MITRE Test: Evaluating Cybersecurity Solutions Against Ransomware

Presented by

Adam Mansour, Chief Security Officer at ActZero

About this talk

Ever wonder why cybersecurity vendors can claim “100% coverage” against frameworks like MITRE, yet their solutions still fall victim to breaches? Adam Mansour, Chief Security Officer, stacks ActZero MDR’s performance against DarkWeb-sourced malware, relative to “top tier” security vendors’ solutions. Endpoint attack simulation performance is evaluated using three critical measures: block rate, dwell time, and signal-to-noise ratio - redefined to elucidate the differences between real-world performance, and scoring publications and frameworks like, eicar, MITRE, and others. We define these critical measures, describe the assessment method, and compare them to established frameworks. We then explain why POC’s that leverage such measures are critical for: - Choosing cybersecurity solutions, and accurately assessing the outcomes they drive - Determining whether such solutions will be able to keep response times below relevant thresholds - Understanding whether the outputs are actually actionable, to stop the attack itself

Related topics:

More from this channel

Upcoming talks (1)
On-demand talks (48)
Subscribers (4646)
ActZero challenges cybersecurity coverage for SMB and mid-market companies. Our intelligent MDR provides 24/7 monitoring, protection and response support that goes well beyond other third-party software solutions. Our teams of data scientists leverage cutting edge technologies like AI and ML to scale resources, identify vulnerabilities and eliminate more threats in less time. We actively partner with our customers to drive security engineering, increase internal efficiencies and effectiveness and, ultimately, build a mature cybersecurity posture. Whether shoring up an existing security strategy or serving as the primary line of defence, ActZero enables business growth by empowering customers to cover more ground.