{"id":24200,"date":"2024-03-20T16:00:52","date_gmt":"2024-03-21T00:00:52","guid":{"rendered":"http:\/\/www.palada.net\/index.php\/2024\/03\/20\/news-17930\/"},"modified":"2024-03-20T16:00:52","modified_gmt":"2024-03-21T00:00:52","slug":"news-17930","status":"publish","type":"post","link":"http:\/\/www.palada.net\/index.php\/2024\/03\/20\/news-17930\/","title":{"rendered":"Microsoft Sentinel delivered 234% ROI, according to new Forrester study"},"content":{"rendered":"<p><strong>Credit to Author: Rob Lefferts| Date: Tue, 19 Mar 2024 16:00:00 +0000<\/strong><\/p>\n<p>In an era defined by rapid technological advancements and digital transformation, protecting it all remains a top challenge. From sophisticated hacking attempts by state-sponsored actors to opportunistic cybercriminals exploiting weaknesses in software and infrastructure, cyberthreats demand constant vigilance and innovative solutions. Traditional security information and event management (SIEM) solutions are complex to implement and have high costs associated with deploying, maintaining, and scaling. They struggle to collect, correlate, and analyze data from disparate sources in real-time, making them an inefficient choice for modern security operations.<\/p>\n<p>To protect your entire multicloud, multiplatform digital estate, consider <a href=\"https:\/\/www.microsoft.com\/en-us\/security\/business\/siem-and-xdr\/microsoft-sentinel?rtc=1?ef_id=_k_9550bbf1794f19ad0c47dfd510510c5e_k_&amp;OCID=AIDcmmdamuj0pc_SEM_k_9550bbf1794f19ad0c47dfd510510c5e_k_&amp;msclkid=9550bbf1794f19ad0c47dfd510510c5e\">Microsoft Sentinel<\/a>, a modern, comprehensive SIEM solution built on the cloud and enriched by AI to rapidly uncover sophisticated cyberthreats and respond at machine speed. Microsoft Sentinel offers a complete security operations solution that is powerful, highly efficient and economic than other SIEM solutions.<\/p>\n<p>To evaluate the benefits of Microsoft Sentinel, Microsoft commissioned Forrester Consulting to conduct a <a href=\"https:\/\/aka.ms\/MsftSentinel_TEI2024\" target=\"_blank\" rel=\"noreferrer noopener\">Total Economic Impact\u2122 (TEI) study<\/a>. Using the methodology of the TEI framework, Forrester consultants evaluated the cost, benefits, and flexibility of Microsoft Sentinel and developed a framework that organizations can use to evaluate the potential financial impact on their organizations. <\/p>\n<p>In this study, Forrester found that interviewees achieved some notable advantages from their investment in Microsoft Sentinel, including increasing the productivity of their security teams, simplifying operations, decreasing their total cost of ownership, and realizing a <strong>return on investment (ROI) of 234%.<\/strong> Here are some other major findings for a composite organization based on what interviewed organizations reported.<\/p>\n<h2 class=\"wp-block-heading\" id=\"1-reducing-time-to-value-compared-to-other-siem-solutions\">1. Reducing time-to-value compared to other SIEM solutions&nbsp;<\/h2>\n<p>Deploying Microsoft Sentinel\u2014and finessing it after implementation\u2014is faster because of the solution\u2019s prebuilt playbooks, automation, and other SIEM tools. <strong>Microsoft Sentinel reduced the time to configure and deploy new connections by 93%, with time saved in configuration valued at $618,000 during the three-year period Forrester analyzed.&nbsp;<\/strong>&nbsp;<\/p>\n<blockquote class=\"wp-block-quote blockquote\">\n<p><em>&#8220;It took us about five years to get to be a six terabyte on-prem customer [with out previous solution]. It took us two months to set up Microsoft Sentinel and another two months to be at data-ingestion parity. It was insane.&#8221;<\/em><\/p>\n<p> <cite>\u2014CISO, financial services<\/cite><\/p><\/blockquote>\n<p>This out-of-the-box functionality also includes simplified data connections and integrations that make it easier and faster to connect Microsoft Sentinel with your non-Microsoft systems, saving the time that employees might otherwise spend doing integration work. Valuable connections can be made across users, devices, apps, and infrastructure. Find even more integrations with <a href=\"https:\/\/www.microsoft.com\/en-us\/security\/business\/ai-machine-learning\/microsoft-security-copilot\" target=\"_blank\" rel=\"noreferrer noopener\">Copilot for Security<\/a>.&nbsp;<\/p>\n<h2 class=\"wp-block-heading\" id=\"2-increasing-the-efficiency-of-the-soc\">2. Increasing the efficiency of the SOC&nbsp;<\/h2>\n<p>Microsoft Sentinel makes it easier for security practitioners at all levels of expertise to detect, investigate, and respond effectively to cyberthreats. The solution harnesses an AI-driven correlation engine and offers a unified set of tools to more easily monitor, manage, and respond to incidents.<strong> <\/strong>Those interviewed praised Microsoft Sentinel\u2019s interface for being easy to use (no specialized security expertise necessary). Because of Sentinel\u2019s process automation, security professionals with less IT knowledge can effectively use the platform to detect and respond to cyberthreats.&nbsp;&nbsp;<\/p>\n<p><strong>The total value of efficiency improvements to the security operations center of a composite organization was $1.5 million over three years. <\/strong>The solution is intuitive enough to use that junior analysts can tackle investigation basics while senior analytics tackle higher-priority tasks, according to Forrester findings. A prebuilt playbook helps further.&nbsp;&nbsp;<\/p>\n<p>Microsoft Sentinel capabilities, including its behavior-based analytics, enable you to boost the mean time to respond (MTTR) as you decrease false positives and minimize the work required of advanced investigations.<strong> <\/strong>In fact, Forrester found that <strong>Microsoft Sentinel helped to reduce false positives by up to 79% and decrease the work required for advanced, multitouch investigations by 85%<\/strong>.<strong>&nbsp;<\/strong>These are critical metrics when every second counts in triage and response.<\/p>\n<blockquote class=\"wp-block-quote blockquote\">\n<p>\u201c<em>The reason we have Microsoft Sentinel is because of its proactive predictive abilities. It is able to respond to threats faster than a human can. We actually were able to stop significant threats that hit other organizations and keep our organization running. Microsoft Sentinel was one of the tools in our Microsoft tool bag that really kept us running as an organization. It kept our operations running<\/em>.\u201d<\/p>\n<p> <cite>\u2014CISO, healthcare<\/cite><\/p><\/blockquote>\n<h2 class=\"wp-block-heading\" id=\"3-reduce-total-cost-of-operation\">3. Reduce total cost of operation&nbsp;<\/h2>\n<p>Implementing Microsoft Sentinel offers several cost savings opportunities, according to interviewees.<strong> <\/strong>One quantified benefit from the study found that the composite organization&#8217;s potential cost savings gained\u00a0by discounting their current legacy SIEM solution and switching to Microsoft Sentinel <strong>could account for realized savings of up to $5.1 million over three years<\/strong>. This is attributed to Microsoft Sentinel\u2019s lower per-GB data ingestion and licensing costs that enables customers to avoid the capital investments necessary to store logs on-premises.\u00a0<\/p>\n<p>Microsoft Sentinel offers smoother deployment because of its prebuilt playbooks, queries, data connections, and free ingestion for certain Microsoft logs including Office 365 audit logs, Azure activity logs, and Microsoft Threat Protection alerts. The more intuitive nature of Microsoft Sentinel makes it easier to onboard employees to the technology.\u00a0\u00a0<\/p>\n<blockquote class=\"wp-block-quote blockquote\">\n<p>\u201c<em>Compared to [our on-premises solution] when we were paying for infrastructure, the savings are significant. Essentially one year of [legacy solution] costs are three years of Microsoft Sentinel costs<\/em>.\u201d<\/p>\n<p> <cite>\u2014CISO, financial services<\/cite><\/p><\/blockquote>\n<p>Interviewees also shared that Microsoft Sentinel helped them decrease compliance costs. They did this by streamlining compliance reporting through the automation capabilities of Sentinel for security data collection and analysis. The alternative option would likely have been to bring in external consultants.&nbsp;&nbsp;<\/p>\n<h2 class=\"wp-block-heading\" id=\"4-minimizing-management-effort\">4. Minimizing management effort&nbsp;<\/h2>\n<p>In interviews with management teams at the organizations, they reported saving time on planning and maintenance, allowing for more time on other critical projects. That\u2019s due to the way the solution decreased the size and complexity of their on-premises infrastructure. <strong>The value of this reduced management amounts to $1.1 million for a composite organization over three years and enabled the redeployment of 50% of infrastructure services professionals and 16% of legacy SIEM specialists. <\/strong>Automatic updates and the platform\u2019s intuitive and centralized nature contribute to lessening the demand for labor.&nbsp;&nbsp;<\/p>\n<blockquote class=\"wp-block-quote blockquote\">\n<p>\u201c<em>In the raw maintenance of the SIEM, it\u2019s pretty hands off. When there is an issue, we open up a case with Microsoft and they assume the burden of trying to fix the issue. I don\u2019t have to maintain staff for that anymore<\/em>.\u201d<\/p>\n<p> <cite>\u2014CISO, financial services<\/cite><\/p><\/blockquote>\n<h2 class=\"wp-block-heading\" id=\"the-advantages-of-microsoft-sentinel\">The advantages of Microsoft Sentinel&nbsp;<\/h2>\n<p>With its modern, cloud-native features and innovations, Microsoft Sentinel has helped organizations like yours deploy faster, increase the efficiency of their threat investigations, save on deployment and training, and gain efficiency in security management. Explore the <a href=\"https:\/\/aka.ms\/MsftSentinel_TEI2024\" target=\"_blank\" rel=\"noreferrer noopener\">Total Economic Impact\u2122 Of Microsoft Sentinel Study<\/a> for more analyst findings as well as to read the perspectives of Sentinel users interviewed in the study. <\/p>\n<p>And to learn more about Microsoft Security, see:<\/p>\n<ul>\n<li><a href=\"https:\/\/aka.ms\/MSOSecurityBlog\" target=\"_blank\" rel=\"noreferrer noopener\">Unified security operations center platform<\/a>.<\/li>\n<li><a href=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/2024\/03\/13\/microsoft-copilot-for-security-is-generally-available-on-april-1-2024-with-new-capabilities\/\">Microsoft Secure announcements<\/a>.<\/li>\n<li><a href=\"https:\/\/go.microsoft.com\/fwlink\/p\/?linkid=2210547&amp;clcid=0x409&amp;culture=en-us&amp;country=us\" target=\"_blank\" rel=\"noreferrer noopener\">Microsoft Sentinel innovations<\/a>.<\/li>\n<\/ul>\n<div class=\"wp-block-msxcm-cta-block\" data-moray data-bi-an=\"CTA Block\">\n<div class=\"card d-block mx-ng mx-md-0\">\n<div class=\"row no-gutters material-color-brand-dark\">\n<div class=\"col-md-4\"> \t\t\t\t\t<img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"576\" src=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/wp-content\/uploads\/2024\/02\/Security_Blog_Motion-01-1024x576.gif\" class=\"card-img img-object-cover\" alt=\"icon\" srcset=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/wp-content\/uploads\/2024\/02\/Security_Blog_Motion-01-1024x576.gif 1024w, https:\/\/www.microsoft.com\/en-us\/security\/blog\/wp-content\/uploads\/2024\/02\/Security_Blog_Motion-01-300x169.gif 300w, https:\/\/www.microsoft.com\/en-us\/security\/blog\/wp-content\/uploads\/2024\/02\/Security_Blog_Motion-01-768x432.gif 768w, https:\/\/www.microsoft.com\/en-us\/security\/blog\/wp-content\/uploads\/2024\/02\/Security_Blog_Motion-01-1536x864.gif 1536w, https:\/\/www.microsoft.com\/en-us\/security\/blog\/wp-content\/uploads\/2024\/02\/Security_Blog_Motion-01-615x346.gif 615w, https:\/\/www.microsoft.com\/en-us\/security\/blog\/wp-content\/uploads\/2024\/02\/Security_Blog_Motion-01-336x189.gif 336w, https:\/\/www.microsoft.com\/en-us\/security\/blog\/wp-content\/uploads\/2024\/02\/Security_Blog_Motion-01-189x106.gif 189w, https:\/\/www.microsoft.com\/en-us\/security\/blog\/wp-content\/uploads\/2024\/02\/Security_Blog_Motion-01-630x354.gif 630w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/>\t\t\t\t<\/div>\n<div class=\"d-flex col-md\">\n<div class=\"card-body align-self-center p-4 p-md-5\">\n<h2>Microsoft Sentinel<\/h2>\n<div class=\"mb-3\">\n<p>See and stop\u00a0cyberthreats across your entire enterprise with intelligent security analytics.<\/p>\n<\/p><\/div>\n<div class=\"link-group\"> \t\t\t\t\t\t\t<a href=\"https:\/\/www.microsoft.com\/en-us\/security\/business\/siem-and-xdr\/microsoft-sentinel\" class=\"btn btn-link text-decoration-none p-0\" > \t\t\t\t\t\t\t\t<span>Learn more<\/span> \t\t\t\t\t\t\t\t<span class=\"glyph-append glyph-append-chevron-right glyph-append-xsmall\"><\/span> \t\t\t\t\t\t\t<\/a> \t\t\t\t\t\t<\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<h2 class=\"wp-block-heading\" id=\"learn-more\">Learn more<\/h2>\n<p>To learn more about Microsoft Security solutions, visit our\u202f<a href=\"https:\/\/www.microsoft.com\/en-us\/security\/business\" target=\"_blank\" rel=\"noreferrer noopener\">website.<\/a>\u202fBookmark the\u202f<a href=\"https:\/\/www.microsoft.com\/security\/blog\/\" target=\"_blank\" rel=\"noreferrer noopener\">Security blog<\/a>\u202fto keep up with our expert coverage on security matters. Also, follow us on LinkedIn (<a href=\"https:\/\/www.linkedin.com\/showcase\/microsoft-security\/\" target=\"_blank\" rel=\"noreferrer noopener\">Microsoft Security<\/a>) and X (<a href=\"https:\/\/twitter.com\/@MSFTSecurity\" target=\"_blank\" rel=\"noreferrer noopener\">@MSFTSecurity<\/a>)\u202ffor the latest news and updates on cybersecurity.\u00a0<\/p>\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n<p>Total Economic Impact is a methodology developed by Forrester Research that enhances a company\u2019s technology decision-making processes and assists vendors in communicating the value proposition of their products and services to clients. The TEI methodology helps companies demonstrate, justify, and realize the tangible value of IT initiatives to both senior management and other key business stakeholders.\u00a0<\/p>\n<p>The post <a href=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/2024\/03\/19\/microsoft-sentinel-delivered-234-roi-according-to-new-forrester-study\/\">Microsoft Sentinel delivered 234% ROI, according to new Forrester study<\/a> appeared first on <a href=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\">Microsoft Security Blog<\/a>.<\/p>\n<p><a href=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/2024\/03\/19\/microsoft-sentinel-delivered-234-roi-according-to-new-forrester-study\/\" target=\"bwo\" >https:\/\/blogs.technet.microsoft.com\/mmpc\/feed\/<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p><strong>Credit to Author: Rob Lefferts| Date: Tue, 19 Mar 2024 16:00:00 +0000<\/strong><\/p>\n<p>A new Forrester study of more than 450 organizations that implemented Microsoft Sentinel found significant benefits, including a 234% return on investment. Read on for the major findings from the report.                <\/p>\n<p>The post <a href=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/2024\/03\/19\/microsoft-sentinel-delivered-234-roi-according-to-new-forrester-study\/\">Microsoft Sentinel delivered 234% ROI, according to new Forrester study<\/a> appeared first on <a href=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\">Microsoft Security Blog<\/a>.<\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[10759,10378],"tags":[],"class_list":["post-24200","post","type-post","status-publish","format-standard","hentry","category-microsoft","category-security"],"_links":{"self":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/24200","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=24200"}],"version-history":[{"count":0,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/24200\/revisions"}],"wp:attachment":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=24200"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=24200"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=24200"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}