The extended detection and response (XDR) market has become more crowded as almost all of the large security vendors and a majority of the endpoint detection and response (EDR) and security information and event management (SIEM) players have rolled out XDR platforms. But not all of those offerings should count as XDR and it is not the holy grail, Trellix’s Chief Product Officer Aparna Rayasam argues.

Per Gartner, XDR offers improved threat prevention, detection, and response capabilities for security operations teams. XDR combines elements of EDR, SIEM, security orchestration, automation, and response (SOAR), and network traffic analysis (NTA) in a software-as-a-service (SaaS) platform. 

An XDR service should have basic ingredients including data, visibility, multi-vector aggregation, incident response, and a strong end-point solution, Rayasam told SDxCentral.

“I get why some of the vendors will go there because it's a growing trend and you want to be on it,” she said. “But we need to be fair to our audience, to our target customers — not everything is an XDR.”

XDR Misconceptions

Rayasam also noted three other common XDR misconceptions.

The first is that XDR will improve your infrastructure defenses and help prevent hacks and breaches.

Rayasam is cautions to use the word “prevent.” Instead, what XDR providers can help is to research and make the policy to automatically block multiple preset vectors through threat intelligence. The exterior visibility helps organizations to stay ahead of the attack actors.

“I'd say anyone that tells you that any software will prevent [breaches] to 100% or to a great degree of confidence is slightly delusional,” she said. 

Second is that XDR is the holy grail and that an organization will not need to hire cybersecurity professionals.

The skill gap is real and many organizations are facing a constant battle to keep their security operation teams fully staffed, Rayasam noted. Plus, given the complexity of the multiple attack vectors, the amount of data security teams need to collect and analyze is another uphill task.

“XDR is definitely every major SOC leader’s friend, and should be the tool of choice because this definitely helps them alleviate their challenges,” she said.

But organizations still need to make sure their business logic is accounted for. “Organizations own their data, they know their business processes, they must adjust XDR posture to those,” she added.

The security team should have introductory roles for traffic watching and anomaly observing, and also more senior-level, experienced talent who are able to triage a security operation center, correlate multiple things horizontally, and make decisions for actions, Rayasam suggests.

The third misconception is that only major organizations and large enterprises will benefit from XDR.

Trellix sees all sizes of organizations using XDR, and Rayasam noted it can help smaller-sized businesses to become more efficient in defense against threats from multiple vectors. 

“It's a refreshing trend that more and more organizations are buying into the premise that no single-linear vector cause is enough for us to determine and protect,” she said. Therefore, there is general awareness and acceptance of using XDR for integrating threat intelligence across multiple attack vectors. 

A recent Cynet survey found that almost all CISOs from organizations with small security teams and limited resources plan to consolidate their security platforms down to more robust and comprehensive tools in order to gain more control and visibility, and they named XDR as their top method of consolidation.

Rayasam expects this to become an evolving trend, despite XDR still being in its early stages of market penetration. 

Plus, XDR can also be a great training tool. “Once you've watched XDR, how traffic and attacks are treated, and how constantly the posture is evolved, then you, as an organization, [will] learn and your operators [will] also become so much more efficient,” she said.