Пётр Куценко
Head of BI.ZONE EDR
Head of BI.ZONE EDR. Over 10 years in cybersecurity — on both the customer and vendor side.
Over 10 years in cybersecurity. Among other things, he worked at Solar and R-Vision, taking part in projects on both the customer and vendor side.
On the customer side, he designed, deployed, and administered IT infrastructure, as well as secured it. Working on the vendor side, he developed and integrated solutions that helped companies effectively protect their data and systems from modern cyber threats.
He currently heads BI.ZONE EDR — a product for protecting endpoints against sophisticated threats. Petr's team develops and refines technologies that help detect signs of suspicious activity on endpoints — servers or workstations. This makes it possible to stop attackers at an early stage — before they can develop an attack and cause damage.
Education
Kuban State Technological University (KubSTU), major in «Comprehensive Protection of Informatization Objects»
Talks and publications
Author's articles
-
EDR vs. Antivirus: What's the Difference and Which One Do You Need
EDR and antivirus solve different problems. We compare the two approaches, break down what each one detects, and explain why organizations use them together.
-
Investigating an Incident in EDR: How to Read Telemetry Without Drowning in Events
A practical breakdown of EDR incident investigation: where to start, which events matter, how to build a timeline, and where SOC analysts most often go wrong.
-
EDR vs. XDR vs. MDR: What's the Difference and Which to Choose
A breakdown of three endpoint protection classes — EDR, XDR, and MDR: architectural differences, a comparison table, and practical guidance on choosing based on SOC maturity and infrastructure type.
-
How to Choose an EDR: Criteria and Evaluation Checklist
A practical checklist for SOC analysts and security engineers evaluating EDR for corporate infrastructure — evaluation criteria, questions to ask vendors, and common pilot pitfalls.
-
Deploying EDR: Common Mistakes and How to Avoid Them
A practical breakdown of the mistakes most often seen when deploying EDR across corporate infrastructure, from the planning stage through post-production operation.
-
What Is EDR? How It Works, How It Differs from Antivirus, and How to Choose
We break down what EDR is, how endpoint protection works, how it differs from antivirus, and what criteria to use when choosing a solution.
-
Threat Hunting: Where to Start and How to Build It Into SOC Operations
We break down how proactive threat hunting differs from alert response, what you need in place before you start, and how to formulate hypotheses, document results, and build hunting into SOC shift work without hurting the current alert queue.
-
Defense in Depth: How to Build Layered Security
A cornerstone piece in the Expertise track: how seven classes of solutions — from email and endpoints to Zero Trust and GRC — combine into independent lines of defense. We cover where to start if you have no layers yet, and which mistakes cancel out the effect of even a full product lineup.
-
How GRC Helps You Prepare for an Audit
A practical breakdown of audit preparation with GRC: requirements, controls, evidence, owners, and reporting — without the spreadsheet chaos.
-
How to Build InfoSec Risk Management with GRC
This article explains how a GRC approach structures information security risk management — from initial threat identification to a risk register, metrics, and regulatory compliance.
-
What Is GRC: Governance, Risk, and Compliance Management, and How to Choose a System
We explain what GRC is, how governance, risk, and compliance connect, what tasks a GRC automation system solves, and how to choose one.
-
Protecting Against Phishing and BEC: A Checklist for Corporate Email
A practical checklist for protecting corporate email against phishing and BEC: setting up SPF, DKIM, and DMARC, filtering messages, and training employees.
-
How Email Protection Works: Filtering, Sandboxing, Anti-Phishing
Email protection works as a multi-layered pipeline — every incoming message passes through authentication checks, reputation analysis, content filtering, link analysis, and dynamic attachment inspection. This article breaks down how each of these layers works.
-
How to Choose a Corporate Email Security Solution
Choosing a corporate email security solution depends on the threat landscape, infrastructure architecture, and integration requirements. This article outlines the criteria to weigh when evaluating tools.
-
What Is Mail Security: How to Protect Corporate Email and Choose a Solution
We explain what Mail Security is, which threats it protects corporate email from, how filtering works, and what criteria to use when choosing a solution.
-
How to Grow a SOC Analyst: A Program from L1 to L2
The article outlines a growth program for SOC analysts moving from L1 to L2: how the levels differ, what to teach and in what order, how to measure readiness for on-call duty instead of just course completion, and how to retain the analyst once they've grown.
-
Why Training Your Team Is Cheaper Than Cleaning Up After an Incident
This article breaks down what makes up the cost of an incident handled by an untrained team, why a security tool delivers no effect without trained people behind it, and how to build a training program and justify the budget to leadership in the language of risk.
-
How to Roll Out PAM in Stages: A Step-by-Step Plan
A step-by-step plan for rolling out PAM: inventorying privileged accounts, secrets storage, session recording, and password rotation without downtime.
-
How to Choose a PAM Solution: Criteria and Checklist
Choosing a PAM solution determines your level of control over privileged access for years to come. We break down the key criteria and provide a practical checklist for comparing systems.
-
Recording Privileged Sessions: How It Works and Why It Matters
Session recording is PAM's functional core. We break down how session control works, what exactly the system captures, and how recordings help during incident investigations.
-
What Is PAM: Privileged Access Management and How to Choose a System
We break down what PAM is, which problems privileged access management solves, how the system works, and what criteria to use when choosing one.
-
SD-WAN vs. VPN: How the Approaches to Corporate Networking Differ
We compare SD-WAN and VPN by policy management, behavior when a channel is lost, and operational load. We give a step-by-step migration scenario with a coexistence period and a readiness checklist for the transition.
-
What Is SD-WAN: How It Works, How It Differs from VPN, and How to Choose One
We break down what an SD-WAN solution consists of, how it chooses a route and what it does when a channel degrades, which deployment scenarios and common mistakes there are. We give a self-check list and criteria for choosing a solution.
-
What Is Secure SD-WAN and Why Does Business Need It
Secure SD-WAN combines software-defined network management with security functions at the perimeter of every branch office. This article is an introductory guide for anyone considering SD-WAN as an alternative to MPLS.
-
How Secure DNS Protects Your Network from DNS Attacks
DNS traffic rarely falls under the control of security tools, even though C2 servers, droppers, and phishing domains rely on it. Here's how Secure DNS closes this gap.
-
What Is Secure DNS: DNS-Level Protection and How to Choose a Solution
We break down what Secure DNS is, how DNS-level protection blocks malicious domains and phishing, how it differs from regular DNS, and how to choose a solution.
-
ZTNA vs. VPN: What's the Difference and When to Choose Each
We compare ZTNA and VPN: how the access models differ, which risks ZTNA closes, and why these approaches aren't always interchangeable.
-
How to Implement Zero Trust in Stages
Zero Trust isn't a product or a one-off project — it's an architectural approach. This article maps out a realistic, phased path to adoption without a full infrastructure overhaul.
-
What Is ZTNA: Access Without Trusting the Network, and How to Choose a Solution
We explain what ZTNA is, how the Zero Trust Network Access approach differs from a classic VPN, and how to choose a solution for secure access.