Organizations are both adopting XDR technology and modernizing the SOC. New ESG research points to areas of potential overlap and even conflict between those two initiatives. Credit: Thinkstock Things have certainly progressed since I started writing about XDR (extended detection and response).There are more vendors claiming to offer XDR—far beyond just the endpoint detection and response (EDR) vendors. XDR now collects, processes, and analyzes telemetry from more data sources, like cloud access security brokers (CASB), SaaS applications, and IAM systems. There are also at least 3 XDR ‘alliances,’ one led by CrowdStrike, another includes vendors like Exabeam, Extrahop, Mimecast, Netskope, and SentinelOne, while a third is based on standards from the Open Cybersecurity Alliance with participants like IBM and McAfee. Yup, XDR is making progress by expanding its features and functionality. That’s a great start, but some vendors believe that XDR can cover the whole security operations center technology enchilada, usurping the role of foundational technologies like security information and event management (SIEM), security orchestration, automation, and response (SOAR), and threat intelligence platforms (TIP) as organizations modernize their SOCs with more intelligence, automated workflows, and decision support for analyst processes.So, while everyone is talking XDR, no one is telling quite the same story. ESG offers this definition: XDR as an integrated suite of security products spanning hybrid IT architectures, designed to interoperate and coordinate on threat prevention, detection, and response. XDR unifies control points, security telemetry, analytics, and operations into one enterprise system.XDR and SOC modernizationIn a recent research project, ESG asked 339 enterprise security professionals what role could XDR play in SOC modernization. Here are their responses and my commentary: 58% of security professionals say XDR could modernize the SOC by enhancing/improving/aggregating current security analytics capabilities. That’s certainly the primary mission for XDR, providing high-fidelity alerts from data analysis across a cyber kill chain. This could modernize the SOC by automating Tier-1 analyst tasks like alert triage, leading to massive improvements in SOC efficiency and analyst productivity.55% of security professionals say XDR could modernize the SOC by integrating with SOAR for security process automation. This objective isn’t nearly as clear. XDR systems codify simple task automation—like matching a file hash with VirusTotal—while SOAR is really built to automate processes end-to-end and even integrate into ITSM systems (i.e., think ServiceNow for both SOAR and ITSM). In other words, XDR and SOAR are loosely coupled at best today, and I don’t see this changing. The best XDR systems will continue to take on basic task automation without the need for SOAR.37% of security professionals say XDR could modernize the SOC by acting as a data lake for queries and investigations. This one is possible and clearly why CrowdStrike acquired Humio and SentinelOne purchased Scalyr—both cloud-based big data analytics engines. Still, many organizations are already using SIEMs as data lakes and most SIEM vendors (i.e., Elastic, Exabeam, IBM, Splunk, SumoLogic, etc.) are already cloud based. There are also big, scalable, cloud-based platforms in this space like Chronicle and Devo that can ingest other data for investigations and threat hunting. Given this, XDR may end up being more of a data stream than data lake.In my humble opinion, large organizations are doing two things simultaneously: adopting XDR technology and modernizing the SOC. XDR is used to improve threat detection efficacy while consolidating point tools, while SOC modernization is about detections as code, aligning with MITRE ATT&CK, canning analyst workflows, and end-to-end process automation. No doubt that XDR will contribute to SOC modernization, but XDR vendors already have their hands full developing advanced analytics, accommodating new data sources, automating tasks, and presenting everything to analysts in an intuitive way. Successful XDR vendors will remain heads down on these developments—at least over the next few years. Related content analysis 5 things security pros want from XDR platforms New research shows that while extended detection and response (XDR) remains a nebulous topic, security pros know what they want from an XDR platform. By Jon Oltsik Jul 07, 2022 3 mins Intrusion Detection Software Incident Response opinion Bye-bye best-of-breed? ESG research finds that organizations are increasingly integrating security technologies and purchasing multi-product security platforms, changing the industry in the process. By Jon Oltsik Jun 14, 2022 4 mins Security Software opinion SOC modernization: 8 key considerations Organizations need SOC transformation for security efficacy and operational efficiency. Technology vendors should come to this year’s RSA Conference with clear messages and plans, not industry hyperbole. By Jon Oltsik Apr 27, 2022 6 mins RSA Conference Security Operations Center opinion 5 ways to improve security hygiene and posture management Security professionals suggest continuous controls validation, process automation, and integrating security and IT technologies. By Jon Oltsik Apr 05, 2022 4 mins Security Practices Podcasts Videos Resources Events SUBSCRIBE TO OUR NEWSLETTER From our editors straight to your inbox Get started by entering your email address below. Please enter a valid email address Subscribe