In the past, it took an average of 44 days for attackers to steal a company's data, even if they were successful. Now, that process is down to a few hours, but it takes an average of 5.5 days to get an incident under initial control, so traditional operational security solutions are no longer fit for purpose.
In the past, it took an average of 44 days for attackers to steal a company's data, even if they were successful. Now, that process is down to a few hours, but it takes an average of 5.5 days to get an incident under initial control, so traditional operational security solutions are no longer fit for purpose. Since its launch, Cortex
XSIAM® has helped customers transform their Security Operations centers (SOCs). For example, one service company reduced the median problem resolution time from days to minutes, 270 times faster than before. Palo Alto Networks (NASDAQ: PANW), a global cybersecurity leader, today announced Cortex XSIAM 2.0, further improving its
award-winning AI-powered security operations platform by adding a new Custom Machine Learning (BYOML) framework.
Pato Networks collects more security data than many cybersecurity companies, obtaining more than 5 petabytes of security data per day, with a total storage volume of more than 1
EB. XSIAM provides powerful, out-of-the-box AI models built for superior security analytics and threat protection. In addition, many established SOCs want to be able to customize and create their own machine learning (ML) models. For the first time, the BYOML framework provides access to large amounts of security data stored in XSIAM, enabling security teams to create their own ML models and integrate them into XSIAM for unique use cases such as fraud detection, security research, complex data visualization, and more.
In addition to the BYOML framework, XSIAM 2.0 incorporates new features that enable enterprises to address today's security operational challenges by increasing visibility and threat prioritization. The new XSIAM Command Center changes the way security teams monitor security operations with a comprehensive view of data sources and alerts, enabling them to easily identify and prioritize security incidents within a
unified platform. With the new MITRE ATT&CK Coverage dashboard, companies can also quickly assess their overall defense capabilities against a variety of threat strategies and tools in an effort to strengthen their overall security posture.
Gonen Fink, senior vice president of Cortex Products at Palo Alto Networks, said: "Effective security operations are a major challenge for businesses around the world. The rapid movement of attackers combined with new regulatory requirements has made traditional manual approaches to cyber threats impossible. XSIAM 2.0 uses artificial intelligence (AI) and automation technologies to fill this gap by reducing operational complexity, stopping threats at scale, and
accelerating incident remediation."
The Cortex XSIAM was named a "leader" and "outperformer" in GigaOm's Autonomous SOC Radar Report 2023.
"Taking lessons learned and re-architected from a range of leading security products, XSIAM delivers a comprehensive set of autonomous SOC solutions that achieve high scores across key criteria," said Andrew Green, research analyst at GigaOm.
XSIAM 2.0 achieved results that could not have been achieved with multiple single point products and isolated data. XSIAM combines SOC capabilities (including XDR, SOAR, SIEM, etc.) into a single platform to streamline security operations. It also continuously collects, articulates and standardizes raw data through a uniform set of methods. The combination of a unified data and AI-driven platform delivers results for customers including:
● Oil and gas companies:
75% fewer incidents requiring investigation. From about 1,000 cases per day to about 250 cases per day, false positives and duplications are eliminated.
● Boyne Resorts: Streamlined and improved surveys by adding more than 20 data sources to a single platform.
● Imagination Technologies: Incident resolution rate increased tenfold from less than 10% to 100%.
"One of our biggest pain points is information overload," says Paul Alexander, Director of IT operations at Imagination
Technologies Group. It's great to be able to grow, but it also means we need to manage more operations. At the same time, the threats are becoming more sophisticated. XSIAM is useful for us because it allows us to get right to the really serious things that need attention, rather than wasting time on data that doesn't need attention."
Mike Dembek, Network architect at Boyne Resorts, said, "Log collection is one of our biggest weaknesses. Our SIEM is expensive and difficult to integrate data sources. We used to struggle to find inaccurate alerts that were a jumble of unrelated alerts. XSIAM increases our visibility and speed of investigation.
Seamless data access and automated setup make a huge difference."
Listing situation
XSIAM 2.0 is now available to customers worldwide.