2025 Active Adversary Report
June 11th 2025 - 12:30p ET
June 11th 2025 - 12:30p ET
What happens after attackers breach a company? Knowing the adversary’s playbook, after all, helps defenders better battle an active attack. Join John Shier, from Sophos, as he explores the data collected and ultimately presented as the Sophos Active Adversary Report.
Key takeaways will include:
Differences between MDR and IR findings show, quantitatively, the statistical value of active monitoring
Compromised credentials continue to lead to initial access; MFA is essential
Dwell time drops (again!)
Attacker abuse of living-off-the-land binaries (LOLBins) explodes
Remote ransomware poses a unique challenge / opportunity for actively managed systems
Attack impacts contain lessons about potential detections
John Shier is a Field CISO Threat Intelligence with more than two decades of cybersecurity experience. He’s passionate about protecting organizations from advanced threats, and has researched everything from ransomware to illicit dark web activity, uncovering insights needed to strengthen proactive cybersecurity defenses.
John works with Sophos X-Ops researchers and incident responders around the world to understand the latest trends and criminal behaviors. John is the principal researcher and author of the Sophos Active Adversary report which helps advance the industry's understanding of evolving threats, attacker behaviors and tooling, and effective security defenses. Having worked as a defender and in sales engineering roles earlier in his career, has enabled him to help organizations design enterprise-scale defense strategies and consult on security planning with some of the largest global brands.
Based in Toronto, John is often consulted by press, and has been quoted in publications like Reuters, WIRED, Fortune, CNN, The Hill, Fast Co, The Times, and more. He’s been a speaker at many industry events including RSA Conference, Infosec, Gitex, Security BSides, and more.
John likes to spend his free time with his family and playing hockey, running, scuba diving, and playing music. John is also available on LinkedIn and Mastodon.