According to Arctic Wolf Field CTO Ian McShane, extended detection and response (XDR) isn’t the holy grail of cybersecurity. XDR is the problem, not the solution, he said in an interview with SDxCentral.

XDR, while a still newish security segment, combines elements of security information and event management (SIEM); security orchestration, automation, and response (SOAR), endpoint detection and response (EDR); and network traffic analysis (NTA) in a cloud-based platform. This centralizes security data, threat hunting, and incident response.

But as the acronym has caught on among vendors, “It’s almost encouraging the use of deploying point products to solve very small problems here, there, and everywhere, and build a bigger footprint of tools and processes and procedures that we know is killing security analysts already through fatigue,” McShane said.

In other words: security vendors pushing the latest buzzy new acronym — in this case, XDR — causes another kind of alert fatigue. While this traditionally refers to unnecessary noise caused by false positives and too many alarms created by too many security tools, noise surrounding XDR causes similar security headaches. XDR, or any shiny new security product, encourages companies to buy products they don’t really need, which also adds to tool overload — or, even worse, organizations buying tools that don’t work in their IT environment, he explained.

To fix this problem, vendors need to shift the focus back to security outcomes and operationalization, McShane added. “That word operationalization is really critical, because if you’re not operationalizing something, you’re not centralizing and bringing it together, then it is just more tools, more collectors, more agents, more locations, and more data to filter through, so it’s 100% at risk of causing even more alert fatigue,” he said.

This is at least partially self-serving. Arctic Wolf, a $4.3 billion cybersecurity company whose new CEO Nick Schneider recently told SDxCentral that his company wants to be the “category-defining platform” for the $150.4 billion security and risk management market, has long touted its vendor-agnostic, security-operations approach. Its platform works with customers’ existing products and infrastructure.

But alert fatigue and security tool sprawl are real problems, too, and it’s hard to argue with McShane when he said the ultimate goal of any security operations product should be to monitor, detect, investigate, and respond to cyberthreats, thus ultimately reducing risk.

“We don’t care what solutions you have, what products you have, we can work with those,” he said. “And the reason that’s really important is that it’s my unscientific guess that nine times out of 10, organizations already have the tools today to fundamentally improve their security posture, but they lack either the people or the skills or the time to be able to do that operationalization.”

The first thing that organizations should do, McShane said, is to stop buying security products — and this is not limited to XDR. “Close all the flashy product PowerPoints that you’re getting sent from vendors, put the purchase order approval stamps away, and really understand what you already have in your environment today.”

Arctic Wolf Takes On XDR

Before becoming field CTO at Arctic Wolf, McShane worked as a Gartner analyst, and he says most of the thousands of organizations he spoke with either didn’t know what security products they had deployed in their environments, or they bought overlapping tools that added to the environments’ complexity. “They weren’t using the tools they had already spent a lot of money on, and they just kept buying new things,” he said.

The COVID-19 pandemic, and related remote work force, compounded this problem. As organizations first sent their employees home, and later adopted work-from-anywhere strategies, they often added more security products and services in addition to employees’ home networks, gear, and shared devices.

“So many sticking plasters, and Band-Aids, and temporary solutions have been put in place that I wager most organizations don’t know what they have,” McShane said. “My guidance is always stop and figure out what you have today, because there’s a great chance that you’ve got a lot of your bases covered, and it’s more about the operationalization.”

Arctic Wolf, similar to several security analytics vendors, takes a hybrid or “open” approach to XDR in that its platform works with other vendors’ security products. McShane says this allows it to better adapt to fit businesses’ needs, changing IT environments, and evolving threat landscape. “That open XDR approach means that it’s built and it’s designed to be extensible, in a way that can adapt with the needs of the business,” he explained. “Cybersecurity, information security, isn’t a one-and-done plan. It’s something that changes every week and evolves over time.”