https://www.channelfutures.com/wp-content/themes/channelfutures_child/assets/images/logo/footer-new-logo.png
  • Home
  • Technologies
    • Back
    • SDN/SD-WAN
    • Cloud
    • RMM/PSA
    • Security
    • Telephony/UC/Collaboration
    • Cable
    • Mobility & Wireless
    • Fiber/Ethernet
    • Data Centers
    • Backup & Disaster Recovery
    • IoT
    • Desktop
    • Artificial Intelligence
    • Analytics
  • Strategy
    • Back
    • Mergers and Acquisitions
    • Channel Research
    • Business Models
    • Distribution
    • Technology Solutions Brokerages
    • Sales & Marketing
    • Best Practices
    • Vertical Markets
    • Regulation & Compliance
  • MSP 501
    • Back
    • 2023 MSP 501 Application
    • 2022 MSP 501 Rankings
    • 2022 NextGen 101 Rankings
  • Intelligence
    • Back
    • Galleries
    • Podcasts
    • From the Industry
    • Reports/Digital Issues
    • Webinars
    • White Papers
  • Channel Futures TV
  • EMEA
  • Channel Chatter
    • Back
    • People on the Move
    • New/Changing Channel Programs
    • New Products & Services
    • Industry Honors
  • Resources
    • Back
    • Advisory Boards
    • Industry Organizations
    • Our Sponsors
    • Advertise
    • 2023 Editorial Calendar
  • Awards
    • Back
    • 2022 MSP 501
    • Channel Influencers
    • Circle of Excellence
    • DE&I 101
    • Technology Advisor 101 (TA 101)
    • Channel Leaders Lists
  • Events
    • Back
    • 2023 Call for Speakers
    • CP Conference & Expo
    • MSP Summit
    • Channel Partners Europe
    • Channel Partners Event Coverage
    • Webinars
    • Industry Events
  • About Us
  • DE&I
Channel Futures
  • NEWSLETTER
  • Home
  • Technologies
    • Back
    • SDN/SD-WAN
    • Cloud
    • RMM/PSA
    • Security
    • Telephony/UC/Collaboration
    • Cable
    • Mobility & Wireless
    • Fiber/Ethernet
    • Data Centers
    • Backup & Disaster Recovery
    • IoT
    • Desktop
    • Artificial Intelligence
    • Analytics
  • Strategy
    • Back
    • Mergers and Acquisitions
    • Channel Research
    • Business Models
    • Distribution
    • Technology Solutions Brokerages
    • Sales & Marketing
    • Best Practices
    • Vertical Markets
    • Regulation & Compliance
  • MSP 501
    • Back
    • 2023 MSP 501 Application
    • 2022 MSP 501 Rankings
    • 2022 NextGen 101 Rankings
  • Intelligence
    • Back
    • Galleries
    • Podcasts
    • From the Industry
    • Reports/Digital Issues
    • Webinars
    • White Papers
  • Channel Futures TV
  • EMEA
  • Channel Chatter
    • Back
    • People on the Move
    • New/Changing Channel Programs
    • New Products & Services
    • Industry Honors
  • Resources
    • Back
    • Advisory Boards
    • Industry Organizations
    • Our Sponsors
    • Advertise
    • 2023 Editorial Calendar
  • Awards
    • Back
    • 2022 MSP 501
    • Channel Influencers
    • Circle of Excellence
    • DE&I 101
    • Technology Advisor 101 (TA 101)
    • Channel Leaders Lists
  • Events
    • Back
    • 2023 Call for Speakers
    • CP Conference & Expo
    • MSP Summit
    • Channel Partners Europe
    • Channel Partners Event Coverage
    • Webinars
    • Industry Events
  • About Us
  • DE&I
    • Newsletter
  • REGISTER
  • MSPs
  • VARs / SIs
  • Agents
  • Cloud Service Providers
  • Channel Partners Events
 Channel Futures

Cloud


MSSPs Wasting Time on False-Positive Security Alerts

  • Written by Edward Gately
  • February 12, 2018
Some 44 percent of ATA survey respondents report a 50 percent or higher false-positive rate on security alerts.

Managed security services providers (MSSPs) are wasting time and resources processing useless security alerts, and many often either reduce the sensitivity of security equipment or ignore alerts altogether.

That’s according to a new survey by Advanced Threat Analytics (ATA). The company polled nearly 50 MSSPs to evaluate the state of incident response within their security operations centers (SOCs).

Advanced Threat Analytics' Alin Srivastava

Advanced Threat Analytics’ Alin Srivastava

Alin Srivastava, ATA’s president, tells Channel Partners that redundant and benign alerts cause the most problems for MSSPs, The most surprising aspect of the survey was the fact that MSSPs “readily admit to ignoring alerts for a service they are being paid for by customers who are entrusting their security to those MSSPs,” he said.

“This research shows that MSSPs are still on the receiving end of an oppressive number of daily security alerts, forcing many analysts and incident responders to spend hours – in some cases, more than five – each day investigating them, many of which turn out to be false-positives,” he said. “Devoting so much time to benign alerts severely compromises security effectiveness, as analysts are distracted from acting on actual threats and incidents.”

Nearly half (44 percent) of respondents report a 50 percent or higher false-positive rate, with 22 percent reporting a 50-75 percent false-positive rate, and 22 percent reporting between 75 and 99 percent.

Nearly 45 percent of respondents investigate 10 or more alerts each day, according to the survey. Nearly two-thirds (64 percent) said, on average, it takes 10 minutes or more to investigate each alert, including 11 percent who said it takes 30 minutes or more.

When asked what they do if their SOC has too many alerts for analysts to process, respondents said they: tune specific alerting features or thresholds to reduce alert volume (67 percent); ignore certain categories of alerts (38 percent); turn off high-volume alerting features (27 percent); and hire more analysts (24 percent).

“The most effective way for MSSPs to break free from ‘alert tyranny’ is to invest in technology that decreases the number of incidents generated, rather than in traditional SIEM and incident-orchestration solutions, which only reduce the time it takes to investigate each one,” Srivastava said.

When respondents were asked what they feel is the main responsibility of their job: Seven in 10 (70 percent) said analyzing and remediating security threats; 20 percent said limiting the number of alerts sent to clients for review; 5 percent said investigating as many alerts as possible; and the remaining 5 percent said reducing the time it takes to investigate a security alert.

“When analysts are no longer bogged down in an unmanageable number of alerts, they can focus on what they were hired to do — mitigate risk by identifying true threats and responding quickly,” Srivastava said.

ATA’s Alert Classification Platform and Mobile SOC allows incident responders to analyze and triage alerts anytime and anywhere.

Critical Start is an ATA MSSP partner. The (ATA platform) is an “integral” part of its managed detection and response business, said Joshua Maberry, its director of security operations.

“The platform enables us to use security tools, such as endpoint detection and response platforms like Carbon Black, without having to set thresholds or arbitrarily reduce alerts to make it manageable,” he said. “ATA enables my team to identify the known good behaviors of a system and remove them from the queue. The team can also go one step deeper by working with our clients to identify their specific known good, such as home-grown applications and/or privileged users who are authorized to use tools that flag as malicious, to further reduce the noise and false-positive events that contribute to alert fatigue and analyst burnout.”

Tags: Agents Analytics Cloud Security

Most Recent


  • Making Waves
    8 Channel People Making Waves This Week at Lumen, Accenture, Amazon, Canalys, More
    Cisco led a “crowded” secure access service edge (SASE) market in terms of revenue in 2022, experts said.
  • network in the cloud
    Fortinet, Huawei, Palo Alto, VMware Lauded in Gartner Peer Insights SD-WAN Study
    Thousands of customers have weighed in on how their SD-WAN vendors have performed.
  • Do AWS, Azure, Google, Oracle, Others, Have Too Much Market Power?
    The FTC, concerned about cloud vendors’ sway over customers, is seeking public comment.
  • Unemployed, layoffs
    Veeam Layoffs Impact 200 Workers, Company Remains 'Strong, Profitable'
    Veeam continues to hire for roles in R&D.

Leave a comment Cancel reply

-or-

Log in with your Channel Futures account

Alternatively, post a comment by completing the form below:

Your email address will not be published. Required fields are marked *

Related Content

  • College classroom
    Community College Ransomware Attack Wreaks Havoc
  • Virtual Desktop
    6 Enhancements to Microsoft’s WVD, Plus a New Name: Azure Virtual Desktop
  • Cloud computing concept
    Cloud Computing Adoption Isn’t Slowing — Need to Convince Clients?
  • Welcome Mat
    Ex-Telarus Exec Scott Forbush Leaves Upstack for PPT Solutions After 5 Months

Upcoming Events

View all

Channel Partners Conference & Expo

May 1, 2023 - May 4, 2023

Channel Partners Europe

June 13, 2023 - June 14, 2023

Channel Futures Leadership Summit

October 30, 2023 - November 2, 2023

Galleries

View all

8 Channel People Making Waves This Week at Lumen, Accenture, Amazon, Canalys, More

March 24, 2023

National Women’s History Month: Channel Women Have Stories to Tell

March 24, 2023

VEC Attack Tries to Steal $36 Million, Ferrari, Dole Hit with Ransomware Attacks

March 23, 2023

Industry Perspectives

View all

Selling Your MSP: Strategic vs. Financial Buyers

March 22, 2023

10 Strategic Smart Enterprise Drivers for 2023

March 16, 2023

Does Your Company Have a Virtual Water Cooler?

March 13, 2023

Webinars

View all

Equipping the Hybrid Workforce: What It Takes to Execute

March 28, 2023

Give Customers the Power: How MSPs Can Leverage Cloud Choice

April 4, 2023

DE&I Dialogue: How the Right DE&I Initiatives Can Propel Your Business

April 5, 2023

White Papers

View all

6 UCaaS Reseller Challenges and How Real World Businesses Solved Them

February 1, 2023

Frost Radar: North American UCaaS Market, 2022

February 1, 2023

The Complete Guide to White-Label UCaaS for Reseller Success

February 1, 2023

Channel Futures TV

View all

Coffee with Craig and James Episode 121: Hewlett Packard Enterprise

Aryaka ‘Driving Value to the Channel Community’ with Throttle

March 24, 2023

Real-Life M&A: Advice for a Successful Channel Deal

March 13, 2023

Coffee with Craig and James Episode 120: Ronnell Richards

March 3, 2023

Twitter

ChannelFutures

Channel people making waves include: @jmcbain, @NetworkMoe, @ajassy, @JulieSweet, @Elvia_Valdes_M, @GovITDave… twitter.com/i/web/status/1…

March 24, 2023
ChannelFutures

We delve into AI impacting the channel, this week featuring @nvidia, @GoTo, @twilio and more.… twitter.com/i/web/status/1…

March 24, 2023
ChannelFutures

[email protected]_Inc's Peer Insights are a treasure trove for partners looking to sell #SDWAN. dlvr.it/SlRDmk https://t.co/oElLXzOIbb

March 24, 2023
ChannelFutures

#CPExpo preview: @GlobalIndirect of @AryakaChannel with a preview of the next phase of the company's channel progra… twitter.com/i/web/status/1…

March 24, 2023
ChannelFutures

U.S. competition regulators want to know if @AWSCloud, @Azure, @GoogleCloud, @OracleCloud hold too much market powe… twitter.com/i/web/status/1…

March 24, 2023
ChannelFutures

📣 Join us on April 13th to hear from the 2023 Channel Influencers and get their insights on the state of the channe… twitter.com/i/web/status/1…

March 24, 2023
ChannelFutures

#CPExpo preview: Learn about why @USWired accepted an #acquisition deal and what partners should look for in an M&A… twitter.com/i/web/status/1…

March 24, 2023
ChannelFutures

.@Veeam lays off 200 workers to increase efficiency. #backupandrecovery dlvr.it/SlQWZW https://t.co/QTJx1NX69q

March 24, 2023

MSP 501

The industry's largest and most comprehensive partner awards program.

Newsletters and Updates

Sign up for The Channel Report, Channel Futures Update, MSP 501 Newsletter and more.

Live Channel Events

Get the latest information on the next industry-leading Channel Partners event.

Galleries

Educational slide shows and images from live events.

Media Kit And Advertising

Want to reach our audience? Access our media kit.

DISCOVER MORE FROM INFORMA TECH

  • Channel Partners Events
  • Telecoms.com
  • MSP 501
  • Black Hat
  • IoT World Today
  • Omdia

WORKING WITH US

  • Contact
  • About Us
  • Advertise
  • Newsletter

FOLLOW Channel Futures ON SOCIAL

  • Privacy
  • CCPA: “Do Not Sell My Data”
  • Cookie Policy
  • Terms
Copyright © 2023 Informa PLC. Informa PLC is registered in England and Wales with company number 8860726 whose registered and Head office is 5 Howick Place, London, SW1P 1WG.
This website uses cookies, including third party ones, to allow for analysis of how people use our website in order to improve your experience and our services. By continuing to use our website, you agree to the use of such cookies. Click here for more information on our Cookie Policy and Privacy Policy.
X