MDR Services Provide Fast Responses at Any Time of the Day or Night
CrowdStrike’s recent 2022 Falcon OverWatch Threat Hunting Report found that organizations are facing 50 percent more intrusion attacks than they were one year ago. Once attackers get inside, it takes only an hour and 24 minutes, on average, for them to gain access to a second system.
For the most effective MDR services, the “response” component is more than just a notification that something has happened that requires a security team’s attention, DeFord says. In these cases, the service provider takes remedial action to stop the attack.
The ideal model, he explains, is one minute to detect an attack, 10 minutes to investigate it and 60 minutes to remediate it — roughly 13 minutes faster than the average attacker.
“If you can create a security program where you are extremely confident that you can detect every adversary within one hour and 24 minutes, odds are good that your program is devastatingly effective,” he says. “That speed is a critical factor in modern security.”
That speed is possible because MDR services are designed to offer 24/7 incident response, which is something even large healthcare organizations may struggle to do. The foundation is an extended detection and response (XDR) platform, which gathers incident data from hundreds of sources in a single data lake to give security analysts a complete view of suspicious activity, says William J. Thorn, senior architect for healthcare at Trellix.
Click the banner below to discover how MDR can support your security strategy.