Guide | A CISO Guide to MDR/MPR | Check Point Software
A CISO Guide to MDR/MPR
In cyber security, you no longer choose your battles. New, sophisticated cyber attacks can dictate your cyber security strategies. As attacks become more advanced, the security practices that may have worked in the past can have diminishing returns. The security practices that may have worked in the past can have diminishing returns. As per Gil Shwed, the founder, and CEO of Check Point, “You don’t pick your battles, they pick you,” in speaking of the turnaround in the cyberthreat world. Attackers decide what you need to deal with.
Against this landscape, your best cyber security is a solution that offers a comprehensive platform, protecting your organization against a wide spectrum of attacks. As a CISO, you no longer have the luxury of allocating security resources to target your biggest perceived threats. There are too many advanced attacks that can bring your operations to a halt for you to focus on isolated threat types.
Prevention and Detection Go Together
Acting on security alerts is a common practice and a necessity. However, the high volume of attacks can overwhelm your on-premise security team, threatening the ability to respond and remediate. Third-party services play a valuable role to offload alert activities and provide other functions to your security operations centers (SOCs). These services use varying models to address alert overload, which can upgrade an organization’s security posture.
Healthcare organizations were a hard-hit cyberattack target in 2022. The average organization now uses 82 different tools, and even the most experienced staff can find it difficult to manage the steady stream of alerts they produce. MDR can provide nonstop coverage to help teams optimize their solutions.
Too many alerts, not enough time
In a recent study, 79% of respondents reported having more than 500 cloud-security alerts open each day. Since it can take up to 30 minutes to investigate each alert, the negative impact on security and staff is tangible. Likewise, the 2022 Devo SOC Performance Report cited information overload and growing workloads as a main factor in worker burnout. The need for outsourcing is a foregone conclusion.
Advantages and Disadvantages of Different Models for Incident Response
Third-party services offer different models for security-event detection and response. Security Information and Event Management (SIEM) is a legacy model that offers in-house staff tools to monitor security events. SIEM is detection without response. Next, adding outsourced staff gives you Managed Security Service Providers (MSSP), security monitoring and management from off-site operation centers. MSSPs might support incident response, but they have concerns:
- Most organizations spend more time on security after hiring an MSSP
- MSSPs specializing in technology offer minimal incident response and forensics, plus they might not know how your internal systems work
- MSSP remote admin tools to access customer systems can be compromised
For better alternatives, Managed Detection and Response (MDR), Managed Prevention and Response (MPR), Extended Detection and Response (XDR) and Extended Prevention and Response (XPR) have come into play.
Managed Detection Response and Managed Prevention Response
MDR’s detection model is built on the fact that to support desired service levels, most security controls permit threats to enter an organization’s environment while security teams analyze traffic for threats. When the detection system discovers a suspicious event, it issues a valid alert or a false positive. However, real attacks are already inside the environment. The MDR’s staff must stop the attack, do forensic analysis to discover the extent of damage, then mitigate damage. In contrast, preventing threats from entering the IT environment is more efficient by minimizing alerts and preventing damage requiring forensic analysis and remediation. Managed Prevention Response (MPR) vendors lead with prevention for less costly labor.
Extended Detection and Response
Augmenting MDR/MPR, extended detection response/extended prevention response (XDR/XPR) identifies threats already inside an organization’s environment. Whereas XDR emphasizes detection, XPR emphasizes preventing threats from spreading by continuously analyzing threat data from all security enforcement points. Like MPR, XPR minimizes forensics and remediation costs.
Five recommendations for choosing an MDR/MPR, XDR/XPR provider
- Does the MDR/MPR provider lead with prevention or only detection?
Prevention means stopping attacks outside your IT environment. Utilizing AI, behavioral analysis and even chip-level threat analysis is necessary for your MDR/MPR’s security stack to recognize new, unknown threats and minimize false positives. In addition, having a massive global threat intelligence network is vital for your MDR/MPR provider to prevent known threats from entering your environment. - How complete is security coverage?
In this new space, some vendors specialize in endpoint detection response (EDR) while others specialize in cloud detection response. Using a patchwork of specialty vendors will fragment security. Others claim to cover everything in the environment, while a few cover the entire environment: network, cloud, SaaS IoT, smartphones, endpoints, and the rest. For effectiveness, the best practice is to find the MDR/MPR provider offering the most comprehensive security stack, consolidated into a single architecture. - What expertise does the SOC staff possess?
An MDR/MPR’s staff should be intimately familiar with advanced cyber security and how it applies to your specific environment. The staff should also be knowledgeable in rapid response, forensics, and mitigation. - What is automation and AI’s role?
Another way an MDR/MPR vendor can improve security while saving operating costs is to automate threat prevention and other operations. Be sure to inquire about the use of automation and AI in a vendor’s stack. - For big threat data, size matters
Having big data on threats is critical to top-tier MDR/MPR vendors in two ways. First, big data on threats is critical for training AI engines to detect and block novel threats and unusual activity. Second, big data containing threat signatures is necessary for preventing known threats. It takes a large vendor to accumulate sufficient data to educate AI and block threats.
Conclusion
Vendors who provide MDR/MPR and XDR/XPR services are improving the effectiveness of their customers' cyber security by helping them respond to high-volume alerts from cyber attacks. Horizon, Check Point’s prevention-first security operations and unified management suite, offers XDR, MDR and events management solutions for complete coverage of networks, endpoints, cloud, email, and IoT. In regards to Horizon, CEO Shwed remarks, “The typical enterprise, a company anything from five hundred employees to even ten or twenty thousand employees, they simply cannot afford having what we call a security response team that will monitor the network twenty-four seven. It is expensive, but also, you cannot get the talent, there’s not enough people like that.” Conversely with Horizon, Check Point runs “one center that sees the data of hundreds of companies. By filtering the attacks from all those companies simultaneously, the Check Point sense of the threats gets sharper. It is a form of leverage that makes the task of defense more efficient. We learn from every customer.”