Guide | A CISO Guide to MDR/MPR | Check Point Software
Guide | A CISO Guide to MDR/MPR
A CISO GUIDE TO MANAGED DETECTION RESPONSE/MANAGED PREVENTION RESPONSE
In cyber security, you no longer choose your battles. New, sophisticated cyber attacks can dictate your cyber security strategies. As attacks become more advanced, the security practices that may have worked in the past can have diminishing returns. The security practices that may have worked in the past can have diminishing returns. As per Gil Shwed, the founder, and CEO of Check Point, “You don’t pick your battles, they pick you,” in speaking of the turnaround in the cyberthreat world. Attackers decide what you need to deal with.
Against this landscape, your best cyber security is a solution that offers a comprehensive platform, protecting your organization against a wide spectrum of attacks. As a CISO, you no longer have the luxury of allocating security resources to target your biggest perceived threats. There are too many advanced attacks that can bring your operations to a halt for you to focus on isolated threat types.
Prevention and Detection Go Together
Acting on security alerts is a common practice and a necessity. However, the high volume of attacks can overwhelm your on-premise security team, threatening the ability to respond and remediate. Third-party services play a valuable role to offload alert activities and provide other functions to your security operations centers (SOCs). These services use varying models to address alert overload, which can upgrade an organization’s security posture.
Healthcare organizations were a hard-hit cyberattack target in 2022. The average organization now uses 82 different tools, and even the most experienced staff can find it difficult to manage the steady stream of alerts they produce. MDR can provide nonstop coverage to help teams optimize their solutions.
Too many alerts, not enough time
In a recent study, 79% of respondents reported having more than 500 cloud-security alerts open each day. Since it can take up to 30 minutes to investigate each alert, the negative impact on security and staff is tangible. Likewise, the 2022 Devo SOC Performance Report cited information overload and growing workloads as a main factor in worker burnout. The need for outsourcing is a foregone conclusion.
Advantages and Disadvantages of Different Models for Incident Response
Third-party services offer different models for security-event detection and response.
- Security Information and Event Management (SIEM) is a legacy model that offers in-house staff tools to monitor security events. SIEM is detection without response.
- Managed Security Service Providers (MSSP) might support incident response, but they have concerns:
- Most organizations spend more time on security after hiring an MSSP.
- MSSP’s specializing in technology offer minimal incident response and forensics, plus they might not know how your internal systems work.
- MSSP remote admin tools to access customer systems can be compromised.
For better alternatives, Managed Detection and Response (MDR), Managed Prevention and Response (MPR), Extended Detection and Response (XDR), and Extended Prevention and Response (XPR) have come into play.
Managed Detection Response and Managed Prevention Response
MDR’s detection model is built on the fact that to support desired service levels, most security controls permit threats to enter an organization’s environment while security teams analyze traffic for threats. When the detection system discovers a suspicious event, it issues a valid alert or a false positive. However, real attacks are already inside the environment. The MDR’s staff must stop the attack, do forensic analysis to discover the extent of damage, then mitigate damage. In contrast, preventing threats from entering the IT environment is more efficient by minimizing alerts and preventing damage requiring forensic analysis and remediation. Managed Prevention Response (MPR) vendors lead with prevention for less costly labor.
Extended Detection and Response
Augmenting MDR/MPR, extended detection response/extended prevention response (XDR/XPR) identifies threats already inside an organization’s environment. Whereas XDR emphasizes detection, XPR emphasizes preventing threats from spreading by continuously analyzing threat data from all security enforcement points. Like MPR, XPR minimizes forensics and remediation costs.
Five recommendations for choosing an MDR/MPR, XDR/XPR provider
- Does the MDR/MPR provider lead with prevention or only detection?
Prevention means stopping attacks outside your IT environment. Utilizing AI, behavioral analysis, and even chip-level threat analysis is necessary for your MDR/MPR’s security stack to recognize new, unknown threats and minimize false positives. - How complete is security coverage?
In this new space, some vendors specialize in endpoint detection response (EDR) while others specialize in cloud detection response. Using a patchwork of specialty vendors will fragment security. - What expertise does the SOC staff possess?
An MDR/MPR’s staff should be intimately familiar with advanced cyber security and how it applies to your specific environment. - What is automation and AI’s role?
Another way an MDR/MPR vendor can improve security while saving operating costs is to automate threat prevention and other operations. - For big threat data, size matters
Having big data on threats is critical for top-tier MDR/MPR vendors as it is necessary for preventing known threats.
Conclusion
Vendors who provide MDR/MPR and XDR/XPR services are improving the effectiveness of their customers' cyber security by helping them respond to high-volume alerts from cyber attacks.