{"id":21570,"date":"2023-03-27T14:01:01","date_gmt":"2023-03-27T22:01:01","guid":{"rendered":"http:\/\/www.palada.net\/index.php\/2023\/03\/27\/news-15301\/"},"modified":"2023-03-27T14:01:01","modified_gmt":"2023-03-27T22:01:01","slug":"news-15301","status":"publish","type":"post","link":"http:\/\/www.palada.net\/index.php\/2023\/03\/27\/news-15301\/","title":{"rendered":"Microsoft Incident Response Retainer is generally available"},"content":{"rendered":"<p><strong>Credit to Author: Christine Barrett| Date: Mon, 27 Mar 2023 22:00:00 +0000<\/strong><\/p>\n<p>The task of securing organizations is constantly changing and getting more complex. Many organizations don\u2019t have the time, resources, or expertise to build an in-house incident response program. For customers that want help remediating an especially complex breach (or avoiding one altogether), <a href=\"http:\/\/aka.ms\/MicrosoftIR\">Microsoft Incident Response<\/a> offers an end-to-end portfolio of proactive and reactive incident response services. We operate in 190 countries and our incident responders are seasoned veterans with more than a combined 1,000 years of career experience resolving attacks from ransomware criminals to the most sophisticated nation-state threat actor groups.<\/p>\n<p>Microsoft Security is expanding its incident response presence and we\u2019re excited to announce the Microsoft Incident Response Retainer is now generally available.<\/p>\n<h2>Incident response retainers are increasingly valuable due to market dynamics <\/h2>\n<p>Customers face persistent attacks from a growing number of vectors that cost time and money and impact reputation. Companies that are unprepared to respond to an incident saw a global average breach cost USD4.3 million (USD9.44 million in the United States) in 2022. This compares to USD3.05 million (USD1.3 million or 30 percent less) for companies\u00a0with incident response and AI\u00a0automation.<sup>1<\/sup> Companies that put these proactive measures in place also detected breaches 74 days faster than those without support (249 days compared to 323 days). Compounding these challenges, only 41 percent of chief executive officers (CEOs) believe they are prepared for cybersecurity crises.<sup>2<\/sup> What this tells us is that customers need incident response help, and they need to engage this help proactively before a crisis happens\u2014and Microsoft has taken note.<\/p>\n<p>\u201cMy team lives and breathes incident response. I literally have to pull them away from work and make them take breaks\u2014they love what they do, and it shows in the quality of their work,\u201d said Dan Taylor, Head Coach of Microsoft Incident Response. \u201cWe are excited for the continued expansion of Microsoft Incident Response and the launch of our Incident Response Retainer, which improves the customer purchase experience and allows for deeper, more meaningful customer engagement.\u201d<\/p>\n<h2>Overview of the Microsoft Incident Response Retainer service<\/h2>\n<p>The Incident Response Retainer provides pre-paid blocks of hours for highly specialized incident response and recovery services before, during, and after a cybersecurity crisis. It\u2019s contracted on an annual basis and the retainer hours can be used in any combination of proactive and reactive services. If additional hours are needed, customers can easily uplift extra hours as requirements change.<\/p>\n<p>This service provides our fastest response times and direct&nbsp;access to our global team of experts. It was designed to work with cyber insurance vendors and has flexible delivery options that meet the unique needs of each customer.<\/p>\n<p><strong>Capabilities<\/strong>:<\/p>\n<ul>\n<li><strong>Assigned Security Delivery Manager (SDM)<\/strong>\u2014A named SDM will work with you throughout the year to proactively schedule services and help you get the full value of your retainer contract.<\/li>\n<li><strong>Assigned Incident Manager<\/strong>\u2014A Microsoft incident response expert to guide your engagement during an active security attack.<\/li>\n<li><strong>Intelligence-driven investigation<\/strong>\u2014Threat investigation, digital forensics, log analysis, malware analysis support, and attacker containment.<\/li>\n<li><strong>Compromise recovery<\/strong>\u2014Assistance in recovery and remediation of critical infrastructure, removing attacker control from an environment, regaining administrative control, and tactically hardening high-impact controls to prevent future breaches.<\/li>\n<li><strong>Proactive services<\/strong>\u2014Compromise Assessments and Crisis Readiness Exercises will test your team\u2019s defenses, increase your security posture, and improve resilience.<\/li>\n<li><strong>Quarterly threat briefings<\/strong>\u2014Threat intelligence briefings with tailored guidance on emerging trends and threats, analysis, and validation of Indicators of Compromise and alerts, and premium delivery of Nation State Notifications (Plan 2 only).<\/li>\n<\/ul>\n<h2>Who Microsoft Incident Response helps<\/h2>\n<p>We hope you never have to experience a breach. But if you do, you can rest assured that we will do everything we can to help your organization get back to business as usual. In alignment with Microsoft\u2019s mission to empower every person and every organization on the planet to achieve more, we help every organization we can, including:<\/p>\n<ul>\n<li>New or existing Microsoft customers.<\/li>\n<li>Customers that don\u2019t use Microsoft Security products (this is a vendor-agnostic service).<\/li>\n<li>Enterprise, government, education, and non-profit customers on the Microsoft commercial cloud.<\/li>\n<\/ul>\n<h2>Ecosystem partnership<\/h2>\n<p>One of our core principles at Microsoft Security is&nbsp;security for all. Meeting the needs of all kinds of organizations means offering choice\u2014not only in the types of services customers buy but in&nbsp;who&nbsp;they buy them from. At the end of the day, we know that a single provider can\u2019t meet the unique needs of every organization. That\u2019s why Microsoft is fully committed to working with an ecosystem of partners and technologies that provide customers the flexibility to choose what fits their needs.&nbsp;<\/p>\n<p>Microsoft has an extensive security services partner ecosystem for customers across the globe to choose from. Our incident response and Microsoft-verified MXDR solution partners have world-class capabilities and domain expertise, each offering a broad portfolio of specialized solutions across the Microsoft security product portfolio. If you are looking for partner services, please go to the <a href=\"https:\/\/www.microsoft.com\/misapartnercatalog?PartnerClassifications=MicrosoftVerifiedManagedXDRSolution&amp;PartnerTypes=MSSP\">Microsoft Intelligent Security Association<\/a> member directory to find a solution to meet your needs.<\/p>\n<p>In alignment with the expansion of our Incident Response portfolio, we are also announcing a new partnership with incident response provider, Kivu. Microsoft and Kivu will jointly work together to utilize existing relationships with cyber insurance providers in responding to customers\u2019 cyber incidents. Kivu will regard Microsoft as the premier option for post-breach remediation services when Kivu clients need them, and Microsoft will regard&nbsp;Kivu as a trusted partner to handle ransomware negotiations for customers seeking that service.<\/p>\n<p>\u201cCybercrime will never stop. We have to partner, pool talent, combine intelligence and work together with our public sector colleagues to protect organizations from cyber threats. Our alliance with Microsoft Security combines our strengths to have more impact on almost any imaginable cybersecurity issue,\u201d said Shane Sims, CEO, Kivu Consulting, Inc.&nbsp;<\/p>\n<p>\u201cOur mission is to secure the world so our customers can thrive.&nbsp; Security is a team sport, and incident response is one of the most important areas for industry leaders to come together in collaboration,\u201d said Kelly Bissell, Corporate Vice President of Security Services, Microsoft. \u201cWe look forward to working with Kivu and other partners to help customers be safe and secure against all cyberattacks. Customers can be confident that their incident response needs will be addressed so their business can thrive.\u201d<\/p>\n<p>To learn more about Microsoft Incident Response and the Incident Response Retainer, please <a href=\"http:\/\/aka.ms\/MicrosoftIR\">visit our website<\/a> or read our blogs in the <a href=\"https:\/\/www.microsoft.com\/security\/blog\/microsoft-security-experts\/\">Microsoft Security Experts series<\/a>.<\/p>\n<h2>Learn more<\/h2>\n<p>To learn more about Microsoft Security solutions,&nbsp;<a href=\"https:\/\/www.microsoft.com\/security\/\">visit our&nbsp;website<\/a>.&nbsp;Bookmark the&nbsp;<a href=\"https:\/\/www.microsoft.com\/security\/blog\/\">Security blog<\/a>&nbsp;to keep up with our expert coverage on security matters. Also, follow us on LinkedIn (<a href=\"https:\/\/www.linkedin.com\/showcase\/microsoft-security\/\" target=\"_blank\" rel=\"noreferrer noopener\">Microsoft Security<\/a>) and Twitter (<a href=\"https:\/\/twitter.com\/@MSFTSecurity\" target=\"_blank\" rel=\"noreferrer noopener\">@MSFTSecurity<\/a>)&nbsp;for the latest news and updates on cybersecurity.<\/p>\n<div style=\"height:63px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n<hr class=\"wp-block-separator has-alpha-channel-opacity is-style-wide\"\/>\n<p><sup>1<\/sup><a href=\"https:\/\/www.ibm.com\/security\/data-breach\" target=\"_blank\" rel=\"noreferrer noopener\">Cost of a Data Breach Report 2022<\/a>, IBM. 2022.<\/p>\n<p><sup>2<\/sup><a href=\"https:\/\/www.conference-board.org\/pdfdownload.cfm?masterProductID=44769\" target=\"_blank\" rel=\"noreferrer noopener\">C-Suite Outlook 2023<\/a>, The Conference Board. 2023.<\/p>\n<p>The post <a rel=\"nofollow\" href=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/2023\/03\/27\/microsoft-incident-response-retainer-is-generally-available\/\">Microsoft Incident Response Retainer is generally available<\/a> appeared first on <a rel=\"nofollow\" href=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\">Microsoft Security Blog<\/a>.<\/p>\n<p><a href=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/2023\/03\/27\/microsoft-incident-response-retainer-is-generally-available\/\" target=\"bwo\" >https:\/\/blogs.technet.microsoft.com\/mmpc\/feed\/<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p><strong>Credit to Author: Christine Barrett| Date: Mon, 27 Mar 2023 22:00:00 +0000<\/strong><\/p>\n<p>Microsoft Security is expanding its incident response presence and we\u2019re excited to announce the Microsoft Incident Response Retainer is now generally available.<\/p>\n<p>The post <a rel=\"nofollow\" href=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/2023\/03\/27\/microsoft-incident-response-retainer-is-generally-available\/\">Microsoft Incident Response Retainer is generally available<\/a> appeared first on <a rel=\"nofollow\" href=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\">Microsoft Security Blog<\/a>.<\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[10759,10378],"tags":[4500,27209],"class_list":["post-21570","post","type-post","status-publish","format-standard","hentry","category-microsoft","category-security","tag-cybersecurity","tag-microsoft-security-experts"],"_links":{"self":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/21570","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=21570"}],"version-history":[{"count":0,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/21570\/revisions"}],"wp:attachment":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=21570"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=21570"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=21570"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}