EPISODE · Sep 8, 2026 · 1H 18M
How Retained NetFlow Found a Five-Year APT Nobody Else Saw | Micah Czigan | EP #16
from Full Metal Packet
Micah Czigan is Chief Information Security Officer at Georgetown University and formerly served as Director of Defensive Cyber Operations at Symantec, with prior roles across the Department of Defense and Department of Energy.He came to security through an unusual path: marine biology, commercial shipping, the Navy as a cryptographic communications specialist, and eventually the Pentagon running enterprise IT.EP #16 goes inside what real incident command looks like. Not the tabletop version.The version where a junior analyst freezes at 2am with a real alert, a third-party platform dies the week of finals, an Active Directory breach lands before the new CISO walks in, and a single TCP packet quietly exfiltrates sensitive data every few days for five years.Micah doesn't clean any of it up. He walks through what happened, what failed, and what no runbook covers when the facts don't match anything you trained for.What we cover in this EP:◼ Why calm is an active leadership decision, not a personality trait◼ The real cost of a delayed 2AM escalation on a genuine government alert◼ When Canvas went down during finals week and security became business continuity◼ One university device, no MFA, Active Directory already breached before Micah arrived◼ How retained NetFlow at the DOE surfaced a five-year APT nobody else found(0:00) – Micah's path to CISO(04:56) – Leading incidents without answers(09:03) – Why tabletops alone aren't enough(11:21) – The first hour: what leaders miss(13:26) – The incident manager bridge(21:54) – Junior analyst froze, incident was real(25:37) – Building a culture of early escalation(31:15) – Should CISOs run incidents themselves?(37:53) – Canvas down during finals week(42:60) – SaaS-first with no failover(48:03) – The Georgetown Active Directory breach(50:14) – How abnormal traffic launched the investigation(54:03) – What Micah would do differently now(56:02) – Free cyber hygiene wins(57:43) – Hardware keys: who gets them first(1:04:53) – One TCP packet. Five years. Undetected.(1:09:41) – Why historical NetFlow changes everything(1:16:40) – Critical thinking over runbooks(1:25:52) – Final takeaway for security leadersGuest ⬇️Micah CziganHosts ⬇️Yegor Sak & Alex Paguis (Co-founders at Control D)Powered by Control D
Embed this episode
Ready to play
How Retained NetFlow Found a Five-Year APT Nobody Else Saw | Micah Czigan | EP #16
No transcript for this episode yet
Similar Episodes
No similar episodes found.