Guide | A CISO Guide to MDR/MPR | Check Point Software

Guide | A CISO Guide to MDR/MPR

A CISO GUIDE TO MANAGED DETECTION RESPONSE/MANAGED PREVENTION RESPONSE

In cyber security, you no longer choose your battles. New, sophisticated cyber attacks can dictate your cyber security strategies. As attacks become more advanced, the security practices that may have worked in the past can have diminishing returns. The security practices that may have worked in the past can have diminishing returns. As per Gil Shwed, the founder, and CEO of Check Point, “You don’t pick your battles, they pick you,” in speaking of the turnaround in the cyberthreat world. Attackers decide what you need to deal with.

Against this landscape, your best cyber security is a solution that offers a comprehensive platform, protecting your organization against a wide spectrum of attacks. As a CISO, you no longer have the luxury of allocating security resources to target your biggest perceived threats. There are too many advanced attacks that can bring your operations to a halt for you to focus on isolated threat types.

Prevention and Detection Go Together

Acting on security alerts is a common practice and a necessity. However, the high volume of attacks can overwhelm your on-premise security team, threatening the ability to respond and remediate. Third-party services play a valuable role to offload alert activities and provide other functions to your security operations centers (SOCs). These services use varying models to address alert overload, which can upgrade an organization’s security posture.

Healthcare organizations were a hard-hit cyberattack target in 2022. The average organization now uses 82 different tools, and even the most experienced staff can find it difficult to manage the steady stream of alerts they produce. MDR can provide nonstop coverage to help teams optimize their solutions.

Too many alerts, not enough time

In a recent study, 79% of respondents reported having more than 500 cloud-security alerts open each day. Since it can take up to 30 minutes to investigate each alert, the negative impact on security and staff is tangible. Likewise, the 2022 Devo SOC Performance Report cited information overload and growing workloads as a main factor in worker burnout. The need for outsourcing is a foregone conclusion.

Advantages and Disadvantages of Different Models for Incident Response

Third-party services offer different models for security-event detection and response.

For better alternatives, Managed Detection and Response (MDR), Managed Prevention and Response (MPR), Extended Detection and Response (XDR), and Extended Prevention and Response (XPR) have come into play.

Managed Detection Response and Managed Prevention Response

MDR’s detection model is built on the fact that to support desired service levels, most security controls permit threats to enter an organization’s environment while security teams analyze traffic for threats. When the detection system discovers a suspicious event, it issues a valid alert or a false positive. However, real attacks are already inside the environment. The MDR’s staff must stop the attack, do forensic analysis to discover the extent of damage, then mitigate damage. In contrast, preventing threats from entering the IT environment is more efficient by minimizing alerts and preventing damage requiring forensic analysis and remediation. Managed Prevention Response (MPR) vendors lead with prevention for less costly labor.

Extended Detection and Response

Augmenting MDR/MPR, extended detection response/extended prevention response (XDR/XPR) identifies threats already inside an organization’s environment. Whereas XDR emphasizes detection, XPR emphasizes preventing threats from spreading by continuously analyzing threat data from all security enforcement points. Like MPR, XPR minimizes forensics and remediation costs.

Five recommendations for choosing an MDR/MPR, XDR/XPR provider

  1. Does the MDR/MPR provider lead with prevention or only detection?
    Prevention means stopping attacks outside your IT environment. Utilizing AI, behavioral analysis, and even chip-level threat analysis is necessary for your MDR/MPR’s security stack to recognize new, unknown threats and minimize false positives.
  2. How complete is security coverage?
    In this new space, some vendors specialize in endpoint detection response (EDR) while others specialize in cloud detection response. Using a patchwork of specialty vendors will fragment security.
  3. What expertise does the SOC staff possess?
    An MDR/MPR’s staff should be intimately familiar with advanced cyber security and how it applies to your specific environment.
  4. What is automation and AI’s role?
    Another way an MDR/MPR vendor can improve security while saving operating costs is to automate threat prevention and other operations.
  5. For big threat data, size matters
    Having big data on threats is critical for top-tier MDR/MPR vendors as it is necessary for preventing known threats.

Conclusion

Vendors who provide MDR/MPR and XDR/XPR services are improving the effectiveness of their customers' cyber security by helping them respond to high-volume alerts from cyber attacks.