CrowdStrike Falcon Complete
Use Cases and Deployment Scope
Pros
- Fast detection and containment, as well as immediate contact to our team
- 24x7 monitoring and response
- Use of AI to triage and carry out safe actions or hand to an Analyst for investigation
- use of multiple data sources for investigation and triage, SIEM, Identity, endpoints, cloud workloads. Allowing analysts and staff to see the full pathway of an attack
Cons
- Portal could be less cluttered and easy to navigate
- Cost for the core product and additional modules is expensive
- Direct access to analysts - sometimes difficult
- Third Party integrations an example of this is Cisco Umbrella being available but Cisco Secure Access is not?
Return on Investment
- We now have a Mature 24/7 SOC that cuts response time from hours/days to minutes. Reducing disruption to staff
- Reduces the requirement for a large in house SOC team, it also has allowed us to retire overlapping tool sets
- It is a premium service which comes at a cost so we need to consistently and continually demonstrate that it is reducing incidents, and easing staffing pressure and maintaining the security of the firm
- It supports the main objectives of confidentiality, uptime and compliance this is through its ability to provide evidence of containment, and expert led investigations when something does happen