Cisco Threat Response automates integrations across select Cisco Security products and accelerates key security operations functions: detection, investigation, and remediation. Threat Response integrates threat intelligence from Cisco Talos and third-party sources, which adds context from integrated Cisco Security products automatically so you know instantly which of your systems was targeted and how.
N/A
Mimecast Threat Intelligence
Score 7.5 out of 10
N/A
Mimecast offers a threat intelligence service, including the company's Threat Intelligence Dashboard, threat remediation, and the Mimecast Threat Feed for integration threat intelligence into compatible SIEM or SOAR platforms.
This is perfect for organisations with small or limited security teams who want to get more from their Cisco and third-party investments. With Secure Endpoint makes detecting and responding to threats much easier. Any organisation looking to overhaul its security infrastructure or even wrap around its cloud-first strategy with solutions such as Intune should seriously look at Cisco’s suite of products. I’ve implemented Secure Endpoint, Umbrella, and Duo for customers primarily using Intune for device management, and the cool new insight features in Cisco SecureX really help with visibility over their estate.
I think Mimecast is great for companies who want granular control over their email. Once it is setup, it really does just run along without IT needing to get involved too much. Any time we have 'issues' - such as incorrectly blocked emails or attachments, we can easily figure out what we need to do and how to fix it. Mimecast is great for teams who don't want to sit there all day and manage and look at emails. It would suit a large organisation who want deep control.
So the product enables end users to get visibility into their security environment, not only across the Cisco products but across the third-party products as well. The product also automates detection and response. So the product really offers end-user efficiency in the security operations center.
Because all incoming and outgoing (with journaling setup for internal email) go through Mimecast it is a one-stop-shop for searching out emails from past months or years. It is light years better than using local archives such as .pst files.
Since they touch all incoming email Mimecast is excellent our filtering out spam, malware and virus emails before it even gets to your server whether on-premise or in the cloud.
Of course, many companies prefer to obtain security from the cloud; however, not all of them prefer it, which is why having a local implementation would allow these companies to also use said software as their ally for their security.
Working with this software can be simple, that is, any threat can be visualized with greater precision, but when it comes to managing its orchestration, it is a bit complex.
Its integration with other software can be simple but with others it is not, that is why it would be ideal if all of them could be carried out in the same way.
Integrating with a larger number of third party software would be of great help, to further enhance the analysis and detection of threats.
It works perfectly and is really easy to manage when you understand the menu and how it works. It really is 'set and forget' with minor changes needed from time to time to blacklist and whitelist senders and domains. It makes our life really easy and gives us a lot of data to understand how or business and users operate.
Mimecast has a 24 hours phone hotline available to assist you with issues as they arise. This is the typical help desk situation where you reach level one and go to level two if this issue is extensive however I have found their level one techs to more than capable of dealing with most issues I have called about. The only negative I would mention is that their email support is less hardy when it comes to response time so I have grown to realize that calling is the only way to get timely support.
A lot of the look and feel of both products is quite similar. There's several best practices on visualization that are followed in both and integration of common telemetry is comfortable and quick. But while Microsoft ATP offers deep insights into mostly the Microsoft environment and a limited view into other common sources, SecureX shines in all the non-client areas Microsoft's product seems lackluster in.