29
Flipped from EDR to XDR after that 4am ransomware call
I spent two years defending our legacy EDR setup until a customer called at 4am with encrypted file shares and I realized we had zero visibility into their email logs, so I moved us to an XDR platform last quarter and the first simulated attack exercise showed the gap instantly, has anyone else made the switch after a late night failure?
1 comments
Log in to join the discussion
Log In1 Comment
coleman.christopher12d ago
Shaking my head reading this because that 4am call is literally my nightmare fuel. We had a similar wake up when a client's CFO started screaming about a phishing email that slipped past our gateway, and I remember staring at four different dashboards trying to piece together what happened. The worst part was realizing our EDR logs stopped at the endpoint, so we had zero clue how the attacker got in or what they touched before the encryption started. That gap between email, network, and endpoint made me feel blind in the middle of a firefight, and honestly I'm still bitter about all those months we spent pretending one tool was enough.
3