What is our primary use case?
It's a part of our security infrastructure. It's next-generation antivirus. It has got endpoint detection and response.
Because we are in the power sector, we have to adopt a strong IT security policy. We have deployed several systems in place. We have a SIEM tool to monitor all logs. We have patch management. We also do a lot of audits. We are an ISO 27001-certified company. So, we do a lot of security audits. We go through a lot of security exercises internally, and we give a lot of importance to security.
The version that we have is built into the product.
How has it helped my organization?
It's the first layer of defense for us on the client and the server side. We haven't come across any instances of ransomware attacks or something else.
Previously, we were using traditional antivirus where a lot of exercises were required from the user's end. We had to monitor the daily updates from the OEM, and in the case of anything suspicious, such as a virus attack or detection of a virus, a lot of exercises were required. With Morphisec, we don't have to do those exercises. It detects everything quickly and takes proactive action as well. It helps with a lot of things. A lot of technical effort gets minimized because of this.
Morphisec has got a lot of features. It's next-generation antivirus. It has got endpoint detection and response. It detects abnormalities or suspicious activities inside the system and reports back. The good part is that we get reports quickly because we get alerts through the server. It provides a quick response, and alerting is also quick. It gives us detailed information about which exact file was infected, what was the suspicious behavior, and how to mitigate it or what steps Morphisec took. If we need any support, we can always contact their support. Their support is very quick.
It has got extended detection and response as a feature. Up till now, we haven't got any ransomware attacks. I've gone through a lot of reviews. A lot of people have recommended it and shared that it works very well when it comes to ransomware attack detection. Up till now, there has been no problem, and it has been working pretty well.
So far, only a few instances of normal infection have been reported. It detected malware on a few systems, but because of early detection, there were no issues. We have a patch-management solution in place. We continue to do all server patching. We have an SOP to do the patching, and Morphisec is also there for protection. Because of these security solutions in place, we haven't had any major security incidents.
Traditional antivirus products take a lot of resources in terms of memory and processor whenever background scanning happens. Morphisec doesn't take many resources. It's very lightweight, which is the best part of Morphisec.
It doesn't require a daily update. If you are installing it on any system that is not always connected to the internet, it doesn't require an update to be done on a daily basis. Whenever there's a patch or a version upgrade, we have to take care of that, but it doesn't require a daily update, which is a good part.
There were a lot of instances where proactive action was taken by the Morphisec agent. When we got an alert and were trying to investigate what exactly we have to do to eradicate or stop the infection, the Morphisec support team told us that there was nothing required to be done from our side. Everything is already taken care of. We now spend less hours than before. We used to daily monitor the logs of the antivirus system. We are PAN India, so we had to do a lot of exercises whenever an infection was found in the system. We had to go for proper patching and update of the antivirus, and we had to look for logs and other things. In the case of an infection, we used to scan in the safe mode, and in some cases, we even had to format the systems to remove the infection. Since having Morphisec, we are not doing those activities. It has saved a lot of our effort. Because of that, we have started concentrating on other securities areas.
Previously, we used to have one dedicated person for the investigation of false positives, and now, we are managing the entire show without a dedicated person. We are now working without that resource for the whole year. It has saved us approximately INR 45,000 or $600 a month.
It has reduced our team's workload. Earlier, we used to go through all the logs and scan the system. It required a lot of effort. When there was any detection, we used to format the systems, which would take six to eight hours and sometimes more than that. That effort has been minimized. In a month, we are saving the effort of four to five days. Similarly, earlier, we used to have a dedicated person, and now, we don't need a dedicated resource, which has reduced our security spending. We are saving approximately $600 a month.
What is most valuable?
We don't have to do anything as a user or as an admin. It does everything by default with its coding and inbuilt AI-based intelligence. We don't have to instruct it about what to do. It automatically takes corrective actions and quarantines or deletes a virus, malware, etc. That is the best part that I like about it.
It's lightweight. It doesn't take many resources. The users can enjoy working on their computers with better performance.
It saves a lot of effort for a technical person. Earlier, we used to monitor the traditional antivirus for updates. Now, we don't have to bother about updates, whether they are happening on a daily basis or not. A lot of the administration work has been reduced. Previously, whenever an infection was found, we used to take corrective action. We used to do a safe mode scanning of that particular computer. We had to remove that from the network. A lot of that effort has been minimized. We can enjoy working on other projects. It saves a lot of our effort with its AI and ML-based intelligence. Of course, no antivirus or OEM can give a 100% guarantee of protection from ransomware, but after having Morphisec in place, based on the reports we have gone through and the instances and suspicious activities that have been blocked by Morphisec, we are more assured that Morphisec will be able to take care of any such attacks.
We do VAPT four times a year. So far, no system-related or server-related vulnerability has been detected by the auditor. It was more related to networking devices. After installing Morphisec, we haven't come across any system-related vulnerability detection.
It has got two agents: one is for the client and the other one is for the server. It provides good protection for the servers. What I like about this product is that they've got a fantastic different system for the server.
What needs improvement?
We sometimes have to depend on the support team to know what action we should take. If the solution for an alert can be built into the report that we are getting, it will save time, and the interaction with support would be less. At times, corrective action is required, but at times, we don't need to take any action. It would be good if we get to know in the report that a particular infection doesn't require any action. It will save us time and effort.
Other than that, nothing else is required. They have taken care of everything. We are getting alerts, and we can have multiple admins. We get a good model with this view.
For how long have I used the solution?
It has been almost a year.
What do I think about the stability of the solution?
It's very stable. It has been almost a year since we have been using it, and so far, it has been stable.
What do I think about the scalability of the solution?
It's easy to scale because it doesn't require anything. We just have to deploy the agent. In our case, we have deployed the agent through the Active Directory policy. It was quick. Once the agent is installed on a system, the system reflects on the server. We can see the client on the server.
We have around 230 users right now, but we have 300 licenses.
How are customer service and support?
We are very satisfied with their support. Their support is quick and prompt. Whenever we need to get details about an infection detected in our environment, we send an email, and their support is very quick. Within half an hour, we get a response with detailed information, which is something good about this product. I would rate their support a nine out of ten. So far, it has been good. There is no problem at all.
How would you rate customer service and support?
Which solution did I use previously and why did I switch?
At my previous company, we used eScan. It's an Indian product, and before that, we used Symantec.
At my current company, we thought to go ahead with Morphisec, as it’s a next-generation anti-virus (NGAV). We switched because we wanted to have a next-generation antivirus solution with good detection. Nowadays, security challenges faced by corporates are very high, and there are a lot of threats and infections. We wanted to have a solution that would take corrective actions and protect our environment quickly so that we don't face any challenges. The major one was ransomware. No one wants to face that kind of crisis. That was the reason we went ahead with Morphisec. It filled a lot of gaps that we had with our traditional antivirus solution.
How was the initial setup?
We haven't found any complexity. It was smooth and pretty easy. We have to deploy the agent and everything starts working. It gets connected to the cloud server, and we get all the reports. That's one of its good features. In traditional antivirus, we had to go through and deploy a lot of policies. There were a lot of things to do, which is not the case with Morphisec. We don't have to do that much configuration. It's ready-made, and it works pretty well.
What about the implementation team?
We have our IT and security teams for its deployment and maintenance. We have got a team of four. It doesn't require a dedicated person. We all are experts on this solution, and not much configuration needs to be done on the server side or the client side. We just do the deployment, and if there's any alert, it automatically comes to our mailbox. So, not much effort is required. We already have a policy in place where as soon as we configure a system on the network, automatically, our agent gets deployed with the Active Directory policy. It hardly takes any time. It's easy, and everything is automatic through our Active Directory policy.
What was our ROI?
It has been a good investment. There was a little bit increase in the cost as compared to a traditional antivirus, but we are now more stress-free. Up till now, we haven't come across any ransomware because of the protection it provides. Even though its cost is a little bit on the higher side, we've seen ROI in terms of security. It's a good investment. If somebody is using traditional antivirus and is infected with ransomware, they would end up paying a ransom.
What's my experience with pricing, setup cost, and licensing?
Price-wise, it's on the higher side. A traditional antivirus solution is cheaper, but in terms of security and manageability, its ROI is better than a traditional antivirus. I would recommend it to anybody evaluating or considering an antivirus solution. If your system gets compromised, the cost of ransom would be a lot more. This way, it saves a lot of cost.
What other advice do I have?
You have to keep a watch on all the alerts you are getting. There is no major thing that needs to be monitored or taken care of during the deployment. You can simply go ahead with it and then forget worrying.
I would recommend it for a small organization. The spending on security is less in smaller organizations, and they often don't go for an alert mechanism or a SIEM tool. A solution like Morphisec is recommended for having an analytical view of what is happening inside the server and what kind of infection is there. It has been working pretty well for us.
I would rate it a nine out of ten.
Which deployment model are you using for this solution?
Private Cloud