Security intelligence: solving the puzzle for actionable insight Fran Howarth Senior analyst, Security Bloor Research
“It is not if, but when and how often” The situation today “It is not if, but when and how often” $ Targeted Sophisticated Well-resourced
Today’s security imperative Prevention Detection Response
Prevention alone is not enough Detection Response
Impact of malicious breaches
Detection is the new imperative Prevention Detection Response
Malicious breaches take time to discover
From detection to containment
Where remediation falls short Prevention Detection Response
Time taken to resolve a breach
The role of security intelligence platforms
Most cost-effective security tools
Core capabilities Actionable intelligence Forensics Log management and analysis Advanced analytics Continuous monitoring Automated remediation Forensics Actionable intelligence
Sample use cases Advanced threat management Compliance management Continuous monitoring Forensic investigation Fraud detection Insider threat detection Monitoring of remote facilities Network behaviour anomaly detection Support for multiple locations Web application defence