do We Set and Manage the TeamVulnerabilities Without CVEs: Governing the Dark Matter of Internal and Unknown SoftwareEpisode 61: Chris Butera, CISA, FIRSTCON26 Speakernx Compromise - AI as an Attack VectorAutomating CNA CVE Reporting and Monthly Bulletins at AtlassianClosing RemarksArtemis: How CERT PL Improves the Security of the Polish InternetImproving Security Across Nations with FIRST: Carlos Leonardo, FIRST Board of Directors MemberOne Poisoned Artifact Can Steer Your AI: How Robust Are Your LLM-Assisted Security Workflows?
FIRST |

Detection Engineering 101 : Establishing a Structured Approach to Detection Engineering

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER