What We Do
How we do it
Resources
SECURITY ADVISORIES
Oct 18, 2021
Grief Ransomware Gang Claims 41 New Victims, Targeting Manufacturers; Municipalities; & Service Companies in U.K. & Europe
Grief Operators Earned an Estimated 8.5 Million British Pounds in Four Months Key Findings: The Grief Ransomware Gang (a rebrand of the DoppelPaymer Ransomware Group) claims to have infected 41 new victims between May 27, 2021—Oct. 1, 2021 with their ransomware.Over half the companies listed on Grief’s underground leak site are based in the U.K. and Europe. The Grief Ransomware Gang appears to…
Read More
View all Advisories →
Company
ABOUT eSENTIRE
About Us
eSentire is The Authority in Managed Detection and Response Services, protecting the critical data and applications of 1000+ organizations in 70+ countries from known and unknown cyber threats. Founded in 2001, the company’s mission is to hunt, investigate and stop cyber threats before they become business disrupting events.
Read about how we got here
Leadership Work at eSentire
LATEST PRESS RELEASE
Oct 12, 2021
eSentire Launches MDR with Microsoft Azure Sentinel Extending Response Capabilities Across Entire Microsoft Security Ecosystem
Waterloo, ON – Oct. 12, 2021 -- eSentire, recognized globally as the Authority in Managed Detection and Response (MDR), today announced the expansion of its award-winning MDR services with Microsoft Azure Sentinel, as part of its integration with the complete Microsoft 365 Defender and Azure Defender product suites supporting Microsoft SIEM, endpoint, identity, email and cloud security services.…
Read More
Partners
PARTNER PROGRAM
Partners
Our award-winning partner program offers financial rewards, sales and marketing tools and personalized training. Accelerate your business and grow your revenue by offering our world-class Managed Detection and Response (MDR) services.
Learn about our Partner Program
PARTNER RESOURCES
Apply today to partner with the Authority in Managed Detection and Response.
Login to the Partner Portal for resources and content for current partners.
Search
Resources
Blog — Jun 30, 2021

Better Together: How Combining MDR and IR Create Stronger Cyber Resilience

It’s impossible for businesses to participate in today’s interconnected and data-centric economy without becoming exposed to cyber risk. No matter how strong your safeguards are or how robust your processes are, cyber defenses can—and will—fail.

For small and midsized organizations without the resources to build, staff, and maintain an in-house 24/7 Security Operations Center (SOC), relying on a trusted partner to deliver these Managed Detection and Response (MDR) capabilities is essential.

Beyond detection and containment

While MDR gives you access to 24x7 expert SOC support necessary to detect and contain potential breaches, it’s not designed to provide evidence that can hold in a court of law. By nature, MDR is meant to stop threat actors before they can successfully gain access into your networks, not remediate a breach.

If you need to conclusively determine the precise extent of data loss, or if you’re looking to investigate an incident in granular detail—right down to the level of the individual compromised record—you’ll need to tap into a different skillset: Digital Forensics and Incident Response.

Incident Response (IR) is explicitly designed to fulfill the most exacting requirements of cyber insurers, regulators, and prosecutors. These services comprise a distinct discipline that incorporate evidence-handling techniques as well as the mastery of digital forensics tools.

It’s important to note that while organizations can engage an MDR provider or IR services provider, there will always be a distinct advantage to augmenting MDR capabilities with Digital Forensics and IR.

Adopting an “assume breached” mentality and the emerging imperative of due diligence

Today’s Chief Information Security Officers (CISOs) and IT departments are increasingly adopting the “assume breached” mentality. This approach includes creating robust security monitoring capabilities which enable teams to rapidly detect, respond to, and contain any cyber threat with the potential to disrupt the business.

New and evolving threats are increasingly revealing the shortcomings of traditional IR. For businesses that operate by driving billable hours, on-site client meetings, and a reliance on stale technologies, legacy IR providers are far too slow and expensive to provide the timely and effective incident response needed.

In addition, trusting IR to a non-expert isn’t really a viable option as doing so introduces different kinds of risks, which defeats the purpose. For example:

Since all cyber risk cannot be mitigated, CISOs and their teams must exercise due diligence to demonstrate that they did what any reasonable person would do to balance these risks. Insurers, regulators, and courts frequently expect that organizations will have IR capabilities in-house or will maintain these capabilities through an external IR retainer agreement.

Organizations must be able to meet these expectations, especially as cybersecurity insurance policies continue to change in the face of the current devastating global ransomware epidemic.

Modern IR to deal with modern threats

In our recent announcement to extend our core response capabilities deeper into the incident lifecycle, Bryan Sartin, our Chief Services Officer, stated, “When faced with a security incident, how quickly an organization can contain and recover is paramount to limiting business disruption and reputational damage.”

That’s why our Digital Forensics and Incident Response capabilities provide a 4-hour remote threat suppression service level agreement for organizations anywhere in the world. This agreement is only possible because of our innovative engagement model that converges Incident Response, Threat Intelligence and our 24/7 SOC Cyber Analyst expertise with advanced technology to deliver time-to-value in terms of threat suppression and complete incident resolution.

In addition to determining the true extent of a breach, eSentire’s Artemis Cyber Investigations team can provide support in satisfying reporting obligations, transitioning findings to law enforcement, implementing lessons learned, and providing guidance through crisis communications—tasks that are challenging, if not impossible, for most businesses to perform on their own.

As we explain in our new ebook, MDR + IR: A Recipe for Cyber Resilience in a Twenty-First Century Risk Landscape, by converging MDR and IR within a single response provider, we are able to:

Ultimately, we’ve created modern IR to deal with modern threats.

To learn more about the IR needs of today’s businesses, please check out the on-demand webinar, The Next Generation of Cyber Investigation and Response, featuring eSentire thought leaders, Bryan Sartin, Chief Services Officer, and Mark Sangster, VP and Industry Security Strategist.

eSentire
eSentire

eSentire is the Authority in Managed Detection and Response, protecting the critical data and applications of 1000+ organizations in 70+ countries from known and unknown cyber threats. Founded in 2001, the company’s mission is to hunt, investigate and stop cyber threats before they become business disrupting events. Combining cutting-edge machine learning XDR technology, 24/7 Threat Hunting, and proven security operations leadership, eSentire mitigates business risk, and enables security at scale. The Team eSentire difference means enterprises are protected by the best in the business with a named Cyber Risk Advisor, 24/7 access to SOC Cyber Analysts & Elite Threat Hunters, and industry-leading threat intelligence research from eSentire’s Threat Response Unit (TRU). eSentire provides Managed Risk, Managed Detection and Response and Incident Response services. For more information, visit www.esentire.com and follow @eSentire.