What is our primary use case?
We use it as our managed SOC instead of contracting with an MSP. It coordinates endpoint and gives us a single pane of glass for our security events.
It fulfills the role of a SIEM, serving as our dashboard.
The automated response to incidents works effectively out of the box, and the number of interfaces and platforms it can work with is impressive. It is very extendable to all the platforms we use.
What is most valuable?
The automated response to incidents works effectively out of the box, and the number of interfaces and platforms it can work with is impressive. It is very extendable to all the platforms we use.
It provides peace of mind knowing that any device on our network, whether it is our own, BYOD device, or an unauthorized device, is being tracked and analyzed at multiple levels.
The false positives are minimal. It picks up on borderline issues, and the price provides good value. The value proposition is solid.
What needs improvement?
There is always room for improvement. I am not giving it a perfect score because I am sure there is something that could be enhanced.
Having some sort of certification or training, along with more periodic webinars might be helpful. Having a larger support network would be beneficial. Nobody I know has heard of Lumu, so they are in the same space as Darktrace or CrowdStrike, but people give blank stares. As the community grows for Lumu then that will improve, but that is not really a criticism of Lumu, they simply have not been around that long.
For how long have I used the solution?
We have been using the solution for one year now.
What was my experience with deployment of the solution?
Compared to some other competitors, Lumu onboarding and setup was very painless. We had experience with several others. It was very easy to integrate and the support made it seamless. It deploys as a virtual machine, so most customers would find it easy to deploy.
The complete deployment took approximately a week.
I handled the deployment alone. The initial deployment was completed in a couple of hours, but connecting it to our firewall and cloud services took longer. The initial setup to get it operational was accomplished in a couple of hours.
What do I think about the stability of the solution?
Stability has been excellent. I have not noticed any problems or incidents with it, other than self-inflicted ones.
What do I think about the scalability of the solution?
We have a small network with a few thousand nodes, so I cannot speak to how it scales in a bigger environment. Since it runs as a VM, I assume it could run on a bigger VM, but I can only speak to running it in our environment.
How are customer service and support?
The false positives are minimal. It picks up on borderline issues that matter, and the price provides good value. The value proposition is solid.
How would you rate customer service and support?
Which solution did I use previously and why did I switch?
We piloted different solutions. Cost was a significant factor. Lumu fit our budget and provided ease of deployment. The main alternative we considered was
Darktrace.
How was the initial setup?
The initial deployment was straightforward, completed in a couple of hours. We then had to connect it to our firewall and cloud services, which took additional time, but the initial deployment to get it operational was brief.
What about the implementation team?
I implemented it myself. The onboarding time varied depending on how deployment is defined.
What was our ROI?
That aspect is hard to quantify. It measures itself and self-reports in terms of engineer time saved. It self-reports as saving 10 to 20 hours a week of engineer time.
What's my experience with pricing, setup cost, and licensing?
In our environment, it costs approximately 1200 a month.
Which other solutions did I evaluate?
We piloted different solutions. Cost was a significant factor. Lumu fit our budget and provided ease of deployment. The main alternative we considered was Darktrace.
What other advice do I have?
The maintenance involves understanding what constitutes a real threat and what can be safely ignored. It requires responding to incidents, but this would be the same on any platform.
The ones I have noticed that are false positives are minimal.
It uses AI to analyze threats, though I am not certain about the extent of its implementation.
We are a government organization.
I would rate it an eight.
Which deployment model are you using for this solution?
Private Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Other