Best MDR and low cost
Use Cases and Deployment Scope
We use Cybereason Managed Detection & Response as our primary Endpoint Detection and Response, and we also have managed services from the Cybereason Team, so it is a complete MDR package that we have from the company. They monitor our environment 24*7 and provide us real time incident details, help us to find the root cause and then provide a way to fix it. The biggest problem for businesses today is data security, and Cybereason is solving it by securing all our endpoints. We have installed it on all our endpoints.
Pros
- Cybereason Managed Detection & Response is an EDR and it does its job well by detecting all types of malware. It does not depend on a global blocklist only like old anti-viruses, but it has advanced features to detect the behavior and characteristics of malware.
- The Policies are well-defined, easy to understand, and implement. So creating and managing new policies will not take much time.
- The MDR team monitors our environment 24*7 and they are well-educated to find the root cause and solution of the incidents.
Cons
- The Cybereason Managed Detection & Response is good, but it has some room for improvement at the user and group management level. You cannot group users in Cybereason Managed Detection & Response. So if you have to apply a policy to a set of users, you have to do it one by one manually by finding the system names.
- The automation is less. No automation is searching for devices, such as network discovery. You do not know if it is installed on all devices or not from Cybereason Itself. You have to check it manually.
- There is no option to search for a user by username. You must know the device name to find the details.
- No web filtering option available. So you cannot block any URL from Cybereason Managed Detection & Response.
Return on Investment
- The Positive impact I can say is that with this cost, it is a good MDR solution and protects our complete endpoint.
- The MDR team is there, so we invest less in the internal SOC team and save a lot of money.
- The negative impact is that it has no control over URL filtering, and when a user is working from home, they can search anything beyond our control.
Usability
Alternatives Considered
Microsoft Defender for Endpoint
Other Software Used
Atera, Mimecast Integrated Cloud Email Security, KnowBe4 PhishER/PhishER Plus