
# Open source culture — Mandy Andress **Live from CybersecNL — Episode 5 of 7**
Recorded at the Atos booth, CybersecNL 2026. Mandy Andress is CISO at Elastic, where she has worked for eight years. She was at CybersecNL to deliver a keynote on moving security from human speed to machine speed. Hosted by Menno van der Horst with Quint Ketting. Atos and Elastic work together in several areas, including search and SOC operations. ## Timestamps 00:00 Welcome, third recording of day two 00:16 Mandy: CISO at Elastic, and why she came to CybersecNL 00:58 How Atos and Elastic already work together 01:30 Speed, trust and instinct: incidents at human speed 02:06 Processes built on human delay no longer hold 02:47 The AI-native mindset security needs 03:22 Real-time analysis, and grounding AI with context 04:21 Drinking your own champagne 05:08 Open code, public detection rules, no black box 05:50 Sharing how the security team works, not only what it ships 06:16 "If I keep it to myself, I'm safer" 06:49 Security by obscurity is dead 07:29 Isn't all that openness a risk? 08:15 Knowing your coverage and your gaps as a practitioner 09:05 Security first versus commercial reality 10:14 Eight years at Elastic, and running security on the ELK stack 11:44 "Everything is a search problem" 13:28 Deciding without information: the TU/e breach 13:56 Log4j as a search problem 14:59 The client that went looking with paper and pen 15:40 Never waste a good crisis, and a business that didn't feel the risk 16:10 What if Slammer had targeted Log4j? 16:56 Mandy's keynote: from human speed to machine speed 17:49 Security hasn't changed. The speed has. 18:40 How many agents do you run, and what access do they have? ## Key takeaways - Most security processes are built on the delays that come with human speed. Those delays are gone, and many processes need to be turned around rather than tuned. - Security by obscurity relied on attackers lacking time, imagination or capability. AI agents have all three. - Openness is a security strength. Public code and public detection rules bring in the insight of the global community. - For practitioners, transparency means knowing exactly what a product covers and where you need to augment. A black box leaves you guessing whether you are safe. - Share how you work, not only what you build. Elastic's security team publishes what works, what doesn't, and what it is still figuring out. - Security is a search problem: finding patterns in data. When Log4j hit, knowing where it ran made the difference between acting in minutes and searching by hand. - Security itself hasn't changed. The speed at which we have to act on it has. ## Mentioned Elastic — https://www.elastic.co Elastic detection rules — https://github.com/elastic/detection-rules Elastic Security Labs — https://www.elastic.co/security-labs ## Also in this series Ramsés Gallego, Kelvin Rorive, Marianne Schinkel and Aernout Reijmer — out now. Gilad Friedman on AI as an attack vector — coming next. Martin de Vries on securing different sectors — the series finale. --- SecurityCafe. Powered by Atos.
- Transcript


















