Advanced Endpoint Detection and Response

In our continuing series on 15 Ways You Can Protect Against Cyber Attack, today’s topic is a rich and somewhat muddled topic: Endpoint Detection and Response. Check out this page to see prior articles in the series. This is a space crowded with similar acronyms and vendors trying to out-do one another with ever cooler-seeming ideas, but when you boil away the marketing, this is the idea that some program is running on your system to see if anything else on your system looks like a threat.  Software in this category goes by EDR, NDR, MDR, and XDR. The Detection and Response part is common to them all, but that first letter is variously Endpoint, Network, Managed, or eXtended to reflect sometimes subtle differences among them.

Fingers on they keyboard of a laptop

The point here is that something is running on your computer, or network gear, which can Detect a cybersecurity threat and take some sort of action in Response.  Your garden variety Norton Anti-Virus, AVG, or Malwarebytes are likely familiar brands designed to do this type of thing in the home-user market. They are typically better than nothing, but the business solutions have some advantages, like centralized management and more robust actions when something is detected. There are also often more scenarios that the business solutions can identify.

If you can only spend a little bit to improve your company’s cybersecurity defenses, this should be part of that spend, and you should seriously consider your options for Response.  The reason the Response part of [a]DR is so important is that humans aren’t going to react quickly enough to help fix a problem being pushed by a bad actor. You really need to have the computer working at computer speed to thwart the bad actor, because you know that he or she is going to be prepared and working at computer speeds to breach your defenses.

One reason we recommend that organizations go with a business-class threat-blocker is because of the much-improved tool sets they provide for managing all the systems in the organization.  False positives are a real hazard in this part of cybersecurity. That software your cousin Bob wrote, that you only run once-per-quarter, it might very well look like a virus to Norton or McAfee.  If everyone runs it, you’d have to teach each PC’s virus package that it’s OK or the software will prevent it from running.

With business-class XDR solutions, you can tell the centralized management software about that program and it will be allowed on all the systems. Most such systems could also prohibit that software on all but the owner’s machine, or give it to a select four of the 44 employed at the company. 

I’ve been pretty free with the You and Yours, so far, but at CMIT, we typically suggest that we manage that type of work for you, as part of a managed service.  We know what we’re doing with all that, and it may be a steep learning curve for you or your team to learn what we’ve known for a while on this topic.  If you’d like to see more about our cybersecurity offerings, please check out those pages on our website.

Contact Us if you’d like to chat more about this topic in person, or shoot us an email at chicago-nw@cmitsolutions.com, or just give us a call at 847-765-8160.

#Algonquin, #Barrington, #BullValley, #Carpentersville, #Cary, #CrystalLake, #DeerPark, #FoxLake, #FoxRiverGrove, #FoxRiverValleyGardens, #HawthornWoods, #Hebron, #HoffmanEstates, #HolidayHills, #Ingleside, #Inverness, #IslandLake, #Johnsburg, #Kildeer, #LakeBarrington, #LakeInTheHills, #LakeZurich, #Lakemoor, #LongGrove, #McCullomLake, #McHenry, #Mundelein, #NorthBarrington, #OakwoodHills, #PortBarrington, #PrairieGrove, #Richmond, #Ringwood, #SolonMills, #SouthBarrington, #SpringGrove, #TowerLakes, #TroutValley, #VillageOfLakewood, #Volo, #Wauconda, #WonderLake, #Woodstock