Posts

Amazon Security Lake is now generally available

Today we are thrilled to announce the general availability of Amazon Security Lake, first announced in a preview release at 2022 re:Invent. Security Lake centralizes security data from Amazon Web Services (AWS) environments,   software as a service   (SaaS) providers, on-premises, and cloud sources into a purpose-built data lake that is stored in your AWS account. With Open Cybersecurity Schema Framework (OCSF) support, the service normalizes and combines security data from AWS and a broad range of security data sources. This helps provide your team of analysts and security engineers with broad visibility to investigate and respond to security events, which can facilitate timely responses and helps to improve your security across multicloud and hybrid environments. Amazon Security Lake is now generally available

Considering an XDR Purchase? Here Are Our Lessons Learned.

  Lessons learned from our search for, and integration of, our XDR Trusted Internet is now deploying  Stellar Cyber XDR  –as a SOC-monitored solution or as an Infrastructure as a Service. The marketing hype around XDR is deafening for those of you considering an XDR. It’s hard to sort through the slick websites and marketing noise to tell what’s actually real. So, I thought I share a few lessons learned –from the viewpoint of the CEO of a self-funded  MSSP , I hope this helps in your buying decisions. For the last four years, we’ve been a died-in-the-wool Fortinet MSSP. We love our Fortinet firewalls, with our people certified through NSE7, working hard to tune the feature-packed high-speed machines to bend to our will. For various reasons, we decided about two years ago to begin the search for a way to accommodate the requests from would-be clients to not have to rip and replace their existing security systems. As well,  SOC , NOC,  EDR , MDR,  NDR ,...

How the Changing Attack and Cybersecurity Solutions Landscape Led Me to Join Stellar Cyber

Image
  Working in Cybersecurity for the past two decades, helping managed security service providers ( MSSPs ) meet the needs of their customers, gives me a unique perspective on how our industry has evolved and ultimately led me to join Stellar Cyber last month to run the Global Service Provider Business. As I get to know Stellar Cyber’s current customers and those within the company that design, build, and deploy the leading   Open XDR Platform   on the market, I will, from time to time, share some insights I’ve gained working for some of the most well-known brands in the industry. Today I thought I would start by outlining the significant changes occurring in the market today and how those changes influenced me to join   Stellar Cyber .  The Rising Demand for Security Services from MSPs Anyone who has been in our industry for any length of time knows that many organizations find it challenging to hire and retain staff for their internal security teams. With a skil...

“Proof of Concept” Season is Coming

Image
  Three signs your cybersecurity vendor might be gaming the system For those of you who attended the  RSA Conference  in April, I am sure the bombardment of vendor emails, phone calls, and LinkedIn meeting requests is underway. While I’d bet many of the vendors begging for meetings offer products or services that are not on your radar for 2023-2024, there are probably a handful that you would like to put to the test to see if they can deliver better results than what you are currently using. For those vendors, after the compulsory introductory meeting, some technical discussion, or even a customer reference call, you will be offered a Proof of Concept (sometimes also called a Proof of Value). This time-honored tradition allows you to  “test the product for yourself.”   During the PoC, the vendor attempts to show you how their product stops more attacks, detects more phishing emails, spots more malicious websites, and the like to validate their marketing claims. ...

What Enterprise C-level Executive Customers Want From MSSPs

Image
For an MSSP, the key to a CIOs heart is reducing risk for a cost that is less than what they’re spending now, Stellar Cyber asserts. A CIOs or CISOs job is never easy, but it’s more difficult now because cyberattacks are more frequent and more complex than ever before.  Cybersecurity  is a top priority for enterprises, and fundamentally, C-level executives are responsible for managing the risk of security breaches at cost points the business can afford. When there’s a serious attack, those executives can lose their jobs. Reducing risk means spending more money on tools and hiring more analysts to run them, but CISOs never have enough budget. Also, really smart security analysts are expensive and very hard to find. In this environment,  CxOs  try to find a balance between spending and risk – they’re always looking for an acceptable level of risk given the resources available. For an  MSSP , the key to a CIOs heart (and wallet), in particular, is stressing that yo...

Unlocking the Potential of AI/ML in Cybersecurity: Challenges, Opportunities, and Progress Indicators

Image
  Artificial intelligence (AI)  has been transforming the  cybersecurity  landscape for over a decade, with  machine learning (ML)  speeding the detection of threats and identifying anomalous user and entity behaviors. However, recent developments in large language models  (LLMs) , such as  OpenAI’s GPT-3 , have brought AI to the forefront of the cybersecurity community. These models use documented  cybersecurity  information to learn how to respond to prompts on the topic.  LLMs  can also explain complex security issues in easy-to-understand language, bringing the non-expert into the world of  cybersecurity . While  LLMs  are not a silver bullet for cybersecurity, they can quickly detect and mitigate cyberattacks at scale. Unfortunately, as with all advancements in the cybersecurity world, bad actors are using  LLMs  to increase the breadth and speed of their attacks with some early success. One of the...