Vice President of Technology at Hallmark Building Supplies, Inc.
Real User
Top 20
Good security response management, helpful technical support, and competitive pricing
Pros and Cons
  • "We can effectively manage the massive amounts of security data that we receive from various sources such as firewalls, switches, endpoints, and other log sources."
  • "I can't think of any specific features that they need to add at the moment. As long as they continue to develop new solutions to support different operating systems and technologies, we are satisfied with their service. We appreciate the effort they put into adding new features and functionality to their service and believe they are doing a great job in providing us with all the necessary tools and resources to stay secure."

What is our primary use case?

They function as our CISO, providing guidance and assistance in establishing our security practices as our Chief Security Officer.

How has it helped my organization?

They have been instrumental in setting up our security response, managing our firewalls, switches, cloud environments, and endpoints, and guiding us to ensure our users' safety with login and other security practices. Their expertise and support make them a valuable resource for all things related to security.

What is most valuable?

We can effectively manage the massive amounts of security data that we receive from various sources such as firewalls, switches, endpoints, and other log sources. They help us filter out the noise and extract meaningful insights that lead us to the necessary action points.

What needs improvement?

In the security industry, there is always room for improvement, and Arctic Wolf ensures that we are continuously updated on areas that require improvement.

They keep us informed about the latest security developments and suggest ways to enhance our security posture. 

It's challenging to identify areas where they could improve as they already do an excellent job of staying up to date with the latest security trends. However, the security landscape is constantly evolving, requiring significant energy and effort to keep pace with.

I can't think of any specific features that they need to add at the moment. As long as they continue to develop new solutions to support different operating systems and technologies, we are satisfied with their service. 

We appreciate the effort they put into adding new features and functionality to their service and believe they are doing a great job in providing us with all the necessary tools and resources to stay secure.

Buyer's Guide
Arctic Wolf Managed Detection and Response
June 2024
Learn what your peers think about Arctic Wolf Managed Detection and Response. Get advice and tips from experienced pros sharing their opinions. Updated: June 2024.
787,226 professionals have used our research since 2012.

For how long have I used the solution?

We are in our third year of using Artic Wolf Managed Detection and Response.

It is a Software as a Service (SaaS) that is constantly updated, and there is no versioning since it is the only solution we use.

What do I think about the stability of the solution?

I would rate the stability of Artice Wolf Managed Detection and Response a nine out of ten.

What do I think about the scalability of the solution?

I would rate the scalability a nine out of ten. I never give anything a ten.

Their solution helps protect our entire company, which includes about 130 employees. However, only three of us directly interact with Arctic Wolf.

Although the IT team may expand in the future, the use of Arctic Wolf's solution is widespread across our company and protects everyone. 

While everyone in the company benefits from the protection it provides, only the three of us directly communicate with Arctic Wolf. 

However, the rest of the company uses the software and the protection without necessarily knowing it.

How are customer service and support?

I would rate the technical support a nine out of ten.

Which solution did I use previously and why did I switch?

We use both Artic Wolf Managed Detection and Response and Artic Wolf Managed Risk.

I have been using Artic Wolf Managed Risk for a little over a year.

We are working with the latest version.

We offer two products: one specifically designed for managing network security, and the other for providing training to your associates.

How was the initial setup?

The initial setup was very straightforward.

They provided us with a seamless onboarding experience, and their team guided us through the process of setting up both cloud and on-premise equipment. 

They ensured that we had everything set up correctly and even conducted tests to confirm its efficacy. 

Their onboarding team did an excellent job of helping us move the project forward from its initial stages to where we are now in our security journey.

What was our ROI?

Calculating the return on investment can be challenging in this type of scenario because ideally, you don't want to experience any security incidents that would require the use of the service. It's similar to insurance in that it's something you pay for but hope to never have to use.

What's my experience with pricing, setup cost, and licensing?

I find their pricing to be reasonable and competitive. While it may not be the cheapest option available, it is fair when compared to other solutions in the market.

What other advice do I have?

Arctic Wolf is a partner of ours.

I highly recommend Arctic Wolf if you are searching for a partner to assist you in securing your network and if your company is not large enough to afford a full-time CISO on its own.

I would rate Arctic Wolf Managed Detection and Response a nine out of ten.

Which deployment model are you using for this solution?

Hybrid Cloud
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
AVP of Tech at a insurance company with 201-500 employees
Real User
Top 10
Keeps us safe, integrates with our other products, and has a great portal
Pros and Cons
  • "They provide useful quarterly updates."
  • "It's nitpicky; however, if it could integrate with more of our products, like our CRM, that would be ideal. They may only integrate with Salesforce. We use a different mid-market CRM."

What is our primary use case?

We use them as our managed doc. Instead of hiring a security specialist, we'd rather pay for a solution and have them monitor our network for any intrusion detection, and geotagging, and that's our use case - to use it to protect our company.

What is most valuable?

For us, the best aspect is not having to hire someone. We have an appliance do the job for us and automatically notify us versus hiring a staff member who we then have to pay. For us, the benefit is it keeps us safe as well as integrates with our other products. For example, we use CrowdStrike as well, which it integrates with, and we use Azure, and Office 365, which also integrates with it. This solution just saves us time. It does all of the scanning and monitoring and lets us know what is going on versus having a staff member do it.

I love their portal and their communication style. They provide useful quarterly updates.

The solution is very stable.

It can scale just fine.

Support is helpful.

The initial setup is pretty straightforward. 

What needs improvement?

It's nitpicky; however, if it could integrate with more of our products, like our CRM, that would be ideal. They may only integrate with Salesforce. We use a different mid-market CRM. We'd like to see integrations with Marketo and other software. 

It can be a bit expensive. 

For how long have I used the solution?

We've had this solution since 2020.

What do I think about the stability of the solution?

I haven't had any issues with the stability. It's reliable. There aren't bugs or glitches, and it doesn't crash or freeze. 

What do I think about the scalability of the solution?

The solution can scale. We have a buffer built into the account as we are growing and intend to scale to cover more people. Our current user base ranges from 230 to 300 endpoints. 

How are customer service and support?

We've dealt with technical support in the past, and they have been great.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

While we have used an antivirus previously, we haven't used anything quite like Arctic Wolf. We chose Arctic Wolf as it integrated with our antivirus and had a strong global presence. 

How was the initial setup?

In terms of deployment, they had sent two devices out to us. My network team installed them, and then we currently rolled them out by endpoint to each device. For every computer we set up, we put their product on it.

There were two of us that handled the deployment process. The implementation happened over a couple of days. However, the actual work may have only taken five hours. 

We don't have to maintain anything. they have a direct connection and can maintain it for us. 

What was our ROI?

The ROI is keeping our business up and running. We have not been down, nor have we had any ransomware attacks or any intrusion into our network in the past three years.

What's my experience with pricing, setup cost, and licensing?

The pricing is a bit on the higher side. 

We have additional software to go along with it. We kept the logging for more than 90 days as well as integrated it with our Office 365.

Which other solutions did I evaluate?

We did evaluate other options before choosing this solution. 

What other advice do I have?

While we have an appliance on-premies, it is available on the cloud as well. 

We are using the latest version of the solution. 

The solution does what they say. They don't overpromise and underdeliver. They actually do what their product's supposed to do, and I find that's very hard with vendors. When you deal with the salesperson and then you get the implementation, there are things missing. With Arctic Wolf, you get exactly what you're supposed to get, and it works. I have not had any downtime.

I'd rate the solution ten out of ten. They're one of the only vendors I would actually give references for.

Which deployment model are you using for this solution?

Hybrid Cloud
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Buyer's Guide
Arctic Wolf Managed Detection and Response
June 2024
Learn what your peers think about Arctic Wolf Managed Detection and Response. Get advice and tips from experienced pros sharing their opinions. Updated: June 2024.
787,226 professionals have used our research since 2012.
IT Director at a legal firm with 51-200 employees
Real User
Easy onboarding, effective monitoring, and excellent support services
Pros and Cons
  • "After an easy onboarding, the monitoring started immediately."
  • "In the future, I would like to see a summary report."

What is our primary use case?

We needed more eyes on the prize and Microsoft performance reporting is severely lacking for security compliance as geo blocking in the firewall can only address a small part of the attack grid. It's nice to know that people and machine learning are monitoring my environment for known assaults and unusual behaviors. 

Being a small business we just can't afford to have a full time security engineer and Arctic Wolf gives us the tools and services the big boys have at a reasonable cost. 

With the playing field always changing, it is nice to know our backs are covered.

How has it helped my organization?

We did not have any advanced tools in place for security monitoring. 

Personally, I love having Big Brother (Blue Eyed Wolf?) watching and it is nice to sleep well knowing 24/7 my network is being protected. 

After an easy onboarding, the monitoring started immediately. 

We also run AV on work stations. There was an instance when AWN notified us of a malware download before the end point monitors kicked in. We immediately shut down and reimaged the machine. 

We feel very strongly that we picked the best solution for our organization.

What is most valuable?

The weekly reports are great. I very much appreciate having a quick review of what occurred over the last seven days. I can't give enough kudos to the folks in the SOC. They are friendly, professional, and always available. Even tickets I put in for educational purposes are responded to quickly, and answers are specific. I enjoy not having to rephrase a question due to a generic response. 

The new dashboard is visually appealing, and I can drill down with just a couple of clicks for details. It offers great, easy navigation.

What needs improvement?

The service is fabulous. AWN is one vendor I don't mind having to call. It doesn't matter what urgency you put on the ticket - all I have entered have always received fast replies. Also, this solution offers huge peace of mind. I know I can pick up the phone and get a live person and not be trapped in a looping call tree. 

In the future, I would like to see a summary report. One of my bosses is on the distribution, and I spend time every Monday explaining what the reports mean. Graphs are nice visuals and would help communicate what's happening more effectively.

For how long have I used the solution?

I've used the solution for 15 months. 

What do I think about the stability of the solution?

The solution is extremely stable. We have not had a single issue with any of the agents.

What do I think about the scalability of the solution?

The solution is very scalable. Our environment is pretty stagnant, however, if I decided to add a server farm, it's just a click, and we pay a little more.

How are customer service and support?

Technical support has been excellent. We haven't had a customer service issue; I have had a few tickets to ask questions, and they have been all handled with high urgency, even if they are not.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

I did not previously use a different solution. I had been asking management and had a budget line item for security services for three years. My request was finally approved.

How was the initial setup?

The setup is straightforward. The documentation was detailed, and the implementation team was available to explain and assist.

What about the implementation team?

The implementation was done with the assistance of a vendor team. I was a bit sad when I was notified that I would be moving from the implementation to the account management team. However, every person I have worked with has been wonderful. 

What was our ROI?

We've witnessed an ROI after three years on software and five on hardware.

What's my experience with pricing, setup cost, and licensing?

The setup was not hard. The implementation was very straightforward, and the team was knowledgeable and easy to work with. Compared to other vendors, licensing was a dream. The cost comes down to what people think their protection is worth. I have no qualms about approving AWN invoices for payment.

Which other solutions did I evaluate?

I did evaluate Sophos, Red Canary, Crowdstrike, and several others that only included monitoring without any security services.

What other advice do I have?

I will be required to obtain additional quotes when our term is up. That said,  unless there is a sleeper that will be coming up in the field, I intend to negotiate a renewal.

Which deployment model are you using for this solution?

On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Service Security Analyst at a government with 11-50 employees
Real User
Top 20
Provides visibility into the environment, responds to threats quickly, and the documentation is pretty good
Pros and Cons
  • "The agents give pretty good visibility into what is happening at the endpoint."
  • "It will be helpful if the dashboard is more granular."

What is our primary use case?

The solution helps monitor our endpoints and network traffic. It alerts us whenever something's going down. It has been pretty helpful.

How has it helped my organization?

The product helps with visibility.

What is most valuable?

The agents that are installed help detect threats. The agents give pretty good visibility into what is happening at the endpoint. The response to threats is pretty quick. Depending on the severity, the team sends an email or gives us a direct call. The weekly and monthly reports through the dashboard are helpful.

What needs improvement?

It will be helpful if the dashboard is more granular. The vendor must allow us to see what they see on their end.

For how long have I used the solution?

I have been using the solution for three months.

What do I think about the stability of the solution?

I rate the tool’s stability a nine out of ten. The product hasn’t gone down since we have had it.

What do I think about the scalability of the solution?

We have around 1000 users.

How are customer service and support?

We have 24/7 support. It’s like an extension of the department. The technical support is pretty helpful. Someone's always there to help us.

How would you rate customer service and support?

Positive

How was the initial setup?

The initial setup is pretty straightforward. The documentation is pretty good. I rate the ease of setup an eight out of ten. It is a SaaS solution. Two network engineers can deploy the product. We have network engineers and analysts on our team. We make sure the agents are not degraded. Most of the maintenance is done by the vendor.

What's my experience with pricing, setup cost, and licensing?

The pricing is pretty competitive.

What other advice do I have?

I will recommend the solution to others. It provides more visibility into the environment. If the staff is pretty short-handed, it helps out. Overall, I rate the product a nine out of ten.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
Flag as inappropriate
PeerSpot user
Director, IT Systems and Security at Union Mutual Fire Insurance Company
User
Top 20
Great support, detailed reports, and excellent real-time monitoring
Pros and Cons
  • "This service makes answering audits much easier since it covers so many security best practices."
  • "I would actually be interested in having fewer features at a lower price."

What is our primary use case?

Having Arctic Wolf sensors and the stand-alone traffic-mirroring appliance within our network provides secure copies of critical logs as well as rapid analysis and response when there is unusual behavior within our network. 

This service is our primary anomaly detection tool. In concert with our endpoint security and our frequent vulnerability scans, Arctic Wolf provides an active review of threat signatures and unexpected events that allows our operations and security team to sleep better at night. 

How has it helped my organization?

This service makes answering audits much easier since it covers so many security best practices. Therefore, any of the popular frameworks are covered by this managed detection and response service.

The real-time monitoring is very real-time. We usually get an alert from Arctic Wolf just as someone on our team says 'oops, I locked my admin account' or 'I just created the new admin account on our device'.

The customer service is excellent. They offer very quick responses to active tickets, and we get great responses from the account reps as well. In a world with thousands of startup security vendors offering various flavors of 'AI-enhanced' snake oil, Arctic Wolf provides an obvious security service well. 

What is most valuable?

The quarterly reviews provide an excellent cadence to help organize our security priorities and help set thresholds to improve our signal/noise ratio, as well as provide a quick overview of the entire threat landscape to our full team. 

The default emailed reports are great for building our audit defense and helping us to meet the requirements of both state and independent auditors. 

The ticketing system is adequate, although the formatting of the auto-generated ticket emails could be updated to a more modern and cleaner style. 

What needs improvement?

This product is very feature-rich. I would actually be interested in having fewer features at a lower price. The problem is that the active responses require a high level of technical staffing and I expect it's hard to scale that down.

I am also interested in the new features which allow the customer access to the raw log repositories and the analysis tools provided by AW, however, I cannot justify the expense or time of adding those features at this time. Overall it is a very appropriately sized product that does not try to do everything. 

For how long have I used the solution?

My company has been using this for several years. However, I have only been here using it for one year. 

What do I think about the stability of the solution?

The solution is very stable. 

What do I think about the scalability of the solution?

It's great for a company our size (~100 employees in total, some on-site IT services, and ~5 network/systems/helpdesk staff). 

How are customer service and support?

Customer support and service are basically what you are paying for. The technical pieces of the solution are great, however, the ticket response and the quarterly reviews are where the real value is. 

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

I am not sure if something was used previously as I've only been in this role with this company for one year. 

How was the initial setup?

I wasn't part of the setup. The maintenance and reconfiguration (from in-line to mirrored traffic capture of the hardware device) have been simple and well-supported. 

What was our ROI?

We would require around 0.75 technical FTE to do the work of this solution, which we could not do for the price. 

What's my experience with pricing, setup cost, and licensing?

In general, it's worth it. If you have any regulatory compliance requirements or other external requirements on your information security approach and you do not have a massive internal team to handle log analysis and similar tasks, this is a great solution. 

Which other solutions did I evaluate?

I did not choose this solution. I came into the company and this product was already here. I will say that I have removed a number of products from our vendor list during my first year, and have not considered removing Arctic Wolf - despite it being one of our costlier contracts. 

Which deployment model are you using for this solution?

Private Cloud
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Senior IT Analyst at a insurance company with 51-200 employees
Real User
Top 5
Provides 24/7 monitoring of all the traffic through our firewall and gives us detailed information about threats
Pros and Cons
  • "Arctic Wolf is our eyes and ears 24/7 because we can't possibly watch all of our alerts. We may see all of these alerts, but our attention is distracted because we're working on other things."
  • "We get a lot of false alarms, but that's because they don't know our network in detail. I think that could be alleviated if we told them more about our network so they could create rules to skip some of those things."

What is our primary use case?

Arctic Wolf monitors all of the traffic through our firewall. It monitors events on each computer in our network using agents. We have detection and as many inputs as we can get, including inputs from our Sophos antivirus and from our duo two-factor authentication. They ingest and process all of those events. If anything looks like it might be a problem, they generate a ticket and we get an email.

We take a look at the ticket and tell them whether it's expected or unexpected, and whether we think it's serious. They also scan our network for critical updates that are missing on the exchange server and issue detailed instructions on how to get the patch and how to execute a workaround if necessary. Arctic Wolf gives very detailed information when they think there's a challenging threat.

What is most valuable?

Arctic Wolf is our eyes and ears 24/7 because we can't possibly watch all of our alerts. We may see all of these alerts, but our attention is distracted because we're working on other things. We're only working certain hours of the day, and we don't have the staff to look at alerts 24/7.

What needs improvement?

We get a lot of false alarms, but that's because they don't know our network in detail. I think that could be alleviated if we told them more about our network so they could create rules to skip some of those things. For instance, we've had alerts that people are coming onto the VPN from outside of Canada. If we told them that someone is going outside of Canada ahead of time, then they wouldn't alert us about it.

Our internal alerting systems generate 10 times as many false alerts, so they're actually doing pretty well.

What do I think about the stability of the solution?

It's very stable.

How was the initial setup?

There are a couple of appliances that need to be used. It's somewhat challenging to set up because you need a special configuration in the network switches, which the firewalls are connected to.

What other advice do I have?

I would rate this solution as nine out of ten. 

It's a good product. It covers us 24/7. It doesn't have nearly as many false alarms as our own internal alerting systems because they're weeding a lot of things out. There's a lot of proactive help if something important needs to be updated or if  there are workarounds that need to be applied.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Senior IT Analyst at a insurance company with 51-200 employees
Real User
Top 5
Alerts and points exactly to where we need to go, gives good prescriptive guidance, and allows customization of alerts based on your requirements
Pros and Cons
  • "Whenever there is a major thing like Exchange vulnerabilities, it scans our Exchange server for indicators of compromise. It then alerts us and points exactly where we need to go to check for ourselves if it is normal or not."
  • "They focus on detecting administrator-level control compromises. Because they're focusing more on administrator-level compromise, they are less able to see if an individual user has been compromised. It is, admittedly, very difficult because they don't know what normal human behavior is. If a hacker compromises a human account and then acts just like the human, how are you ever going to notice, unless you have some inside knowledge of how the company works? For example, they overlook account lockouts on user accounts, whereas in our own alerting system, we do not. We review every account lockout, and if it is bad, we contact the person, whereas they think of that as noise because they're more focused on the administrator-level compromise."

What is our primary use case?

We are basically using it to catch things that we are missing in terms of alerts and other things. We are also using it to provide 24x7 coverage, which we just can't do.

It has sensors that are on-prem, but the data is kept in the cloud. All the alerting and consoles are also in the cloud, but it obviously needs to see our infrastructure in order to see anything that is going on.

How has it helped my organization?

It has provided just a little bit more peace of mind in terms of not having to be constantly on our toes and wondering if something is going on while we're trying to enjoy our weekends.

It gives us prescriptive guidance regarding how exactly to install the updates, etc. It doesn't do it for you, but it gives you good heads up and collects good information to let you hit the ground running instead of having to do the research yourself and maybe miss things.

We have also subscribed to an additional feature that they offer for vulnerability management and risk management. It a little bit outside of the SOC. They scan daily for vulnerabilities, and they perform them by using agents. They scan for vulnerabilities on a daily, weekly, or monthly basis based on your preference. They also do a brute force scan of all your equipment, acting like a hacker with a scanner, and then in the risk management console, they list all of your current vulnerabilities that have been detected and what level of risk they present. You can kind of attack the high-level ones first and work your way down. It gives you kind of an action plan. It gives you a place in the console to manage it. This is an additional module that isn't part of the primary Arctic Wolf SOC. It is Arctic Wolf's risk management. It has the same agents and same equipment, but it is an additional feature.

What is most valuable?

Whenever there is a major thing like Exchange vulnerabilities, it scans our Exchange server for indicators of compromise. It then alerts us and points exactly where we need to go to check for ourselves if it is normal or not.

What needs improvement?

They focus on detecting administrator-level control compromises. Because they're focusing more on administrator-level compromise, they are less able to see if an individual user has been compromised. It is, admittedly, very difficult because they don't know what normal human behavior is. If a hacker compromises a human account and then acts just like the human, how are you ever going to notice, unless you have some inside knowledge of how the company works? For example, they overlook account lockouts on user accounts, whereas in our own alerting system, we do not. We review every account lockout, and if it is bad, we contact the person, whereas they think of that as noise because they're more focused on the administrator-level compromise. This is not their fault. I'm sure this is common with all SOCs. They can't look at everything, so they look at the important stuff.

For how long have I used the solution?

I have been using this solution since February. It has just been a few months.

What do I think about the stability of the solution?

Its stability is good.

What do I think about the scalability of the solution?

It is scalable. If you have particular things that you want them to watch, they'll basically accept an unlimited amount of these additional alerts. If you say, "This should never happen on my network.", they will detect it and tell you whenever it happens. They allow you to customize the kinds of alerts. Something normally might not have been on their radar, but we know that this should never happen. So, for us, that's a definite indicator that an intruder is inside. So, we tell them, "Look at this. Alert us, and call us in the middle of the night if you see this because it is something bad. It may happen all the time in other networks, but it won't happen here."

How are customer service and technical support?

Their support is good. If you have questions, you can call them or submit a ticket. They're good to work with. They phoned us about the Exchange vulnerability to walk us through that.

Which solution did I use previously and why did I switch?

We hadn't used anything before.

How was the initial setup?

Its initial setup is fairly straightforward. They put in a couple of appliances, and we have to tie them to our firewall. That's the tricky part. 

If you're monitoring network traffic going out through the firewall, then you would have to tap into the firewall traffic. Some do this, and some don't. Some only have agents, and some have historically been traffic-only. Nowadays, most companies are trying to do both, but some still focus mostly on traffic, and some still focus mostly on agents. I'm sure some focus mostly on just detecting indicators of compromise that they're aware of. They are only looking for those. They are not looking at traffic or agents. So, there're many ways to skin the cat, and different companies are taking or have gotten really good at different approaches. Arctic Wolf's approach is primarily traffic-based, agent-based alerting, and a little bit of indicators compromise.

In terms of duration, if you had all your ducks in a row, it would take a week to wrestle the firewall resources, move cables around, etc.

In terms of maintenance, it doesn't take too much maintenance. The SOC is basically very low maintenance. When they alert you, they need someone to talk to who has administrator access and can deal with the problem. They'll help you deal with the problem, but they don't deal with it for you. They still need on-the-ground company staff to actually take the actions needed to shut down a breach. Normally, we don't have to do much unless they indicate that there has been a compromise, which is fairly rare. It is kind of an all-or-nothing thing. You either have it, or you don't. We may fine-tune it, but it is just there in the background almost invisible, and then they tell you if there is a problem.

What about the implementation team?

We had a consultant for the firewall configuration and the switch configuration. Our experience with them was fine. They manage our Cisco switches and firewalls. They were good.

What was our ROI?

It is difficult to know. If they managed to stop a major breach that we evaluate as really bad, they might have saved us $4 million, but there is no way to know. Did we prevent something from happening because we were on our toes or because they have a good risk management solution that helped us figure out the vulnerability and be proactive and avoid it altogether? It is hard to know whether they prevented something or not. It is like insurance.

What other advice do I have?

I would rate Arctic Wolf AWN CyberSOC a nine out of ten.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Network Security Administrator at a non-profit with 51-200 employees
Real User
A 10 out of 10 because they prevented a couple of attacks and alerted us when there was a big vulnerability
Pros and Cons
  • "The integration between Cisco AMPs and the Windows servers is most valuable. So, they can also sandbox machines on which they see something suspicious."
  • "They could probably expand on their integration tools. They can integrate with more security tools."

What is our primary use case?

It is for 24-hour monitoring of the network. We have risk management and detection.

Its deployment is hybrid. They have their sensors here. We install it ourselves, and they help us along.

How has it helped my organization?

They prevented a couple of attacks and alerted us when there was a big vulnerability.

What is most valuable?

The integration between Cisco AMPs and the Windows servers is most valuable. So, they can also sandbox machines on which they see something suspicious.

What needs improvement?

They could probably expand on their integration tools. They can integrate with more security tools.

They can expand their Linux flavors. I believe they only have Ubuntu and one more flavor.

For how long have I used the solution?

We've had Arctic Wolf for a little bit over a year.

What do I think about the stability of the solution?

It is stable.

What do I think about the scalability of the solution?

It is scalable. It gets used almost every day. We have only four admins who actually log into the portal to check the network and information. Each one is assigned and looks at a certain aspect of the network.

How are customer service and support?

Their support is good. They have 24-hour support, and they're always a call away.

Which solution did I use previously and why did I switch?

This is the first MDR solution we are using.

How was the initial setup?

It was straightforward. The initial deployment took about a month, and then getting the Arctic Wolf clients literally for 600 devices took about three months.

What about the implementation team?

We installed it ourselves, and they helped us along. You don't need many people for its deployment. You don't need to do a lot of work to deploy the software, but you do need money to implement it.

For its maintenance, you don't need many people. One person should be enough. We're an organization with more than a thousand devices. We have one technician or engineer who looks into how to deploy the patches in the quickest way.

What's my experience with pricing, setup cost, and licensing?

It is more expensive than CrowdStrike, but it also has more features. I don't remember the amount, but I do remember that it was on the higher side. 

I believe we have five sensors, and the sensors have a yearly cost. We don't have any additional costs, but I know that if we have more features, they will add to the cost.

Which other solutions did I evaluate?

We evaluated CrowdStrike, and we also evaluated a Cisco product. 

What other advice do I have?

It is a straightforward solution. It is not complicated. Its deployment is also straightforward.

I would rate it a 10 out of 10. They alerted us when there was a big vulnerability, so we're happy with their solution.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Buyer's Guide
Download our free Arctic Wolf Managed Detection and Response Report and get advice and tips from experienced pros sharing their opinions.
Updated: June 2024
Buyer's Guide
Download our free Arctic Wolf Managed Detection and Response Report and get advice and tips from experienced pros sharing their opinions.