Andrew Lynes

Andrew Lynes

Lead Investigator
Microsoft

Andrew Lynes is a Lead Investigator with Microsoft Incident Response (Microsoft IR), where he leads complex cyber intrusion investigations — coordinating technical response activities to contain threats, determine root cause, and support organisational recovery. Delivered by Microsoft’s Detection and Response Team (DART), Microsoft IR supports customers before, during, and after cyber incidents to remove threat actors, restore systems, and strengthen long‑term resilience against future attacks.

Andrew has over 25 years of IT industry experience, including more than 20 years at Microsoft. During that time, he has held a range of technical roles including software developer, solution architect, and enterprise support engineer. Most recently he was a security architect within Microsoft Industry Solutions, where he worked with a global team of specialists to help customers modernise their security strategies using Microsoft’s security technologies.

Privileged by design: The attack paths you already built

Andrew Lynes & Alex Carr
2026-10-15 3:50 pm
2026-10-15 4:30 pm
Room 218

MFA and EDR alone cannot stop attackers who exploit administrative practices and identity workflows, the attack paths organisations already built themselves.

World-Class Speakers

Hear from the most influential leaders and experts who will discuss pressing issues and emerging trends in cyber security.

Speaker in a grey suit presenting at a lectern on stage
Woman in headphones taking handwritten notes during a session
Audience members smiling and taking photos on their phones during a session
Woman in a hijab talking with a delegate at an exhibition stand
Keynote speaker presenting on stage with a title slide behind him
Panellists seated in white armchairs on stage during a conference discussion
Woman being interviewed with a Ticker microphone on the expo floor