TechValidate Research on Cisco SecureX threat response

4 Case Studies


Cisco SecureX threat response Case Study

Citynet

Introduction

This case study of Citynet is based on a May 2020 survey of Cisco SecureX threat response customers by TechValidate, a 3rd-party research service.

“Cisco AMP and Firepower is how we use it and love it!”

“It simplifies the review, research and impact analysis of security events and frees our team up to work on other security initiatives.”

Challenges

The business challenges that led the profiled company to evaluate and ultimately select Cisco SecureX threat response:

  • Needed to solve the following security challenges when they started using SecureX threat response with their Cisco Security products:
    • Needed their security technologies to work together
    • Wanted to identify and remediate threats faster
    • Wanted to maximize the time of their skilled resources due to being understaffed

Use Case

The key features and functionalities of Cisco SecureX threat response that the surveyed company uses:

  • Uses SecureX threat response at least once a week.
  • Improved collaboration across the following teams after using Casebook in SecureX threat responsee:
    • Improved collaboration within SecOps
  • agrees that SecureX threat response’s ability to connect with 3rd party security tools for comprehensive investigations is important to them.

Results

The surveyed company achieved the following results with Cisco SecureX threat response:

  • Greatest value they get from the Chrome or Firefox browser plug-in for SecureX threat response:
    • Ability to kick off an investigation
  • Eliminated the following tasks after using SecureX threat response:
    • Detection & Analysis tasks
    • Containment, Eradication, and Recovery tasks
  • Weekly time savings their Security Operations team achieved by using SecureX threat response for the following use cases:
    • incident management: at least 1-3 hours/week
    • threat intelligence and investigations: at least 1-3 hours/week
    • remediation / first strike response actions: at least 1-3 hours/week

Cisco SecureX threat response Case Study

Large Enterprise Retail Company

Introduction

This case study of a large enterprise retail company is based on a May 2020 survey of Cisco SecureX threat response customers by TechValidate, a 3rd-party research service. The profiled company asked to have their name blinded to protect their confidentiality.

“Email and web security. These products have extended our ability to search for iocs through the message header and body, a very complex thing to do without it.”

“It allows me to easily search and remediate systems "

Challenges

The business challenges that led the profiled company to evaluate and ultimately select Cisco SecureX threat response:

  • Needed to solve the following security challenges when they started using SecureX threat response with their Cisco Security products:
    • Needed their security technologies to work together
    • Needed a better way to visualize whether a threat has impacted their environment
    • Wanted to identify and remediate threats faster
    • Wanted to centralize and triage high priority alerts
    • Wanted to maximize the time of their skilled resources due to being understaffed

Use Case

The key features and functionalities of Cisco SecureX threat response that the surveyed company uses:

  • Uses SecureX threat response daily.
  • Improved collaboration across the following teams after using Casebook in SecureX threat responsee:
    • Improved collaboration across NetOps and/or IT
  • agrees that SecureX threat response’s ability to connect with 3rd party security tools for comprehensive investigations is important to them.

Results

The surveyed company achieved the following results with Cisco SecureX threat response:

  • Greatest value they get from the Chrome or Firefox browser plug-in for SecureX threat response:
    • Ability to kick off an investigation
  • Eliminated the following tasks after using SecureX threat response:
    • Planning tasks
  • Weekly time savings their Security Operations team achieved by using SecureX threat response for the following use cases:
    • incident management: at least 4-6 hours/week
    • threat intelligence and investigations: at least 4-6 hours/week
    • remediation / first strike response actions: at least 1-3 hours/week

Cisco SecureX threat response Case Study

Global 500 Media & Entertainment Company

Introduction

This case study of a Global 500 media & entertainment company is based on a May 2020 survey of Cisco SecureX threat response customers by TechValidate, a 3rd-party research service. The profiled company asked to have their name blinded to protect their confidentiality.

“Umbrella – we have integrated SecureX threat response with Demisto using a custom integration and no longer need to constantly go back and forth between Umbrella and other solutions.”

“The API is easy to utilize and integrate with other solutions.”

Challenges

The business challenges that led the profiled company to evaluate and ultimately select Cisco SecureX threat response:

  • Needed to solve the following security challenges when they started using SecureX threat response with their Cisco Security products:
    • Needed a better way to visualize whether a threat has impacted their environment
    • Wanted to identify and remediate threats faster
    • Wanted to centralize and triage high priority alerts

Use Case

The key features and functionalities of Cisco SecureX threat response that the surveyed company uses:

  • Uses SecureX threat response daily.
  • Improved collaboration across the following teams after using Casebook in SecureX threat responsee:
    • Improved collaboration within SecOps
  • agrees that SecureX threat response’s ability to connect with 3rd party security tools for comprehensive investigations is important to them.

Results

The surveyed company achieved the following results with Cisco SecureX threat response:

  • Greatest value they get from the Chrome or Firefox browser plug-in for SecureX threat response:
    • No feature (have not used the browser plugin)
  • Eliminated the following tasks after using SecureX threat response:
    • Detection & Analysis tasks
    • Containment, Eradication, and Recovery tasks
  • Weekly time savings their Security Operations team achieved by using SecureX threat response for the following use cases:
    • incident management: at least 1-3 hours/week
    • threat intelligence and investigations: at least 7-12 hours/week
    • remediation / first strike response actions: at least 4-6 hours/week

Cisco Threat Response Case Study

Oznet

Introduction

This case study of Oznet is based on a May 2020 survey of Cisco Threat Response customers by TechValidate, a 3rd-party research service.

“All these solutions we handle in the Threat Response Stealthwatch Enterprise, Firepower, Umbrella.”

“It is a very good tool to perform event analysis in a centralized console, for me it is the best.”

“Cisco allows me to visualize quickly and to correct in time.”

Challenges

The business challenges that led the profiled company to evaluate and ultimately select Cisco Threat Response:

  • Needed to solve the following security challenges when they started using Threat Response with their Cisco Security products:
    • Needed their security technologies to work together
    • Needed a better way to visualize whether a threat has impacted their environment
    • Wanted to identify and remediate threats faster
    • Wanted to centralize and triage high priority alerts
    • Wanted to maximize the time of their skilled resources due to being understaffed

Use Case

The key features and functionalities of Cisco Threat Response that the surveyed company uses:

  • Uses Threat Response daily.
  • Agrees that Threat Response’s ability to connect with 3rd party security tools for comprehensive investigations is important to them.

Results

The surveyed company achieved the following results with Cisco Threat Response:

  • Greatest value they get from the Chrome or Firefox browser plug-in for Threat Response:
    • Ability to kick off an investigation
    • Ability to consume threat intelligence blogs
    • Immediate access to context from Cisco Security products
    • Immediate access to context their 3rd party web-based product (SIEMs or other security consoles)
  • Eliminated the following tasks after using Threat Response:
    • Planning tasks
    • Detection & Analysis tasks
    • Post-Incident Activity tasks
  • Weekly time savings their Security Operations team achieved by using Threat Response for the following use cases:
    • Incident management: at least 12-18 hours/week
    • Threat intelligence and investigations: at least 7-12 hours/week
    • Remediation / first strike response actions: at least 7-12 hours/week



More Research on Cisco SecureX threat response