What is our primary use case?
We have been CrowdStrike Falcon Complete MDR customers for about four years, and before that, we were standard CrowdStrike Falcon users. After having that for a year, we upgraded to the MDR solution.
Our main use case for CrowdStrike Falcon Complete MDR is that we really want 24/7 visibility. I am the only security person on staff where I work, and so having that extra layer of visibility was a big plus.
A quick specific example of how that 24/7 visibility has helped me in my day-to-day work is that even after hours, we get alerts to our email if there's anything we need to look at. By the time I see the email, I can log into the Falcon console, and I can already see that the Falcon Complete team has already closed the ticket and checked on the alert for us.
We chose CrowdStrike Falcon Complete MDR because I'm just one person, and I cannot be looking at alerts 24/7. Eventually, I clock out and get to go home, so having Falcon Complete MDR has been a big help to have that 24/7 visibility.
What is most valuable?
The best features CrowdStrike Falcon Complete MDR offers are a lot of information that you get every time you get an alert. There is so much telemetry that the sensor is pulling, so it is really easy to figure out what is going on on the computer. Since we are MDR customers, so many of those different alerts are already worked for us. We still look at them and check on them, but normally by the time we get to them, that status is already closed because it has already been checked on.
Out of all those features, the one that I find myself relying on the most day-to-day is having that person on your team to help augment your staff. Since I am the only one on the team, it is super nice and super helpful knowing that we have someone else on the team, that being the MDR team that we have. That is probably the biggest difference, knowing that even if I do not understand a specific alert that comes in, I can send a chat to the Falcon Complete team through the support message, and they will explain in pretty great detail about what the alert is doing and if there is any extra remediation I need to do.
CrowdStrike Falcon Complete MDR has impacted my organization positively because we have not been hacked yet, and that is a great thing. There are several municipalities or other organizations in our area and our state that have been hit, that obviously do not use CrowdStrike. We obviously do use CrowdStrike, and we have not been hacked, and so that is the biggest impact that you could ask for.
What needs improvement?
The biggest improvement that could be made to CrowdStrike Falcon Complete MDR, and I have actually brought this up to our representative, is that since we are Falcon Complete customers, I would love to see some more annual reporting on basically how many alerts were worked and by the MDR team, especially material that we could give to executive management to help justify the price tag of Falcon Complete MDR. I think that would be the biggest benefit, having some end-of-year reports going over all the things that Falcon protected us against.
For how long have I used the solution?
We have been CrowdStrike Falcon Complete MDR customers for about four years, and before that, we were standard CrowdStrike Falcon users.
What do I think about the stability of the solution?
CrowdStrike Falcon Complete MDR is stable.
What do I think about the scalability of the solution?
I do not have anything to complain about regarding the scalability of CrowdStrike Falcon Complete MDR. I have never had any issues with it.
How are customer service and support?
The customer support for CrowdStrike Falcon Complete MDR is pretty good. We raise tickets when we have issues or questions, and they get back to us real quick.
I have pretty good visibility into the investigations and actions performed by the Falcon Complete team because they have notes on every alert. If I ever have another question, I will put in a ticket right from that console, and they will usually get back to me pretty quick.
Which solution did I use previously and why did I switch?
We were previously using Rapid7, so we used their Rapid or their InsightVM and their InsightIDR tool for their vulnerability management and detection and response.
How was the initial setup?
My experience with pricing, setup cost, and licensing is that it is pricey. It is worth it, but I was involved with all three things: getting the pricing, helping set it up, looking at our licensing, and everything.
What was our ROI?
I do not have any metrics, such as return on investment, especially coming from the public sector. We do not get a lot of metrics, such as money saved or fewer employees needed, but it is not a tangible return on investment. Knowing that you are protected feels a pretty good return on investment.
What's my experience with pricing, setup cost, and licensing?
My experience with pricing, setup cost, and licensing is that it is pricey. It is worth it, but I was involved with all three things: getting the pricing, helping set it up, looking at our licensing, and everything.
Which other solutions did I evaluate?
We actually did not evaluate other options before choosing CrowdStrike Falcon Complete MDR. I had heard about CrowdStrike from other vendors and other conferences, so when I was looking to switch from Rapid7's offering, I went right to CrowdStrike.
What other advice do I have?
My advice to others looking into using CrowdStrike Falcon Complete MDR is to go for it. It is going to be an investment, but it is an investment in protecting your company and your company's data. I have no issues with us switching to CrowdStrike. It has been super beneficial, so I would tell other people to go for it.
Since using CrowdStrike Falcon Complete MDR, I feel a lot more confident knowing that we have help when it comes to the MDR side. Sometimes when an alert comes in, I am sitting there looking at it for a few minutes, trying to figure out what is actually going on. I am trying to decipher if it is a false positive or if it is an actual event, and while I am sifting through all that information trying to figure it out, our MDR team has already checked on it for us, so having that extra confidence is invaluable.
The combination of CrowdStrike technology and human security expertise in the MDR service is super valuable for me because I can quickly get an answer that comes back really fast, but then double-checked with the actual team. It is super valuable.
My experience with Falcon Complete MDR's capabilities for threat detection, investigation, and response is that every time we get an alert, I am logging in and looking at the alert. By the time I get logged in and look at it, the Falcon Complete team has already assessed what is going on and either closed the ticket because it was a false positive or remediated the issue, such as removing a file or blocking a file.
CrowdStrike Falcon Complete MDR has changed the workload of my internal security team because it has removed some material off our plate, but it has also added some material. We have a lot of different modules bolted onto our Falcon console, so there is a lot of remediation that we need to do to make ourselves more secure. It has offloaded a lot of the responsibility of these different alerts that come in and double-checking and making sure everything is good on that front. It has added some material to our workload, but it has also taken away.
I give CrowdStrike Falcon Complete MDR a rating of 10 out of 10. We are probably going to be Falcon Complete customers as long as I am at this organization. I love it.
I feel strongly about giving it the highest rating of a 10 because we have not been hacked, and we have not been close to being hacked. What more can you ask for from your antivirus? It is protecting us on all fronts. They have a lot of bolt-ons with the identity, the Next-Gen Identity, and a lot of those other things. It is protecting us from all angles, so why not give it a 10 if it is doing that great of a job?
Regarding CrowdStrike Falcon Complete MDR's AI capabilities, I think it is good. It is something that we are looking at rolling into and rolling out, and it is something that I have little experience with, but it is supposed to be doing a good job.
Regarding CrowdStrike Falcon Complete MDR's AI capabilities, I think its accuracy and reliability of output are pretty good. There have been a few times that I have asked it questions, and the response was just okay or not super detailed, but recently, it has been pretty good.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?