fbpx

如何讓 Elastic Security 為您的公司創造價值?

Elastic Security 被超過 50% 的《財富》500 強企業使用,能夠降低總擁有成本(TCO),並提供現代化的檢測、調查和應對方式,以提升安全團隊的效率。

對於希望加強防禦、獲取即時洞察的組織來說,基於搜尋 AI 平台的 Elastic Security 提供了整個攻擊面可見性,幫助您達成商業目標。

Elastic 如何利用 Elastic Security

在解釋價值驅動因素之前,讓我們聽聽 Elastic 的首席資訊安全官 Mandy Andress 的看法。

Mandy 將她在一家《財富》100 強企業和 Elastic 整合技術堆疊的經驗進行比較,發現 Elastic 的市場上線速度快了 87.5%。

想了解完整影片,請參考:How does Elastic Security drive value to your organization?

以下將 Mandy Andress 的影片,轉為文字檔:

點擊了解 Mandy Andress 的看法
Video transcript:
Hi, all. I’m Mandy, Elastic’s CISO. Before I compare the above outcomes, let me first share my perspective for context. Fundamentally, I see security as a data problem, and I’m often asked, what keeps you up at night? I always give the same answer: what do I not know? There are so many things changing and happening in the global threat environments and our overall environment that I’m always concerned about what we are missing. What actions should we be taking that we don’t have the visibility or are just not looking at with the correct perspective? With that in mind, I try to build a diverse team that brings different skills and different perspectives and stays really connected with the community.

But there will always be things that we don’t know. And how do we learn that? How do we apply Elastic and the power of the ELK stack to provide us that visibility? Elastic helps our organization uncover some of those unknown unknowns with data. There are so many great stories I can tell you about how Elastic enables organizations to do that. But fundamentally, it’s a mindset shift.  How do you transition from focusing on discrete activities that you don’t want to see happening in your environment to really understanding the baseline of how your environment should be behaving and what anomalous activities are occurring that you should investigate? With today’s scale and overall significant amounts of data. Elastic provides the ability to quickly process significant amounts of data at scale. That speed, combined with our machine learning and generative AI capabilities, means we don’t have to do it the same way. When you replace the tech stack for your SOC. These combined capabilities are some of the most powerful I have seen and some of the easiest to configure just out of the box, turning on machine learning rules. We gain significantly more insight than organizations can achieve with the traditional SIEM. We’re all awaiting the addition of Elastic Security Assistant that utilizes generative AI to shorten the learning curve of analysts.

Before Elastic, I was working at a Fortune 100 firm. We wanted to completely rebuild our SOC and expand to provide global 24×7 support. We were ingesting daily about five terabytes of data with 50,000 events per second. Additionally, we had daily bursts, occasionally reaching 100,000 events per second. We knew we wanted detection and analysis with some behavioral analytics. We wanted to start moving into anomalous behavior. Understanding what was suspicious about our environment, whether it was a user or a machine. Getting all of that stood up took us three tools, 24 months, millions of dollars in licenses, and even millions of dollars more in services. And after 24 months, we were functional, but we still had a lot of work to do to get us to our desired end state. 

When I started at Elastic, I was looking to achieve the same thing, and we were able to do that with one product and one license, Elastic. We’re known to Elasticians as customer zero. We start testing and consuming capabilities as soon as possible. In that first three months, we were ingesting about 32 terabytes of data daily, 350,000 events per second. And we only had four SOC analysts distributed across the globe. From an information security perspective, we were up and running in three months versus 24. Not to mention that our current architecture is ingesting daily 200 terabytes of data, but this story doesn’t tell us the rest of the power across the environment. Utilizing cross-cluster search on petabytes of data across multi-cloud and on-prem environments, searching many, many petabytes of data in just under 30 seconds. 

This provides insights allowing us to respond to real-time events like Log4j and helps us provide data analysis to answer some of those questions to help ensure that we’re knowing what’s happening in our environment and identifying, as best we can, those unknown unknowns. With elastic security, we’ve seen clear productivity gains, risk reductions, and cost savings, and we look forward to continuing on this journey to improve the security of elastic. I encourage you to evaluate the gains your organization can achieve using elastic. Thank you.

安全團隊帶來的價值

現代安全解決方案通常在以下四個主要領域帶來價值:

成本節省

這包括透過降低直接影響利潤的成本,進而節省的資金。

風險降低

透過 Elastic 減少安全事件發生的可能性和嚴重性,並量化其價值。

Elastic 致力於在風險發生前識別潛在威脅,幫助企業避免損失並實現額外的財務利益。

生產力提升

Elastic 通過加速分析、促進協作以及自動化關鍵步驟來提高生產力,從而提升效率、加速決策並使企業能夠將資源重新分配到新項目中。

收入恢復

「服務中斷」和「客戶體驗問題」可能會影響收入和客戶保留,這一領域反映了降低這些風險的底線價值。

Elastic Security 帶來的價值

安全團隊效率提升

Elastic Security 從商業分析的角度推動安全分析師、工程師和管理人員的生產力增長。

我們首先考慮提高每個安全運營中心(SOC)最有價值資源——技術熟練的從業人員的生產力的經濟價值。

如果時間就是金錢,您的團隊可以通過「自動化威脅檢測」和「簡化調查及事件響應」來節省許多時間

通過集中數據,安全團隊可以更快地分析信息,並通過嵌入式案件管理和自動化行動加快響應速度。

這使得團隊能夠快速確定根本原因並減少升級。

通過改善平均調查、檢測和響應時間(MTTX),並減少誤報警報和升級,團隊可以降低每次事件的整體成本。

安全技術整合與優化

Elastic Security 將幾種關鍵技術(SIEM、端點和雲安全)統一在一個平台上。

在此計算中,我們估算降低許可證和基礎設施成本、減少技術開銷以及簡化新用例實施的價值。

業務中斷風險降低

任何由安全事件(無論是內部還是外部)造成的業務中斷都可能對您的組織造成損失。

Elastic Security 使您能夠改善可見性、消除盲點、增加自動化並減少事件數量。

在此計算中,我們考慮與內部和面向客戶的服務及應用相關的停機時間。

這可以為員工帶來生產力提升,並恢復先前因停機、SLA違規和客戶流失而損失的收入。

事件風險降低

憑藉強大的端點安全解決方案和能力,Elastic Security 防止並檢測勒索病毒、惡意軟件、釣魚攻擊和其他攻擊,並能在整個環境中啟用自動響應。

在這裡,我們衡量降低這些風險的影響,並根據 IBM 的數據洩露成本報告衡量潛在的財務節省。

避免事件成本

Elastic Security 現代化了安全運營,為從業人員提供了保護、檢測和應對複雜攻擊的能力。

憑藉開放和透明的平台,以及能夠阻止勒索病毒和先進威脅的代理,它幫助組織降低風險,提升安全運營成熟度,並加固 DevSecOps 流程。

在這裡,我們考慮事件後的成本節省,包括系統重建和外部事件響應公司所花費的時間。

Elastic AI 助手

這些計算未反映最近推出的 Elastic AI 助手在 Elastic Security 中所提供的價值。

AI 幫助從業人員利用快速變化的 LLM 環境來解決各種安全用例。

它提供有「關警報摘要、分流步驟、查詢轉換」和「自定義數據攝取」等多種主題的指導。

這些功能簡化了分析師的工作流程,減少了平均調查、檢測和響應時間。

Elastic Security 如何為我們的客戶創造價值?

查看 Proficio 如何轉向 Elastic Security 並使用 Elastic AI 助手將調查時間減少 34% 和項目成本節省。


想要了解更多 Elastic Security 相關資訊,歡迎加入歐立威 Line 好友,或閱讀:10 分鐘掌握 Elastic Security 四大功能

本文翻譯自:How does Elastic Security drive value to your organization?

Related Posts