What is our primary use case?
Clients are primarily using Secureworks Taegis XDR for securing endpoints, networks, and extending to cloud, identity management, and email protection. It functions as an antivirus in enterprise terms, known for being an EDR, MDR, and XDR. For organizations looking for ransomware protection, threat detection, and incident response, it works as cloud security monitoring as well, monitoring cloud environments for any suspicious activity and detecting threats.
What is most valuable?
Threat hunting and SOC augmentation represent the most special features about Secureworks Taegis XDR, where some of the best people in cybersecurity proactively search, provide reports, and deliver indicators of compromise for any activity in your network. This monitoring and reporting can be conducted weekly or monthly.
Centralized security monitoring and reporting is one of the most valuable aspects, as security fundamentally revolves around compliance. Having a centralized security monitoring platform that detects endpoints, networks, and cloud environments, including servers and switches, is essential. Secureworks Taegis XDR's architecture involves a collector device that collects all your data, even from small laptops, and allows you to monitor everything in one platform. This centralized system provides compliance and security visibility, ensuring evidence and visibility for your security and any compliance requirements you have.
Analytics with Secureworks Taegis XDR give you a full preview of everything on your device. It takes all the inputs and outputs of your infrastructure; for example, if it is a firewall, it scans all of the traffic. While it is not a SIEM, it is an open XDR, which excels at conducting analytics. This represents one of its best features because Secureworks has implemented a machine learning model that can detect and analyze everything independently, providing AI-driven features.
Integration with third-party tools is quite seamless. Secureworks Taegis XDR can integrate with virtually anything. One of the best features of this product is its integration capabilities with multiple sources of EDRs and any operating system, whether protecting Linux or Windows servers. It boasts very good integration, and if a specific integration is not available, you can raise a ticket to Secureworks, and they will work on your integration, whatever it is, even if it is custom-built software.
Secureworks Taegis XDR absolutely aids in efficiency. SOC augmentation extends an organization's existing SOC, which helps reduce alert fatigue significantly. It provides additional threat intelligence and expert investigation, making it very useful for organizations that have a security team but lack twenty-four seven coverage.
What needs improvement?
If there were a next release of the product, I would like to see an increase in playbooks, specifically for augmentation and automation. Increasing the automation playbooks would be beneficial, as there are templates for implementing automation.
What do I think about the stability of the solution?
I have not heard anyone report stability issues, and I believe Secureworks Taegis XDR is approximately ninety-nine point nine percent stable without any reliability issues or latency problems.
What do I think about the scalability of the solution?
Secureworks Taegis XDR is very highly scalable.
How are customer service and support?
The customer service from Secureworks is quite helpful. The best aspect of this is the support window; you can click on the support link, and you will connect with a real person, not an AI, who will assist you. Given the high cost of the product, you would expect high-quality support, and security being a critical aspect elevates this expectation. I would rate the support a ten out of ten.
What about the implementation team?
The deployment usually depends on the implementation team itself.
What was our ROI?
I see a return on investment despite the price being relatively high. It is costly, but it delivers whatever you ask for. Some people perceive advantages and disadvantages here; it can be complex if you want to integrate and tune multiple data sources based on your requirements. While some users find it complicated due to the numerous integrations in their environment, others find it very simple, as it allows for a plug-and-play setup where everything can be read seamlessly, and reports are generated easily.
What's my experience with pricing, setup cost, and licensing?
One negative aspect I always hear from customers is about the cost. This product is not aimed at SMB regular customers, and it is definitely not for small businesses. Cost is a factor when considering this solution, particularly for large environments. Even with notable clients like the Pentagon and Qatar Energy, the high enterprise solution necessitates a total cost of ownership analysis before quoting.
Which other solutions did I evaluate?
I would not say there is anything that provides a one-to-one comparison with Secureworks Taegis XDR, but I think vendors like CrowdStrike, Fortinet, Palo Alto, and Trend Micro have their own open XDR solutions.
What other advice do I have?
One of the best features of this product is its integration capabilities with multiple sources of EDRs and any operating system, whether protecting Linux or Windows servers. Secureworks Taegis XDR boasts very good integration, and if you do not have that integration, you can raise a ticket to Secureworks, and they will work on your integration, whatever it is, even if it is custom-built software.
The model clients usually use is a hybrid approach, as it can stretch to the cloud. I believe they utilize various cloud providers, including AWS, GCP, and Azure.
I rate this product a nine out of ten overall.