4IR Simplified
John Tseriwa
A RECENT Gartner Peer Community survey found that 62 percent of information technology (IT) and security leaders have experienced burnout due to what they call “unique stressors”.
This is a scary figure indicating the demanding nature of IT leadership positions.
While many, especially young people, find IT work appealing due to its perceived excitement and innovation, the reality can be different. IT careers can involve a wide range of tasks, some of which can be quite complex and demanding.
The demanding responsibilities of IT professionals include keeping servers running smoothly, ensuring network functionality, assisting users with technical problems, contributing to software development and in some cases maintaining a strong cybersecurity posture. These comprehensive responsibilities can lead to burnout for IT professionals, if not managed effectively.
Cybersecurity firms are coming up with solutions to resolve this; and this is where managed detection and response (MDR) comes in.
Sophos defines MDR as a fully managed 24/7 service delivered by experts who specialise in detecting and responding to cyber-attacks that technology solutions alone cannot prevent.
By combining human expertise with protection technologies and advanced machine learning models, MDR analysts can detect, investigate and neutralise advanced human-led attacks, preventing data breaches and ransomware. Sophos is one of the leading cybersecurity giants, which was recently named the best-managed security service in the 2023 SC Awards Europe.
The ever-evolving threat landscape, coupled with the increasing complexity of IT systems, makes effective cybersecurity management a significant challenge for most organisations.
We should agree that technology will not be able to stop every attack. Sophisticated attackers leverage on a variety of tactics, including, exploiting stolen credentials. Compromised login information grants easy access to systems.
These attackers constantly adapt their methods, making it a relentless race. To effectively detect and neutralise these determined threats, 24/7 human analysis is essential. Security operations professionals can identify suspicious activity that might evade even the most advanced technology.
Unfortunately, maintaining round-the-clock expert monitoring is often unrealistic for most companies due to resource constraints.
Remember, it is usually the same team that you expect to attend meetings, who sometimes fall sick or leave the company for greener pastures, usually after training.
MDR features and functionalities vary depending on the service provider. Sophos has six primary steps to the detection and response process. These are:
Collection: Security telemetry is gathered from across the full IT ecosystem — endpoint, firewall, network, cloud, email and identity solutions. The more analysts can see, the faster they can respond.
Threat detection: Threat intelligence and business context are added to the data to provide a more complete view. Related security events are grouped into clusters for complete and efficient investigation.
Threat hunting: Highly trained analysts proactively detect threats that bypass security products. They look for tactics, techniques and procedures commonly used by cybercriminals and threats that may bypass various security tools.
Investigation: Analysts determine the scope and severity of the threat and identify next steps.
Remediation: Analysts interrupt the attack to prevent it from spreading, removing malware and isolating impacted systems.
Neutralisation: Analysts perform root cause analysis to fully eliminate the attacker and prevent recurrence.
MDR can be utilised by all types of organisations across all sectors, from small companies with limited IT resources to large enterprises with an in-house security operations centre group. MDR has been known to quickly detect and respond to a variety of cyber threats, including those that might evade traditional detection methods.
While MDR providers leverage on network security tools to block common attacks, today’s cyber threats are often more cunning. Sophisticated attackers can exploit vulnerabilities or bypass traditional defences.
According to Microsoft, MDR experts know specialised tactics to deal with these more advanced cyber threats. As of May 2023, Sophos earned the highest rating and had more reviews than any other MDR vendor, according to the Gartner Peer Insights.
Gartner Incorporated is one of the world’s largest IT research and advisory company.
MDR is successful when it functions as a well-coordinated orchestra, with three key instruments playing in harmony: people, processes and technology. When these three elements work together seamlessly, MDR delivers its full potential. Organisations gain a comprehensive security posture that can effectively address today’s ever-evolving cyber threats.
John Tseriwa is a technology entrepreneur and a digital transformation advocate focusing on delivering business solutions powered by Fourth Industrial Revolution technologies. He can be contacted at: [email protected] or +263773289802.




