Discussion about this post

User's avatar
Richard Stiennon's avatar

Great insight Adrian. One of my litmus tests for evaluating the potential of a new start up is: Do they exist to generate more alerts or is their productive something that blocks attacks so the only log is "attack blocked."

Sadly, the latter vendors have to swim against the current of industry analysts who ask for "more telemetry." Cylance and Morphisec fit into these categories. Built to stop attacks, both had to layer in additional detection capability to satisfy the craving for alerts.

And then, ironically, the deception vendors come along with alerts that are high quality and they can't sell them because orgs are not mature enough to deal with real alerts. :-(

Jonathan Cote's avatar

Very well done, sir.

No posts

Ready for more?