eSecurity Solutions Articles/Blog
Search by Keyword
Blog Categories
Selecting the Right Detect and Respond Security for Your Company
Published On:June 16, 2024 By: Tom Ruffolo 

Why you Need MDR Detect and Respond Security
The first thing to look at when selecting MDR detect and respond security is why you need it. If you look at the history of cybersecurity, you
could have at one time asked the same question about firewalls, MFA, email security, mobile security, and cloud security. But the reality is that attacks get more sophisticated, they penetrate security designed to prevent attacks and attacks have a long life inside networks before being detected.
Detect and Respond as a Requirement of Regulations
Protect, Detect and Respond are all fundamental components of cybersecurity regulations frameworks. Those categories of security are part of all major regulations and frameworks. The list of security required to satisfy each category grows each year as threats continue to evolve and evade other security. Thus regulation compliance is the primary reason to add detect and respond security. If your company is regulated, it will likely select most of the detect and respond security solutions that are available.

Security Solutions are defined to be in one of several categories:
- Assess or Identify
- Protection & Prevention or
- Detect, Respond and Recover
Regulations require Detect and Respond solutions because Protection/Prevention solutions by themselves are not sufficient. Attacks still happen. Strong security starts with 3rd party security assessments to define your specific security needs and gaps
MDR Detect & Respond for Strong Security
Stronger security Should be the #1 reason for adding MDR Detect & Respond Solutions. Companies that are serious about security know they need a balanced approach to security.
Regulations require Detect & Respond because it is important to provide adequate security
Breach analysis shows that cyber-attacks are often inside networks for months because they evaded Protect level security and evade other methods for discovery.

Appropriate security Should:
- Addresses Top Gaps or Needs for YOUR specific company
- Provides balanced security appropriate utilizing:
- Assessments and gap prioritization
- Protect & Detect solutions, and
- Your company’s ability to Respond
Understanding Protect versus Detect & Respond Security
Protect Security:
Traditional Security solutions were built around the concept of:
- Blocking or preventing attacks – worked fine until cybercriminals regularly found ways to circumvent most security. Security holes get closed, but then another loophole is found.
- Traditional solutions include: MFA, endpoint security (including EDR), firewalls email security etc.
See the table below for a list of Protect objectives and security solutions that are typically considered preventative.
Detect & Respond Security:
MDR Detect and Respond security monitors your security, infrastructure or assets to detect indications of attack or indications of compromise (IOA/IOC).
Ideally, detection security will:
- Monitor all your security, users, and key IT infrastructure
- Correlate all data from all sources
- Analyze the information utilizing all the information for draw smart conclusions
- Validate the alert information or change the alert rules
Once threats are detected (in as automated way as possible):
- Attacks will be blocked and stopped from propagating
- Attack chain can be analyzed
- Conclusions can be drawn that aid in a broader response to the attack and how to adjust security to prevent future attacks
Listed below is a definition of what Detect & Respond security objectives as well as criteria for selecting Detect & Respond security.


Selecting the Right Detect & Respond Security for Your Company
When trying to determine which Detect and Respond solution to own here is a guideline. For the solutions we defined here (SIEM, EDR and NDR), these solutions are not redundant but rather are additive. They provide very different security and in fact only SIEMs and NDR are truly Detect & Respond solutions. EDR is primarily the next generation of endpoint security using AI to enhance what it can detect.
We classify companies in 3 categories (See diagram below)
- Compliance driven (Regulations, Cyber Insurance or Customer Requirements)
- Strong security focused (but not regulated)
- Companies evolving their security but at their own pace
Our Recommendations for Detect & Respond Security Selection:
- For companies in the compliance group, we recommend all 3 D&R solutions as soon as possible. Each makes your security meaningfully more secure. Compliance driven companies want the best security and know that compliance if a moving target.
- Companies in the Strong security group will want to define a short-term roadmap to acquire all 3 solutions as well. Strong security dictates adopting new security over time to respond to new threats.
- Companies in the Evolving Security group, should create a longer term roadmap to acquire all 3 solutions. Lagging too far behind the current generation of security can result in unexpected attacks and dealing with the consequences.
Pros & Cons of Different Detect & Respond Solutions
Let’s quickly review the different Detect & Respond Solutions in the Market:
SIEMs
- Monitor All Key assets (Security, key IT like servers & networks, and user behavior)
- SIEMS provide a complete picture of attacks by correlating ALL data into a rule and AI based threat detection model
- It really is the only threat detection that looks at a broad set of threat data
- Cons: It is complex and can be expensive, but affordable managed SIEMs do exist (we can help)
EDR
- Many people think EDR is all you need.
- What it does is provide the latest generation of mostly Protect Level security leveraging AI
- Cons: what it does not do is monitor your endpoints looking for all types of attacks and it is ONLY looking at endpoint
NDR
- Network Detect and Respond fills the need to look at network traffic looking for anomalous behavior that is indicative of attacks
- NDRs look at North/South and East/West traffic on your network to provide 360 degrees of threat visibility
- It is a great way to detect complex attacks not detectable in other ways
- Cons: It focuses on network traffic
Cloud Monitoring
- Most cloud infrastructure monitoring is focused on public/private cloud server security
- Can be important to monitor large server installations
Vulnerability Scans
- Great solutions that scan looking for defined security deficiencies
- These have a very limited scope and must repeatedly be run for a new snapshot test results
Detect & Respond Solution Pros & Cons

In conclusion, these solutions are all essential and all will become standard building blocks of core security.
By getting a 3rd party risk assessment and prioritizing your security in your security roadmap, you can maximize the security with the lowest budget.
eSecurity Solutions can help you define your security gaps, define an appropriate security roadmap, acquire, implement and manage your security. Let us help you select the right Detect & Respond Security for your company.
Contact us today.