Detection Is Not the Problem. Selection Is
Threat Detection and Response Keynote Speaker
Most organisations do not have a detection problem. They have a selection problem. The signal is usually in the console already, sitting underneath everything else that fired that morning. Mark Lynd covers what separates teams that find the one that matters from teams that find it three weeks later. He also covers what changes now that both sides of that contest have AI.
Live on stage · International keynote
Quick Answer
Most organisations do not have a detection problem.
Keynote Topics
Volume Is Not the Problem. Selection Is
Adding a detection source rarely helps and often hurts. Mark covers how mature teams decide what to look at, what to suppress, and how they know the suppression is safe.
Best for: Security operations events, CISO summits
Duration: 45 minutes
The Gap Between Detection and Response
An alert becomes an incident through a human decision, and that step is where hours disappear. Mark covers escalation authority, thresholds and the handoff that most runbooks leave undefined.
Best for: Security conferences, SOC and MSSP audiences
Duration: 45 minutes
What AI Actually Does in the SOC
Triage, enrichment and summarisation are working. Autonomous containment is not, yet, and the reasons are instructive. Mark is specific about where a team gets hours back this quarter.
Best for: Security operations events, technology conferences
Duration: 45 minutes
Buying Detection Without Buying a Second Problem
The tooling market rewards coverage claims. Mark covers what to test during evaluation, the questions vendors dislike, and how to avoid a stack nobody can operate.
Best for: CISO audiences, procurement and technology leadership
Duration: 45 minutes
Detection for Teams of One or Two
For organisations without a security operations centre. What to monitor, what to outsource, what to ignore, and the small number of detections that carry most of the value.
Best for: Public sector, education, mid-market and association events
Duration: 45 minutes
When the Alert Was There All Along
Post-incident reviews almost always find the signal was present. Mark covers why it was missed, which is rarely incompetence and usually structure, and what to change so it is caught next time.
Best for: Security leadership events, risk audiences
Duration: 45 minutes
I don't give speeches. I bring the view from the frontlines, what I'm actually seeing this quarter running enterprise AI and cybersecurity programs and advising boards, so your audience leaves with something real.
Mark Lynd, 5x CEO/CIO/CISO, Head of Executive Advisory & Strategy at Netsync
Why Mark on this subject
A 5x CEO, CIO and CISO who has owned detection and response outcomes, including the budget and the staffing.
Ranked number one globally in Cybersecurity by Thinkers360 in 2023, and CISSP, ISSAP and ISSMP certified by ISC2.
More than 150 executive incident response tabletop exercises, which repeatedly show the detection to response handoff as the point of failure.
Works at the AI and security intersection daily, so the question of what AI does in the SOC gets an answer grounded in deployments rather than product marketing.
Currently Head of Executive Advisory and Strategy at Netsync, which keeps the tooling view current.
Publishes Hype Check Now and Hype Check Live, both built on separating capability from claim.
Will discuss technology categories and their limits openly, without endorsing products from the stage.
Speaker Reel
Watch Mark on Stage
A sampling of keynotes, panels, and live broadcast appearances, RSA, Oracle CloudWorld, Dell Technologies World, ESPN College Football Awards, and the Technology Ball.
What Audiences Say
Feedback From Event Hosts and C-Suites
Mark stands apart. His credibility isn’t rooted in a title from years ago, it’s built through the work he’s doing every day in the field. When he speaks about our technology, enterprise buyers pay attention because they know his perspective is grounded in real-world experience.
Shira Rubinoff
CEO, The Cybersphere Group
Mark delivers more than a presentation, he delivers operational insight from the front lines. Instead of theory, he shares what is actually working in real environments. Our audience of CISOs and security leaders left with practical strategies they could begin implementing immediately.
Jo Peterson
CIO, Clarify360
Where Has Mark Spoken?
According to venue records, Mark has delivered keynotes at: RSA Conference · Oracle CloudWorld · Cisco Partner Summit · Dell Technologies World · IBM Think · T-Mobile Events · Gartner Security & Risk · InfoSecurity · ISACA Conferences · ISSA Events · Cloud Security Alliance · CyberSecurity Summit · BSides · FLGISA · MISAC · SMU Cox School of Business · and 100+ more.
How Do You Book Mark Lynd for Your Event?
The booking process is straightforward and typically completes within 3 business days. Mark customizes every keynote to the audience, industry, and event objectives.
- Submit an inquiry. Fill out the contact form with your event date, audience, and objectives. Response within 48 hours.
- 15-minute discovery call. Discuss your event in detail, including audience makeup, key messages, and desired outcomes.
- Proposal & contract. Receive a tailored proposal with format options (keynote, workshop, panel), fee, and travel terms.
- Customization. Mark customizes content to your audience, industry examples, and desired takeaways.
- Expert delivery. Mark brings 25+ years of real-world executive experience to every stage.
Frequently Asked Questions
Is this a technical talk?
Do you recommend specific tools?
How does this differ from the incident response talk?
We already have a managed detection provider. Is this still relevant?
Does he cover threat hunting?
Can he look at our detection coverage?
Is AI going to replace the SOC analyst?
Ready to Book Mark?
Mark customizes every keynote to the audience, industry, and event objectives. Contact the booking team to check availability.
600+ projects, keynotes, panels and workshops · audiences from 50 to 5,000+
Formats: In-person, virtual, hybrid · international available
Duration: 30–120 minutes depending on format
Custom by event · educational pricing available