{"id":5975,"date":"2024-10-28T18:04:44","date_gmt":"2024-10-28T23:04:44","guid":{"rendered":"https:\/\/www.darkreading.com\/identity-access-management-security\/sophos-secureworks-deal-focuses-on-building-advanced-mdr-xdr-platform"},"modified":"2024-10-28T18:04:44","modified_gmt":"2024-10-28T23:04:44","slug":"sophos-secureworks-deal-focuses-on-building-advanced-mdr-xdr-platform","status":"publish","type":"post","link":"https:\/\/ddi.mohflo.net\/index.php\/2024\/10\/28\/sophos-secureworks-deal-focuses-on-building-advanced-mdr-xdr-platform\/","title":{"rendered":"Sophos-SecureWorks Deal Focuses on Building Advanced MDR, XDR Platform"},"content":{"rendered":"<div class=\"media_block\"><a href=\"https:\/\/i0.wp.com\/eu-images.contentstack.com\/v3\/assets\/blt6d90778a997de1cd\/blt3108fd3821dd879e\/66d1ae5bf25c7181ba8ff5cd\/acquisition-puzzle-DigtialStorm-iStock_64062359_MEDIUM.jpg?ssl=1\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/10\/sophos-secureworks-deal-focuses-on-building-advanced-mdr-xdr-platform.jpg?w=640&#038;ssl=1\" class=\"media_thumbnail\"><\/a><\/div>\n<div><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/10\/sophos-secureworks-deal-focuses-on-building-advanced-mdr-xdr-platform.jpg?w=640&#038;ssl=1\" class=\"ff-og-image-inserted\"><\/div>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Sophos is doubling down on managed detection and response (MDR) services with last week&#8217;s agreement to acquire SecureWorks. The $859 million all-cash deal, set to close in early 2025 pending customary approvals, will accelerate Sophos&#8217; push into MDR and extended detection and response (XDR) with SecureWorks&#8217; popular Taegis platform at the core, the company said.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">SecureWorks has only 4,000 customers to Sophos&#8217; 600,000, but the company offers &nbsp;advanced XDR capabilities built on a cloud-native data lake architecture to larger enterprises delivered by service providers. Building on its managed XDR capabilities, SecureWorks this year has added network detection and response (NDR), vulnerability detection and response (VDR) and most recently, identity threat detection and response (ITDR) to the Taegis platform.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Dell Technologies, which owns nearly 80% of SecureWorks&#8217; publicly traded shares, has been exploring ways over the years to <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.reuters.com\/article\/technology\/exclusive-dell-explores-sale-of-cybersecurity-company-secureworks-sources-idUSKCN1PW21W\/\" rel=\"noopener\">divest its control<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> of the security provider. Dell joins the small club of large companies quitting the operations business this year: <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cybersecurity-analytics\/ciso-grapple-with-ibm-unexpected-cybersecurity-software-exit\" rel=\"noopener\">IBM abruptly announced<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> the sale of its QRadar SaaS portfolio to Palo Alto Networks, and <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cybersecurity-operations\/att-splits-cybersecurity-services-business-launches-levelblue\" rel=\"noopener\">AT&amp;T spun out<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> its managed security business, now known as LevelBlue.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Meanwhile, Sophos was looking to add an advanced XDR and MDR platform that it could integrate with its own Sophos Central security operations center (SOC). The central management tool provides endpoint, server and email protection and access to other security services, including firewall, cloud and encryption, among other point offerings.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Sophos, which also added its &#8220;vendor agnostic&#8221; <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.sophos.com\/en-us\/press\/press-releases\/2022\/11\/sophos-launches-mdr-service-that-integrates-vendor-agnostic-telemetry\" rel=\"noopener\">MDR service<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> to its portfolio in late 2022, quickly saw demand for it from its customers, says Enterprise Strategy Group principal analyst Dave Gruber. &#8220;Scaling operations to serve an audience of this size is challenging, making this acquisition a smart move for Sophos, as SecureWorks has many of the best and brightest security professionals in the industry,&#8221; Gruber says. &nbsp;<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Building an XDR Platform on Taegis\">Building an XDR Platform on Taegis<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Sophos CEO Joe Levy says he can&#8217;t reveal specific integration plans before the deal closes in the first quarter of 2025 as it undergoes regulatory clearance processes. But he doesn&#8217;t dispute that bringing Taegis and Sophos Central together is what is driving this deal, which would mark the largest since the company was founded in 1985. &nbsp;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;We&#8217;re aiming toward this world where we bring together the best hits of the two operations,&#8221; Levy tells Dark Reading. &#8220;We will figure out that combination of the technology stack&#8211;Taegis inside Sophos Central and the security operations center itself.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">According to Levy, that will include delivering the MDR business and the vulnerability detection and response, managed risk, identity, threat, detection and response. &#8220;[It&#8217;s] the service component that customers are relying on to help to keep them secure,&#8221; he says.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Levy explains that besides determining a unified approach to provisioning services from SecureWorks and Sophos offerings, a key challenge will be enabling collaboration among the security operation teams within its MDR business, customers and partners, notably MSPs and MSSPs who deliver the two companies&#8217; respective offerings.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;We want to produce the best possible workflows while demonstrating empathy and understanding of what the security operators are doing every single day,&#8221; Levy says. &#8220;These are the driving principles that are going to be guiding the way that we undertake this.&#8221;<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"SecureWorks Shift to XDR Platform\">SecureWorks Shift to XDR Platform<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">SecureWorks began developing Taegis in 2017 and launched it in early 2021. Taegis is built with a data lake architecture designed to ingest and normalize data and an analytics engine built to identify, prioritize, and block threats.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Wendy Thomas, SecureWorks CEO, told investors during the company&#8217;s Q2 &nbsp;2025 quarterly earnings call in September that she sees continued growth potential for Taegis. &#8220;We&#8217;ve increasingly seen customers more than ready to move away from noisy, hard and expensive to maintain SIEMs to an XDR approach to detection and response,&#8221; she said. &#8220;That trend is only accelerating.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Since Taegis was released, analysts and customers have given the platform high marks. &#8220;The Taegis platform from SecureWorks has great detection and response capabilities,&#8221; says IDC analyst Craig Robinson.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">While SecureWorks&#8217; and Sophos&#8217; respective MDR services offer many similar features, Robinson notes that Sophos&#8217; offering has a more vendor-independent model than Taegis. &#8220;While there&#8217;s overlap, Sophos has more individual products while Taegis is a platform,&#8221; he says.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Independent consultant <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.wilklu.me\/\" rel=\"noopener\">William Klusovsky<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> believes that adding SecureWorks is poised to deepen Sophos&#8217; reach into larger enterprises and offer richer services to small and mid-sized organizations. But he warns Sophos could &#8220;fumble&#8221; that potential if it doesn&#8217;t adequately invest in the integration of the products.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;If they are too short-sighted and focus only on financials and returns, they could end up with two businesses that don&#8217;t work together and lose the talent they need to create the right business,&#8221; Klusovsky says. &#8220;They need to have a vision, stick to it, and believe in it.&#8221;<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Transition to Managed Security Services\">Transition to Managed Security Services<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Klusovsky notes that Sophos is owned by private equity firm Thoma Bravo, whose portfolio he says is mostly product companies, while both SecureWorks and Sophos have been shifting to services.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;The services industry is very different,&#8221; he says. &#8220;The good news is the product road maps, and integrations should be something they can create efficiency with and drive in a positive direction. The unknown is going to be in managing service delivery, sales, the channel, and go-to-market as these motions are very different for a managed services provider than a product company.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Levy says he first started driving the shift from a product-only cybersecurity business to a hybrid product and services business in 2018 before Sophos<\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/endpoint-security\/sophos-for-sale-thoma-bravo-offers-3-9b\" rel=\"noopener\"> agreed to be acquired<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> by Thoma Bravo.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;We now think of it more in terms of life cycles of engagement with our customers, rather than just selling them a product or selling them a service,&#8221; Levy says. &#8220;We&#8217;re working in collaboration with this ecosystem of cyber security players to maintain life cycle engagements with customers, so just pray that the next point solution they buy is actually going to provide better security.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Similarly, SecureWorks has undergone several significant changes, having shifted from operating as a managed security services provider (MSSP) to a platform supplier. Instead, SecureWorks tapped its ecosystem of channel partners to offer the Taegis platform with their own managed security services.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">IDC forecasts that demand for managed security services will grow to $44 billion in 2024, up from $39.5 billion in 2023. Demand is estimated to grow to $49.2 billion next year, IDC&#8217;s Robinson says. Driving the growth are shrinking budgets and a dearth of skilled security operations talent.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;Everyone&#8217;s looking at and making sure that for every dollar spent, it&#8217;s being spent in the right way,&#8221; he says. &#8220;And managed security services is not only a better way, but it&#8217;s also, more often, a better outcome.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&nbsp;<\/span><\/p>\n<p><a href=\"https:\/\/www.darkreading.com\/identity-access-management-security\/sophos-secureworks-deal-focuses-on-building-advanced-mdr-xdr-platform\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Sophos is doubling down on managed detection and response (MDR)<\/p>\n","protected":false},"author":12,"featured_media":5976,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[1],"tags":[809],"class_list":["post-5975","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-dark-reading"],"featured_image_urls":{"full":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/10\/sophos-secureworks-deal-focuses-on-building-advanced-mdr-xdr-platform.jpg?fit=1600%2C900&ssl=1",1600,900,false],"thumbnail":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/10\/sophos-secureworks-deal-focuses-on-building-advanced-mdr-xdr-platform.jpg?resize=150%2C150&ssl=1",150,150,true],"medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/10\/sophos-secureworks-deal-focuses-on-building-advanced-mdr-xdr-platform.jpg?fit=300%2C169&ssl=1",300,169,true],"medium_large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/10\/sophos-secureworks-deal-focuses-on-building-advanced-mdr-xdr-platform.jpg?fit=640%2C360&ssl=1",640,360,true],"large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/10\/sophos-secureworks-deal-focuses-on-building-advanced-mdr-xdr-platform.jpg?fit=640%2C360&ssl=1",640,360,true],"1536x1536":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/10\/sophos-secureworks-deal-focuses-on-building-advanced-mdr-xdr-platform.jpg?fit=1536%2C864&ssl=1",1536,864,true],"2048x2048":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/10\/sophos-secureworks-deal-focuses-on-building-advanced-mdr-xdr-platform.jpg?fit=1600%2C900&ssl=1",1600,900,true],"chromenews-featured":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/10\/sophos-secureworks-deal-focuses-on-building-advanced-mdr-xdr-platform.jpg?fit=1024%2C576&ssl=1",1024,576,true],"chromenews-large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/10\/sophos-secureworks-deal-focuses-on-building-advanced-mdr-xdr-platform.jpg?resize=825%2C575&ssl=1",825,575,true],"chromenews-medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/10\/sophos-secureworks-deal-focuses-on-building-advanced-mdr-xdr-platform.jpg?resize=590%2C410&ssl=1",590,410,true]},"author_info":{"display_name":"Dark Reading","author_link":"https:\/\/ddi.mohflo.net\/index.php\/author\/darkreading\/"},"category_info":"<a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/uncategorized\/\" rel=\"category tag\">Uncategorized<\/a>","tag_info":"Uncategorized","comment_count":"0","jetpack_featured_media_url":"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/10\/sophos-secureworks-deal-focuses-on-building-advanced-mdr-xdr-platform.jpg?fit=1600%2C900&ssl=1","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/5975","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/comments?post=5975"}],"version-history":[{"count":0,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/5975\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media\/5976"}],"wp:attachment":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media?parent=5975"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/categories?post=5975"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/tags?post=5975"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}