Managed detection and response (MDR) provider eSentire is expanding its partnership with CrowdStrike to migrate a large number of its customer base from Broadcom Carbon Black to the Falcon platform. One of their joint customer — Thomas H. Lee (THL) equity firm — shared the story and driving factors behind the Carbon Black to CrowdStrike migration.
The acquisition of Carbon Black by Broadcom, followed by the attempted divestiture and pending merger with Symantec, created waves of uncertainty among Carbon Black customers.
“When we started with Carbon Black, they were very good at what they did,” eSentire CEO Kerry Bailey told SDxCentral, adding the provider witnessed Carbon Black’s journey from initial public offerings (IPOs), deterioration, to acquisition by VMware and then Broadcom. “Then we saw Broadcom kind of spin it out to Symantec, and it worries me.”
“They've got to be on their game, or we're not going to succeed together as partners. So it is in my best interest for our customers representing them to move them as fast as I can,” he added. “And that's our intention.”
eSentire is migrating over a third of its Carbon Black customer base to CrowdStrike's Falcon platform within a year.
“We actually have I believe the largest incumbent Carbon Black base … we owe it to our customers they can't afford to be on a legacy technology, one that's not responding as fast, one that's not giving us the coverage,” Bailey said.
The driving factors lead to THL's migration decision THL is one of eSentire’s clients that is migrating from Carbon Black to CrowdStrike.
Mark Benaquista, managing director at THL Partners, said that the equity firm has about 20 portfolio companies managed through eSentire for security. “We invest mostly in mid-market [where] management team is focused on growth and may not necessarily have all the experience and certainly not all the deep pockets to properly secure their investments.”
For the portfolio companies that are using Carbon Black’s endpoint security tools managed by eSentire, “the time for renewal or some change, that's when we take advantage of moving them over to CrowdStrike.”
The decision to migrate from Carbon Black to CrowdStrike was influenced by several factors.
“It has to make business sense,” Benaquista said. “There's a decision matrix around this, so you're measuring disruption to the business, the cost to the business, the capability of the tools and where they they score.”
But not all of these factors are weighed the same, Benaquista highlighted the research and development (R&D) investment and “staying ahead of the curve” capabilities of CrowdStrike.
“We've seen levels of capability and the R&D investment on the CrowdStrike side outpace others in the marketplace,” he said. “When we just look from a technology perspective at what CrowdStrike can do capability-wise, it's been one of our preferences.”
Ensuring a smooth transition from Carbon Black to CrowdStrike One of the critical aspects of such a significant migration is ensuring minimal disruption to customers' operations.
“Anytime you make changes, there's always some risk, but I will say we haven't had any disruption. The plans that we put in place are coordinated,” THL’s Benaquista said. “The agents themselves coming on and off, have worked well. We may have had the force some folks that are remote to give us access to machines, some anomalies that are in the long tail, but no disruptions to our team.”
eSentire’s Bailey echoed the smooth transition facilitated by advanced deployment technologies with automation capabilities, adding that eSentire migrated close to 1,000 endpoints from Carbon Black to CrowdStrike in a couple of days.
CrowdStrike Chief Business Officer Daniel Bernard told SDxCentral this migration isn’t anything new to the company. “Since day one we've been replacing legacy anti-virus. The definition of legacy tools has changed, but the ability to deploy an agent [remains] very quickly. We're the lightest weight agent on the market. We don't require a reboot.”
CrowdStrike expands partnerships with eSentire To enhance eSentire’s 24/7 managed security operations, the provider expanded its partnership with CrowdStrike to combine eSentire’s MDR solution with the Falcon platform capabilities across endpoint detection and response (EDR), identity and cloud security, intelligence and threat hunting and security information and event management (SIEM) (SIEM).
Benaquista noted, from THL’s perspective, it hands over the complexity of handling various tools to eSentire and CrowdStrike, but the platform approach offers a single interface and reference point.
“All the attack surfaces need to be covered. When we make a decision, we go sort of full robust,” he said. “This whole protect layer is about the entire footprint from endpoint to cloud network as well as the logs.”
Comments