What is our primary use case?
IBM Security MaaS360 with Watson's main use case for my organization is cybersecurity threat detection and response. It helps us monitor security events, detect threats, investigate incidents, and respond to cybersecurity challenges.
A specific example of how I've used IBM Security MaaS360 with Watson for threat detection and incident response occurred when QRadar detected a suspicious privileged account. It helped us investigate and contain the compromised account quickly, which represented a smarter response.
Besides threat detection and incident response, I use IBM Security MaaS360 with Watson for continuous security monitoring, log analysis, threat hunting, and compliance reporting. It helps to centralize security data.
What is most valuable?
The best features IBM Security MaaS360 with Watson offers are AI-powered alert triage, automated threat investigation,
SIEM collaboration and
SOAR automations, threat intelligence integrations, and user behavior analytics. These features help the security team detect threats faster, reduce false positives, and respond to incidents more effectively.
The biggest hidden benefit of IBM Security MaaS360 with Watson is how much time it saves through event correlation and automation, not just threat detection.
IBM Security MaaS360 with Watson has improved threat detection, reduced response time, and increased overall security team efficiency in my organization.
What needs improvement?
To improve IBM Security MaaS360 with Watson, I would like to see easier setup, simpler customization, and even better false positive reduction.
Better cloud integrations for IBM Security MaaS360 with Watson would be another needed improvement.
For how long have I used the solution?
I have been using IBM Security MaaS360 with Watson for the last two years.
How was the initial setup?
My advice to others looking into using IBM Security MaaS360 with Watson would be to invest time in proper planning and tuning during the initial setup. The platform is very powerful, but it delivers the most value when your sources are well-integrated and your use cases are clearly defined. Focus on a good setup.
What was our ROI?
Organizations typically see a strong return on investment with IBM Security MaaS360 with Watson through improved analyst efficiency and reduced incident response time.
What's my experience with pricing, setup cost, and licensing?
My experience with the pricing, setup cost, and licensing of IBM Security MaaS360 with Watson is that it's enterprise-grade and relatively expensive with a complex license based on data volume, but it offers strong security value in return.
What other advice do I have?
We use
Microsoft Azure as the cloud provider for our hybrid deployment of IBM Security MaaS360 with Watson.
Regarding IBM Security MaaS360 with Watson's AI capabilities, it has strong access control and auditability, but could improve transparency and customization of AI decisions.
The AI capabilities of IBM Security MaaS360 with Watson are generally accurate and reliable, especially when it comes to correlating events and prioritizing alerts. It's reliable for alerts and prioritization, but accuracy depends on the data quality and tuning, with some false positives.
We have reduced investigation and response time by approximately thirty to fifty percent with IBM Security MaaS360 with Watson and improved analyst efficiency by cutting down on false positives. I would rate this product an eight out of ten.
Which deployment model are you using for this solution?
Hybrid Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Disclosure: My company has a business relationship with this vendor other than being a customer. Reseller