Martin Yarborough

Martin Yarborough is an IT executive and cybersecurity consultant with more than 15 years of experience leading cybersecurity, enterprise technology, and digital transformation initiatives across education, government, and commercial organizations.

As Principal Consultant and Owner of Martin Yarborough & Associates LLC and its cybersecurity practice, Beacon One Services, Martin helps organizations develop practical, cost-effective approaches to improving their cybersecurity posture. His work includes vulnerability management, SIEM and security monitoring, penetration testing, cybersecurity risk assessments, incident response, phishing simulations, security awareness training, and alignment with frameworks including NIST 800-53.

Martin specializes in helping organizations turn complex technical findings into actionable security strategies that technology leaders and executives can understand and implement. His approach combines hands-on technical experience with strategic IT leadership, focusing on building measurable cybersecurity programs that improve visibility, reduce risk, and remain practical for organizations with limited resources.


Session

10-23
14:30
45min
Cyber Monitoring: From Vulnerability to SIEM
Martin Yarborough

Cybersecurity monitoring is often treated as a collection of separate activities—vulnerability scanning, endpoint monitoring, log collection, SIEM alerting, and security assessments. The result can be an abundance of security data without a clear understanding of what actually represents risk.

This session presents a practical approach to building an integrated cybersecurity monitoring program that connects vulnerability discovery with endpoint visibility and SIEM monitoring. We will examine how external and internal vulnerability scanning, endpoint vulnerability detection, security-event collection, and SIEM analysis complement one another—and, equally important, where each technology has visibility gaps.

Attendees will learn how to move beyond periodic vulnerability reports and isolated security alerts toward a continuous monitoring model that answers three fundamental questions: What is vulnerable? What is happening now? And what requires action?

Using practical examples and lessons learned from real-world monitoring environments, the session will demonstrate how organizations of varying sizes can develop meaningful security visibility without creating an unmanageable volume of alerts, reports, and data.

Walnut