Video: Announcing Sophos Advisory Services | Duration: 3348s | Summary: Announcing Sophos Advisory Services | Chapters: Introducing Advisory Services (2.96s), Introducing Advisory Services (106.635s), Explaining Advisory Services (316.735s), Security Assessment Services (919.68s), Internal Penetration Testing (1391.965s), Detailed Report Overview (2095.455s), Expanding Advisory Services (2285.715s), Sophos Advisory Services (2542.515s), Exploiting Discovered Vulnerabilities (3021.2s), Security Posture Assessment (3094.855s), Conclusion and Q&A (3190.895s)
Transcript for "Announcing Sophos Advisory Services":
Good morning. Good afternoon, everyone, depending on where you are joining us from. My name is Anna Becker. I'm the director of EMEA channel marketing, and I welcome you to our very special launch session on announcing Sophos advisory services. As our partners, you probably know that, especially in this quarter, we have a lot of amazing news for you as our partners on new solutions, new services that we are launching. And today is exactly one of those sessions where we would like to give you all the details about, our newly launched set of services, namely advisory services. And today, I am accompanied by, my two great colleagues, namely Bart Ellis, who is the senior product marketing manager, who will be presenting to us today and, showing you all the details about the new services set. And we have Paul Renouf with us, the director of penetration testing, Sophos team Red, who will be answering your questions in the chat while Bart is presenting. And then we'll have a quick q and a session, and Paul will also come, on stage to us to, run through the frequently asked questions that you might have. Speaking of which, please ask all your questions in the q and a section that you can see on your screens. We will be answering them during the presentation, and then afterwards, we'll pick up some live ones. We are recording the session, and you will receive the recording and the slides with a follow-up email afterwards. And with this, I am happy to hand over to Bud, please. Alright. Thank you very much, Anna. Hello again, everybody. My name is Bud Ellis. I came over from SecureWorks as part of the acquisition back in February. It's been a very busy nine months as I'm sure you know from the amount of, initiatives that we have rolled out to the market. But I greatly appreciate you taking some time today to, dive in a little bit to Sophos advisory services. And let me just start by giving you guys a little bit of background. Right? So I'm actually doing this from the old SecureWorks office here on the North Side Of Atlanta, Georgia, my hometown. And I got to SecureWorks in 2009, and I built and I ran our RFP response team for a little over seven years. Right? And the very first week I was here, the first RFP that I worked on was a penetration testing RFP, and we won it. We won it. And probably six months, eight months later, early two thousand and ten, the sales rep comes to me and says, hey, bud. Remember that RFP you did? And I said, yeah. I'll never forget it. It's the first RFP I've ever done in in my life. He and we want it. He said, well, here's a managed security services RFP from the same customer. They were so impressed with the job that the SecureWorks consultants did in performing this penetration test that it's the proverbial, hey. This was great. What else do you have to offer? Right? I cannot tell you the number of times that scenario was repeated on the SecureWorks side in my fifteen plus years there. Right? Advisory services are a tremendous way to introduce your customers to not just proactive security, not just assessing where their weak spots may be, not just emphasizing the, you know, ways to elevate their resiliency, but expanding your book of business, expanding your footprint in a customer. We're gonna spend the next twenty, twenty five minutes or so kinda talking about that. So let's go over to the next slide, and I appreciate you guys indulging me with a little, little trip down memory lane. But what we're going to do today is I'm gonna talk about why advisory services matter, why are service offerings like this important for the organizations that you serve. And a lot of times, you know yeah. Sure. It's tied to industry and compliance regulations and so forth. We get all that. But I'm telling you, a lot of times, it is no matter your size, no matter your industry, no matter your geography, no matter how long you've been in business or not, if you're in an organization, you need to assess where where your weak spots are secured, you know, from a security perspective. So we're gonna talk about the services that we've rolled out so far. Spoiler alert, there's more to come. So, it's a very busy time, obviously, here at, at Sophos, and that's a great thing. We're gonna talk a little bit about the services, how they're delivered, kinda what what we're looking for when we when we perform these types of engagements, and then talk a little bit about, you know, how to position and how to talk about these with your customers. So let's dive in here. Our first section is explaining advisory services. And before we get into what services are now available and how do they work and why do they matter, I think it's important to kinda set that baseline for what advisory services are. I mean, it's possible that, you know, some of the organizations that you work with haven't purchased these types of offerings in the past or maybe look at them as just a, oh, that's something I have to do, and it's just a pass, fail, check the box. It's it's not really that important. And, honestly, they are important. Right? So let's look at this. So what is security testing? Security testing at its essence is designed to find the weak spots, find the vulnerabilities and the flaws in an organization's security program. A security program's built to obviously keep the organization secure, protect data devices, IP, integrity, so on and so forth. Right? If you're in charge of securing an organization, you gotta fill gaps. You gotta fill gaps in that security posture, but you can't fill a gap if you don't know that gap exists. Right? So we talk about using security testing as a mechanism in which an organization's leadership can go in and walk out of that engagement saying, okay. Here are the areas that we're doing really well from a security perspective, and here are the areas where we really have got the focus. And it's a great way for security leaders to be able to take those results, go up the chain, and say, hey. We've got an independent assessment. These are three areas that we need to shore up. It's a way for them to fight for budget. It's a way for them to prioritize. Security testing unlocks a lot of things for an organization. But and and with that said, of course, there's a ton of security testing out there because, you know, everybody, you know, sees a need for this. But for all the emphasis on technology and the power of what that technology can do, strong and impactful security testing at its heart really comes back to the people who are performing the test. There's a lot of vendors out there who don't put a whole lot into the security testing that they deliver. It's basically very, very quick, easy, you know, run a script, pass, fail, check the box, rinse, and repeat. Right? But the impactful security testing really leans on the expertise of people, and your best security testing organizations at the heart of of their organization has people who are world class, that have performed thousands upon thousands of engagements that have seen everything that there is to see out there, and is ready for what's coming next because also important is the infusion of impactful threat intelligence. Right? Current threat intelligence, emerging threat intelligence, insights from threat hunting activities, and incident response engagements. Those real world learnings combined with a high level of expertise from the people is what sets security testing services apart. And that's what we believe we have here at Sophos, and we'll talk a little more about that as we go. But, basically, these services help organizations to gauge their ability to discover threats and respond to them if those threats are present in their environment. It also helps them get that fundamental understanding of where they're at from a security posture perspective and where their weak spots are. Obviously, the compliance is part of it as well. Meet NCSEA compliance regulations. And, honestly, as cyber insurance continues to become more and more important, if you're an organization looking for good coverage and good rates, it's really helpful to have had these types of assessments done where you can go to your cyber insurer event or these organizations can go to their cyber insurer vendor and say, hey. I've assessed my environment. I've had these types of tests performed. Here's things that I've done after these tests to elevate my resilience and fortify my posture. Right? So we talk about what these are. Why why do why do organizations buy advisory services? You know, there there's a handful of things that happen that, you know, make it wanna do this kinda quickly. You know, if there's a security incident or a breach, if there's a new CSO who comes in and wants to understand what the security posture of the organization looks like or if there's a leadership change, if there's merger and acquisition activity, a lot of times, pre deal due diligence and or post acquisition integration, the organization wants to run tests like this to buy tests like this to see where the the new technology and where the new organization stands. And then, of course, you know, thinking about annual budgets and planning cycles, these are more the annual and quarterly, you know you know, buying things, compliance deadlines, audit deadlines, or, you know, if there's a big board or executive review. So there's a need for these types of services, and there are a lot of things that are spurring security leaders to go out and try to find these services. And now, lo and behold, Sophos has these services. So, basically, what advisory services, at Sophos is, it's us evaluating an organization's security program, their policies, their controls, their posture through the eyes of an adversary, the way a threat actor would look at that organization. How would that adversary assess that organization's security program, their weak spots, their vulnerabilities? And how would they try to exploit those shortcomings? Right? So our services provide that expert independent guidance, and that guidance that has been shaped through years and years of performing these types of tests. And the the high level of skill of the testers and the infusion of the threat intelligence from Sophos ex ops. And, of course, SecureWorks Counter Threat Unit is now part of Sophos ex ops. So weaving all of that together to help identify where are those spots in an organization's environment that need to be addressed to be shored up, to strengthen those defenses, and to elevate and enhance that organization's resiliency. And listen. It's not just some dude sitting in an empty office in Atlanta talking about this this morning. Right? Advisory services are a critical element of organizations having a proactive security approach, and and the market and the research tells us that. Right? So this first stat here, more than 90% of those who responded to a Gartner survey say that when they're establishing a strategic security architecture, they're looking for these types of services to help shape what that architecture needs to look like from the security perspective. Our state of the ransomware report that came out just a few months ago, we found almost two thirds of organizations have cited a security gap, either a gap that they knew existed and they weren't able to do anything about or a gap that they just didn't know about. Citing those things as a reason that their company was exposed to a ransomware attack. And I don't have to sit here and tell anybody on this call that if your organization said we're ransomware, it's probably one of, if not the worst day of your career. Right? Also, in that state of ransomware report, we discovered more than half of organizations who did have that worst day ever, who did suffer a ransomware attack, cited either exposed vulnerabilities or compromised credentials as the technical root cause for being hit. And you don't have to dig very far into the the cybersecurity news, to see that these are two very common causes for ransomware attacks as well. Advisory services look for things like this, things that your average CISO security leader, if it's a smaller organization, the one person who's tasked with security on top of 10 other things they must do every day, These services are gonna look for the things that a lot of times companies miss. And companies missing them opens up the opportunity for threat actors to take advantage of that, and that's why there's such a big market for advisory services because organizations wanna do everything they can to avoid becoming a statistic or becoming a headline. So let's talk a little let's let's take an overview look now at the services that Sophos now offers. But there's one point that I wanna make before I dive into this section. I I want you to think about this as as we're going along. Right? I talked about how there is such a heavy concentration in the market of vendors who are providing these services. And it's like, okay. Well, great. Sophos does this. Now why is this different? Right? One of the ways that we stand out is because we partner with customers to really understand what their security goals are. Right? And we call it our goal based methodology, and that that at its essence, that's what it is. If we're doing a penetration test or web application security assessment for a customer, we are going to meet with that customer before the engagement begins, and we're gonna talk about their security life. What are their challenges? What are they doing well? What do they think they're not doing well? What do they not know about? Right? Part of security effective security testing is shining a light on things that otherwise have gone unnoticed. And what are the objectives? Why is this organization looking to do a particular type of test? What are their goals? What what are the drivers behind them looking for these services? Determining what's in scope, what's out of scope, right, and how the communication with that organization will transpire during the engagement. So this section, we've got kind of an overview slide that I'm gonna walk through in a little bit of detail. And then each of the services that we have, there's two slides. The one slide that I'll really focus on for each of the services is more of what it is, the value it provides, the questions that it helps answer, and the benefit. The second slide is a little more about the methodology and the process. I'll probably touch on a couple points on those slides just at a high level, but you'll get the deck after the, presentation. So, you can dive into that a little deeper if you wish. Okay. So let's talk about the services. And there's four services that we have come out of the gate with. Right? These are four services that were very successful for us on the SecureWorks side, and we are proud and honored to have those as part of the Sophos portfolio now as of October 1. So the first one is external penetration testing. And the way that I explain this to people who don't do what I do for a living or don't know anything about technology is think about an organization security program as the metaphorical four walls. Right? I know everything's remote now and all of that, but back back in the day, like, when I was coming down here every day in 2009, you have your your four walls, and it's taking a look at the gaps from the outside the way that a threat actor would. Right? So think about, you know, VPNs and websites and ways that the public interacts with an organization. And, you know, touching on my my years in the newspaper business covering sports way back in the day, you know, I I like to think about external penetration testing as a coach who's developing a game plan for, you know, a soccer match or a baseball game or whatever. Where are the weak spots, and how can we take advantage of of those to to defeat our opponent? Well, external penetration testing is like the threat actor standing outside those proverbial four walls thinking about a way that they can get into an organization's system and environment. Right? That to exploit a gap or an opening in, you know, an organization's security program, you know, a port that's left open, a vulnerability that hasn't been patched, something like that to for them to get access. So what can that attacker see from the outside, from the Internet? And does the organization have exposures that are unintentional or unknown? So we're gonna, you know, test public facing websites, you know, look for unpatched vulnerabilities, you know, old ports that are open, things like that. The internal penetration testing by its nature and by its name should be pretty easy to figure out. Right? So we're assuming that the threat actor has either gained access through one of those vulnerabilities or gaps that we talked about with the external net. The threat act we're assuming the threat actors either gained access or this is a threat that's emanating from inside the, quote, unquote, four walls. Right? So things on the internal network systems, apps, and data, you know, answering, you know, what could an what could a threat actor do if they got on the inside? Right? You know? They're not they're not kicking down the door trying to pick the lock. They're they're in your they're in your living room trying to get the TV and the furniture out. Right? And could we detect that type of activity on the inside? So testing how easy it would be to escalate privileges to, you know, pull out sensitive data and exfiltrate that. Wireless network pen testing obviously is very popular now because, you know, find me find me any place in the world that doesn't have Wi Fi. And, you know, the Wi Fi, it's not just, you know, internal Wi Fi for employees that are, you know, you know, logging in from wherever they're working from remotely or, in my case today, being actually in the physical office. But it's your visitors. It's your vendors. It's your suppliers. It's contractors. It it's all those people who are interacting with an organization and, you know, getting into you know, being able to have access to the Wi Fi. So the encryption protocols, the access controls, those are things that we're that we're looking at, the actual infrastructure of the Wi Fi network. And is that network secure? Are there ways that unauthorized or rogue devices can gain access? And then what can they do once those unauthorized connections have made it on to the Wi Fi network? What are they what are they able to accomplish? And then our final final of the four offerings that we've rolled out is our web application security assessment. Right? You think about the web, it's I like to tell people it's an organization's window to the world. Right? You know? That's that's how we connect as I point back at the windows behind me that are closed. You know? But in the in in the rush sometimes of of building out great compelling websites and writing awesome web content, sometimes the designing and code security takes a little bit of a back seat. Right? So we're looking for and threat actors know this as well. So we're looking for, you know, flaws in coding, authentication and session, you know, management issues, access control. How secure is that window to the world for that organization? Is there a way that someone could go through the web app and get sensitive data? Are there vulnerabilities there? Is that an access point that a threat actor can use to get in and cause havoc? So we're testing not just a website, but, you know, there's customer portals out there. There's, internal web act. It's ecommerce sites. A variety of ways that someone can interact with that company through a web based infrastructure, that's what we're testing for with the, web application security assessment. K? So let's go now into these slides. So external penetration testing. Right? So, again, we talked about that, you know, an attacker who's trying to breach the perimeter and get in from the outside. And we're focusing on those systems that are accessible from the outside. Why it's valuable is we're gonna take a look at vulnerabilities that are facing the Internet, unpatched software, unpatched vulnerabilities, weak login credentials. There's a value here because it not only proves the ROI of the methods that an organization has in place or shows the gaps that are avail the gaps that can be exploited. But it's also required by a lot of compliance frameworks. I won't read them all here. So it's also a great way if you have a security if an organization has a security solution in place to put that, you know, detect and, you know, monitor, detect, and respond cycle into a test. Right? You know, hey. Did our did our MDR solution pick up on this? Did our, you know, did our firewall technology denote this activity? Right? And it shows everybody in your organization and everyone who deals with your organization that you're actively trying to manage and lower your risk of being hit. So, again, what can attack or see an access from the Internet? Are there any unintentional exposures? Can our MSSP or our IT or security team detect this type of activity? What types of best practices do we have, and are they working or are they not? Organizations that conduct regular pen test experience about half fewer security incidents and about a 30% reduction in the overall cost of an incident if they are hit. So penetration testing is really important. These are structured engagements. We have execution steps that we follow. We also have manual analysis and testing. Remember, again, talking about the human element and how important it is. We'll talk about the reporting, and I'll also talk about remediation validation once we get down the road here just a little bit. And I realized I didn't skip the slide forward, so my apologies there. But, yeah, we'll talk about, we'll talk about what goes into the reporting, our reporting methodology and the way that we approach the reports, and then, remediation validation, which is a differentiator for us. But at the end of the day, we've got expert testers. They're using some of the most advanced tools in the industry, but that's also shaped by the real world experience that we have and that current and emerging threat intelligence from Sophos XOps to simulate a sophisticated attack. These are not just, you know, super simple tests that we're doing. We're really trying in all of these services to emulate what a threat actor would do, a real world threat actor would do targeting that organization. Okay. So internal pen test, again, this is, insider threat, someone who's maybe on the inside. Maybe it's a disgruntled employee, someone who's being let go, someone who's not happy, or it's someone who found their way into the environment, was able to breach the the four walls, if you will. And the design here is what would it be like and how easy would it be for that threat actor, that disgruntled person to escalate privileges, disrupt operations, take down critical components of of the business, escalate privileges, you know, get into places they're not supposed to get into. Again, pretty heavy compliance framework here. Test for that insider threat, and then identify those gaps in the in the monitoring, the detecting, and the responding cycle. What could an attacker do if they gained access? A lot of times, that opens up leadership's eyes to, wow. Well, if someone got in here and ran amok, we would be in a a lot of trouble, so we probably should short some things up. That's a very simplistic way of of of illustrating those are real world conversations that happen a lot of times after security testing. It's kinda that, come to realization moment for security leaders, that, yeah, we need to prioritize these steps moving forward to elevate our resiliency. 95% approximately are security breaches attributed to human error. Right? And a lot of sometimes these errors have ill intent, and sometimes these errors are just good people working really hard, really fast under a lot of pressure, and they make a mistake. Right? Port doesn't get closed. Vulnerability that shoulda gotten patched didn't get patched because there was something else that happened. This is why testing is so important and why your customers and the organizations that you work with really need to be interested in these types of solutions. So, again, you know, these these engagements are structured, but they're not structured in a way where they're so rigid. Right? And I talked a little bit about the goal based methodology of meeting with customers and figuring out kinda what their goals are and so forth. Again, detailed reporting and remediation validation, which we'll talk about here momentarily. Okay. Wireless network pen testing. Evaluating the wireless network, evaluating the the policies and the setup, making sure that, there's not there's not anyone connected who shouldn't be. I know the I know our red team has got some unbelievable stories around being able to get in through wireless networks and the havoc they've been able to cause in testing in the past. If you ever have a chance to be on a webinar with, you know, our consultants talking about war stories or if you see the videos that are on our YouTube page, You know? I mean, it's it's mind blowing. Right? It's a lot more interesting than listening to me. So, anyway, discovering those rogue access points, you know, seeing if there's misconfigurations that need to be cleaned up, testing how an organization responds to a malicious rogue connection or a rogue access point, being able to answer to leadership, you know, hey. You know, can can unauthorized users gain access to our network? And, you know, our wireless protections. How sound are they are they? Can they be bypassed? And what can we do to further elevate that, that security? One out of four wireless networks are considered highly vulnerable. So think about that. So if you go obviously, I won't name brand names here, but if you go into a coffee shop, you go into a restaurant, you go into a retail store, you go to a a ballpark or, you know, there there's four right there. Odds are one of those four, the network that you're connecting to, pretty vulnerable. So that emphasizes the importance of doing wireless network penetration testing. And then the final one that we have launched is web application security assessment. Again, broken access controls, security misconfigurations, application design. Again, that's one where, again, there's always the push to, let's get it out. Let's have it great. Let's get it going. And, again, I don't think this is as much the case as it used to be maybe ten, fifteen years ago because security is so prevalent. But at the same time, you know, deadlines are deadlines, and I think sometimes, you know, design and configurations and all that can the security of that might take a little bit of a back seat, and that can be an issue. So this test is designed to find that, those configuration and coat coding flaws. You know, there's compliance standards that this helps with. And it's an outsider's perspective as well as that kinda deep analysis of an organization's web application security. And, again, over six out of 10 of web applications exhibit at least one high or critical severity security vulnerability that's not listed in the OLAP's top 10. So, you know, you think about that from from the perspective of, you know, these top tens have been known for years, but there's more. And I think that's kinda out of sight, out of mind. Well, this test is designed to see if that's something that an organization has frozen or needs to worry about. Okay. So one note that I wanna make here, and you've seen it on a couple of the slides, the remediation validation box. And I need to go back and change the wireless network pen test slide, because it's not applicable to that. So that's a that's that's a miss on my part, so we'll get that updated. But for external pen test, internal pen test, and web app security assessment, we have remediation validation. So what we're gonna do is we're gonna go out, and we're gonna perform the test. And we're going to provide you a report of our findings, and I'll go through the mechanisms of the report in a second. But if there's high and critical findings, organizations have thirty days to inform us that they would like the opportunity to remediate those and then ninety days to actually remediate those. So fill those gaps, patch those vulnerabilities, fix those fix those issues, right, that we found. And then remediation validation, we'll go back in and take a look. It's not a complete total, you know, soup to nuts retest, but it's looking at those high and critical findings that the organization has said, wow. We've gotta do something about this right now. We did this. Can you come back and take a look at this, right, if we can do this within ninety days? So we're actually gonna come back. We're not again, this is not just, hey. Check the box. Thank you. Cut a check and move on to the next. There is a a very, very, strong desire to help your customers elevate their security posture. It and it's baked into the DNA of of everything we do at Sophos. It was that way at SecureWorks, which is why, you know, this integration for me has been amazing. But we wanna look and make sure that the customers properly remediated those things that we identified during the engagement. Right? And that's included at no additional cost. So when we think about those vendors who are just, you know, kinda throwing a a a technology only test out there that runs automatically, it's an automatic scan with no real context, no real threat intelligence, no human expertise. Those things certainly do not have, the opportunity for those experts to come back in and kinda check the work that an organization has done. So that's a pretty interesting differentiator as well. Now let's talk about report as I go to our slide here. Excuse me. So this is not check the box, spit it out. It's a template with you know, we'll change we'll change the customer's name. We'll change the date. We'll check the box. We'll hand it to them, tell them they passed, tell them they failed, and go on about our business. This is a complete detailed report. And, I mean, it is detailed to the point that there are sections in here that are segmented for different audiences. A lot of your c suite executives aren't gonna be able to dive into the nuts and bolts that your security team's going to dive into. Right? So we've got an executive summary for the c suite and the board members. We've got detailed findings for the technical staff. When the engagement is complete, we'll do this final report. We'll talk about our findings, what we found in detail with technical technical details and recommendations for improvement. We're gonna talk about how we put the test together. Right? Customers can trace every step that we took and whether or not every action we took was successful or not in this report. This report goes through multiple review stages before it's handed over to a customer, technical quality assurance, management review, detailed recommendations, links where an organization can go and further their knowledge, best practices, evidence of findings, and, you know, when possible, sufficient information so if the customer doesn't believe us, they can go and replicate the findings themselves. We have, and I'll talk about resources available to you here in a little bit, but we have sample reports that are available. And they're really powerful of showing an organization, you know, your customers who are like, well, okay. That's great. What do I get out of this? Well, here you go. Here's a example, a detailed example of the detailed report that you are going to get. And a lot of times, that leaves a really good impression. Okay. So let's talk about and I'll do this relatively quickly because, I do wanna leave time for questions. But this section kinda covers the aspects of the Sophos SecOps portfolio. And, of course, that portfolio has been very busy over the last few few weeks as well with some of the changes we made to, you know, the endpoint family and and adding other services besides advisory services. But, again, just kind of a reminder of how it, addresses kind of the full spectrum, right, of wherever an organization is at on their security journey, no matter their budget, no matter their understanding of the threat landscape, industry, geo, size, segment, whatever, that we have solutions that can help them fortify that security resilience. So, you know, wanting to improve incident response readiness, being ready if that you know, I don't like to say it's not a matter of if an organization's gonna get attacked. It's when. That's a little almost too much fear, uncertainty, doubt for me. I try to stay away from the FUD, but the reality is threats continue to increase. They continue to evolve in complexity. And, you know, you, you know, if you if you don't have a plan, then you have to plan at the last minute, and that's never a good thing. Right? So organizations who wanna improve their readiness. Adding advisory services provides a really impactful way with really robust options that emphasize the importance of proactive security and the impact that those measures can have on an organization's security posture and program. There are more advisory services releases planned across the next three to four quarters. We're continuing to take kind of those services that we offered as part of the SecureWorks portfolio through the years and integrate those into the Sophos family. So this is not gonna be advise Sophos advisory services is not gonna be limited to just these four services, and then that's it forevermore. Nope. There there's more coming, so stay tuned for that. And then, you know, other security services that kinda fit here include, you know, incident plan reviews, helping to develop incident response plans, and proactive manage vulnerability risk with, you know, our our managed risk offerings there. So we go to the next, next one here talking about, the twenty four seven threat monitoring investigation and incident response. Of course, Sophos is a leader in MDR, you know, well over 30,000 customers using MDR solutions that are based on either Sophos Central or the SecureWorks Tejas solutions that came over. Active active, efforts on integration continue every single day and night, so stay tuned for updates from that. I'm sure, you know, your cams and, you know, Sophos leadership will be providing lots of updates as we work to bring Sophos Central and Tejas together, and it's gonna be amazing when when we get there. And it's probably not gonna be super, super long since there's been a lot of work that's been done already. And then I mentioned identity threat detection and response, ITDR launching, back on the twenty first of last month. ITDR, for those of you who don't know, provides organizations faster visibility into identity risk and provides really strong robust protection against identity based attacks, which is one of the fastest growing threat vectors out there globally. Something I was involved with, the first Convergence of Sophos and SecureWorks offerings post acquisition back, in June was the Converge emergency incident response offering. So those organizations who, have experienced something or think they've experienced something maybe after the fact, and they need, experts to come in, eliminate active threats if there's an active threat, investigate something that happened, identify the root cause, monitor for reoccurrence. This service brings together the years of incident response from both the Sophos side and the SecureWorks side into a single hourly build offering, and it's available to any organization experiencing a live incident. Doesn't have to be a sofa an existing Sophos customer. And then our final slide here in this section is gonna be talking about, well, you know, we have emergency incident response. What about something that we already have in our pocket in case something happens? And that's a incident response, incident response retainer. We are working to converge the, incident response retainers from Sophos and SecureWorks into one offering in the not too distant future. So stay tuned for that as well. Okay. Let's go to who delivers these services, and I'll go through this relatively quickly. The team that delivers these services is commonly referred to as the Sophos red team, and it possesses vast experience from delivering testing and assessment services for years and years and are comprised of some of the top talent in the industry. I won't read everything on the slide here, but you can see very diverse background that gives us a real unique perspective that's not just security vendor focused. Right? You can see, you know, where we go to get, you know, the best of the best here in, delivering these tests. We've numerous accolades, DEFCON wireless capture the flag. We won it three years in a row, and then we literally were told, hey. You cannot participate in this anymore because you keep winning. We now help Defcon host that competition. And then, you know, our team our team composition, you know, is not just the 60 plus testers, but the hundreds of security analysts and the, you know, hundreds of threat intelligence team members and researchers from Sophos ex ops. Again, all those findings from Global Threat Intelligence, all those findings from threat hunting and incident response engagements all feeds into this view of the threat landscape that we're able to use in our, in our testing. And then, you know, just some of our global accreditations here. So let's go ahead and wrap this up because I did wanna leave time for questions. And, yes, somebody mentioned I forgot to turn Outlook off, and it bit me because I just got two emails, and y'all heard the emails come in. So my apologies for that. But, so let's talk just a little bit about how Sophos advisory services stand out. Right? So, we believe that, our team and its long track record of proven excellence, you know, stands out as as being a leader in this space and delivering these types of proactive tests. Our threat research and threat intelligence has an impact on that emerging threat knowledge and our understanding of the overall global threat landscape, which we're able to cascade into our testing methodology and what we're able to deliver to our customers. And, honestly, many testing and assessment services really don't have the depth of cross discipline security expertise that we have. We're able to tailor these tests to, our customers and and what they need for their business. And, again, that's that discussion of, you know, upfront, that goal based methodology of talking about, hey. What are you looking to accomplish here? Where are you struggling? Where do you think you're strong? And let's go prove that. Right? The customized reporting, again, that goes above and beyond what a lot of vendors are able to provide with that level of detail and not just a narrative detail of, hey. Here's let's dump a bunch of technical info in here. The technical info's in there, but it's done in a way where, again, an organization can basically walk behind us as if they shadowed us through every step of the test and, most importantly of all, kind of the so what. What does this mean? What can I do about this? Here's detailed recommendations. There's a remediation validation for those high and critical findings. The report in and of itself stands out. And then just positioning, positioning yourselves, you know, by using Sophos as a trusted adviser for your customers. Right? Beyond the initial assessment, again, there's a lot of things that we can provide for organizations, but I think you're going to find that there are a lot of your customers who are really interested in this because it addresses things that they know that they need to address. Maybe they haven't had the time to address it. And, certainly, you know, if you have a hurricane or a typhoon that's coming into your, your part of the coast, if you live on the coast, you wanna make sure that your roof's fortified before that storm hits. Right? It's better to do it on the front side than have to try to fix it on the backside. So what should you do next? We've got a ton of content on the partner portal. There's there's solution brief, solution brochure, FAQs, internal content, example emails, sample reports. There's there's a variety of things, customer facing slides that you can take and go introduce your customers to these solutions. Some of the slides will look familiar because they were in this presentation. Take a look at your customer base. Right? Think about your current customer list and those opportunities where maybe this is an entry point to have a conversation with a new customer. Or if it's an existing customer who you already have a relationship with, then you can have a conversation about, hey. This is something that that, you know, we can offer now through Sophos. And, you know, a lot of times, if it's an organization that is really takes security seriously and they really don't have a lot of needs, they're still gonna wanna do a penetration test once a year. Right? And maybe they've used a vendor and they wanna get a different perspective from a different vendor. Well, now Sophos can provide that. And then positioning advisory services. Right? So at the end of the day, we're looking to assess the risk of an organization being breached and impacted by an incident. It's an independent and proactive assessment of an organization's security controls to find those weak spots, to fortify their resiliency before a threat actor strikes, delivering expert security guidance on how to better secure a customer's environment, using that latest threat intelligence and the expertise of our people, the impactful research and findings that we do, weaving all of that together, bringing that perspective and putting a customer's, security posture into that lens, which is better than a threat actor getting the opportunity to do it first. And then finally, being able for the organization, your customers, to show their customers, their partners, their vendors, their cyber insurance provider, the security is a high priority for them. So this is another opportunity for us to work together to accomplish kind of the the end goal at the end of the day. We want we wanna sell. We wanna be successful. But above all else, we wanna be able to help organizations be better secure because that makes everything better. Alright. So q and a time. Paul, you wanna jump on stage with me here? I actually went longer than I thought, so, I apologize. I think we're gonna get links to the partner portal assets popped up here in a little bit. But, Paul, I've been going on. I know you've been answering some questions. So if you wanna take couple seconds to introduce yourself and say hi, and then, let's get into some q and a. Yeah. Thanks, Bart, and and good job on the presentation. So good to meet everyone. I've been with Sophos and SecureWorks now for just over, five years. I'm the director for red team services within EMEA. So basically looking after all aspects of delivery and customer satisfaction for our red team services in the region. Alright. Thanks a lot, Paul. Couple questions that kinda stand out here, as I look at, as I look at the q and a that we'll just touch on kinda kinda verbally here. So we got a question in. Are you trying to exploit vulnerabilities that you found during penetration tests? So so and I and I think that's an interesting point because this is not just kinda, you know, basic discovery of, hey. That might be an issue. Our experts are really looking to show customers what could happen if it was a threat actor doing this and not a Sophos red team member. Correct? Yeah. That that's kind of a key point. So we start a lot of our penetration tests with vulnerability scans, but we go a lot further than just providing those scan results to customers. So we we do see that some other vendors will call a a penetration test, a penetration test, but actually they're providing a vulnerability scan. What we will do is take that scan, and then look at the results, and try and exploit those as a real threat actor would. And and the reason that's important is sometimes our testers won't be looking at the ones that come up or automatically flagged as criticals and highs, they'll be looking further down that list as well and and know that this thing's down there as low informational findings that they can exploit and and gain access to a to a customer environment. Good stuff right there. Another another question, and and this is one that I've gotten, you know, when I go to trade shows and and all of that is you know? And, of course, we both came over from SecureWorks. But just from our perspective, you know, I think at the end of the day, everybody's in sales no matter their role. But how important is it to have capabilities and offerings like this to be able to go out and meet customers where they are in your security journey, especially customers who might not realize they need to go on a security journey because they haven't done a whole lot and they don't really know where they stand. Yeah. It's a good point. And we we consider ourselves of although we are part of Sophos and we're part of SecureWorks previously, we also consider ourselves independent as well within the organization. So there's no there's no backdoors we can use with if it's a if it's a Sophos MDR customer, we approach every customer as if it's, an a new experience to us and as if as any other threat actor would. So that can often obviously, after reports are read on the back of our engagements, that can give huge amounts of insight to that customer on where they are, in reality, in terms of their security posture and where they might wanna focus next. And that may lead to conversations with Sophos or that could lead to conversations with other vendors. That that's not our decision. We just provide the results and and give you that insight to your security posture. Right. Couple other questions that have come in. GA for EMEA, GA was October 1. I I. know that Sophos has thrown a lot at the partners in the last forty five to sixty days. But, yes, the these are available to sell right now. So you can go to the partner portal and get that information. You can reach out to your cams if you have questions. Let's say a couple others here maybe. Are these services only for Sophos customers? No. No. Not at all. You can sell these to net new customers. These are not limited to the these are not add ons to existing Sophos services or limited to the Sophos customer base. And, you know, Paul kinda touched on this a little bit. I touched on it in a little bit in nostalgic storytelling at the beginning, but I cannot tell you how many times I have seen something like a pen test or a web application assessment or another type of advisory services that eventually leads a customer to become a you know, to buy something, you know, that's more impactful like an MDR solution or, you know, some type of monitoring or some type of, you know, you know, device management solution, some type of security product. And, again, to Paul's point, it may not be with us. It might be with someone else. Right? But at least they get that information. Sometimes I think the worst thing in the world is not knowing. At least when you know, then you can go on and, go on and start addressing the, the issues there. Alright. We've we're getting close to the top of the hour. There's a couple questions that have come in. We'll reach out directly and answer those, but really appreciate all of the questions. Appreciate Paul being a a part of this and lending his insights, and, I appreciate you guys joining us today. Again, if you have questions, you know, partner portal is a great place to start. You can reach out to, your your your cams if you have questions, and we look forward to, we look forward to this being very successful in helping you in, in your, selling efforts as we continue to give you guys plenty of stuff to sell. And, most of all, thank you for being a Sofa's partner. Thank you for joining us today, and I think that's it. So I wish you guys, good day.