The Next Evolution of MDR: Preemptive Defense and Agentic Investigation


For years, security operations followed a familiar sequence: detect suspicious activity, investigate what happened, and respond before it caused significant harm. That model developed in a threat landscape where defenders had considerably more time to establish the facts and decide what to do next. In 2019, the average data breach took 206 days to identify and another 73 days to contain, creating a total breach lifecycle of 279 days.

As the time between initial access and attacker movement continues to contract, security teams are being asked to operate within a much narrower window. AI is accelerating reconnaissance, vulnerability discovery, and campaign execution, while defenders are responsible for growing volumes of data across cloud, identity, endpoint, SaaS, and AI environments, often without equivalent growth in analyst capacity.

Read more…
Source:  Rapid7 News


Sign up for the Cyber Security Review Newsletter
The latest cyber security news and insights delivered right to your inbox


Related:

  • UK government “left council to deal with ransomware attack” that cost £11m

    February 9, 2023

    The government left Redcar and Cleveland Borough Council to fight a massive ransomware attack alone for a week, with minimal support or correspondence, the council’s leader has said. Mary Lanigan told MPs yesterday that while police and cybercrime officers were on site within two days, help from Westminster was lacking. Recovering from the incident cost ...

  • Ontario: Children’s Hospital Expects Weekslong Ransomware Recovery

    December 28, 2022

    Nearly a week after a ransomware attack forced a network shutdown at Toronto’s Hospital for Sick Children, patients are still experiencing delays in treatment and diagnostic procedures. The hospital says it has restored some systems, phones and websites, but the recovery process could take weeks. Hackers targeted the hospital’s network on Dec. 19, forcing it to ...

  • Guardian hit by serious IT incident believed to be ransomware attack

    December 21, 2022

    The Guardian has been hit by a serious IT incident, which is believed to be a ransomware attack. The incident began late on Tuesday night and has affected parts of the company’s technology infrastructure, with staff told to work from home. There has also been some disruption to behind-the-scenes services. Read more… Source: The Guardian  

  • Antwerp cyber attacks: Mayor says city will not negotiate or pay

    December 18, 2022

    For over a week, the services of the city of Antwerp have been targeted by a nefarious hacking collective called Play, which alleges to have stolen sensitive data that it will publish if the city fails to pay a ransom by Monday. After a week of administrative services – including libraries, museum booking sites, and council ...

  • REvil-hit Medibank to pull plug on IT, shore up defenses

    December 8, 2022

    Australian health insurance company Medibank will take all of its IT systems offline and close its branches over the weekend as part of its ongoing efforts to improve security and recover from a massive data security breach in October. The planned outage, dubbed Operation Safeguard, begins at 2030 Sydney time on Friday, December 9. The insurer ...

  • Rackspace rocked by ‘security incident’ that has taken out hosted Exchange services

    December 3, 2022

    Some of Rackspace’s hosted Microsoft Exchange services have been taken down by what the company has described as a “security incident”. The company’s most recent incident report at the time of writing, time-stamped 01:57 Eastern Time on December 3rd, offers the following information. “On Friday, Dec 2, 2022, we became aware of an issue impacting our Hosted ...