EeSentire
Available through IT Raven
- Cybersecurity
eSentire is a managed detection and response provider that runs 24/7 security operations centers on its own open XDR platform. Managed detection and response, or MDR, means an outside team watches your environment around the clock, investigates what looks wrong and acts to stop an attack, rather than only sending you an alert. eSentire calls its approach multi-signal: telemetry from your network, endpoints, cloud, logs and identity systems lands in one platform, on the reasoning that a threat missed in one place shows up in another. Founded in 2001, it runs two operations centers, in Waterloo, Ontario and Cork, Ireland, with more analysts across the United States, Europe and Asia-Pacific, backed by a research team it calls the Threat Response Unit. It states that 65 percent of its customers are classed as critical infrastructure and that its centers are PCI compliant and SOC 2 and ISO 27001 certified. For a buyer, eSentire is the team that takes the response part of security operations off your hands.
Best for
- Companies without a 24/7 security team of their own that need someone watching and acting overnight and on weekends, beyond business hours alone.
- Organizations that have bought several security tools and want one team to correlate the signals across all of them instead of chasing each console separately.
- Microsoft-heavy environments that want their existing Microsoft Sentinel and Defender licensing monitored and acted on, with no additional software or hardware to install.
- Companies running workloads in AWS, Microsoft Azure and Google Cloud at once that want one posture and workload protection service rather than a tool per cloud.
- Businesses that want incident response contracted before a breach, on retainer with a suppression guarantee, rather than hunting for help mid-crisis.
A company that only wants software to run itself, with no outside team taking action, is buying a different kind of product than eSentire sells.
What they offer
Managed Security. The core service is managed detection and response from round-the-clock operations centers on the eSentire Atlas XDR platform, which normalizes signals across the whole customer base and, eSentire says, recognizes more than 12,000 malicious indicators that feed an automatic global block list. Response is a spectrum from detection through remediation: isolating an endpoint, quarantining a file, killing a process, purging a phishing email after delivery, suspending an account or correcting a cloud misconfiguration, with unlimited threat hunting and incident handling stated as standard. MDR for Endpoint blocks known and fileless attacks and lets hunters isolate compromised machines, using a machine-learning tool called BlueSteel that classifies PowerShell commands, and it also runs on endpoint tools you already own. MDR for Cloud covers AWS, Azure and Google Cloud, with workload protection delivered through Lacework. Two Microsoft-specific versions layer eSentire's hunters onto a customer's own Microsoft Sentinel or Defender for Endpoint licensing; eSentire is a Microsoft Security Solutions Partner and MISA member with MXDR status. Around the core sit exposure management, which finds and prioritizes gaps before an attacker does and includes managed vulnerability scanning and phishing training, dark web monitoring drawn from more than 700 deep and dark web sources, and incident response: an on-demand retainer with a four-hour remote threat-suppression guarantee, on-site responders within 24 hours, and one tabletop exercise or response-plan review a year, or emergency response when an incident is already underway.
Cybersecurity
Managed Security
Proof
A global asset management firm. eSentire's analysts spotted the firm's own systems downloading malicious payloads from outside, engaged the customer, added the attacker's infrastructure to the global block list, reset compromised accounts, blocked the addresses at the firewall and isolated the affected systems. The root cause was traced to a Citrix vulnerability, CVE-2023-4966, and the customer rebuilt the systems on patched software; no data left the network. The story is eSentire's own published account, told here without the customer's name.
eSentire also states that it contains a threat in a mean of 15 minutes, that 99.3 percent of threats isolated at the first point of compromise, 99.99 percent noise suppression, and an operations team with 96 percent analyst retention and an average tenure of six years. Its Threat Response Unit says it detected activity from the 2021 Microsoft Exchange ProxyLogon campaign a day before public disclosure and remediated 22 true positives in customer environments. These figures are eSentire's own.
Good to know
- The response commitment is the point of the service. eSentire states 15 minutes as its mean containment time and 14 days for onboarding, though other sheets describe onboarding in hours or days. Get the commitment you are relying on written into the agreement.
- The service is people-led as much as software-led. Ask who on the eSentire team is assigned to you and what they are authorized to do on your systems during an active incident.
- Full digital forensics, litigation support and expert testimony come through the incident response retainers, and are not part of base MDR.
- Its scale figures disagree by document vintage: 1,000 organizations in 70 countries on one sheet, 1,500 in 80 on another, 2,000 in 80 and 35 industries on the newest. Treat any one as sheet-specific.
- Three vertical solution briefs in the collateral carry a restricted marking and were not read for this page. Figures and product names here are the company's own material.
Similar companies
They offer some of the same services. Add two or more and we quote them against each other.
- Network and Voice
- Cybersecurity
- Cloud and Infrastructure
- Backup and Continuity
- +1 more
- Network and Voice
- Cybersecurity
- Cloud and Infrastructure
- Data Center and Colocation
- Cybersecurity
- Network and Voice
- Unified Communications
- Cybersecurity
- Cloud and Infrastructure
- +2 more
How buying works
The store is the easy part. Staying on the account is the job.
Anyone can show you logos. The reason to buy here is what happens on install night, and on the ticket you open nine months later.
- 01
Build your quote list
Add services and companies as you shop. No form stands between you and the shelf.
- 02
We bring back real options
A person shops the bench against your addresses, then walks you through what fits and what does not.
- 03
We handle the order and install
Paperwork, site survey, install dates, cutover night. You get one thread, not five vendors.
- 04
We stay on your account
Same team for moves, adds, tickets and the next renewal. That is the part everyone else drops.
