Jason Chan has 26 minutes to shut down a hacker hidden in plain sight (Live Tabletop Exercise)
What do you do when an attacker doesn’t break into your network, but simply walks in by turning your own multi-factor authentication against you? In this episode of The Tabletop, Jason Chan takes the hot seat and works the problem in real time.
Jason spent over a decade building and leading Netflix’s information security team, an organization that became as well known for giving back to the security community as it was for protecting one of the world’s most-watched platforms: 30-plus open source releases, a long run of conference talks, and a genuine belief that a rising tide lifts all boats. Before Netflix, he ran security at VMware and cut his teeth in consulting. If anyone knows what a real incident looks like from the inside, it’s him.
In this episode, host Khush Kashyap drops Jason into the following scenario: He’s roleplaying the CISO at Clustrd, a 30,000-person tech company with a 107-person security team. Mid-afternoon on a Thursday, a marketing employee sends him a screenshot. Someone has posted in a company-wide Slack channel, 800 members strong, claiming they have access to Clustrd’s internal systems, with a shot of the admin dashboard as proof. The monitoring stack shows zero alerts. The access logs tell a different story: a contractor account, logged in through a legitimate remote-access tool, session still live. The way in wasn’t an exploit or malware, just an attacker spamming the contractor with MFA prompts until fatigue did the rest. Across escalating injects, the intruder moves laterally through a forgotten production script with hard-coded credentials and no owner, and Jason has to scope a breach he cannot fully see.
Jason walks through out-of-band communications when your own Slack is compromised, the cost-benefit of watching a live intruder versus cutting the session, the security archeology of tracing an unowned script, and the quiet regulatory risk of logs that were never retained. Along the way, he makes the case that the real work - the trust with engineering, the identity hygiene, the discipline not to overload users until they reflexively click approve - happens long before the incident does. At the end, he renders his verdict: real incident or constructed fiction?
The Tabletop is by Vanta, the leading Agentic Trust Platform helping security leaders manage compliance, reduce risk, and prove their programs work—before the incident, not after. Learn more about Vanta: bit.ly/44IhpUQ
Quotes
“The adversary used essentially legitimate, authorized access to do unauthorized things.”
“Sometimes our security controls get used against us.”
“Archeology is part of our jobs, figuring out what this thing does.”
“If you can limit the number of systems somebody can access, you’re going to almost by definition control the blast radius before anything happens.”
Time Stamps
[00:00] Welcome to The Tabletop: Meet Jason Chan and Today's Scenario
[01:01] The Rules: CISO at Clustrd, a 30,000-Person Company with a 107-Person Security Team
[01:31] Inject One: A Slack Post Claims Access to Clustrd's Internal Systems
[03:07] They Didn't Break In, They Walked In: MFA Fatigue and the Contractor Account
[07:56] The Attacker Wants You to Know: Going Public in Your Own Slack
[08:40] Forced Choice: Coordinating a Response When Slack Is Compromised
[08:40] Building a War Room You Can Actually Trust
[09:53] Inject Two: A Forgotten Production Script with Hard-Coded Credentials
[10:06] Two Fires at Once: A Live Session and an Unknown Blast Radius
[14:23] Inject Three: A Reporter Calls and the Clock Goes Public
[15:19] Scoping a Breach Without Evidence: Four Services You Can't Account For
[16:40] Accessed or Compromised? Why the Distinction Matters
[20:02] Two Weeks Later: The One Decision That Set Clustrd on This Path
[20:46] The Moment of Truth: Real Incident or Fiction?
[21:18] Off the Table: The Control Employees Treat as a Formality
[23:13] The Lesson the Industry Still Hasn't Absorbed
[25:28] Security for AI, AI for Security: What Jason Watches Now