What is our primary use case?
The main use cases of this solution include:
It is an out-of-the-box automated integration with our 20 departments. We perform L1 LiveOps automatically through the portal.
We direct log ingestion from other sources, bypassing the need to send logs to SIEM first. Critical log forwarding and server-side code execution. Integration with threat intelligence.
What is most valuable?
The open API for integrating any available tools not currently offered in D3, without any recurring cost. So, it is one of the most valuable aspects for me.
What needs improvement?
Reporting needs improvement. MTTR and MTTD metrics aren't directly available in playbooks and require manual effort to achieve.
For how long have I used the solution?
I have been using this solution for over a year.
What do I think about the stability of the solution?
Unlike our previous service-based incident response product, which had many issues, D3 has been very stable. They even proactively update machines if they find bugs, notifying us about scheduled upgrades to fix issues we might not even be aware of. This proactive support is invaluable compared to our previous situation of constantly chasing QA tasks around the clock.
The stability and future potential of D3 are impressive.
What do I think about the scalability of the solution?
It's very scalable. We evaluated its ability to function in a cluster environment and allow module updates without needing to update everything else. It's flexible and easily expands to accommodate our needs, unlike our previous products.
We have around five end users using this solution.
How are customer service and support?
We are really happy with the support team. We achieved all the targets we set and the overall ROI.
Which solution did I use previously and why did I switch?
We thought QRadar integration would be easier with Resilient product, but their integration method wasn't good. They used an app for data fetching and required several manual tasks, including professional services for integration and playbook creation.
FortiSOAR seemed promising with its deep integration and easy playbooks, but the main dealbreaker was our desire for principal participation in future deployments, particularly for integrations and network aspects.
With Forti, we would have to work with a local partner, whereas D3 allowed us to work directly with their team within three days.
How was the initial setup?
What about the implementation team?
Since D3 itself handled the configuration without involving any partners, it was very smooth. We were up and running in two days, as documented, so it's quite easy for them to set up in an on-premises environment.
Since it is Docker-based as well, it was easy to set up.
What was our ROI?
D3 offers exceptional value for the investment.
What's my experience with pricing, setup cost, and licensing?
We follow a different procurement process. For example, Fortinet qualified technically but lost out in the financial stage due to a two-stage bidding process.
So, pricing can be subjective and depend heavily on local partners and competition. However, I found D3 Security to be more cost-effective than Fortinet, especially considering the valuable knowledge transfer they provide.
Which other solutions did I evaluate?
We evaluated IBM Resilient and FortiSOAR.
What other advice do I have?
Before committing, I recommend a Proof of Concept (POC) or demo first. This way, you can see if the product aligns with your specific use cases and security needs. Knowledge transfer is key, and D3 Security's team excels in this area.
During the POC, your analysts gain valuable product knowledge, putting them ahead of the curve for deployment. In our case, the learning curve was steep initially, but by the end of the POC, my team was already building playbooks independently. D3 Security also schedules dedicated knowledge transfer sessions during the POC, making it a win-win for both parties.
Since technology transfer is crucial for government entities like ours, this approach eliminates the need for additional learning after deployment, unlike with certain competitors like the Fortinet FortiSOAR case.
While Fortinet FortiSOAR achieved the desired tasks, its knowledge transfer process was lacking, leaving us with a shaky foundation. D3 Security's approach solidifies the learning and empowers our team.
Overall, I would rate the solution an eight out of ten.
Which deployment model are you using for this solution?
On-premises