Become a partner

Resolving security incidents in an enterprise environment (7 min)

Lukáš Hlavička - Technical Director, IstroSec ·

Incident response (IR) in an enterprise environment is no longer just about “putting out fires.” This presentation will show a proven framework for preparing your organization for attacks, quickly detecting them, coordinating response across teams, and safely restoring operations—with an emphasis on metrics that reduce MTTR and minimize business impact. In the second part, we will introduce the IstroSec Gryphon tool, which complements EDR/XDR and SIEM with behavioral ransomware detection and the ability to operate in offline mode, which is key for sensitive or isolated network segments (OT/ICS, regulated environments). We will demonstrate selected features relevant to IR, including the isolation of compromised endpoints, blocking granularity (by path/file/hash), tactical use of ZTNA, real-time detection via kernel-level rules, centralized “server-side” task management, remote PowerShell/RDP/ Filemanager for rapid investigation, and integration with third parties. We will also show how Gryphon supports post-attack recovery (file recovery, VSS protection) and threat hunting over acquired artifacts.

Slovak company Istrosek has unveiled its own MDR platform, Istros Griffon, which targets primarily ransomware threats. It was created in response to expensive or unsuitable tools and to experience from incidents where attackers manage to circumvent standard EDR solutions. Griffon combines prevention, detection, response, and recovery with an emphasis on speed and reliability.

Why Istros Griffon was created

According to the Istrosek team, roughly 80 % of handled cases are still linked to ransomware, even though one often hears that its era is ending. Attackers infiltrate infrastructures via external networks, subcontractors, or a simple VPN login, and they are often detected only by active MDR monitoring "five minutes to midnight." Existing tools tend to be slow to react to new types of encryption and TTPs, and while updates make their way through the development of large vendors, victims remain vulnerable. This is why the team decided to build its own platform aimed at rapid identification and immediate response.

Read more

Sign in to ITAPA Health & Care 2026

Lukáš Hlavička

IstroSec
Lukáš Hlavička, CISSP, GCFA, GXPN is currently serving as CTO of IstroSec. Previously he served as Director of DFIR department, Director of Governmental CSIRT and Court Expert. He has more than 14 years of experience in cybersecurity including experience managing an analytical team in a European country governmental CSIRT team and after serving …

Recommendation speakers

Johanna-Kadri Kuusk

e-Estonia Briefing Centre

Vanda Tuxhorn

Head of the Department of Pediatrics and Neonatology, Landau in der Pfalz, Germany

Christian Kumar

Capital Kinetics

Lukáš Benzl

Czech Association of Artificial Intelligence
Páčil sa ti článok? Zdieľaj ho a povedz o ňom aj ostatným