Next-generation endpoint security action is divided into two camps: Advanced prevention and in-depth detection and response. In between these poles lie an assortment of additional security controls. My colleague Doug Cahill and I are knee-deep into a research project on next-generation endpoint security. As part of this project, we are relying on real-world experience, so we’ve interviewed dozens of cybersecurity professionals working at enterprise organizations (i.e. more than 1,000 employees) who have already deployed new types of endpoint security software.Now, all of the organizations we interviewed are already running antivirus tools, but day-to-day responsibilities are often delegated to an IT operations team rather than the infosec staff. So organizations are at somewhat of a disadvantage because they delegated it to an IT generalist team. Still, many of the organizations we’ve interviewed have turned on all of their AV’s advanced features, and are still being compromised.So what happens next? Enterprises are deploying next-generation endpoint security solutions along a continuum flanked by two poles:Advanced prevention. Many organizations are overwhelmed by all of their security tasks and simply want a better endpoint security mousetrap than their existing AV. These firms are opting for solutions from vendors like Confer, Crowdstrike, Cylance, and Invincea that have better detection efficacy than traditional antivirus software. Organizations opting for advanced prevention are looking to “stop the bleeding” by preventing a higher percentage of attacks and addressing the daily grind of system re-imaging. These firms are also most likely to replace AV with a next-generation endpoint security tool. Advanced detection and response. At the opposite extreme, well-resourced and highly-skilled organizations are instrumenting endpoints with forensic capture capabilities from vendors like Carbon Black, Countertack, Guidance Software, and RSA. These firms no longer think of endpoint security as independent, but rather as part of the overall IR process rather (note: See my recent blog titled the incident response “fab 5” for more details). They are also willing to work with (and stick with) their AV vendors. So prevention sits at one end, while detection and response sits at the other. What makes this a continuum is the multitude of actions that happen in between these poles. Organizations are slowly moving forward with a whole bunch of additional security controls, like application whitelisting, browser sandboxing, endpoint firewall rules, attribute-based access controls, etc. These supplementary endpoint controls are intended to decrease the attack surface. Based upon our research, organizations are gravitating toward one end of the continuum or the other by moving forward with advanced prevention or detection/response bandwagon. These polar projects are getting funded and seem to be where all the activity (and money) is. Once new endpoint security programs are established, CISOs steadily move on to implement additional endpoint security controls, but this can require analysis, testing, and gradual implementation over time. Want to know more about next-generation endpoint security? I’ll be presenting our findings at the RSA Security conference on Thursday March 3. Hope to see you there. Related content analysis 5 things security pros want from XDR platforms New research shows that while extended detection and response (XDR) remains a nebulous topic, security pros know what they want from an XDR platform. By Jon Oltsik Jul 07, 2022 3 mins Intrusion Detection Software Incident Response opinion Bye-bye best-of-breed? ESG research finds that organizations are increasingly integrating security technologies and purchasing multi-product security platforms, changing the industry in the process. By Jon Oltsik Jun 14, 2022 4 mins Security Software opinion SOC modernization: 8 key considerations Organizations need SOC transformation for security efficacy and operational efficiency. Technology vendors should come to this year’s RSA Conference with clear messages and plans, not industry hyperbole. By Jon Oltsik Apr 27, 2022 6 mins RSA Conference Security Operations Center opinion 5 ways to improve security hygiene and posture management Security professionals suggest continuous controls validation, process automation, and integrating security and IT technologies. By Jon Oltsik Apr 05, 2022 4 mins Security Practices Podcasts Videos Resources Events SUBSCRIBE TO OUR NEWSLETTER From our editors straight to your inbox Get started by entering your email address below. Please enter a valid email address Subscribe