Uploaded August 2025 | Updated September 2026, 6 minutes ago
Tomohisa Ishikawa (Tokio Marine Holdings, JP)
Tomohisa is a Distinguished Cyber Security Architect at a global insurance company, bringing a wealth of expertise across diverse domains of cybersecurity. His professional experience spans global security strategy, security architecture, detection engineering, security operations, threat intelligence analysis, and digital forensics and incident response (DFIR). He has also been involved in red teaming and delivering security training. Tomohisa holds a Doctor of Engineering degree and a broad array of industry-recognized certifications, including CISSP, CSSLP, CCSP, CISA, CISM, CDPSE, and PMP.
Beyond his corporate responsibilities, Tomohisa has made significant contributions to the cybersecurity community. He has served as a speaker, a Cybersecurity Expert Advisor to the Ministry of Internal Affairs and Communications (MIC) in Japan, and a member of the national IT exam committee. He is also a translator and author. Tomohisa has spoken at international conferences such as SANSFIRE 2011 & 2012, DEFCON 24 SE Village, and FIRSTCON23, as well as numerous domestic conferences in Japan. As an author, he has written a book on threat intelligence in Japanese and translated seven security books published by O'Reilly Japan.
Detection Engineering (DE) is a vital aspect of modern cybersecurity operations, aimed at enhancing detection and response capabilities to address the ever-evolving threat landscape. This session presents a structured approach to DE, centered around the Detection and Response Development Lifecycle (DR-DLC) and supported by key frameworks and methodologies. These include the three techniques for improving detection capabilities, the HOPE framework, the VECTOR framework, the 3M+C framework, and three essential metrics (Time, Efficiency, and Coverage) for evaluating and managing an effective DE program. Together, these tools and processes enable a systematic approach to conducting DE and building a robust program.The key takeaway for attendees is a set of actionable strategies and thought toolbox to implement and refine DE practices. Participants will gain practical insights into structured processes and standardized methodologies, equipping them to enhance their organization's detection engineering capabilities effectively.
Tomohisa Ishikawa (Tokio Marine Holdings, JP)
Tomohisa is a Distinguished Cyber Security Architect at a global insurance company, bringing a wealth of expertise across diverse domains of cybersecurity. His professional experience spans global security strategy, security architecture, detection engineering, security operations, threat intelligence analysis, and digital forensics and incident response (DFIR). He has also been involved in red teaming and delivering security training. Tomohisa holds a Doctor of Engineering degree and a broad array of industry-recognized certifications, including CISSP, CSSLP, CCSP, CISA, CISM, CDPSE, and PMP.
Beyond his corporate responsibilities, Tomohisa has made significant contributions to the cybersecurity community. He has served as a speaker, a Cybersecurity Expert Advisor to the Ministry of Internal Affairs and Communications (MIC) in Japan, and a member of the national IT exam committee. He is also a translator and author. Tomohisa has spoken at international conferences such as SANSFIRE 2011 & 2012, DEFCON 24 SE Village, and FIRSTCON23, as well as numerous domestic conferences in Japan. As an author, he has written a book on threat intelligence in Japanese and translated seven security books published by O'Reilly Japan.
Detection Engineering (DE) is a vital aspect of modern cybersecurity operations, aimed at enhancing detection and response capabilities to address the ever-evolving threat landscape. This session presents a structured approach to DE, centered around the Detection and Response Development Lifecycle (DR-DLC) and supported by key frameworks and methodologies. These include the three techniques for improving detection capabilities, the HOPE framework, the VECTOR framework, the 3M+C framework, and three essential metrics (Time, Efficiency, and Coverage) for evaluating and managing an effective DE program. Together, these tools and processes enable a systematic approach to conducting DE and building a robust program.The key takeaway for attendees is a set of actionable strategies and thought toolbox to implement and refine DE practices. Participants will gain practical insights into structured processes and standardized methodologies, equipping them to enhance their organization's detection engineering capabilities effectively.










