How threat research and MDR help SMEs gain a defensive edge

How threat research and MDR help SMEs gain a defensive edge

Person on a computer

Corporate IT and security teams have the unenviable task of keeping relentless and increasingly sophisticated adversaries at bay. They often face limited resources and growing attack surfaces, but recruiting and retaining top security professionals to run an internal Security Operations Center (SOC) is out of reach for many organizations.

At the same time, threats evolve and adversaries refine their techniques, resulting in incidents that often disrupt business operations.

To avoid falling behind, defenders need a proactive approach that combines prevention, detection and remediation with accurate and timely threat intelligence. If it is impractical to build this capability in-house, renting or purchasing as a service is a more realistic option.

Of course, this is not a new concept – smaller organizations have been reaping the benefits of new IT innovations through offices, managed services providers and cloud computing for decades.

There is a good case to be made for doing the same with advanced cybersecurity services, and this is where Managed Detection and Response (MDR) can have a big impact. MDR provides organizations with a proactive, expert-driven and scalable threat monitoring and hunting capability, without the cost of an elite SOC.

Not long ago, an MDR was expensive and complex – although less so than a dedicated in-house facility. It is now becoming increasingly practical for smaller organizations to consider this.

In a recent conversation, the director of ESET Threat Research said Jean Ian Boutin discussed his team’s work and how threat research and intelligence are incorporated into MDR workflows.

He also shared where the combination of cutting-edge technology and human expertise provides the greatest practical benefit, particularly for SMB environments.

What benefits most small business users? ESET Threat Research? How does this change if you use ESET MDR?

ESET has a threat research team spread across multiple regions. I’m part of the team in Montreal, but we have researchers all over Europe and also in the US.

There are things that everyone can see: our publications on WeLiveSecurityand speaking and presenting at cybersecurity conferences worldwide.

Then there are things that only ESET business customers get: all sorts of “tips and tricks”; That is, information about threat actors: what they do, how they operate – all things that help our customers stay safe.

When it comes to that managed detection and response, Threat intelligence is a key component that helps our detection and response team understand how different threat actors operate and how they can use this information to protect our customers from security breaches.

What if your security team had the support of global threat researchers?

ESET MDR is powered by world-class threat intelligence and security experts who help uncover attacker tactics, investigate suspicious activity, and respond quickly when threats emerge.

Learn more about ESET MDR

You’ve talked a little bit about the tip of the iceberg – the entire backend of MDR that users rarely see but is absolutely crucial. Could you explain that?

The various alerts you may see in your console are sometimes endpoint detections that we want to investigate. And my team is responsible for ensuring that all new samples and threats in customer environments are addressed and detected. So one of the team’s tasks is to ensure that all of these new trends, all of these new patterns are viewed, examined and then discovered on site with our customers. This is one of the key aspects.

We place a strong emphasis on organizing threat intelligence data on e-crime, ransomware, APT groups, and nation-state actors targeting global organizations. Our researchers use these insights to link new breaches to previous cases.

They also assess the severity of the breach and we can also assess what the purpose of the attack might be. It really gives the customer a complete overview of what may have happened, whether or not a breach occurred, or even the specific group that targeted them.

What does MDR add to existing ESET endpoint protection?

MDR is more tailored and the relationship with the customer is improved and expanded. But my team’s output is spread across the entire product set.

There was talk about it ESET private reports recently: How relevant are they to the challenges faced by most small and medium-sized businesses? Are you facing targeted attacks? What about nation-state actors?

The threat profile varies from organization to organization, and a nation-state actor typically has predefined goals and targets victims who align well with those goals.

When it comes to e-crime, this is far-reaching. This is aimed at masses. We see a lot of info stealers. We also see a lot of ransomware.

So our job is to understand how all of these groups work and make sure that when they have new techniques, we can actually act very quickly and make sure that we block any attempts.

This is the ultimate goal, but there are also so many threat actors that do things like this and there are so many more malware families. Ensuring customers are protected is truly a daily task. There is definitely no shortage of work.

James Rodewald, one of ESET’s security analysts, uses this concept of triangulation: see something in the wild, hear from an affected customer, and report back to the threat intelligence team. An example he used is an attack with FamousSparrow. Can you explain this in more detail from your perspective?

It’s important to have close relationships with the people who actually deal with cases like this, because my team’s main job is to look at the telemetry, so collecting the data from all the endpoints, and we try to find interesting cases and the cases that we need to work on to improve overall protection.

But sometimes the MDR team comes across something we’ve seen in the past, and that also gives us a better understanding of how the threat actor actually operates.

In this particular case, this was an eye-opener for us as we have not seen this threat actor in quite some time. Whenever there is a case where a customer uses MDR, it is better from a research perspective because through the closer relationship with the customer we know more about their infrastructure and can therefore help them better. We can better understand the impact of the case. And that is then passed on to other threat intelligence customers. That’s why we try to be as close as possible to all of these teams and link these incidents so that we can improve our reporting and improve our understanding of all of these threats.

You talked about working with the MDR analysts and the D&R (Detection and Response) team. How does that change the way you work and understand threats when you have that one-on-one relationship with the analysts and perhaps the customer?

It changes everything because with MDR we already have a working relationship with the person responsible for the security of that organization, so we can very quickly understand the scale of the attack, what exactly happened, why the attackers were there and so on.

The information available to us is exponentially greater than what we can obtain with regular endpoints. For us, this relationship is therefore invaluable in terms of insight, visibility and our understanding of the case.

Last year there was a wave of attacks in the UK, with major companies such as Jaguar Land Rover and Marks & Spencer compromised via outsourced helpdesk services. Small and medium-sized companies also have such outsourced services as part of their supply chain and are often the less well-protected parts of a larger company’s supply chain. Should they be worried?

The risk posed by supply chain attacks is significant. Over the years, there have been numerous documented cases of threat actors targeting supply chain vulnerabilities, often focusing on third parties with less stringent security measures. From such providers compromiseAttackers can first gain access to an organization’s network.

A benefit of MDR is its comprehensive visibility, ensuring a comprehensive overview of all detections and alerts. This capability allows us to detect even smaller anomalies more effectively. Because our team continually monitors these organizations for potential incidents, we are able to promptly detect and respond to subtle mistakes made by threat actors.

Supply chain attacks pose significant challenges because it is difficult to secure all third parties. However, implementing an effective solution improves our ability to respond to such events quickly and efficiently.

As the leader of a threat intelligence team, what difference do you see MDR making for clients? What implications does this have for an organization that has an MDR service and for an organization that may not necessarily have taken this step yet?

In general, as I mentioned, continuous visibility is much better with MDR. If your organization is affected by a campaign, you will have better tools to summarize the attackers’ various actions and understand what they have done on your network.

Simply put, MDR provides deeper insight into attacks. From a threat research perspective, this is the biggest advantage, and another important reason to value such transparency is the speed of response. With MDR, there is already a secure channel between researchers and your organization, making it easier to reach someone who can quickly take action to contain a breach.

Last question: What would you say to organizations that may think MDR is too complicated or too expensive?

MDR acts like an insurance policy, helping to detect threats like ransomware early – often before major problems arise. Attackers typically use initial access brokers to gain access, but several warning signs can be identified in advance. Although paying a ransom is never recommended, recovery can still be disruptive. MDR supports business continuity so you can continue to focus on your core offerings.

Sponsored and written by ESET.

Leave a Reply

Your email address will not be published. Required fields are marked *