{"id":34019,"date":"2022-01-14T12:00:00","date_gmt":"2022-01-14T11:00:00","guid":{"rendered":"https:\/\/www.avanet.com\/blog\/managed-threat-detection-24-7-monitoring-and-detection\/"},"modified":"2023-03-22T16:01:39","modified_gmt":"2023-03-22T15:01:39","slug":"managed-threat-detection-24-7-monitoring-and-detection","status":"publish","type":"post","link":"https:\/\/www.avanet.com\/en\/blog\/managed-threat-detection-24-7-monitoring-and-detection\/","title":{"rendered":"Managed Threat Detection &#8211; 24\/7 monitoring and detection"},"content":{"rendered":"\n<p>In this blog post, I would like to introduce Managed Threat Detection (MTD) for endpoints and Server, which can be purchased since the end of July 2021. With MTD, Sophos primarily targets customers who are not (yet) ready to replace their existing third-party endpoint and Server with the Sophos agent. For all other customers who already have a Sophos agent installed on their computers and servers and are running at least Intercept X Essentials, Managed Threat Detection is not relevant.  <\/p>\n\n<h2 class=\"wp-block-heading\" id=\"h-die-erfolgsgeschichte-von-managed-threat-response-mtr\">The Managed Threat Response (MTR) Success Story<\/h2>\n\n<p>Just recently, Sophos announced that <strong>Managed Threat Response<\/strong> (MTR) now <a href=\"https:\/\/news.sophos.com\/en-us\/2021\/10\/26\/another-milestone-for-sophos-managed-detection-and-response-mdr-service\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">protects more than one million devices<\/a>. The products <a href=\"https:\/\/www.avanet.com\/en\/shop\/sophos-central-managed-detection-and-response-complete\/\"><strong>Managed Threat Response<\/strong><\/a> Standard and Advanced are the two most expensive options to protect computers and servers, but also provide the highest security and detection. You get an expert team of analysts, programmers and threat hunters who work around the clock (24\/7) to keep you and your employees safe from cyberattacks.<\/p>\n\n<h2 class=\"wp-block-heading\" id=\"h-paralleler-betrieb-mit-drittanbietern-bisher-nicht-moglich\">Parallel operation with third-party providers not possible so far<\/h2>\n\n<p>&#8220;Sophos Managed Threat <strong>Response<\/strong>&#8221; requires the MTR client, which cannot be run in parallel with third-party solutions such as Microsoft, Symantec, Kaspersky, McAfee or others.\nThe new &#8220;Managed Threat <strong>Detection<\/strong>&#8221; service, on the other hand, was developed specifically for parallel use with third-party providers and is thus intended to appeal to a further target group in order to get a foot in the door with the Sophos brand. <\/p>\n\n<p>But anyone who thinks they can keep their third-party protection with Managed Threat Detection and get the same benefits without the MTR client as customers with Managed Threat Response is sadly mistaken.<\/p>\n\n<h2 class=\"wp-block-heading\" id=\"h-einschrankungen\">Restrictions<\/h2>\n\n<p>The lack of Sophos&#8217;s powerful MTR client understandably brings with it a few limitations.\nThe following comparison table shows which features you have to do without: <\/p>\n\n<figure class=\"wp-block-gallery has-nested-images columns-default is-cropped wp-block-gallery-1 is-layout-flex wp-block-gallery-is-layout-flex\">\n<figure class=\"wp-block-image size-large\"><a href=\"https:\/\/www.avanet.com\/assets\/sophos-central-mtr-mtd-comparison-de-scaled.jpg\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"566\" data-id=\"13475\" src=\"https:\/\/www.avanet.com\/assets\/sophos-central-mtr-mtd-comparison-de-1024x566.jpg\" alt=\"Sophos Central MTR &amp;amp; MTD comparison chart\" class=\"wp-image-13475\" srcset=\"https:\/\/www.avanet.com\/assets\/sophos-central-mtr-mtd-comparison-de-1024x566.jpg 1024w, https:\/\/www.avanet.com\/assets\/sophos-central-mtr-mtd-comparison-de-scaled-64x35.jpg 64w, https:\/\/www.avanet.com\/assets\/sophos-central-mtr-mtd-comparison-de-scaled-300x166.jpg 300w, https:\/\/www.avanet.com\/assets\/sophos-central-mtr-mtd-comparison-de-scaled-600x331.jpg 600w, https:\/\/www.avanet.com\/assets\/sophos-central-mtr-mtd-comparison-de-768x424.jpg 768w, https:\/\/www.avanet.com\/assets\/sophos-central-mtr-mtd-comparison-de-1536x848.jpg 1536w, https:\/\/www.avanet.com\/assets\/sophos-central-mtr-mtd-comparison-de-2048x1131.jpg 2048w, https:\/\/www.avanet.com\/assets\/sophos-central-mtr-mtd-comparison-de-18x10.jpg 18w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/a><\/figure>\n<\/figure>\n\n<h2 class=\"wp-block-heading\" id=\"benachrichtigung-als-einziger-handlungsschritt\">Notification as the only action step<\/h2>\n\n<p> <a href=\"https:\/\/www.avanet.com\/en\/shop\/sophos-central-managed-detection-and-response-complete\/\">Managed Threat Response<\/a> Standard and Advanced offer a choice of three response levels:<\/p>\n\n<ol class=\"wp-block-list\">\n<li><strong>Notification<\/strong>: When the Sophos MTR team detects a threat event or attack, it will notify, but will not take action on its own.\nYou get a report on the cause and detection with actionable steps to remediate the threat on your own. <\/li>\n\n\n\n<li><strong>Collaboration<\/strong>: The Sophos MTR team works with your own IT team, or with an external IT firm if desired, to respond to the appropriate threats.<\/li>\n\n\n\n<li><strong>Authorization<\/strong>: The MTR team takes care of containment and neutralization actions completely independently and only informs about the measures taken.<\/li>\n<\/ol>\n\n<p>With Managed Threat <strong>Detection<\/strong>, on the other hand, only the &#8220;<strong>notification<\/strong>&#8221; response option is available.\nThis means that although you receive an alert via the Central Dashboard or via e-mail when a threat has been detected by the MTR team, you have to neutralize and eliminate it on your own responsibility.\nIf it is an active threat, where every second counts, the MTR team will at least briefly inform you by phone (but really only for active threats).  <\/p>\n\n<h2 class=\"wp-block-heading\" id=\"sophos-rapid-response-als-letzte-instanz\">Sophos Rapid Response as a last resort<\/h2>\n\n<p>In the event of an active threat, Managed Threat Detection leaves you on your own to stop an attack.\nUnfortunately, the MTR team cannot provide support here, since the in-house Sophos MTR client is not installed on the computers and servers.\nThis is exactly where the third-party protection software used should actually shine.\nIf it does not, there is always the option of using the <a href=\"https:\/\/www.avanet.com\/en\/blog\/sophos-rapid-response-immediate-help-for-active-threats\/\">Sophos rapid response service<\/a>.    You will receive lightning-fast assistance from a team of Sophos experts, who will disable existing protection software on all computers and servers and install the MTR client.<\/p>\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p><strong>Attention!<\/strong>  Sophos Rapid Response is not part of Managed Threat Detection and must be purchased separately at a fixed price.<\/p>\n<\/blockquote>\n\n<h2 class=\"wp-block-heading\" id=\"abschliessende-worte\">Closing words<\/h2>\n\n<p>Sophos has created Managed Threat Detection, a service that makes the expertise of its MTR team available to customers who have not built their network security on Sophos solutions.\nAnd that makes perfect sense from a strategic perspective.\nEven if an IT administrator makes the decision today to equip the corporate network with Sophos solutions in the future, this cannot always be implemented in the short term.\nThere may be ongoing contracts that get in the way or active licenses that have already eaten into the budget for the next 3 years.   <\/p>\n\n<p>With Managed Threat Detection, Sophos has created a kind of &#8220;<strong>add-on service<\/strong>&#8221; for precisely such scenarios, which can be considered in the short term to strengthen the security concept.\nThe resources of the MTR team for threat detection are thereby made available to a much larger target group, with which Sophos can only gain.\nThe more data available for analysis, the better the algorithms can be tuned, and it doesn&#8217;t matter whether that data is contributed by customers using the MTR or the MTD agent.  <\/p>\n\n<p>In principle, we would always recommend the MTR variant to all customers who want to protect their endpoints and servers with Sophos. But we also realize that this solution is not designed for every budget. However, it is better to start from the most expensive product with the highest security and work your way down, because security solutions are like insurance &#8211; you only regret having saved money when the damage has been done. \ud83d\ude1c<\/p>\n\n<p>For anyone else who, for whatever reason, doesn&#8217;t want to or can&#8217;t yet throw their entire infrastructure overboard, <strong>Sophos Central Managed Threat Detection<\/strong> for endpoints and Server is certainly a strong addition.\nIt is highly recommended to have a team of experts monitor network activity. <\/p>\n","protected":false},"excerpt":{"rendered":"<p>In this blog post, I would like to introduce Managed Threat Detection (MTD) for endpoints and Server, which can be purchased since the end of July 2021. With MTD, Sophos primarily targets customers who are not (yet) ready to replace their existing third-party endpoint and Server with the Sophos agent. For all other customers who [&hellip;]<\/p>\n","protected":false},"author":4,"featured_media":21347,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[1],"tags":[],"class_list":["post-34019","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-unkategorisiert"],"blocksy_meta":[],"acf":[],"_links":{"self":[{"href":"https:\/\/www.avanet.com\/en\/wp-json\/wp\/v2\/posts\/34019","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.avanet.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.avanet.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.avanet.com\/en\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/www.avanet.com\/en\/wp-json\/wp\/v2\/comments?post=34019"}],"version-history":[{"count":0,"href":"https:\/\/www.avanet.com\/en\/wp-json\/wp\/v2\/posts\/34019\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.avanet.com\/en\/wp-json\/wp\/v2\/media\/21347"}],"wp:attachment":[{"href":"https:\/\/www.avanet.com\/en\/wp-json\/wp\/v2\/media?parent=34019"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.avanet.com\/en\/wp-json\/wp\/v2\/categories?post=34019"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.avanet.com\/en\/wp-json\/wp\/v2\/tags?post=34019"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}