The Next Evolution of MDR: Preemptive Defense and Agentic Investigation


For years, security operations followed a familiar sequence: detect suspicious activity, investigate what happened, and respond before it caused significant harm. That model developed in a threat landscape where defenders had considerably more time to establish the facts and decide what to do next. In 2019, the average data breach took 206 days to identify and another 73 days to contain, creating a total breach lifecycle of 279 days.

As the time between initial access and attacker movement continues to contract, security teams are being asked to operate within a much narrower window. AI is accelerating reconnaissance, vulnerability discovery, and campaign execution, while defenders are responsible for growing volumes of data across cloud, identity, endpoint, SaaS, and AI environments, often without equivalent growth in analyst capacity.

Read more…
Source:  Rapid7 News


Sign up for the Cyber Security Review Newsletter
The latest cyber security news and insights delivered right to your inbox


Related:

  • Ministers coordinating ‘resilience response’ after ‘major’ cyber attack hits NHS systems across UK

    August 6, 2022

    The Welsh Ambulance Service says the outage is significant, far-reaching and affects all four nations in the UK, but NHS England says there’s “currently minimal disruption”. People seeking medical help via the NHS 111 service have been warned there could be delays after the attack led to a “major” computer system outage. The security issue was identified ...

  • Ukraine’s secret cyber-defense that blunts Russian attacks: excellent backups

    June 8, 2022

    The Kremlin-backed cyberattack against satellite communications provider Viasat, which happened an hour before Russia invaded Ukraine, was “one of the biggest cyber events that we have seen, perhaps ever, and certainly in warfare,” according to Dmitri Alperovitch, a co-founder of CrowdStrike and chair of security-centric think tank Silverado Policy Accelerator. Alperovitch shared that opinion during a ...

  • Team of experts help Rutube to recover from the May 9 cyberattack

    May 11, 2022

    Rutube involved several expert teams, including a team of specialists from Positive Technologies security center, to deal with the aftermath of the May 9 cyberattack, the website said in its Telegram channel. “In order to investigate the attack and deal with its aftermath, several expert teams were involved, including a team of specialists from the Positive ...

  • SpringShell RCE vulnerability: Guidance for protecting against and detecting CVE-2022-22965

    April 4, 2022

    On March 31, 2022, vulnerabilities in the Spring Framework for Java were publicly disclosed. Microsoft is currently assessing the impact associated with these vulnerabilities. This blog is for customers looking for protection against exploitation and ways to detect vulnerable installations on their network of the critical remote code execution (RCE) vulnerability CVE-2022-22965 (also known as ...

  • IT outage at Scotland’s Heriot-Watt University enters second week

    March 24, 2022

    Edinburgh’s Heriot-Watt University has entered a second week of woe following a vist by an infosec nasty. The 200-year-old institution’s IT team first referred to the crisis as a “security incident” but a spokesperson confirmed to The Register that it was a cyber attack. A week on, things remain resolutely broken. VPN? Down. Oracle R12 Finance System? ...

  • ENISA: Incidents Handling and Cybercrime Investigations

    March 8, 2022

    The European Union Agency for Cybersecurity (ENISA) explores how CSIRTs, law enforcement agencies and the judiciary cooperate and how they can train together to better tackle cyber incidents and respond to cybercrime. The report published today facilitates the cooperation between CSIRTs and law enforcement agencies (LEAs) and looks into their interaction with the judiciary (judges and ...