Dr Anton Chuvakin Blog (Original)

Security writing since the mid-2000s. New posts are mirrored from Anton on Security on Medium.

EDR Tool Wins – Only For The Enlightened?

Historical Archive Note: This post was originally published on the Gartner Blog Network on April 25, 2016 by Anton Chuvakin.
Original URL: http://blogs.gartner.com/anton-chuvakin/2016/04/25/edr-tool-wins-only-for-the-enlightened/ | Archive.org Snapshot

We are nearing the end of our Endpoint Detection and Response (EDR) research project; we just pushed our first paper – on EDR operational practices – into review and are concentrating on a technology comparison paper, a more difficult effort.

One thing has emerged from many of the recent conversations with EDR vendors and users. The thing we secretly suspected, but feared to explicitly say – until we have more data.

What IS this thing?

So far in our experience, EDR tool WINS (= examples of wildly successful deployments) tend to be concentrated at a highly mature, “Type A of Type A”, lean-forward, advanced security organizations.

Huh? Are you simply saying that “if you are better at something, things tend to be better for you”? Or are you saying “warning: EDR is a tool for security 1%-ers?”

Not exactly! We are a bit more careful here and we are not branding EDR “a 1%-er tool.” However, success with EDR is found more often in the land of 10+ person SOCs and full-time standing CIRTs, rather than in the land of “we just hired our 1st security person.”

When buying an EDR tool, please be aware of that!

Blog posts related to our current EDR research: