Enhancing Incident Response with AWS CIRT, MSSPs, and ISVs @FIRSTdotorg
Enhancing Incident Response with AWS CIRT, MSSPs, and ISVs  @FIRSTdotorg
Uploaded August 2025 | Updated September 2026, 5 hours ago
Matthew Gurr (Full Membership via Amazon, AU), Lindsey Henry (AWS, US)

Matt Gurr is a Senior Security Engineer with the AWS Global Services Security Organisation. In his role, Matt is responsible for a team of incident responders that assist customers during active security events on the customer side of the shared responsibility model. The team is made up of Senior Security Engineers and Solution Architects with experience in performing incident response in AWS. Prior to joining AWS, Matt brings over 25 years of experience in security roles in the banking and finance, government and defense industries. Matt holds a master's degree in Information Technology from Queensland University of Technology (QUT), and industry certifications from ISC2, ISACA, SABSA and SANS organisations. In his spare time, Matt enjoys being outdoors with family and cycling.

Lindsey Henry is the Head of the AWS Customer Incident Response Security Operation Team. In this role he is responsible for leading a team of geographically distributed AWS Security Engineers to build and operate product-led, people-powered security incident response (IR) service that directly support customers experiencing active security events. Lindsey joined AWS in 2020 after serving as the Chief Information Security Officer within elements of the US Department of Defense and 23 years in the United States Navy as a Cryptologist and Information Systems Officer. He has earned a B.S in Information Systems, MS in Digital Forensics and Cyber Investigations and MBA from Grand Canyon University in Phoenix, AZ. Lindsey currently resides in Austin, Texas in the United Stated.
--
AWS strategically partners with Managed Security Service Providers (MSSPs), Independent Software Vendors (ISVs), National Computer Security Incident Response Teams (CSIRTs), and other agencies to amplify and enhance its security and incident response capabilities. This global ecosystem leverages AWS's robust cloud infrastructure while incorporating specialized security expertise and innovative software solutions developed by partners. MSSPs can offer managed security services, continuous monitoring, and rapid incident response, complemented by ISVs who create the cutting-edge security tools and integrations tailored for AWS customer environments. National CSIRTs and other agencies contribute their unique insights and capabilities to this collaborative framework. Together, these partnerships form a comprehensive security ecosystem that addresses evolving threats, ensures compliance, and enables rapid threat detection and mitigation. This multi-faceted approach empowers organizations with robust, highly scalable security solutions, expert management, and seamless integrations, significantly bolstering a customers' overall security posture in the cloud.
Enhancing Incident Response with AWS CIRT, MSSPs, and ISVsEpisode 55: Merike Kaeo, FIRSTCON26 Program ChairProactive EDR Against Adaptive Evasion: Countering Self‑Modifying Agentic MalwareProduction Is the New Attack Surface: Why Post-Deployment Endpoint Detection Is Now CriticalOROCHIFY - An Assist to Product Developers in Manufacturing Industry to Find VulnerabilitiesRemediation-Aware Reachability: Patching Containers, Prioritizing with Agentic-CTI, and Scaling...Threat Hunting with Python & PandasEpisode 56: Mor Weinberger and Lior Kaplan, FIRSTCON26 SpeakersBuilding a Regional ISAC for West Africa that Works: Governance, Tools and Community MaturityThe EUs Cybersecurity Resilience Act (CRA) has Begun – How Can Manufacturers Confidently Addres ...Chaos Stack: Designing Layered Tabletop Exercises for Complex Crisis Simulation99 Bottles of Trust on the Wall: Approaches to Building Convivial Communities
FIRST |

Enhancing Incident Response with AWS CIRT, MSSPs, and ISVs

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER