Corporate Overview 2017-04...Why LogRhythm As Your Strategic TLM Partner Broad Regulatory Compliance...

28
LogRhythm Overview Rev. April 2017

Transcript of Corporate Overview 2017-04...Why LogRhythm As Your Strategic TLM Partner Broad Regulatory Compliance...

Page 1: Corporate Overview 2017-04...Why LogRhythm As Your Strategic TLM Partner Broad Regulatory Compliance Focus Innovation Customer Success Platform Scalability & Flexibility Market Leadership

LogRhythmOverviewRev.April2017

Page 2: Corporate Overview 2017-04...Why LogRhythm As Your Strategic TLM Partner Broad Regulatory Compliance Focus Innovation Customer Success Platform Scalability & Flexibility Market Leadership

TheModernCyberThreatPandemic 3,930Breachesin2015

953Breachesin2010

321Breachesin2006

736millionrecordswereexposedin2015,comparedto96millionrecordsin2010

Thesecurityindustry isfacingserioustalentandtechnologyshortages

Selected

DataBreaches

Source:World’s BiggestDataBreaches,Informationis Beautiful

Page 3: Corporate Overview 2017-04...Why LogRhythm As Your Strategic TLM Partner Broad Regulatory Compliance Focus Innovation Customer Success Platform Scalability & Flexibility Market Leadership

NoEndInSight

MotivatedThreatActors

Cyber-crimeSupplyChain

ExpandingAttackSurface

MotivatedThreatActors

Cyber-crimeSupplyChain

ExpandingAttackSurface

Page 4: Corporate Overview 2017-04...Why LogRhythm As Your Strategic TLM Partner Broad Regulatory Compliance Focus Innovation Customer Success Platform Scalability & Flexibility Market Leadership

Modernthreatstaketheirtimeandleveragetheholisticattacksurface

TheCyberAttackLifecycle

Recon.&Planning

InitialCompromise

Command&Control

LateralMovement

TargetAttainment

Exfiltration,Corruption,Disruption

Page 5: Corporate Overview 2017-04...Why LogRhythm As Your Strategic TLM Partner Broad Regulatory Compliance Focus Innovation Customer Success Platform Scalability & Flexibility Market Leadership

ProtectionThroughFasterDetection&Response

HighVulnerability LowVulnerability

Months

Days

Hours

Minutes

Weeks

MTTD&M

TTR

MEANTIMETODETECT(MTTD)Theaveragetimeittakestorecognizeathreatrequiringfurtheranalysis andresponse efforts

MEANTIMETORESPOND(MTTR)Theaveragetimeittakestorespondandultimatelyresolve theincident

Asorganizationsimprovetheirability toquickly detectandrespondtothreats,theriskofexperiencingadamagingbreachisgreatlyreduced

ExposedtoThreats ResilienttoThreats

Page 6: Corporate Overview 2017-04...Why LogRhythm As Your Strategic TLM Partner Broad Regulatory Compliance Focus Innovation Customer Success Platform Scalability & Flexibility Market Leadership

Detection&Response

ITBudgets2013

Prevention

Detection&Response

Prevention

ITBudgets2020

StrategicShifttoDetectionandResponseisOccurring

Sources:Gartner,ShiftCybersecurity InvestmenttoDetectionandResponse, January2016;Gartner,Forecast:InformationSecurity,Worldwide, 2014-2020,1Q16Update,April 2016Note:Excludessecurity services fromestimatedoverallmarketspend forenterprise informationsecurity

By2020,60%ofenterpriseinformationsecuritybudgetswillbeallocatedforrapiddetectionandresponseapproaches,upfrom20%in2015.–Gartner,2016

Detection&Response

ITBudgets2015

Prevention

Page 7: Corporate Overview 2017-04...Why LogRhythm As Your Strategic TLM Partner Broad Regulatory Compliance Focus Innovation Customer Success Platform Scalability & Flexibility Market Leadership

ObstaclesToFasterDetection&Response

AlarmFatigue

SwivelChairAnalysis

ForensicDataSilos

FragmentedWorkflow

LackofAutomation

EffectiveThreatLifecycleManagementü Addressestheseobstaclesü Enablesfasterdetectionand

responsetothreats

Page 8: Corporate Overview 2017-04...Why LogRhythm As Your Strategic TLM Partner Broad Regulatory Compliance Focus Innovation Customer Success Platform Scalability & Flexibility Market Leadership

ThreatLifecycleManagement(TLM)

• Seriesofalignedsecurityoperationscapabilities

• Beginswithabilityto“see”broadlyanddeeplyacrossITenvironment

• Endswithabilitytoquicklymitigateandrecoverfromsecurityincidents

Goalistoreducemeantimetodetect(MTTD)andmeantimetorespond(MTTR),whilekeepingstaffinglevelsflat

Page 9: Corporate Overview 2017-04...Why LogRhythm As Your Strategic TLM Partner Broad Regulatory Compliance Focus Innovation Customer Success Platform Scalability & Flexibility Market Leadership

End-to-EndThreatLifecycleManagementWorkflow

TIMETODETECT TIMETORESPOND

ForensicDataCollection

InvestigateQualifyDiscover RecoverNeutralize

Securityeventdata

Log&machinedata

Forensicsensordata

Searchanalytics

Machineanalytics

Assess threat

Determinerisk

Isfullinvestigationnecessary?

Analyzethreat

Determinenatureand

extentofincident

Implementcounter-measures

Mitigatethreat&associatedrisk

Cleanup

Report

Review

Adapt

Page 10: Corporate Overview 2017-04...Why LogRhythm As Your Strategic TLM Partner Broad Regulatory Compliance Focus Innovation Customer Success Platform Scalability & Flexibility Market Leadership

ThisApproachIsNotEffective

LogManagement SIEM

EndpointMonitoring&Forensics

SecurityAutomation&Orchestration

NetworkBehavioralAnalytics

SecurityAnalytics

Page 11: Corporate Overview 2017-04...Why LogRhythm As Your Strategic TLM Partner Broad Regulatory Compliance Focus Innovation Customer Success Platform Scalability & Flexibility Market Leadership

OurApproachIs

ForensicData

CollectionDiscover Qualify Investigate Neutralize Recover

Page 12: Corporate Overview 2017-04...Why LogRhythm As Your Strategic TLM Partner Broad Regulatory Compliance Focus Innovation Customer Success Platform Scalability & Flexibility Market Leadership

12 |©2016LogRhythm

LogRhythm’sApproachtoThreatLifecycleManagement

Page 13: Corporate Overview 2017-04...Why LogRhythm As Your Strategic TLM Partner Broad Regulatory Compliance Focus Innovation Customer Success Platform Scalability & Flexibility Market Leadership

UnifiedPlatformforEnterpriseThreatLifecycleManagement

ForensicDataCollection

InvestigateQualifyDiscover RecoverNeutralize

LogManagement

SecurityAutomationandOrchestrationCaseManagement,SmartResponse,Metrics…

SecurityAnalyticsAIEngine,AICloud,Alarming,Prioritization,Search,Dashboards…

User&EntityBehavioralAnalytics

NetworkBehavioralAnalytics

NetworkMonitoring

EndpointMonitoring

DataCollectionEnterpriseForensicDataLake

poweredbyLogRhythmMachineDataIntelligenceandElasticsearch

EndpointBehavioralAnalytics

Page 14: Corporate Overview 2017-04...Why LogRhythm As Your Strategic TLM Partner Broad Regulatory Compliance Focus Innovation Customer Success Platform Scalability & Flexibility Market Leadership

LogRhythmTLMPlatformTop5Differentiators

TIMETODETECT TIMETORESPOND

ForensicDataCollection

InvestigateQualifyDiscover RecoverNeutralize

2.PrecisionSearch

3.HolisticThreatDetection

5.EmbeddedSecurityAutomationandOrchestration

1.MachineDataIntelligence Fabric(MDIF)

4.Risk-BasedMonitoring

Page 15: Corporate Overview 2017-04...Why LogRhythm As Your Strategic TLM Partner Broad Regulatory Compliance Focus Innovation Customer Success Platform Scalability & Flexibility Market Leadership

MachineDataIntelligenceFabric

DataCollection

DataGeneration

MachineDataIntelligence(MDI)Fabric• UniformDataClassification• UniformDataStructure• TimeNormalization• RiskScore

• UserPersona• HostPersona• Geolocation• FlowDirection• …more

BenefitsüServesasITenvironmentabstractionlayerüEnablesgenericscenariorepresentationüAllowsforhigh-efficacypackagedanalyticsmodules

Page 16: Corporate Overview 2017-04...Why LogRhythm As Your Strategic TLM Partner Broad Regulatory Compliance Focus Innovation Customer Success Platform Scalability & Flexibility Market Leadership

CurrentTechnologyAllianceEcosystemIPS/MALWARE

ENDP

OINTSECU

RITY

VULNERABILITYMANAGEMENT VERTICALSOLUTIONS NEXT-GENFIREWALLS

NETWORKING&

INFRASTRUCTURE

THREATINTELLIGENCEOTHERNETWORKPACKETBROKERSIDENTITY&ACCESS

Page 17: Corporate Overview 2017-04...Why LogRhythm As Your Strategic TLM Partner Broad Regulatory Compliance Focus Innovation Customer Success Platform Scalability & Flexibility Market Leadership

PrecisionSearchPoweredbyElasticsearch

StructuredSearch UnstructuredSearch

Benefitsü Quickresultsü Less“noise”ü Investigationautomationü Fastandaccuratedecisions

Machine-AssistedSearch

Page 18: Corporate Overview 2017-04...Why LogRhythm As Your Strategic TLM Partner Broad Regulatory Compliance Focus Innovation Customer Success Platform Scalability & Flexibility Market Leadership

HolisticThreatDetectionPoweredbyAIEngine

Benefitsü Real-timeadvancedthreatdetectionü Detectionacrossfullattacklifecycleü Easilycustomizableü LowerfalsenegativesANDfalsepositives

UserThreats

NetworkThreats

Endpoint Threats

LogData

ContextualData

Page 19: Corporate Overview 2017-04...Why LogRhythm As Your Strategic TLM Partner Broad Regulatory Compliance Focus Innovation Customer Success Platform Scalability & Flexibility Market Leadership

Risk-basedMonitoring

Benefitsü Focusesanalysts’timewhereitmattersmostü Fasterrecognitionofthreatsthatneedattentionü Reducesalarmfatigue

RiskPrioritizedAlarms

! 56RISK! 68 RISK

! 97 RISK

Risk-basedPrioritizationAlgorithm

EventsConfidenceScore

ConfidenceScore

ThreatScore

WeightingsWeightings

RiskScore

Page 20: Corporate Overview 2017-04...Why LogRhythm As Your Strategic TLM Partner Broad Regulatory Compliance Focus Innovation Customer Success Platform Scalability & Flexibility Market Leadership

EmbeddedSecurityAutomationandOrchestration

CaseManagement SmartResponseAutomation

Benefitsü Centralizessecurityinvestigationsü Fasterinvestigationswithsingletoolsetü Efficient,confidentialcollaborationü Automatesworkflowsandresponsesü Reducesmeantimetorespond(MTTR)

Page 21: Corporate Overview 2017-04...Why LogRhythm As Your Strategic TLM Partner Broad Regulatory Compliance Focus Innovation Customer Success Platform Scalability & Flexibility Market Leadership

WhyLogRhythmAsYourStrategicTLMPartner

BroadRegulatoryCompliance

Focus

Innovation

CustomerSuccess

PlatformScalability&Flexibility

Page 22: Corporate Overview 2017-04...Why LogRhythm As Your Strategic TLM Partner Broad Regulatory Compliance Focus Innovation Customer Success Platform Scalability & Flexibility Market Leadership

MarketLeadership

Certifications&Validations

IndustryAnalysts CompanyAwards

Company of the Year

IndustryAwards

Page 23: Corporate Overview 2017-04...Why LogRhythm As Your Strategic TLM Partner Broad Regulatory Compliance Focus Innovation Customer Success Platform Scalability & Flexibility Market Leadership

23 |©2016LogRhythm

Page 24: Corporate Overview 2017-04...Why LogRhythm As Your Strategic TLM Partner Broad Regulatory Compliance Focus Innovation Customer Success Platform Scalability & Flexibility Market Leadership

24 |©2016LogRhythm

Appendix

Page 25: Corporate Overview 2017-04...Why LogRhythm As Your Strategic TLM Partner Broad Regulatory Compliance Focus Innovation Customer Success Platform Scalability & Flexibility Market Leadership

LogRhythmLabs

ThreatResearch

ComplianceResearch

StrategicIntegration

MachineDataIntelligence

Page 26: Corporate Overview 2017-04...Why LogRhythm As Your Strategic TLM Partner Broad Regulatory Compliance Focus Innovation Customer Success Platform Scalability & Flexibility Market Leadership

World-ClassServicesForCustomerSuccess

Classroom, OnsiteorVirtual

Training

Administrator

Analyst

AdminCo-Pilot

ProfessionalServices

CoreDeployment

AnalyticsCo-PilotThreatManagementFoundations

ComplianceFoundations

ExpertConsulting

ContentCo-Pilot

Follow-the-Sun &StandardBusiness

Support

ProactiveMaintenance

CustomerOrientation

Embedded Labs

Forensics Co-Pilot

Page 27: Corporate Overview 2017-04...Why LogRhythm As Your Strategic TLM Partner Broad Regulatory Compliance Focus Innovation Customer Success Platform Scalability & Flexibility Market Leadership

ComplianceAutomation

ComplianceAutomation

Automateandassureregulatorycompliancewithpre-configuredcontentfor15+regulatoryframeworks:

• PCI• SOX• GLBA• NERC-CIP• HIPAA• GDPR

• FISMA• GPG-13• ISO27001• NIST800-53• NISTCSF• DODI8500.2andmore…

Benefitsü Rapidcustomervalue

ü Reduceburdenofassuringanddemonstratingregulatorycompliance

ü Easilydeploy pre-configuredreportsanddashboards formanagementandauditors

ü Detectcomplianceviolationsautomatically,inreal-time

EmbeddedCompliance• Experiencedcompliance experts

• BuildMachineDataIntelligence,withsupportfor785+devices

• Developpre-configuredcompliancemodules:• AIEnginerules

• Reports&SavedSearches• DashboardLayouts• SmartResponse™plugins

• Frequentupdatesviacloud

Page 28: Corporate Overview 2017-04...Why LogRhythm As Your Strategic TLM Partner Broad Regulatory Compliance Focus Innovation Customer Success Platform Scalability & Flexibility Market Leadership

HolisticThreatAnalytics

EmbeddedSecurity• Recognizedsecurity experts• BuildMachineDataIntelligence,withsupport for785+devices

• Developpre-packagedthreatmanagementmodules:• AIEnginerules• Reports&SavedSearches• DashboardLayouts• SmartResponse™actions

• Frequentupdatesviacloud

UserandEntityBehaviorAnalyticsInsiderThreats,CompromisedUserAccounts,PrivilegeAbuse,BruteForceAttempts&more

NetworkBehaviorAnalyticsMalwareOutbreak,SuspiciousNetworkCommunications,DOSAttacks,Network-borneDataExfiltration&more

EndpointBehaviorAnalyticsEndpointManipulation,MalwareActivity,SuspiciousProcess&ApplicationActivity,LocalDataExfiltration&more

Benefitsü Rapidcustomervalue

üWork smarterandfasterwithmachine-based analytics

ü Detect&respondtothreatsacrosstheattacksurface

ü Acceleratedeploymentwithpre-packagedthreatmanagementmodules

ThreatIntelligence

CommercialFeeds

CustomSources

STIX/TAXIIFeeds

OpenSourceFeeds