How has it helped my organization?
We internally use Kaspersky Endpoint Detection and Response Optimum, which is a highly recommended solution. We leverage it for our detection data box, particularly when working with Azure.
What is most valuable?
All the features work together to provide alerts and help evaluate potential issues related to the detected threats. It's difficult to single out one feature since they all contribute to creating a normal usage profile and detecting abnormal behavior within the business infrastructure. It's a comprehensive solution.
What needs improvement?
There are certainly some weaknesses. In terms of the product itself, the main weakness lies in the need for highly skilled personnel to operate it effectively. This is why I prefer to use Managed Detection and Response.
The problem is that there are millions of people worldwide who lack the necessary security skills and resources to manage security issues. It's a specific challenge for each company. If you don't have your own Security Operations Center (SOC) and lack the complete set of competencies and skills to manage the hardware, using Managed Detection and Response instead of Endpoint Detection and Response allows you to delegate the high-scale layer to experts who will handle a part of the job. Then, you only need to decide whether to rely on their advice or not, which requires fewer skills. Therefore, the main weakness lies in the inherent complexity of the solution.
In future releases, I would like to see an eXDR layer for Kaspersky. It's something that is essential.
For how long have I used the solution?
I've been using it for more than a year now. We were one of the early adopters. We started using it fully internally about six or seven months ago for protection purposes.
What do I think about the scalability of the solution?
When it comes to Kaspersky, it's not a simple yes or no answer. It depends on various factors. Kaspersky's concept allows you to work with different components to achieve a specific level of detection and response. You can integrate it with other consoles, which is missing in Azure. This includes analyzing the network and cloud. EDR focuses on endpoint information, but there are two crucial aspects missing: network security and cloud security.
However, if you have EDR components and use QM, you can achieve a fully scalable solution. You can also integrate it with other products like a threat-hunting portal and link flows. In the future, there will be integration with Azure. Without incorporating Kaspersky Endpoint, it may not be completely scalable. So, to achieve full scalability, you'll need to integrate an XDR solution.
In our company, we have around 250 end users utilizing the MDR solutions for our external customers. It's quite a significant number.
How are customer service and support?
Customer service and support are really good. We receive responses within hours. We have the option to contact the German or English-speaking team, which provides a good quality of service.
Additionally, we can also reach out to the French support team without any issues. Most of the time, we receive prompt and helpful assistance, including detailed instructions to troubleshoot the problem effectively.
The support is highly reliable compared to other providers like Sophos, which has the worst reputation. Personally, I would rate Kaspersky's support as excellent, although individual experiences may vary. The quality of support is crucial and Kaspersky delivers in this regard.
How would you rate customer service and support?
Which solution did I use previously and why did I switch?
From a technical point of view, I don't see any reason why I need to prefer competitors over the solutions provided by Kaspersky at the moment.
How was the initial setup?
The initial setup was easy. Once you have the advanced solution point protection from Kaspersky, you just need to set up the technology through the web console. It's a yearly business license that needs to be activated on the endpoint. We had no issues with that. It's a critical aspect for us, and the deployment process was straightforward.
We only have one full-time administrator managing the solution. Although we are three people who are capable of administering it, in reality, it's a full-time job that requires less than half an hour per day. This includes selling the project, checking alerts, and handling the EDR component. The setup is designed to be efficient.
What about the implementation team?
The deployment took less than a day, and there were no specific prerequisites. I read the solution and the manual, asked some questions, and within eight hours, the deployment was complete.
There was a main point of contact who assisted throughout the process. It went smoothly. However, if you start from scratch without any existing enterprise protection, it may require more guidance.
Managing the endpoint protection feature is the main priority. If you're starting from scratch, it might take around a week to deploy the Kaspersky Security Center, which is a preconfigured web or MST component. After that, you'll need some skills to create a strategy and deploy it on the data points.
Initially, it might seem challenging, but once you understand the basics and have the necessary knowledge about Kaspersky products and endpoint relations, you'll be able to handle it. I would estimate around forty hours for someone unfamiliar with the system to complete the deployment, which is quite impressive.
What's my experience with pricing, setup cost, and licensing?
It's a yearly business license that needs to be activated on the endpoint. We had no issues with that. It's a critical aspect of the deployment.
The pricing is totally reasonable. However, you need to consider the cost of the yearly solution and also the enterprise protection. Currently, you cannot use the NDR solution without the endpoint protection. But in terms of the product portfolio, the pricing is very fair. After the events surrounding the invasion of Ukraine, some of our customers asked us to explore alternative solutions because they didn't want to work with Russian products anymore. So we conducted comparisons based on pricing. In the best-case scenario, the prices of other solutions were two or three times higher than Kaspersky. To be honest, Kaspersky is significantly cheaper while maintaining high-quality solutions. It's a bit more challenging to compare only the EDR solution since there are considerable differences between different EDR solutions as well as endpoint protection.
One crucial factor to consider is the quality of the threat center, and Kaspersky is widely recognized as one of the best threat intelligence providers globally. When choosing a security solution, the quality of the solution heavily relies on the expertise of the individuals working on-site to identify threats and assess their severity.
I recently analyzed a few phishing attacks targeting iOS devices. The exploit patch was released in 2019, and Kaspersky's EDR played a vital role in identifying and mitigating the malware. No other security solution around the world was able to detect this iOS issue, despite the fact that it had been present since 2019. Kaspersky's EDR was the first to uncover the problem, which was later confirmed by the XDR network analysis component of their solution. This is a testament to the product's quality because no other vendors or iOS solutions managed to detect the issue. These are facts that speak for themselves and provide strong evidence of the product's superiority compared to others.
Which other solutions did I evaluate?
We offer a range of products, including Endpoint Protection, MDR, XDR, password manager, VPN clients, email protection, email gateway, Internet gateway, and Azure automation.
In addition, we provide CITO and DITC services for IT crews. Our main focus is on business customers, both final customers and managed direction. We prefer to provide them with the necessary expertise and knowledge since they may lack the resources to handle intense situations and make informed decisions.
The main advantage that competitors have over Kaspersky is that they are not limited by software versions. One issue I have with Kaspersky is that some customer requirements may involve sharing specific details with us, which can pose challenges in certain projects. And that is one of the recent projects that may be a problem. The only advantage I see over other competitors is that.
What other advice do I have?
Overall, I would rate it around nine out of ten at the moment.
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner