We Didn't Have a Patch: How Defence in Depth Saved Our Customers from Log4Shell
In December 2021, we had the Log4J / Log4Shell Zero day
This isn't a talk about Log4Shell itself. It's the story of how an customers application was initially compromised but protected from exploit success before a patch was deployed, not because we predicted the vulnerability, but because years earlier we'd implemented a layered security approach based on default-deny principles.
The technology has changed since 2021. The principles haven't.
This talk focuses on why good engineering decisions made months or even years earlier can dramatically reduce risk when the next zero-day arrives.
I'll walk through a real customer incident from the perspective of an MSP responsible for protecting small and medium-sized businesses. Using anonymised evidence from the event—including firewall logs and the customer timeline—we'll examine how multiple independent security controls worked together to reduce exposure before patches could be deployed.
points ill make >
Why "default deny" is a security philosophy rather than a firewall setting.
Defence in depth and why every layer matters.
Reputation filtering and IPS working together.
Why egress filtering deserves more attention.
Lessons learned (and not learned) from responding to a global zero-day.
Why small engineering decisions made years before can have a huge impact during a crisis.
This session is aimed at MSP engineers, system administrators, blue team defenders and anyone responsible for security
Attendees willl leave with some ideas of how to improve security
Simon Wilks is Technical Director at Emerald IT, a UK-based Managed Service Provider specialising in Microsoft 365, Azure and cyber security for small and medium-sized businesses.
With over 30 years' experience in IT, Simon spends most of his time investigating security incidents, designing layered security solutions and helping organisations improve their cyber resilience.
This is his first conference talk.
LinkedIn: https://www.linkedin.com/in/wilmerism/