https://www.channelfutures.com/wp-content/themes/channelfutures_child/assets/images/logo/footer-new-logo.png
  • Home
  • Technologies
    • Back
    • SDN/SD-WAN
    • Cloud
    • RMM/PSA
    • Security
    • Telephony/UC/Collaboration
    • Cable
    • Mobility & Wireless
    • Fiber/Ethernet
    • Data Centers
    • Backup & Disaster Recovery
    • IoT
    • Desktop
    • Artificial Intelligence
    • Analytics
  • Strategy
    • Back
    • Mergers and Acquisitions
    • Channel Research
    • Business Models
    • Distribution
    • Tech Services Brokerages
    • Sales & Marketing
    • Best Practices
    • Vertical Markets
    • Regulation & Compliance
    • Diversity, Equity & Inclusion
  • MSP 501
    • Back
    • MSP 501 Information Center
    • 2021 MSP 501 Rankings
  • Intelligence
    • Back
    • Galleries
    • Podcasts
    • From the Industry
    • Reports/Digital Issues
    • Webinars
    • White Papers
  • Channel Futures TV
  • EMEA
  • Channel Chatter
    • Back
    • People on the Move
    • New/Changing Channel Programs
    • New Products & Services
    • Industry Honors
  • Resources
    • Back
    • Advisory Boards
    • Industry Organizations
    • Our Sponsors
    • Advertise
    • 2022 Editorial Calendar
  • Awards
    • Back
    • 2021 MSP 501
    • Circle of Excellence
    • DE&I 101
    • Top Gun 51
    • Channel Partners 101 (CP 101)
  • Events
    • Back
    • CP Conference & Expo
    • MSP Summit
    • Channel Partners Europe
    • Channel Partners Event Coverage
    • Webinars
    • Industry Events
  • About Us
  • DE&I
Channel Futures
  • NEWSLETTER
  • Home
  • Technologies
    • Back
    • SDN/SD-WAN
    • Cloud
    • RMM/PSA
    • Security
    • Telephony/UC/Collaboration
    • Cable
    • Mobility & Wireless
    • Fiber/Ethernet
    • Data Centers
    • Backup & Disaster Recovery
    • IoT
    • Desktop
    • Artificial Intelligence
    • Analytics
  • Strategy
    • Back
    • Mergers and Acquisitions
    • Channel Research
    • Business Models
    • Distribution
    • Tech Services Brokerages
    • Sales & Marketing
    • Best Practices
    • Vertical Markets
    • Regulation & Compliance
    • Diversity, Equity & Inclusion
  • MSP 501
    • Back
    • MSP 501 Information Center
    • 2021 MSP 501 Rankings
  • Intelligence
    • Back
    • Galleries
    • Podcasts
    • From the Industry
    • Reports/Digital Issues
    • Webinars
    • White Papers
  • Channel Futures TV
  • EMEA
  • Channel Chatter
    • Back
    • People on the Move
    • New/Changing Channel Programs
    • New Products & Services
    • Industry Honors
  • Resources
    • Back
    • Advisory Boards
    • Industry Organizations
    • Our Sponsors
    • Advertise
    • 2022 Editorial Calendar
  • Awards
    • Back
    • 2021 MSP 501
    • Circle of Excellence
    • DE&I 101
    • Top Gun 51
    • Channel Partners 101 (CP 101)
  • Events
    • Back
    • CP Conference & Expo
    • MSP Summit
    • Channel Partners Europe
    • Channel Partners Event Coverage
    • Webinars
    • Industry Events
  • About Us
  • DE&I
    • Newsletter
  • REGISTER
  • MSPs
  • VARs / SIs
  • Agents
  • Cloud Service Providers
  • Channel Partners Events
 Channel Futures

MSSP Insider


Shutterstock

XDR

Optimizing XDR Through MSSP Collaboration

  • Written by Michael Vaughn
  • May 2, 2022
Drive efficiencies in security operations and address evolving security threats with detection and response options.
AT&T Cybersecurity's Michael Vaughn

Michael Vaughn

Having a strong, effective security stack can help protect an organization’s data. While some believe this is achieved by activating numerous security solutions, having too many tools at a security team’s disposal can transform into organizational kryptonite.

Security stack overload creates internal challenges and distracts from the primary business mission. One of the best ways an organization can protect itself from security threats, while also achieving business goals, is to work with a managed security service provider (MSSP) to manage an extended detection and response (XDR) solution. This can improve security coverage in busy and complex environments.

Defining XDR and Its Benefits

Similar to the way secure access service edge (SASE) combines several network security protections, XDR combines network and endpoint detection and response capabilities with endpoint protection and security orchestration, automation, and response (SOAR). This approach to threat detection pays close attention to even the smallest details, monitoring network activity widely and ensuring endpoints are protected from threats.

Extended threat detection and response solutions provide protection, detection, and response across the security ecosystem, in addition to allowing users to expand their service catalogs and increase revenue with essential security and compliance offerings. By utilizing XDR, business leaders have access to a broad inherent toolset that enables partners to deliver on their promise to protect their customers’ networks, endpoints, cloud infrastructure, and cloud applications as they navigate dynamic environments.

The Importance of Intelligence

Implementing XDR-as-a-service also supports scalability, which allows for better responses to emerging threats. With that said, this can quickly become too complicated for a single security team to manage. One tangible and immediate way to simplify security is to enlist the aid of an MSSP. These experts understand how the tools work and have experience installing and running a variety of products and platforms in different business verticals.

In addition to having security expertise, threat intelligence is critical for accurate detections and reducing false positives. Machine learning and security analytics can help correlate the data and provide context so threats that can be identified faster and more accurately. However, given the ever-changing nature of the cyber threat landscape, business leaders need to be certain that their XDR solution, and, more importantly, their MSSP, can discover infrastructure and tools used by threat actors to host their operations and launch ransomware and other sophisticated cyberattacks. Using this approach of concentrating on threat actor tactics, techniques and procedures (TTPs) provides early-stage, more predictive identification of threats. This means higher-fidelity detection of evolving threats. Such threat intelligence is a key element in minimizing the margin of error in threat detection.

Choosing a Vendor

When implementing security tools, one of the main decisions business leaders make is to decide whether they want to lock in with one vendor or opt for a multivendor integration. One approach to addressing security tool complexity is to go “all-in” with one vendor. Because one vendor’s tools are all designed to work together, many believe that standardizing one vendor’s approach across an organization is the optimal approach. However, often one vendor’s products are a collection of acquired technology versus an integrated solution, and road maps for consolidation frequently stretch to the horizon.

Another approach to consider is an open XDR solution. This approach brings together two important existing solutions: advanced security information and event management (SIEM) platforms with correlation engines, and endpoint detection and response agents. They also have deep integrations with third-party tools such as firewalls, SaaS/IaaS clouds, SASE solutions and more. These integrations make responding to incidents and automating responses quick and easy. With this approach, business leaders are free to choose best-in-class security vendors with the confidence that they can be used together without needing to replace an entire technology stack.

Although many of today’s security challenges don’t have quick fixes, choosing products and services that offer smooth integration to current technology and the flexibility to mix and match critical components is the best step to take toward simplifying them. Detection and response solutions have significant learning curves and, because of this, relying on MSSPs is an optimal approach for organizations to feel confident that professionals are protecting their networks, while also realizing cost savings. Once the right XDR solution and MSSP provider are identified, they will drive efficiencies in security operations in finding and addressing continuously evolving security threats.

As product manager for the global MSSP and channel at AT&T Cybersecurity, Michael Vaughn oversees strategy for the USM Central platform and partner program. You may follow him on LinkedIn or @attcyber on Twitter.

Tags: MSPs Best Practices MSSP Insider Security

Most Recent


  • Twenty, 20
    The CF List: 2022's 20 Top SD-WAN Providers You Should Know
    A leading SD-WAN provider has to show greater value across a number of different domains.
  • Look ahead
    Marketing All-Stars Share Their Focus for 2022 and Beyond
    Where do our CMO roundtable members expect to be concentrating their efforts in the months ahead?
  • 6 Takeaways from the Ingram Micro Executive Panel
    “Ingram's role is to be the enabler of an ecosystem,” one panelist said.
  • threat report provides information about cyber threats
    A Sneak Peek at the 2022 BrightCloud Threat Report
    The 2022 threat report shows soaring ransomware payments, consistent infections, deceptive URLs and more.

Leave a comment Cancel reply

-or-

Log in with your Channel Futures account

Alternatively, post a comment by completing the form below:

Your email address will not be published. Required fields are marked *

Related Content

  • Revenue up
    The Gately Report: CrowdStrike Channel Partners Crucial to Reaching Ambitious Revenue Goals
  • Growth
    The Gately Report: Sherweb MSP Partners Fueling Cybersecurity Growth, More on Synopsys' WhiteHat Security Buy
  • Vulnerability
    ESET: Millions Using Lenovo Laptops Potentially Vulnerable to Malware Attacks
  • Broken Blockchain
    Alert: North Korea Hackers Targeting Blockchain, Crypto Companies

Upcoming Events

View all

Channel Partners Europe

June 14, 2022 - June 15, 2022

MSP Summit

September 13, 2022 - September 16, 2022

Galleries

View all

The CF List: 2022’s 20 Top SD-WAN Providers You Should Know

May 18, 2022

Marketing All-Stars Share Their Focus for 2022 and Beyond

May 18, 2022

6 Takeaways from the Ingram Micro Executive Panel

May 17, 2022

Industry Perspectives

View all

A Sneak Peek at the 2022 BrightCloud Threat Report

May 17, 2022

Build Customers for Life with CX and Lifecycle Selling

May 16, 2022

Voice Analytics Are a Must-Have as Companies Evolve COVID-Rushed Tech

May 12, 2022

Webinars

View all

Simplifying SaaS Security for MSPs

April 27, 2022

How to Supercharge The Network to Support Your IT Superhero Moves

May 3, 2022

The 2022 MSP Challenge: Scale Service Delivery Despite the Talent Gap

April 21, 2022

White Papers

View all

The New Bottom Line: How MSPs Can Meet the Healthcare Crisis While Evolving Their Businesses

April 19, 2022

How to build a Security Operations Center (on a budget)

April 4, 2022

The AT&T Cybersecurity Incident Response Toolkit

April 4, 2022

Channel Futures TV

View all

AT&T, Microsoft, Cisco, ThreatLocker on Unlocking Partner Potential

Agents Share ‘Secrets,’ Industry Opportunity

May 11, 2022

Vonage Addresses Potential Partner Opportunity via Acquisition by Ericsson

May 5, 2022

Lumen Technologies ‘Built for Growth and Scale’

May 4, 2022

Twitter

ChannelFutures

[email protected] now reaches 177 countries — 80 more regions for the channel to target. And #AWS has a new #publicsector… twitter.com/i/web/status/1…

May 18, 2022
ChannelFutures

Our CMO roundtable series concludes with members’ predictions on what their primary focus will be in the months ahe… twitter.com/i/web/status/1…

May 18, 2022
ChannelFutures

“@IngramMicroInc's role is to be the enabler of an ecosystem,” @SahooSanj said at the company's cloud summit.… twitter.com/i/web/status/1…

May 18, 2022
ChannelFutures

Take a sneak peak at BrightCloud's 2022 Threat Report. #Channel Partners #CyberThreats @Webroot… twitter.com/i/web/status/1…

May 18, 2022
ChannelFutures

#GoogleCloudSummit unveils new solutions for #zerotrust, supply chain security. @googlecloud dlvr.it/SQZ2By https://t.co/37buEDQ030

May 18, 2022
ChannelFutures

.@Veeam CEO @anandeswaran is gunning for outsized share of data protection market at #veeamOn2022… twitter.com/i/web/status/1…

May 18, 2022
ChannelFutures

#ChannelEurope keynote with @contextworld addresses partners staying calm amid market volatility.… twitter.com/i/web/status/1…

May 17, 2022
ChannelFutures

Read about how the partnership between @AryakaNetworks and @AppSmartcom is a milestone for both companies.… twitter.com/i/web/status/1…

May 17, 2022

MSSP Insider

Business advice for MSSPs and news from the broader security channel.

Newsletters and Updates

Sign up for The Channel Report, Channel Futures Update, MSP 501 Newsletter and more.

Live Channel Events

Get the latest information on the next industry-leading Channel Partners event.

Galleries

Educational slide shows and images from live events.

Media Kit And Advertising

Want to reach our audience? Access our media kit.

DISCOVER MORE FROM INFORMA TECH

  • Channel Partners Events
  • Telecoms.com
  • MSP 501
  • Black Hat
  • IoT World Today
  • Omdia

WORKING WITH US

  • Contact
  • About Us
  • Advertise
  • Newsletter

FOLLOW Channel Futures ON SOCIAL

  • Privacy
  • CCPA: “Do Not Sell My Data”
  • Cookie Policy
  • Terms
Copyright © 2022 Informa PLC. Informa PLC is registered in England and Wales with company number 8860726 whose registered and Head office is 5 Howick Place, London, SW1P 1WG.
This website uses cookies, including third party ones, to allow for analysis of how people use our website in order to improve your experience and our services. By continuing to use our website, you agree to the use of such cookies. Click here for more information on our Cookie Policy and Privacy Policy.
X