sb-eu logo
Story image

Sophos acquires Rook Security to provide managed detection and response

12 Jun 2019

Network and endpoint security company Sophos announced that it has acquired managed detection and response (MDR) services provider Rook Security. 

Rook Security provides a 24/7 team of cyberthreat hunters and incident response experts who monitor, hunt for, analyse and respond to security incidents for businesses of all sizes. The privately-owned company was founded in 2008 and is headquartered in Indianapolis.

Sophos is creating re-sellable MDR services by combining Rook Security’s threat detection, investigation and response capabilities with its recently acquired DarkBytes technology platform.

As a channel-first security provider, Sophos will deliver the new MDR services through its network of approximately 47,000 channel partners worldwide.

“Cybercriminals are relentlessly trying to exploit organisations with techniques ranging from tried-and-true phishing emails to the more recent trend of ‘hacker pen-testing’ to find weaknesses in their surface area.

“As a result, businesses need 24/7 monitoring and management of what is happening on their network, yet many of them do not have the expertise, can’t keep up or don’t have the security teams in-house to optimally configure and manage security around-the-clock,” says Sophos chief technology officer Joe Levy.

“With MDR, Sophos’ channel partners will be able to provide businesses of all sizes with services that continuously detect, hunt for and respond to security incidents.”

In addition, Sophos plans to align its synchronised security technology and product portfolio with Rook Security’s 24/7 services for MDR customers. 

Rook Security experts will also be able to review these customer security postures to ensure optimal policy configurations for Sophos products across estates.

“Rook Security provides managed detection and response services to detect and eliminate cyber threats. Through threat hunting and data analytics, Rook Security’s experts rapidly detect and mitigate active attacks,” says Rook Security founder and CEO JJ Thompson.

“We are excited to bring our experts and service delivery innovation to Sophos.

“Together, we can implement faster, more effective threat detection and response capabilities to better protect businesses.”
Sophos is releasing no further details at this time.

Earlier this year, Sophos announced its Intercept X for Server with Endpoint Detection and Response (EDR) offering.

The product aims to allow users to proactively detect stealthy attacks, better understand the impact of a security incident and quickly visualise the full attack history.  

“When adversaries break into a network, they head straight for the server. Unfortunately, the mission-critical nature of servers restrains many organisations from making changes, often significantly delaying patch deployment,” Sophos chief product officer Dan Schiappa said.

“Cybercriminals are counting on this window of opportunity. If organisations do fall victim to an attack, they need to know the full context of what devices and servers were hit in order to improve security as well as answer questions based on stricter regulatory laws,” he added.

Story image
Palo Alto Networks advances attack surface management with Expanse
"By integrating Expanse's attack surface management capabilities into Cortex after closing, we will be able to offer the first solution that combines the outside view of an organisation's attack surface with an inside view to proactively address all security threats."More
Story image
Cybersecurity strategies must involve every part of the organisation - study
In the past year, a third of the breaches incorporated social engineering techniques and the cost of a breach caused by a human error averaged to $3.33 million. More
Story image
Kaseya announces unified RMM solution
The new unified remote monitoring and management solution is a major component of Kaseya VSA.More
Story image
Huawei: Corporates must focus on data minimisation and business continuity to mitigate data security challenges
"From a long-term sustainable point of view, organisations will need to adopt data minimisation and privacy by design and default."More
Link image
The optimal solution for strong customer authentication
Strong authentication is not only good practice, it is also increasingly becoming a regulated standard. Here's why robust solutions, like True Passwordless Authentication, are the way of the future.More
Story image
APAC secure content management market to hit $2.2 billion by 2024
The proliferation of cloud-based deployments will largely drive this, the report says, as the COVID-19 pandemic motivates more enterprises to move their workloads to the cloud and rely more on the internet. More