Best-in-Class Comfort level high
Use Cases and Deployment Scope
Pros
- Provides a guarantee backed by $1M that no threats compromise our infrastructure or endpoints.
- Gives a sense of a bit more security that someone else is keeping an eye out for threats.
- If something were to compromise a system, CrowdStrike Falcon Complete Next-Gen MDR would take action and either mitigate the threat or network-contain the system until someone on the IT team could take a look. Even overnight when no one else is watching.
Cons
- The CrowdStrike Falcon Complete Next-Gen MDR console is very "big". There is a lot going on, and for a lean IT team, it is cumbersome to manage.
- Any alerting you want is on a "do it yourself" model. When setting up workflows and alerts, the learning curve for configuration is steep. Although every situation is unique, I'd like to see a place to grab a bunch of commonly configured workflows and set them up as-is, or modify them to fit our needs.
- CrowdStrike Falcon Complete Next-Gen MDR is constantly evolving and improving, which is good, but that also means lots of changes and updates to the platform and GUI. Sometimes I won't be in there for a month, and when I return, there are whole new sections, or it looks different. I'm sure for teams that have dedicated security personnel, it's easier to keep up, but it can get difficult to always know where to go for a particular feature.
Return on Investment
- Our customers find comfort that we are using the best MDR and SIEM.
- We feel that some of the modules have simplified configuration and application of policies.
- Having another set of eyes on our environment has been a comfort.
