In our most recent post, we covered a short history lesson on Antivirus. It is important to understand history, lest be bound to repeat it. There are certain events that take place in the course of history that stand out. In the timeline of cybersecurity, the fourth generation of antivirus (AV), also known as endpoint detection and response (EDR), is one of those events.
In future posts, we will cover the effect of COVID-19 on organizations and the risks it places on their data. That being said, it is ever more critical to protect your organization’s data where it meets the human. This most often occurs at the endpoint, making your choice of AV/EDR all that more critcal. You should think about the types of data that your organization uses. Is the data personally identifiable information (PII) of your customers? Is the data trade secrets about your latest product offering that is going to give your company the upper hand against competitors? Are you able to understand where that data sits, how it is used, and most importantly, making sure that it is protected to the fullest extent possible?
The good news is that there have been significant improvements not only in AV/EDR technologies themselves, but delivery and consumption options have dramatically changed, often times removing barriers and pain points associated with Gen 1-3 AV/EDR products. First, we will cover service providers. A key question is: Does your organization provide cybersecurity as a core competency of your business? As an executive, driving value for your stakeholders (shareholders, board of directors, employees, etc.) is priority above all else. One question that many executives need to consider is if the business is performing functions that do not directly drive benefit to the business’s value proposition. An example of this could be going to market for a financial accounting function. Unless you are in the business of performing accounting, it makes sense to look for efficiencies and expertise in the market. This is true for the cybersecurity services function.
Specific to AV/EDR, there are a number of managed security service providers (MSSP) that have significant technology delivery capability, as well as incident response expertise. Instead of the “roll your own” approach by keeping the function in-house, you have the opportunity to “buy up” through engaging with reputable MSSPs that bring not only expertise and technology, but battle tested and hyper focused experience. You can focus on the bottom line in your organization at the same time you improve your cybersecurity capabilities and significantly reduce risk. An added bonus is that the MSSP will always be looking for a competitive advantage of having the latest and greatest AV/EDR platform available to their customers. This takes you out of the technology refresh procurement cycle where you are forking over significant capital every three years, just to feel protected.
You should take a hard look at your AV/EDR. If you are Gen 1-3, you have a ways to go to reduce your risk. You don’t have to go through the pain of procurement and forking over that big check. We recommend you take a “bottom line” approach by concentrating the efforts of your existing staff on inwardly focused and elevated business problems. Let the innovations of the market drive a better product and set of services to your door.

Download our recent white paper, "Solving CyberSecurity's Achilles' Heel".

Thank you! You will receive an email withing 24-hours.

Share This