Safe XDR
A managed service that not only detects and responds to threats but also provides the visibility of your attack surface and the control you need to feel cyber safe.
Coverage gaps
Detection and response technologies commonly provide incomplete coverage of your IT environments. Attackers exploit these gaps.
Safe XDR defends the whole of your attack surface. It validates that your security controls are working and enables you to proactively close the gaps in your defence.
Threat identification
Sophisticated attacks such as advanced persistent threats (APTs) employ tools and techniques that help attackers remain undetected by most traditional security solutions. Safe XDR detects and responds to threats at machine-speed, delivering cyber safety through resilience.
Threat remediation
Detection and response technologies generate a lot of security alerts, leading to alert fatigue. Safe XDR provides 95% workflow automation and 100% transparency. It delivers rapid security outcomes, with specific recommendations linked to business risk.
Skills shortage
Due to a shortage of skills in the cyber security industry, organisations are finding it difficult to recruit and retain professionals. Safe XDR enables our clients to augment their security expertise and staff.
Safe XDR is the first platform in the market built to enable Continuous Threat Exposure Management (CTEM). It combines ASM and XDR technologies in a single platform that provides visibility of your attack surface and the control you need to feel cyber safe. Safe XDR comprises:
Encore Attack Surface Management (ASM) service that provides an attacker's view of your attack surface and shows gaps and misconfigurations in your defences that create risk
Extended Detection and Response (XDR) service delivered from the Security Operations Centre (SOC), proactively hunts for evidence of attack, supported by automation that empowers analysts and reduces response times
Risk Operations Centre (ROC) that prioritises exposure risks, develops risk mitigation plans, provides execution support to clients, and ongoing service management.
Scoping
- Discovery
- Prioritisation
- Validation
- Mobilisation
- Scoping review
Scope Safe XDR service
Cyber risk assessment and security controls review and refinement by a CTEM Security Optimisation Manager.
Exploit threat Intelligence
Threat intelligence, threat model, and asset registry drive CTEM scoping, threat detection, and how actions to mitigate exposure risk are prioritised.
Hunt threats
Proactive, automated, and human-driven hunting for evidence of attack improves detection and informs prioritisation.
Identify exposures
- External ASM provides an attacker's view of your attack surface
- Internal ASM shows gaps in tool coverage and identifies misconfigurations that create risk
Discover threats
24/7 XDR monitoring of cloud and on-premises IT, by experienced analysts.
Rules, analytics, and AI used with human expertise to filter out false positives and benign events, from real threats.
Automate operations
Security incidents are reverse-engineered to refine CTEM scope and to automate incident prevention and response.
SOAR automation eliminates the time and effort of assembling data to investigate alerts, reducing response times, improving the quality and consistency of response.
Triage and investigate alerts
Expert investigation of alerts and incidents, to quickly understand the scope and details of threats.
Contextual information is used to understand what happened and when, as well as who was affected and how far the attack could go.
Respond to threats
Performanta provides actionable advice on how to best contain and remediate a certain threat.
Examples include:
- Advice on how to isolate a system
- Step-by-step guidance on eliminating the threat
Remediate incidents
Remediation is performed in two parts:
- Where Performanta manages the technology on behalf of the client, we are able to remediate the immediate threat.
- If the client does not have the skills or capacity to perform the mitigating actions, we can supply specialist expertise.
Prioritise
Risk Operation Centre:
- Correlate system information with known vulnerabilities
- Evaluate controls within defined risk tolerance levels and assess likelihood that an asset could be compromised.
Evaluate risks
Risk Operation Centre evaluates:
- Exploitability of vulnerabilities to ensure risk is accurate;
- Impact to business of prioritised asset being compromised.
Mobilise risk mitigation
- Risk Operations Centre prioritises exposure risks for mitigation, based on the likelihood and impact of exploitation.
- Security Optimisation Manager organises on-demand supply of specialist expertise.
Validate and refine service scope
- Monitor vulnerabilities and track resolution activities.
- Ensure compliance and regulatory requirements are met.
- Security incident data used to refine CTEM scope.