What’s Included
Managed Solution will deploy ConnectWise MDR endpoint security solution for all workstations and servers in scope, paired with the ConnectWise Security Operations Center (“SOC”). We will continuously monitor and map each running process for malicious behaviors, utilizing artificial intelligence to detect thousands of virus and malware attack variants, fileless attacks, and root cause diagnostics in real-time.
Upon detection of a security incident or indicator of compromise on a Client endpoint, Managed Solution will undertake the following steps in coordination with the ConnectWise SOC:
- All security alerts from Client’s endpoints are initially analyzed by the ConnectWise SOC, triaged, and contextualized, with significant alerts escalated to Consultant’s security team. Our security analysts will investigate each escalated alert to confirm whether it represents a true security incident and assess the threat’s severity and impact on Client’s systems.
- Managed Solution will leverage unified monitoring dashboards (e.g., ConnectWise BrightGauge or equivalent) to maintain real-time visibility into threats across Client’s environment, utilizing global threat intelligence sources and data aggregated by the MDR platform to assess the nature, origin, and potential propagation of detected threats.
- Upon verifying a security incident or high-risk threat, Consultant will promptly notify Client’s designated security contact(s), providing threat details and preliminary recommended actions, and will collaborate with Client to determine appropriate response actions consistent with Client’s operational considerations and any predefined incident response plan.
- Managed Solution, in concert with the ConnectWise SOC, will execute containment and remediation measures for confirmed threats, which may include isolating affected endpoints, terminating malicious processes, quarantining infected files or systems, and utilizing response features (requires Defender for Endpoint) to isolate a device or quarantine a file. Remote remediation commands may also be executed across Windows, macOS, or Linux devices. Remediation commands are based on the specific Defender for Endpoint feature for each operating systems. Not all remediation types are available for all operating systems and all Defender for Endpoint plans.
- For any significant incident, Managed Solution will document the event and actions taken in a report or within the ticketing system, including the nature of the threat, detection and neutralization methods, and recommendations for Client regarding additional steps or security improvements.