White Paper | CISO Guide to TDIR Innovation with XDR, AI and Automation
Discover how extended detection and response (XDR) empowers enterprises to outpace sophisticated cyber threats with cutting-edge TDIR capabilities, including AI, automation, and hybrid IT integration. Learn why Omdia highlights XDR as the key to achieving unmatched speed and precision in modern threat defense. Download the White Paper to explore the full insights.

Brought to you by Informa Tech
Publication date: June 2024
Author:
Eric Parizo
Omdia’s CISO Guide to TDIR Innovation with XDR, AI and Automation
Commissioned by
Omdia’s CISO Guide to TDIR Innovation with XDR, AI and Automation
Omdia commissioned research, sponsored by Check Point
Contents Summary 2
The desperate need for TDIR innovation 5
TDIR Innovation: XDR offers a new path 7
XDR: The Change Agent for Enterprise TDIR Innovation 8
Conclusion 10
Appendix 11
Omdia’s CISO Guide to TDIR Innovation with XDR, AI and Automation
© 2024 Omdia. All rights reserved. Unauthorized reproduction prohibited.
2
Summary
Achieving desired outcomes in enterprise threat detection, investigation, and response (TDIR) in an increasingly challenging threat environment requires an aggressive commitment to TDIR technology innovation. To keep pace with the breadth and sophistication of adversaries, Omdia believes that extended detection and response (XDR) is well positioned to deliver innovative TDIR capabilities, such as hybrid IT estate integration, AI, and automation, enabling organizations to match the speed and scale of today’s threats.
Omdia’s CISO Guide to TDIR Innovation with XDR, AI and Automation
© 2024 Omdia. All rights reserved. Unauthorized reproduction prohibited.
3
Introduction Most cybersecurity research reports begin with frightening rhetoric that describes the state of the enterprise cybersecurity threat landscape. But if you’re a chief information security officer (CISO), you live those realities daily. And, more than likely, you’ve recently experienced exactly how quickly a missed or mishandled threat detection can result in a damaging, costly incident.
Findings from Omdia’s 2023 Cybersecurity Decision Maker survey back that up: Omdia’s survey of more than 600 security leaders found that a majority of organizations have faced numerous security mishaps, with more than a third enduring either several severe incidents requiring meaningful escalation or having material impact to the organization.
Figure 1: Which best characterizes the security issues your organization dealt with in the past 12 months?
Source: Omdia
And additional data points illustrate that the threat landscape isn’t getting any easier to deal with:
Numerous severe security incident(s) with material
impact to the organization, 9%
Several severe security
incident(s) that required
meaningful escalation, 27%
Numerous security mishaps with limited impact to the
organization, 31%
Several security mishaps with
limited impact to the
organization, 23%
We have not had any
security issues, 10%
Note: n=627 © 2023 Omdia
Omdia’s CISO Guide to TDIR Innovation with XDR, AI and Automation
© 2024 Omdia. All rights reserved. Unauthorized reproduction prohibited.
4
▪ According to Check Point’s 2024 Cyber Security Report, organizations face an unprecedented
surge in ransomware attacks, with 1 in every 10 organizations globally being targeted in
2023.
▪ Mandiant, in its M-Trends 2024 Special Report, found that average attacker dwell time – the
length of time from initial compromise to detection – has decreased to 10 days, but its “red
teams” need only 5-7 days to accomplish their goals, meaning adversaries can also get in
that quickly.
▪ And when the worst happens, it is increasingly common for seemingly everyone to know
about it: in its above-mentioned report, Check Point found that more than 5,000 cyberattack
victims were publicly extorted in 2023, a 90% increase from the previous year.
When the stakes are so high, it is critically important for CISOs to ensure their TDIR programs can identify and address critical threats quickly and successfully. Adversarial intrusions, in particular, should ideally be detected in minutes or hours, not days or weeks.
https://protect.checkpoint.com/v2/___https://research.checkpoint.com/2024/2024s-cyber-battleground-unveiled-escalating-ransomware-epidemic-the-evolution-of-cyber-warfare-tactics-and-strategic-use-of-ai-in-defense-insights-from-check-points-latest-security-re/___.YzJlOmNwYWxsOmM6bzpjMjkzMmI5ZjBhYmRiYThhOTcyNTk3NzExY2RiODJkODo2OmRiYTk6MWJhODg4OGFlZGU2YzA2ZmJlYTY5M2YxNTgxNWVkYTM3ZTY0ZjE1ZDZiNGJjNzZjYzIwOWQzZmQxMzU2NjFhYjpwOlQ
Omdia’s CISO Guide to TDIR Innovation with XDR, AI and Automation
© 2024 Omdia. All rights reserved. Unauthorized reproduction prohibited.
5
The desperate need for TDIR innovation
Conducting the same TDIR processes in the same way with the same technologies will only yield similar results. Hence Omdia strongly advocates for an innovation-led approach to TDIR. From a philosophical standpoint, it means making the commitment to seek out, experiment with, and ultimately embrace new technologies, approaches, and skillsets for the betterment of TDIR outcomes.
While there are numerous opportunities for innovation in TDIR, Omdia believes there are several areas of emphasis that deserve special focus of CISOs and security leaders.
Elimination of threat detection data siloes One of the industry’s long-standing frustrations with traditional TDIR solution architectures, namely those largely centered on security information and event management (SIEM) and security orchestration and automated response (SOAR) deployments, is the way in which solutions address the heterogeneous nature of threat detection data. TDIR depends on input—that is, data—to find threats, but for many organizations, the scope of TDIR input spans dozens of sources, exists in a wide variety of log formats, and requires significant threat detection data lifecycle engineering before a data corpus can foster consistent and effective threat detection. Furthermore, without an effective set of analytics capabilities across the entirety of the dataset, the system will produce excessive “noise” in the form of false and redundant positive detections, while failing to consistently identify critical threats that could be identified through correlation of related data from disparate sources.
Reduction of redundant threat detections A large proportion of the “noise” involved with threat detection—the abundance of discrete threat detections many TDIR solutions produce—is actually good noise. The solution is detecting threat events that meet established criteria for alerting, but many of these alerts are redundant. The same infected server may create dozens of alerts, or a variety of compromised hosts may all be impacted by the same intrusion event. While technically the solution is working, in reality the inability of the solution to effectively correlate those events into consolidated incidents for the purpose of alerting, investigation and remediation ultimately makes the TDIR process more challenging.
Remediation-response enablement There are many TDIR solutions that can gather data, detect threats, and facilitate investigations. However, Omdia has found that even today there are few TDIR solutions that can do all those things
Omdia’s CISO Guide to TDIR Innovation with XDR, AI and Automation
© 2024 Omdia. All rights reserved. Unauthorized reproduction prohibited.
6
and subsequently foster a quick, effective remediation response. There is an inherent divide between the conclusion of an investigation and the beginning of a remediation-response: experienced incident responders know that determining the cause of an incident doesn’t necessarily elucidate how best to mitigate the immediate threat or permanently resolve it. Even when the investigation does identify the response, TDIR solutions offer mixed results, at best, at enacting those responses, often relying on minimally transparent third-party integrations.
These challenges clearly illustrate the need for innovation in enterprise TDIR solutions.
Hence, to bridge the gap between the threat landscape and the ability of each enterprise to keep pace, Omdia asserts it is critical for enterprises to adopt a similarly aggressive posture with regard to TDIR technology management. Specifically, this means undertaking several key initiatives, including:
▪ Reevaluate existing TDIR solutions, and key capabilities within, on a rolling basis—at a
minimum of every 12 months—against key performance indicators, which should be based
on both industry best practices (e.g. MTTD/MTTR) and organization-specific business
requirements. Data should be based on a mix of solution reporting capabilities and human
input.
▪ Employ metrics to identify outlier incidents, e.g. those that required far more time than
average to analyze and/or remediate, and understand the role that tooling played in the
course of those incidents. Which elements of the TDIR architecture aided and/or inhibited a
successful outcome, and why? Use these examinations to develop an ongoing, prioritized list
of TDIR technology gaps to address.
▪ Identify and maintain a running list of emerging technologies and capabilities. This can be
informal, but should serve to support the ongoing exercise of discovering opportunities to
augment existing solutions or, ultimately, move toward more advanced ones. Identify exactly
what’s new or different, how it would provide value, and whether it would fully or partially
address an existing TDIR technology gap. To be clear, not every new capability will prove
valuable or worth pursuing, but seeking out technological innovation in TDIR should be an
ongoing exercise.
Omdia’s CISO Guide to TDIR Innovation with XDR, AI and Automation
© 2024 Omdia. All rights reserved. Unauthorized reproduction prohibited.
7
TDIR Innovation: XDR offers a new path
Omdia strongly believes all facets of effective enterprise cybersecurity require a combination of people, processes, and technology; TDIR is no exception. However, in light of the realities of the threat landscape, and the likelihood that the challenges posed by adversaries will only further increase, it is reasonable to conclude that even the most effective teams of defenders and highly tuned processes can only scale so far. Cybersecurity technology must bridge the gap, by doing more to support people and processes; in TDIR, security operations (SecOps) solution architectures must be able to facilitate business objectives. While these can be many and varied, there is little question that the top objective for most organizations is to ensure cybersecurity threats with the potential to cause business harm are detected and addressed before adversaries can meet their objectives.
Unfortunately, the complexities associated with traditional SOC technology architectures are often at odds with these objectives. As Omdia research has shown, SOC architectures based on SIEM/SOAR have commonly proved to be too expensive; too hard to deploy, configure, and manage; and often too inconsistent in their ability to meet key enterprise key performance indicators for TDIR success. In response, XDR recently emerged as a fresh, innovative approach to an old problem. Indeed, in its report, Fundamentals of Comprehensive XDR, Omdia identified four primary catalysts that led to the creation of the XDR product segment:
▪ The need for improved, unified data normalization and correlation among primary threat
detection telemetry sources.
▪ The need to natively incorporate new and more advanced approaches to threat detection,
including behavioral analytics, machine learning, artificial intelligence (AI), and correlation of
multiple related events.
▪ The need to react, respond, and resolve threats more quickly and successfully, primarily
through orchestration and ultimately automation of investigation and remediation-response
activities.
▪ The need for these capabilities among organizations of all types and sizes, including those
with relatively low states of cybersecurity program maturity.
As more enterprises prioritize these catalysts in their TDIR programs, Omdia sees XDR as having the potential to displace or supplement traditional TDIR solution architectures in the coming years. Omdia’s latest Enterprise Cybersecurity Operations Market Tracker – 1H24 Database finds that after a short growth slowdown due largely to uneven global macroeconomic performance, the size of the XDR market in 2023 grew to $876 million, and is forecasted to reach $2.554 billion in 2029, at a compound annual growth rate (CAGR) of 19.51%.
https://protect.checkpoint.com/v2/___https://omdia.tech.informa.com/om025510/fundamentals-of-comprehensive-extended-detection-and-response-cxdr___.YzJlOmNwYWxsOmM6bzpjMjkzMmI5ZjBhYmRiYThhOTcyNTk3NzExY2RiODJkODo2OjA5ODU6YjE5N2MyYTY2NWRjMWFmN2UwMzc1MTgwZGI5Yjc4MjZmY2ZhOTY5YzUzNDg3MzI2M2YxZGI3MzM1N2E5ZDE3ZTpwOlQ
Omdia’s CISO Guide to TDIR Innovation with XDR, AI and Automation
© 2024 Omdia. All rights reserved. Unauthorized reproduction prohibited.
8
XDR: The Change Agent for Enterprise TDIR Innovation
Omdia believes XDR technology vendors can embrace the opportunity to provide differentiated TDIR outcomes through differentiated approaches.
While Omdia has identified several capabilities areas in which XDR solutions offer the potential to improve upon legacy TDIR solution architectures, here Omdia outlined several selected areas where XDR vendors should have a particularly strong rationale for leveraging their solutions to offer differentiated approaches.
Correlated, streamlined, prioritized detections Comprehensive XDR solutions, as defined by Omdia, provide single-vendor platforms or solution sets (or even services) with integrated threat detection, investigation, and remediation-response capabilities. In other words, a single TDIR solution acquires and analyzes data from key IT estate regions—endpoints, networks, and cloud assets—and directly facilitates remediation-response activities back to those same sources. This closed-loop capability is intended to accelerate the TDIR lifecycle, but can only do so if threat detections are correlated (so a multipronged attack or series of activities related to a single event or threat action are brought together for better, easier analysis), streamlined (so repeated or related detections across multiple devices or estate regions are not alerted on repeatedly), and prioritized (so high-priority threat events are assigned priority status in such a way that they can receive immediate attention from SOC analysts).
Integration across hybrid IT estate TDIR solutions (also referred to by Omdia as reactive security solutions) should work in combination with preventative solutions such as firewalls and web gateways that seek to block identifiable threats before the point of intrusion, and Proactive Security solutions that seek out and mitigate threats and threat conditions before they can pose a danger to an IT environment. Because XDR solutions natively integrate with security assets across the aforementioned key IT estate regions, that level of integration becomes more achievable, even in granular operational scenarios. For example, when an XDR solution employs the combination of endpoint activity data and network logs to identify malicious activity and its external source, hybrid IT estate integration provided by XDR can enable not only neutralize the threat at hand, but also suggest or even facilitate new blocking rules at the gateway level or even match the activity with techniques, tactics, and procedures (TTPs) so that exposure management capabilities can be employed to prevent similar future attack opportunities.
Omdia’s CISO Guide to TDIR Innovation with XDR, AI and Automation
© 2024 Omdia. All rights reserved. Unauthorized reproduction prohibited.
9
Measurable benefits from AI-driven capabilities At the top of many organizations’ list of desired emerging technologies and capabilities for TDIR is artificial intelligence, particularly generative AI (GenAI). Being able to employ AI to quickly answer questions, gather data, identify next steps, or even initiate remediation-response actions represents an alluring new approach that many believe represents the best long-term hope defenders have in keeping pace with fast-acting adversaries. Omdia believes not all AI-driven TDIR capabilities are created equal though; many newly debuted chatbots have proven to be a fascinating novelty among TDIR solutions, but few have provided meaningful benefits. Comprehensive XDR solutions, however, are well-positioned to deliver meaningful AI-driven capabilities because of its closed-loop approach. For example, because Comprehensive XDR solutions correlate threat detections across IT estate regions, it becomes easier to combine threat intelligence inputs with AI-curated analysis to deliver prioritized, contextually relevant comparisons of detections versus known exploitation events in the wild. Similarly, because of the unified interface Comprehensive XDR solutions provide, AI can enhance that “single pane of glass” experience by providing SOC analysts with auto-generated summaries of complex threat events, as well as suggested next steps to accelerate remediation- response activities. Any AI-driven capability in an XDR solution should be evaluated through measurable metrics, such as detection accuracy, reduced false positives/negatives, MTTD/MTTR, and the like.
Facilitated path toward orchestration and automation The acknowledged, long-standing gap between the average time needed to execute an attack and the average time defenders need to stop it is in itself an admission that orchestration and automation must play a larger role in the TDIR lifecycle. Once again, XDR is well positioned to address the challenge. Omdia has observed these solutions can excel in automating routine response actions—such as isolating hosts, initiating kill processes, and notifying admins—but also customizing more advanced orchestration functions, such as continuously collecting and analyzing new indicators of compromise (IoCs) from various locations, and initiating automated response actions based on pre-defined conditions. This helps SOC teams to not only employe orchestration and automation capabilities effectively, but also at a customized pace that lines up with a variety of organizational security maturity levels.
Omdia’s CISO Guide to TDIR Innovation with XDR, AI and Automation
© 2024 Omdia. All rights reserved. Unauthorized reproduction prohibited.
10
Conclusion
The most sophisticated and dangerous threat events are often unique, and there are no easy answers. However, Omdia believes a relentless pursuit of innovation in enterprise TDIR can foster significantly improved outcomes. But that requires an aggressive approach to TDIR that involves actively seeking out meaningful technology innovation.
Omdia believes XDR represents a promising new TDIR solution approach. Its ability to unify and centralize TDIR activities across hybrid IT estates; to correlate, streamline, and prioritize detections; to simplify and guide organizations on the journey toward TDIR orchestration and automation; and to facilitate the delivery of innovation, including meaningful AI-driven capabilities, underscore the meaningful gains organizations can make when employing XDR to detect and prevent advanced threats faster and more effectively than ever before.
Omdia’s CISO Guide to TDIR Innovation with XDR, AI
and Automation 11
© 2024 Omdia. All rights reserved. Unauthorized reproduction prohibited.
11
Appendix
Author
Eric Parizo
Managing Principal Analyst
eric.parizo@omdia.com
Omdia’s CISO Guide to TDIR Innovation with XDR, AI
and Automation 12
© 2024 Omdia. All rights reserved. Unauthorized reproduction prohibited.
12
Get in touch Omdia consulting
www.omdia.com
askananalyst@omdia.com
Omdia is a market-leading data, research, and consulting business
focused on helping digital service providers, technology companies, and
enterprise decision-makers thrive in the connected digital economy.
Through our global base of analysts, we offer expert analysis and strategic
insight across the IT, telecoms, and media industries.
We create business advantage for our customers by providing actionable
insight to support business planning, product development, and go-to-
market initiatives.
Our unique combination of authoritative data, market analysis, and
vertical industry expertise is designed to empower decision-making,
helping our clients profit from new technologies and capitalize on
evolving business models.
Omdia is part of Informa Tech, a B2B information services business
serving the technology, media, and telecoms sector. The Informa group is
listed on the London Stock Exchange.
We hope that this analysis will help you make informed and imaginative
business decisions. If you have further requirements, Omdia’s consulting
team may be able to help your company identify future trends
and opportunities.
https://protect.checkpoint.com/v2/___http://www.omdia.com/___.YzJlOmNwYWxsOmM6bzpjMjkzMmI5ZjBhYmRiYThhOTcyNTk3NzExY2RiODJkODo2OmQwMmE6NDIwZGNmNGMyOGFmYmU1NzJhMzQwMjA0MGQ0ZGM3ZWM0MjAyMzZiY2EyYzYxZmEyY2U4Yzg5NTcxMTgwMmU3ODpwOlQ
Omdia’s CISO Guide to TDIR Innovation with XDR, AI
and Automation 13
© 2024 Omdia. All rights reserved. Unauthorized reproduction prohibited.
13
Copyright notice and disclaimer
The Omdia research, data and information referenced herein (the “Omdia
Materials”) are the copyrighted property of Informa Tech and its
subsidiaries or affiliates (together “Informa Tech”) or its third party data
providers and represent data, research, opinions, or viewpoints published
by Informa Tech, and are not representations of fact.
The Omdia Materials reflect information and opinions from the original
publication date and not from the date of this document. The information
and opinions expressed in the Omdia Materials are subject to change
without notice and Informa Tech does not have any duty or responsibility
to update the Omdia Materials or this publication as a result.
Omdia Materials are delivered on an “as-is” and “as-available” basis. No
representation or warranty, express or implied, is made as to the fairness,
accuracy, completeness, or correctness of the information, opinions, and
conclusions contained in Omdia Materials.
To the maximum extent permitted by law, Informa Tech and its affiliates,
officers, directors, employees, agents, and third party data providers
disclaim any liability (including, without limitation, any liability arising
from fault or negligence) as to the accuracy or completeness or use of the
Omdia Materials. Informa Tech will not, under any circumstance
whatsoever, be liable for any trading, investment, commercial, or other
decisions based on or made in reliance of the Omdia Materials.