Detect and Respond

Threat Monitoring and Analytics

8x5 or 24x7 monitoring and analytics of security events, including triage, incident escalation, tailored SIEM content development for client- and industry-specific use cases, and log source integration.

Challenges

Who has the time and staff? Can we detect an attack? Are we vulnerable? How to prioritise? How quick?

Common challenges that many companies are facing often relate to the budget. Why is that?

While the common phrase is “people, process and technology”, the reality at the end of the day is that many times the budget dictates the options. At least until an incident occurs.

We do see a challenge with companies having difficulty hiring staff with the correct skillsets to handle sophisticated cyber threats. There are still a talent shortage, so utilising existing staff would be an option, however, it takes a lot of time and therefore represents additional costs to improve those resources’ skillsets as required and allow them to gain the experience required.

Some companies might not have a department for managing threat detection-related activities, such as alert monitoring, triage, incident response. While other companies might have a department of IT security staff, they do not have the skillsets required and do not want to keep the threat detection related activities in-house.

Taking the time to monitor the existing cyber threats and constantly verifying security products can be rather resource intense and is often an activity that is given a very low priority or not being performed very often.

Keeping up with all the technologies and knowing how to adapt them to the detection capability can be a challenge, as it will require continuous training, which again adds to the cost of having the service.

Our approach

8x5 or 24x7 monitoring and analytics of security events, including triage, incident escalation, tailored SIEM content development for client- and industry-specific use cases, and log source integration.

Threat Monitoring and Analysis provides a range of services that address the pain many companies have.

  1. Monitoring 8x5 to 24x7

    Deloitte offers Level 1 and Level 2 analysts who provide monitoring and analytics services in terms of security events, including alert response, triage, rule maintenance and incident escalation. It also includes monthly reporting of the service provided.

  2. Use Case Development and Maintenance

    Based on the focus of current cyber threats, knowledge gained from the threat intelligence and our experience from incident response tasks, we build use cases to help customer detection to become even stronger. Assistance in terms of custom use case development is also an option.

  1. Monitoring 8x5 to 24x7
  2. Use Case Development and Maintenance

Deloitte offers Level 1 and Level 2 analysts who provide monitoring and analytics services in terms of security events, including alert response, triage, rule maintenance and incident escalation. It also includes monthly reporting of the service provided.

Based on the focus of current cyber threats, knowledge gained from the threat intelligence and our experience from incident response tasks, we build use cases to help customer detection to become even stronger. Assistance in terms of custom use case development is also an option.

Why Deloitte?

Awarded market leaders

We strive to continuously lead the market in the area of cyber risk and security services. We are awarded and acknowledged by some of the most renowned institutions within the area of cyber, e.g. Gartner, ALM Intelligence and Forrester. In 2020, we were named global leader in Security Consulting Services for the 9th year in a row by Gartner.

Leading-edge technologies

We are committed to investing in innovation and emerging technologies to ensure that we are equipped with the latest tools to solve current and future challenges for our clients. Alliances with market-leading cyber vendors and groundbreaking startups around the world offer our clients access to a wide range of cyber-risk technologies and leading-edge technology innovation.

Global intelligence delivered locally

We have the largest professional services network in the world. Diversity across our cyber teams helps us work across the globe with a local and personal lens. We have over 8,600 dedicated cyber-risk service practitioners of which 1,300 are dedicated to Europe and the Middle East alone, ready to help our clients everywhere with any challenge.

End-to-end cyber-risk services

We cover every aspect of cyber risk — from advisory and implementation of strategic transformations to managed security services, product solutions and incident management. This enables us to deliver more resilient and silo-breaking solutions, taking the whole business chain into account. This helps our clients to leverage their potential and growth even more.

Reach out

If you recognise some of these challenges, or if you would like to know more about how we can help your company strengthen its detection capability, please do not hesitate to contact us.

Søren Tillebæk Jensen

Senior Manager

Afshin Mir

Director

$(document.head).append(''); $(document.head).append('