MKKPRO

How do I pick the best detection & response?

Published On: 05/08/2023 Author: MKK

Confused selecting a right detection & response solution?

It takes patience, expertise, money, and effort to detect and respond to a problem. Take a look at this article to get a feel for the different options available to your company. Implementing a managed detection and response service will be easier with this guidance. In addition to service-specific recommendations for endpoint, network, or log-based detection, you’ll also see guidance on how to respond to the issue.

100% protection is neither practical nor cost-effective in the dynamic environment of today. Threats must be swiftly identified and eliminated. Based on my personal experience after deploying 27+ SOCs, 18+ detection and response solutions, and handled 12+ Ransomware recovery scenarios, I’ve prepared 4 multiple-choice questions. By responding to these questions, I can quickly assess and instantly show you which detection and response service would be the best fit for your organization’s current needs.

Note: It is assumed that some form of public cloud is already in place in your environment.

Question 1: Consider the current state of your company's security infrastructure?*

Question 1: Consider the current state of your company's security infrastructure?*

Consider the security maturity level of your business in its current state. Which of the following statements best describes your organization:

Question 2: Do you have a significant number of unmanaged devices connected to your network?*

Question 2: Do you have a significant number of unmanaged devices connected to your network?*

In your organization, even when few devices are unmanaged, that is also considered as unmanaged, so please answer accordingly

Question 3: Do you need to keep raw log data for a certain amount of time to meet regulatory requirements?*

Question 3: Do you need to keep raw log data for a certain amount of time to meet regulatory requirements?*

Are there any compliance obligations in place that necessitate the retention of raw log data for a specified duration, in other words, a legal hold?

Question 4: Could you add a new sensor to your endpoints to improve their ability to detection and response?*

Question 4: Could you add a new sensor to your endpoints to improve their ability to detection and response?*

Would it be possible to implement the installation of a sensor on the endpoints in order to enhance the capabilities of detection and response?

Leave A Comment

You cannot copy content of this page