
SysteCom was proud to participate in the ISC2 Hellenic Chapter’s end-of-year event, “Staying prepared: Managing incidents and beyond”, an insightful gathering that brought together cybersecurity professionals to discuss how incident response (IR) must evolve in today’s highly interconnected environments.
During the event, Nikos Niskopoulos, Chief Operations Director at SysteCom S.A., shared practical insights on Incident Response in Hybrid Environments, focusing on how organisations can effectively detect, respond to, and recover from incidents across on‑premises, cloud, DevOps, OT, and AI-driven ecosystems.
Below are the key takeaways from the session.
Hybrid Environments Are the New Normal
Modern organisations no longer operate within clearly defined boundaries. Today’s environments are hybrid by default, combining:
- On‑premises infrastructure and Active Directory
- Cloud and SaaS platforms
- DevOps and CI/CD pipelines
- OT, ICS, and IoT systems
- AI-enabled tools and internal agents
While on‑prem infrastructure is still relevant, it is now just one part of an expanded and highly interconnected attack surface. As a result, incident response strategies must extend far beyond traditional perimeter-based thinking.
Attackers Follow the Path of Least Resistance
One of the most important messages of the presentation was that attackers rarely start with advanced exploits. Instead, they:
- Exploit legitimate credentials
- Abuse low-privileged accounts
- Move laterally across DevOps, cloud, and on‑prem systems
- Pivot into production and, in some cases, OT environments
Recent data shows that only a small percentage of breaches begin with vulnerability exploitation. The human element—phishing, credential theft, and social engineering—remains the dominant entry point.
DevOps, Cloud, and AI: The Biggest Blind Spots
Traditional SOC visibility often focuses on endpoints and on‑prem identity systems. However, some of the most critical risks today lie elsewhere:
- Compromised developer identities using legitimate access
- Abuse of CI/CD runners and automation
- Long-lived tokens and service accounts
- Silent exfiltration of entire code repositories
- Theft of proprietary AI training data
- Prompt injection and manipulation of AI agents
In real-world incidents, attackers have compromised entire DevOps environments and intellectual property without triggering a single alert.
AI Expands Both Capability and Risk
AI adoption is accelerating innovation—but also expanding the attack surface. Emerging risks include:
- Internal AI agents accessing sensitive data
- Leakage of system prompts and training datasets
- Shadow AI development without security oversight
- Custom AI-powered DevOps tools creating unmonitored access paths
Attackers are already leveraging AI for advanced phishing, deepfakes, and automated reconnaissance, while defenders often lack the visibility needed to detect abuse of AI systems.
Visibility Is the Foundation of Effective Incident Response
A recurring theme of the session was that you cannot respond to what you cannot see. Effective IR in hybrid environments requires unified visibility across:
- Cloud audit logs (compute, storage, networking, APIs)
- DevOps telemetry (pipelines, repositories, runners, deployments)
- Endpoint detection and response data
- OT network traffic and anomalies
- AI agent interactions and data access
- Secrets, tokens, and service account usage
Many SIEM platforms do not natively understand DevOps or AI-related telemetry, making custom parsing and detection engineering essential.
Incident Response Must Go Beyond Traditional Pentesting
Classical penetration testing alone is no longer sufficient. Modern organisations must adopt:
- Continuous threat emulation
- Purple team exercises to validate detections
- Attack path assessments across cloud, DevOps, OT, and AI systems
The true risk is not the compromise of a privileged account, but the undetected theft of intellectual property or manipulation of the pipelines that produce it.
Incident Response Is an Organisational Capability
Effective incident response today is not just a technical process—it is an organisational capability that spans people, processes, and technology. Key building blocks include:
- Unified, cross-domain visibility
- Advanced detection engineering tailored to hybrid threats
- Continuous validation through simulations and purple teaming
- Deep technical expertise across multiple environments
- Documented attack paths and interconnections
- Cross-environment incident response playbooks
Closing Thoughts
The session highlighted a critical shift in cybersecurity thinking: the question is no longer if an incident will occur, but whether organisations can detect it early, before attackers move silently across DevOps, cloud, on‑prem, OT, and AI systems.
At SysteCom, we remain committed to helping organisations build resilient incident response capabilities that reflect the reality of today’s hybrid and AI-driven environments—moving beyond compliance and toward true cyber resilience.
