November 22, 2024

Sophos Partners With Tenable To Unveil SMRS

Facebook
Twitter
LinkedIn
New fully managed solution provides visibility, risk monitoring, prioritization, investigation, and proactive notification to prevent cyberattacks
Representational Image Showing Cybersecurity Shield background-Image Credit- Getty Images

Sophos, a global leader in innovative security solutions that defeat cyberattacks, recently announced a strategic partnership with Tenable, the Exposure Management company, to offer Sophos Managed Risk Service (SMRS), a worldwide vulnerability and attack surface management service.

This latest service features a dedicated Sophos Team that utilizes Tenable’s exposure management technology and partners with the security operations experts from Sophos Managed Detection and Response (MDR) to provide attack surface visibility, continuous risk monitoring, vulnerability prioritization, investigation, and proactive notification designed to prevent cyberattacks.

Industry sources added that the modern attack surface has expanded beyond traditional on-premises IT boundaries, with organizations operating frequently unknown numbers of external and internet-facing assets that are unpatched or under-protected, leaving them vulnerable to cyber attackers.

Industry sources also added that This is evident in the newest Sophos Active Adversary Report, which identifies three tasks that organizations must prioritize to minimize the risk of brazen intrusions that lead to ransomware or other types of attacks. These include closing exposed Remote Desktop Protocol (RDP) access, enabling multi-factor authorization, and patching vulnerable servers, all of which were top entry points in breaches handled by Sophos Incident Response in 2023. The Sophos Managed Risk service can assess an organization’s external attack surface, prioritize the riskiest exposures, like the open RDP, and offer tailored remediation guidance to help curb the blind spots and stay ahead of potentially devastating attacks.

From L To R – Rob Harrison, senior VP for endpoint and security operations product management at Sophos And Greg Goetz, VP of global strategic partners and MSSP, Tenable

Rob Harrison, senior vice president for endpoint and security operations product management at Sophos stated “Sophos and Tenable are two industry security leaders coming together to address urgent, pervasive security challenges that organizations continuously struggle to control. We can now help organizations identify and prioritize the remediation of vulnerabilities in external assets, devices, and software that are often overlooked. Organizations must manage these exposure risks, because unattended, they only lead to more costly and time-consuming issues and are often the root causes of significant breaches. We know from Sophos’ worldwide survey data that 32% of ransomware attacks start with an unpatched vulnerability and that these attacks are the most expensive to remediate. The ideal security layers to prevent these issues include an active approach to improving security postures by minimizing the chances of a breach with Sophos Managed Risk, Sophos Endpoint, and 24×7 Sophos MDR coverage.”

Greg Goetz, vice president of global strategic partners and MSSP, Tenable stated “While the latest zero day may dominate the headlines, the biggest threat to organizations, by a large margin, is still known vulnerabilities – or vulnerabilities for which patches are readily available. A winning approach includes risk-based prioritization with context-driven analytics to proactively address exposures before they become a problem. Sophos Managed Risk, powered by the Tenable One Exposure Management Platform, delivers outsourced preventive risk management, enabling organizations to anticipate attacks and reduce cyber risk.”

Craig Robinson, research vice president of Security Services, IDC

Craig Robinson, research vice president of Security Services, IDC stated “One of the biggest challenges organizations face when improving their security posture is prioritizing what to handle first. This type of guidance helps solve that issue and reduces the workload for security teams tasked with tackling vulnerability and exposure management. Solutions such as Sophos Managed Risk can be a differentiator by enabling overwhelmed teams to take a more holistic approach to continuous monitoring and threat management.”

Kieron Stone, cybersecurity business development manager at Phoenix Software Ltd

Kieron Stone, cybersecurity business development manager at Phoenix Software Ltd stated “Sophos Managed Risk simplifies the difficult and resource-consuming task of identifying vulnerabilities, really understanding the extent of risk exposure, and prioritizing necessary remediations. As a trusted managed service provider (MSP), this is a service we’re proud to stand behind, and nearly all our customers using it have already discovered significant vulnerabilities that they were previously unaware of. For organizations that don’t already have a well-defined vulnerability patching cadence, this is a must-have service for the identification of vulnerabilities and building that schedule; and for organizations that are already managing vulnerabilities, it’s a second set of eyes for added peace of mind that they’re not missing anything.”

Brooks Roy, president at Communications Consulting, Inc.

Brooks Roy, president at Communications Consulting, Inc. stated “You can’t fix what you can’t see. Sophos Managed Risk is shining a light on areas of exposure that require remediation in order to keep customers protected. Combining Sophos’ elite MDR experts with Tenable’s industry-leading exposure management technology gives us a full-picture view of vulnerabilities with the guidance we need to minimize risk. The real value add for us as a channel partner is having the ability to easily manage Sophos Managed Risk’s prioritized alerts across our customer base on the Sophos Central dashboard.”

Specific key benefits of Sophos Managed Risk comprise of:

  • External Attack Surface Management (EASM): Advanced identification and classification of internet-facing assets, such as web and email servers, web applications, and public-facing API endpoints
  • Continuous monitoring and proactive notification of high-risk exposures: Proactive notification when a new critical vulnerability is identified in an organization’s internet-facing assets
  • Vulnerability prioritization and identification of new risks: Swift detection of high-risk and zero-day vulnerabilities, followed by real-time notification to ensure critical internet-facing assets are promptly identified, investigated, and responded to by order of importance.

Industry sources added that Sophos Managed Risk is available as an extended service with Sophos MDR, which already shields more than 21,000 organizations globally. The Sophos Managed Risk team is Tenable-certified and works closely with Sophos MDR to share essential information about zero-days, known vulnerabilities, and exposure risks to assess and investigate possibly exploited environments.

Industry sources confirmed that the organizations benefit through regular interaction, including scheduled meetings with Sophos experts to review recent discoveries, insights into the current threat landscape, and recommendations for remediation and prioritizing actions. Additionally, organizations can initiate inquiries via the Sophos Central platform, allowing users to directly engage with the Sophos Managed Risk team for tailored support, and reports and to review their latest prioritized alerts.

Source

 

Share.

RELATED POSTS

(Centre) Patrick Chalhoub, Group President of Chalhoub Group, Manos Raptopoulos, President of SAP EMEA, and Marwan Zeineddine, Managing Director, SAP UAE, were joined by executives from both organizations at the signing ceremony. Image courtesy: SAP
SAP And Chalhoub Group Alliance Adopts Rise With SAP Platform
Azad Properties Streamlines Operations and Boosts Efficiency with Yardi Technology. Image courtesy: Yardi
Azad Properties Assigns Yardi Technology To Boost Its Operations And Productivity
du, the leading telecom and digital services provider, today announced an innovative connectivity portfolio designed to address the digital transformation needs of government and large organisations. Image courtesy: du
du Unveils Enterprise Plus Connectivity Platform To Boost Digital Transformation
  • Capital Securities Corp
  • Asialink Finance

LATEST POSTS

Representational Image
Imdaad has announced its strategic regional expansion into Oman through a joint venture with Oman Real Estate and Investment (Oris). Image courtesy: Imdaad
Azad Properties Streamlines Operations and Boosts Efficiency with Yardi Technology. Image courtesy: Yardi
(Centre) Patrick Chalhoub, Group President of Chalhoub Group, Manos Raptopoulos, President of SAP EMEA, and Marwan Zeineddine, Managing Director, SAP UAE, were joined by executives from both organizations at the signing ceremony. Image courtesy: SAP