XDR and the Benefits of Managed Services episode artwork

EPISODE · Jan 16, 2024

XDR and the Benefits of Managed Services

from Info Risk Today Podcast · host InfoRiskToday.com

Extended Detection and Response (XDR) has evolved significantly over the past few years, becoming more critical than ever for organizations in need of enhanced capabilities. But so, too, have the accompanying managed services evolved. Port53 Technologies President Omar Zarabi explains.

Episode metadata supplied by the publisher feed · Published Jan 16, 2024

Embed this episode

NOW PLAYING

XDR and the Benefits of Managed Services

0:00 0:00
of MATCHES

TRANSCRIPT · AUTO-GENERATED

Hi there, I'm Tom Field. I'm senior vice president of editorial with Information Security Media Group. My topic of conversation today, XDR and the benefits of managed XDR. Here to talk about it with me is Omar Zarabi.

He's president and CEO of Port 53 Technologies. Omar, thanks so much for taking time to speak with me today. Definitely. Thanks for having me, Tom.

So here we are, 2024 in today's context. How do you define XDR and why would you say it's more critical than ever? I think it's important to understand that most cybersecurity in general has the most acronyms in any part of technology. So XDR is just another one of those acronyms.

The stands for extended detection in response to more of a maturation of EDR, which has been in the industry for a while. And really, at the end of the day, a lot of organizations realize that it's not just about detecting the organization against these threats. That's going to revolve being as becoming more dynamic, as it becomes more sophisticated, more adaptive. They realize that it's a matter of when they're going to get penetrated and really having the ability to detect those incidents or those breaches or really timely manner and being able to respond to those is absolutely critical.

And with EDR, having a detection and response capability at the endpoint level, that was really effective. But as organizations move to the cloud, as we adopt any technologies in SAS environments, adding it towards a remote work environment or remote to work the world, we can realize that endpoint is not the only sort of edge of that active exploit. So that led to organizations really understand that they have to do detection response across the email process and point across identity across the network. And that's really what the goal of extended detection response is, being able to have that monitoring of your entire environment, your entire organization, the infrastructure, and be able to detect any incidents or any alerts and respond to those in a very timely manner.

Well, you've pretty much described this the past four years. Over that time, how would you say that XDRs evolved the most? Yeah, definitely. I think a lot of the promises that XDR aims to deliver is sort of outcomes that most enterprises have been trying to go back and pursue over the last four or five years, like you mentioned.

So again, when EDR came out, it's really kind of getting like a crowd strike back in 2016, 2017 with their Falcon Overwatch where they don't be sold at the next gen of antivirus, but they said, hey, we'll have a full team monitoring your environment and we'll actually respond to them and help you even resolving it to the mediating those incidents. And a lot of enterprises said that once they saw those capabilities at the endpoint level, essentially, we won't do that across our entire infrastructure. So that's really when you saw the sort of the revolution of the SIM, where enterprises had to submit environments, they had these massive data links where they store a lot of their data. It also happened to be where a lot of their loss and a lot of the data on the information across the vendor controlled across the different layers of security exhibited and resided in.

So in 2017, 2018, you saw a lot of the short capabilities come about the security orchestration and automation response capabilities. Those sorts of playbooks being built out within SIM environments, enterprises. So that basically allowed for automated playbooks to be able to not only look at the endpoint, but be able to correlate to what's going on on the endpoint across what the SIM was seeing happening at the network, at the email, at the identity level. And then from there, allow the analysts to take the correct action.

The end goal of all of that, again, was to be able to detect at the more time, the manner and be able to respond to the actual threats of the minimal effect, the more efficient manner. So that went from doing all of that into the SIM, because it was in the SIM, that's when you saw SIM sort of a crisis skyrocket, when there was a SaaS quad, most of the way it was based off the suggestion. And you saw SIM really be sort of confined to the enterprise space. A lot of mid-market companies, a lot of SMDs could not really implement this sort of ability to do that detection response across multiple different layers of security.

So that's where XDR came into play. So as organizations do that, they want to do this deep level of detection response. They want to be able to do correlating across endpoint, across identity, across their network, across their email. But they don't have to do that in a SIM environment.

That XDR is really building XDR and XDR as a platform where a lot of those capabilities are happening at the control level, as opposed to happening back calling the data and doing it at the SIM level. So that's sort of the evolution of XDR. And at the end of the day, what it's allowing us to do is deliver those enterprise level sort of capabilities, downmarket, enabling more mid-marketed more S&U organizations to be able to do that detection response again before any breach, any incident positive having in their environments. And what would you say today are the key elements of an effective XDR solution?

Yeah. I mean, again, XDR is very much so, I would say, no reuse term right now in the industry. If you've been to an RSA type of event, you'll really, every vendor's talking about XDR, probably just as much as they're talking about AI right now. But it's really important to understand what makes a true XDR architecture environment.

When you talk to the partners of the world, we talk to the forces of the world, because it's so saturated, it's a term that kind of split it up to two different types of XDR. There's the open XDR and there's the native XDR. Open XDR is where you're starting to see a lot of these EDR vendors or a lot of these, you know, managed detection response vendors that did sort of single source detection response, you know, sort of managed services offerings. What you're starting to see a lot of them under the claim is, you know, by, again, doing the traditional back calling of data into a SIM environment and then doing, you know, building up the correlations within the SIM that are claiming to do XDR and offer XDR.

So, you know, that's, you know, the difference between open XDR, but what true XDR is, and what native XDR is, is the fact that that level of correlation is happening at the control level. So the way you're able to do that is one, by making sure that all the N controls are integrated, that they are able to, you know, have that deep bi-directional integration to not only pull information from each other, you know, but also be able to push information and push actions down to each other. You know, in the last year, that used to be confined to single vendors, and that's why Gardner Forester said that it's the only true vendor that could claim native XDR. There's only a handful that was Cisco, those power-offs and networks, I was fortunate at any other thing in Microsoft.

Every other vendor, because of the fact that that deep integration, bi-directional integration that exists within the controls, every other vendor that was claiming actually, I was really just doing, again, an open XDR environment. They're just back calling, you know, the data to a SIM and doing those level correlations there. So a key component is that deep correlation, the deep integration between those N controls, again, a level, like a blue type of NDR capability to be able to, again, you know, have those different layers talk to each other and perhaps be no time. And then the short capabilities are still a key component.

So the ability to create automated playbooks, orchestrated playbooks, you know, to take action as you detect these incidents, that's a key component of a modern day truly native XDR architecture. Oh, I want to double down on the BMDR. What are the benefits of a managed detection and response service for XDR? XDRs is a complex, a computing general is extremely complex.

And when you look at XDR, it really is a productivity tool, right? So XDR is a tool to empower your analysts or your security practitioners that are doing the detection responses, allowing them to really cut through the noise, sort of bubble up the true positives, you know, take away the false negatives and be able to respond, you know, in a more timely, more effective manner, basically 10x the output, right? But the challenges most organizations today do not have internal security operations center. It's one or two, you know, individuals on the IT team, maybe a small security team, but a full wall security operations center that can utilize the ability and the promise that XDR brings.

It's very difficult to build out in house, you know, the way I like to sort of position on my toxic customers is it's a lot like what was going on, you know, in the initial, you know, internet boom, when every company was becoming, you know, at the end of the infrastructure company, whether they were target, whether they were making America, you know, whatever realization they were, whatever the initiative they were in, because they were trying to go online, they were having to manage massive amounts of data centers, right? So whether they were bank, whether they're financial services, whether they're health care, at the end of the day, they became an infrastructure company until AWS came about until Amazon came and said, Hey, you know what, you don't have to worry about the data centers, you don't have to worry about the servers, we'll manage all that, you just build your application to focus on your core business that's going to help your head customers. That's exactly what's happening with the NDR space right now for cyber security, not every company wants to be able to be a cyber security company, you know, not every manufacturing company is a cyber security company. However, every company is digitizing, if you're not digitizing, if you're not taking advantage of the promise of technology today, if you're going to be left behind in the water supply industry, and that's true in the automobile industry, in the manufacturing industry, you know, in the journalism industry, everywhere, right?

So you're introducing a lot of these risks into your organization, as we continue to digitize, so that's forcing you to become a cyber security company, just like an initial internet boom, if you weren't becoming an internet company, if you weren't putting your solution on behind it and building any console, you weren't going to be around for much longer, right? So that's what's happening right now with cyber security. If you don't have a mature cyber security program, and mature security operations that are that it's able to do the detection and response in as close from real time as possible, I mean, average attention on a breach, even up until 2020 was around 280 days, you know, and that's absolutely unacceptable. So if you don't have those mature enterprise low security programs and security operations in place, you're going to introduce an exuberant amount of risk that's not going to be okay for organizations.

So that's where MDR partners really come into play. The MDR managed detection partners like port 53, there's a lot of other, you know, both of those large ones that have came out, those sorts of partners are going to become absolutely critical for organizations, especially the small, the mid-sized, the mid-market businesses who not only don't have the resources, but at the end of the day, they don't have the personnel, you know, they don't have the ability to build out the teams, they don't have the resource, they don't have the real estate to build out security operations centers. There's a lot of challenges towards building out what they're going to 100% need if they want to see the full promise of digitization, and that's where you will see the explosion of MDR partners like us and the importance of them over the next year or three to five years. Let's talk about port 53.

How are you and Cisco partnering to bring XDR solutions and services to your customers? When we initially partnered with Cisco, you know, our big goal, and so our ethos here at 43, is being able to empower and enable the IT teams, resources and IT teams to run enterprise-level security programs in the city of Austin, and from the Cape, though, our partnership with Cisco has been extremely critical in being able to accomplish that, right? So when we're working with a lot of these linear IT teams, they seem to have the personnel or the resources to, you know, run through proactive, you know, the church security programs, the Cisco security portfolio initially will be a great entryway for those sorts of businesses to, you know, start moving towards that more mature security posture. So they're easy to deploy, they're extremely simple to manage, and we will be able to remotely help them and fully optimizing the solution in their environment, make sure the policy is set up, right?

Make sure it's doing what it's promised that it will do whether that's at an endpoint level, the identity level with MFA, you know, the network level with firewalls, you know, the email level with CES, obviously with umbrella, protecting the connectivity and protecting the internet usage. So the cloud security portfolio with Cisco has really allowed us to get customers comfortable, you know, and sort of security against one solution. It's not one product and it's definitely not a point in time, sort of endeavor, right? So it's a continuous journey and the cloud security portfolio with Cisco allowed us to really sort of ease customers into that journey as they go into building their true sort of mature security posture.

Well, when you talked about your customers, what are some of the tangible benefits you see them realizing them? At the end of the day, I mean, the tangible benefits of what's not security, I mean, you know, what makes tangible a lot of times is the compliance aspect of it. So when they're working for it, they're very much so makes, you know, being compliant, not only with regulatory arms, you know, if they're a part of, you know, let's say government entities or supply chains and things like that, but if you're starting to see more and more larger customers requiring, you know, doing third party use security assessments and requiring their contractors or their vendors to meet certain standards of proof that they're meeting certain standards. So the potential standpoint, when you work with 43, when you get everything documented, you have everything that you can easily report.

We have, you know, SaaS platforms that really sort of now automate the assessments of the really sort of, you know, allows the continuous performance management of how you're running your security programs and things like that. So potential standpoint, obviously, being able to really, you know, move away from this reactive ad hoc implementation of security controls and towards this risk management approach where you're following a framework, you understand, you know, based off the best practices where you are, you know, where your gaps are, where you want to be from a tangible standpoint from security portfolio as well. Again, you're working with a lot of SMB organizations, a lot of mid-sized organizations, we understand there's a lot of financial restraints and you can talk about, you know, resources, you know, more of those resources is financial at the end of the day. So we offer a lot of flexible payment plans, a lot of, you know, offers and solutions that are delivered as a service, which really allows organizations to be able to consume them, how their sort of, you know, finances allows them to consume technology or consume, you know, operational or capital expenses and things like that.

And at the end of the day, you know, when they purchase our man's detection of the sponsor, our MDR services with the system of technology behind it, the tangible, you know, sort of benefit to them is our SLAs, the total guarantee, the time that we detect, you know, any incident to pause their retirement and the time that we actually respond to it, we address it, we handle it and then we help them in recovering their environment. So those are enterprise level, you know, we take our SLAs up against the largest of the largest of our providers out there. And that benefit of us really leaning in with Cisco on the back and as our technology foundation is that we're working hand-in-hand with Cisco to push the edge of what we're automating in that SOC, what again is leading us to be able to automate the detection, automate the response, the remediation, and the recovery, which gives us to practically real-time detection, real-time response, real-time mediation with the end goal of the next two to three years, working hand-in-hand with Cisco to help organizations create this sort of self-securing, self-healing environment around their architecture and around their infrastructure. Very good.

Before we sign off here, what are the questions that our audience, security and technology leaders, really need to be asking today about their current detection and response capabilities? I think it's understanding exactly what those capabilities are. You know, a lot of organizations that we talk to, even in the mid-market sector, are kind of flying wide around what their capabilities to detect an incident on their endpoint level is, what their capabilities and the type of incidents on an email level is so really getting granular and understanding what you're currently able to accomplish, whether that's in-house with your current SOC and your current security team, or through a detection and response, you know, a partner that you brought on with an SSP or the big players like 453 or like, you know, like Arctic World, Roth, and everyone of those guys. So really understanding exactly what, you know, your SLAs are in terms of across your different control, you know, whether you're able to detect when people are guaranteeing that respond, and remember, there's a difference between responding to an alert and remediating an alert.

So what is the guarantees that they put in place around actually being able to remediate something and recover from it as well? So really drive those questions, push those SLAs. But again, the detection and response from it, if you are looking at MDR providers, you know, what you're getting out of it is the SLAs that they're delivering. But you want a push of what else can they provide you to help you in building a proactive security posture?

Can they help you with, let's say, a continuous vulnerability, sanity, and any way that penetration testing, you know, can they help you with tabletop exercises once or twice a quarter or once or twice a year, where they come and help you in a case you Google through, you know, ransomware incidents or, you know, a successful breach? How do you address that as an organization? Are you prepared for that? You know, an organization to run fire drills all the time, but they don't really want, you know, cybersecurity breach drills and, you know, so is that something that you're going to provide?

Can they provide you, you know, proactive cyber threat intelligence, you know, as a service? And can they meet you when you want to be met? You know, is this something as an MDR provider, where it's an all or nothing? Or, hey, if you have one or two, you know, full-time employees, can you're an MDR provider, you know, compliment them and supplement them and allow them to do the detection response from nine to five, and then they take on the auth hours or, you know, allow them to do it during the weekdays and you know, they take it on during the weekend.

So looking for that flexibility as well, for a company, because every organization and every organization type of security maturity in-house is different. So look for an MDR partner that can be where you are, and look for an MDR partner that can be becoming more and more proactive in mitigating the cybersecurity risk that your organization presents as they continue to digitize. Well said, Omar, thank you for your time. Thank you for your insight.

Of course. I really appreciate it. Thank you, Tom, what are you connecting? Kevin Taub has been actually the benefits of managed XDR.

You just heard from Omar Zarrabi. Again, his president and CEO of Port 53 Technologies. For information security media group, I'm Tom Field. Thank you so much for your time and your attention to that.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

When was this Info Risk Today Podcast episode published?

This episode was published on January 16, 2024.

Can I download this Info Risk Today Podcast episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!