SES MDR POC : Frequently Asked Questions (FAQs)

Description

Description

We offer (but don’t mandate) a twenty-one day Proof of Concept (PoC) to all of our prospect partners. The PoC is to evaluate the products.

What is the goal of the PoC?

The goal of the PoC is to evaluate products/tools that are used in this offering.

What is the timeline of the PoC?

A PoC is typically broken down into three phases over a 3-week period. Depending on the situation, multiple phases can be accomplished within one meeting, or a single phase can map to one meeting.

  • Phase 1 / Day 1 - Kick off Meeting
    • Introductions
    • Confirm Access to Account and Documentation
    • Review deployment process
    • SonicSentry team implements initial Detection/Learning phase policy
    • Review list of pre-approved applications from partner
  • Phase 1 / Week 1- Learning Phase
    • Endpoint Installs
  • Phase 2 / Week 2 - Threat Baseline
    • SonicSentry team reviews alerts that have been identified as a potential threat
    • SonicSentry team provides a breakdown of alerted items and the Excluded/Blocked status
    • Partner responds to breakdown with approval or needed changes
    • Partner uninstalls prior Anti-virus if still installed
    • SonicSentry team modifies/enables Protection Phase
  • Phase 3 / Week 3 - Follow-Up
    • Review current implementation
    • Confirm protected status
    • Additional Questions as needed

Are SOC services included in the PoC?

Yes. We have now enabled SOC services during the PoC process.

Please Note:

  • If a compromise is identified during the PoC, the Proof of Concept will end
    • The partner will have to decide whether to immediately convert the offering into production or cancel the services
    • This PoC is not meant for or an alternative to an Incident Response event
What if I don’t complete every step of PoC process?

We understand that unforeseen circumstances might arise during your PoC that might prevent you from focusing on/evaluating every feature. In many circumstances, PoC’s only progress to the 'baseline' process due to lack of time/availability of the evaluator. Unfortunately, we can only extend the PoC past the 21 days if there are technical issues that are related specifically to the product. We ask that all potential partners make the best effort to progress the PoC as far as possible to have a full evaluation of the products. The benefit to our offering model, is that a partner may proceed to evaluate the offering on a consumption based & month to month offering in a live offering until they have had enough time to decide if this is the right solution for their business.

What are the Deliverables from SonicSentry Services?
  • Architecture setup and configuration
    • Provisioning and staging of initial recommend policies and templates
    • Syslog/SIEM settings provisioning within the SIEM/SOAR platform
  • Training and Support
    • Provide training, support, and documentation as outlined per offering details
  • Security Operations Center (SOC) services
What are the responsibilities of the partner?
  • Management of the deployment process
    • Deployment of the Agents
  • Maintaining polices and exclusions
  • Communicating to SonicSentry team for removal of duplicate or retired machines
  • Providing Tier 1 support to your users
  • Contacting SonicSentry for any Tier 2 or Tier 3 issues that you are unable to resolve
  • Further investigate alerts sent from the SonicSentry SOC
How do I move forward after the PoC?
  • Support team sends a Wrap-Up email at the end of the PoC indicating that the PoC has ended and if any action is needed on your part to convert to Production and live Billing
    • Support team confirms the following has been setup and configured properly:
      • Preferred Contact info
        • General Contact
        • Audit Report
        • SOC Alerts
        • Emergency Contact Information
      • SOC services
What if I decide not to move forward?

While we hope everyone sees the value of the offering and tools we are using, there are times where it does not meet the requirements of some organizations. If a partner opts to not move forward after the PoC, the following actions will be taken before the PoC end date:

  • SonicSentry Actions:
    • Apply a policy that allows the removal of the agents
    • Push uninstall of the SES MDR agents
    • Removal of login access to the PoC account
    • Decommission Account/Management portal
      • This will not prevent a manual uninstall

Related Articles

  • SonicWall Endpoint Security (SES) MDR : Frequently Asked Questions (FAQs)
    Read More
  • MSS Managed Firewall Best Practice Configuration
    Read More
  • Cysurance - SonicWall Configuration Guide
    Read More
not finding your answers?