A survey commissioned by VMware and conducted by Forrester Consulting showed a majority (75%) of security leaders are in the discovery phase of their extended detection and response (XDR) journey and nearly half (45%) stated XDR lacked a clear, standard industry definition despite the increased XDR adoption and return on investment (ROI).
The report, “Evolving Security Operations Capabilities: Insights Into the XDR Paradigm Shift,” surveyed 1,291 global IT, networking, and security decision makers responsible for the security and network strategy at their organization.
XDR is a threat detection and response approach that provides protection against cyberattacks, unauthorized access, and misuse. XDR collects and automatically correlates data across multiple security layers – email, endpoint, server, cloud workload, and network. This allows for faster detection of threats and improved investigation and response times through security analysis.
XDR commonly combines elements of security information and event management (SIEM), security orchestration, automation and response (SOAR), endpoint detection and response (EDR), and network traffic analysis (NTA) in a software-as-a-service (SaaS) platform to centralize security data and incident response.
According to Forrester’s survey, around one-third of those that were not using XDR said they still need proof that the technology is legitimate before adoption, while at least 75% of those who already adopted XDR believed XDR includes both EDR and network analysis and visibility.
XDR ConfusionVMware last year introduced its Carbon Black XDR platform built on its EDR and Contexa threat intelligence capabilities
The market is “very confusing,” Tom Gillis, former SVP and GM of VMware’s networking and advanced security business group, told SDxCentral in an earlier interview. “The industry talks an awful lot about XDR, but it’s our view that much of what is being discussed and marketed as XDR is nothing more than a rebranding of a SIEM because it’s relying on sample data [and] metadata,” which leads to a high false positive rate in SIEM.
But, VMware is not replacing SIEM with XDR, and is instead adding its standalone endpoint and network detection and remediation (ENDR) service into Carbon Black EDR that feeds alerts into SIEM or XDR platforms, Gillis explained.
The vendor is also a member of the XDR Alliance to help the community build standards.
XDR BenefitsThe survey also looked into how security leaders whose organizations have adopted XDR see benefits.
Those in the survey that have adopted XDR identified improved speed and accuracy of threat detection as one of their top five drivers. About 75% of them also stated increased ROI was one of the top XDR business benefit. They reported a 13.9% increase in ROI as a result of adoption, with that number increasing as implementation matured.
Additionally, the study found a majority (83%) of XDR adopters stated automation and repeatability can complement other tools in their security tech stack. And 75% agreed that XDR enables their team to skip some of the tedious, common, or repetitive detection engineering work they would otherwise have to do to focus on more targeted attacks, with this number rising to 91% among more mature adopters.
To better embrace the benefits of a mature XDR strategy, Forrester recommends organizations adopt all of the most important XDR components that include EDR, vulnerability management, identity and access management, and network analysis and visibility; enable employees to focus on more strategic functions; and showcase top organizational benefits, which will help further strengthen the XDR business case.
Comments