TrustRadius: an HG Insights company

Cybereason MDR

Score8.5 out of 10

14 Reviews and Ratings

What is Cybereason MDR?

Cybereason Managed Detection & Response (MDR) is a managed security service emphasizing behavioral analysis and incident response.

Read more details.

Best MDR and low cost

Use Cases and Deployment Scope

We use Cybereason Managed Detection & Response as our primary Endpoint Detection and Response, and we also have managed services from the Cybereason Team, so it is a complete MDR package that we have from the company. They monitor our environment 24*7 and provide us real time incident details, help us to find the root cause and then provide a way to fix it. The biggest problem for businesses today is data security, and Cybereason is solving it by securing all our endpoints. We have installed it on all our endpoints.

Pros

  • Cybereason Managed Detection & Response is an EDR and it does its job well by detecting all types of malware. It does not depend on a global blocklist only like old anti-viruses, but it has advanced features to detect the behavior and characteristics of malware.
  • The Policies are well-defined, easy to understand, and implement. So creating and managing new policies will not take much time.
  • The MDR team monitors our environment 24*7 and they are well-educated to find the root cause and solution of the incidents.

Cons

  • The Cybereason Managed Detection & Response is good, but it has some room for improvement at the user and group management level. You cannot group users in Cybereason Managed Detection & Response. So if you have to apply a policy to a set of users, you have to do it one by one manually by finding the system names.
  • The automation is less. No automation is searching for devices, such as network discovery. You do not know if it is installed on all devices or not from Cybereason Itself. You have to check it manually.
  • There is no option to search for a user by username. You must know the device name to find the details.
  • No web filtering option available. So you cannot block any URL from Cybereason Managed Detection & Response.

Return on Investment

  • The Positive impact I can say is that with this cost, it is a good MDR solution and protects our complete endpoint.
  • The MDR team is there, so we invest less in the internal SOC team and save a lot of money.
  • The negative impact is that it has no control over URL filtering, and when a user is working from home, they can search anything beyond our control.

Usability

Alternatives Considered

Microsoft Defender for Endpoint

Other Software Used

Atera, Mimecast Integrated Cloud Email Security, KnowBe4 PhishER/PhishER Plus

Best MDR in low price

Use Cases and Deployment Scope

Cybereason Manage Detection and Response (MDR) is our primary antivirus on end user devices including Windows workstations and Servers. It's agent is installed on all the devices across the organization. The agent is used to collect the logs from the end points and then they have their global servers across the globe so that the agent can send the information to the main Cybereason server. Agent is also responsible for actions taken by the Cybereason main dashboard. All the rules will be defined on the main dashboard of Cybereason.
It is a cloud based EDR and will not take your host or server to store and analyze logs.
Since we have a very small team in our company, Cybereason MDR provides 27*7 monitoring to our environment and they also help us to find the root cause and provide the remediation as well.



Pros

  • Cybereason Managed Detection & Response (MDR) tool provides comprehensive monitoring of endpoint systems.
  • Cybereason Managed Detection & Response (MDR) is a cloud-based model and does not require any servers or systems on the client side.
  • Cybereason Managed Detection & Response (MDR) team is well certified to collect, analyze, and find the root cause of malicious events.
  • The Policies in Cybereason dashboard and simple and easy to understand.

Cons

  • Cybereason solution does not provide any web-based filtering solutions that modern EDR tools have.
  • Cybereason solution does not have any URL based blocking.
  • Cybereason solution does not have any IP address blocking mechanism. It only detects when an inside malware connects to a malicious IP and then it will inform you, but will not block it automatically.

Return on Investment

  • As per the current price point, it is doing its job well by protecting our business data from malware and ransomware by monitoring the systems 24*7.
  • The MDR team is monitoring our systems all the time and informs us of any anomalies with very little amount on monitoring part
  • We can set different policies for different departments of devices and this makes sure that our business is secure with all security controls as per the department/device wise.

Usability

Alternatives Considered

Trend Micro Worry-Free Services Suite and Microsoft Defender for Endpoint

Other Software Used

Atera, Mimecast Email & Collaboration Threat Protection, KnowBe4 Security Awareness Training, KnowBe4 PhishER/PhishER Plus

The only Tool which always eye monitoring your company as a defending wall for any attacks

Use Cases and Deployment Scope

Cybereason Managed Detection & Response (MDR) is being used in our organization primarily to manage all the servers, client machines, and plant floor machines from threat, malware, or any malicious operation. It has a strong root of responding to any incident it detected and responds back quickly so the analyst gets all the deep causes--when, where, which file, the user, the extensions, everything. The UI is so easy to handle and manage. The sensors have a powerful ability to catch any threat happening and with every detail in it. The business problems solved are Works like a black box flight recorder for all the PCs Provides information after the fact that otherwise is unobtainable from anywhere The information is used to reconstruct how a PC becomes compromised

Pros

  • It helps us in improved security overall
  • It removes all the litter and never fails to miss a critical alert
  • It remediates malops before a threat occurs in a faster way (detect -> triage -> remediate)
  • The reporting it provides from head to toe is just beyond good

Cons

  • No Cybereason Managed Detection & Response (MDR) sensor for Mac and Linux system; they are still under construction or building it.
  • The company always gives a sensor upgrade as a solution for the issues that occurred; they have many sensors to back up as a bug fix
  • The pricing is little high but if they provide such good services and features, we surely go for it

Return on Investment

  • Secures Network with strong and robust security with managed solution
  • Guided response and root cause analysis for every malop so this is the best ROI we have we don't have to dig much it automatically gives all the relevant details which makes it best from others
  • The Customer Service Support is best they have , they keep time tracking of cases , immediate responses, meetings, problem solving everything they provide is fabulous from support point of view
  • In any issue engineers contact the user and gets the issue resolved and do good level of troubleshooting

Alternatives Considered

Sophos Managed Threat Response (MTR)

Other Software Used

Cofense Triage, Symantec Endpoint Security, Nagios XI