What is our primary use case?
I have a project with McAfee and a customer to deploy and roll out the solution for ADR and other components from the McAfee ecosystem. The entire solution is for endpoint security with the new component, ADR, the adaptive threat protection, and the TIE server, which is responsible for the threat information exchange between the product of the ecosystem. There’s a sandbox connected to the endpoint protection, to the ePolicy Orchestrator, and also the network security platform to connect the sensor for EPS or EDS.
We have several components on top of the McAfee agent. Each component performs different activities. We have the base component that is the classic anti-malware, and then the endpoint security, which we call the endpoint security platform. We also have adaptive threat protection that can handle the reputation on file.
If the file is unknown and the GTI (global threat intelligence) of McAfee doesn't know the reputation of a file, this file can be sent to the sandbox. Then, the sandbox analyzes the file to discover if it's zero-day ransomware or something else. They can then decide if the file needs to be blocked or if some other action needs to be taken.
There’s the new component ADR on top of the solution from McAfee Complete Protection that can collect the index of items compromised inside the computer. All this information is sent to the cloud, to the console ADR in the cloud. We can analyze everything with the security operation center.
What is most valuable?
The adaptive threat protection and the new component of EDR are excellent.
It's a new technology. However, it’s already improving with new additions. It gives new releases more frequently than in the past with other McAfee products. It evolves quickly.
The console of the EDR is totally in the cloud.
We have all we need, and the customer is happy.
It's very configurable, McAfee. If we talk about McAfee, we have a lot of opportunities to configure the product, customize features, views, or reports, et cetera.
What needs improvement?
The solution already has a lot of really great features. Nothing is missing.
As a new technology, it does need to grow. They need to continue to grow security aspects.
For how long have I used the solution?
I’ve used the solution over the last six months.
What do I think about the stability of the solution?
It's stable. It depends on the product. For instance, if we talk about solid core application control, that is one of the products that McAfee can manage and administer with the Policy Orchestrator. This product is very complex, and it's not so easy to maintain and set up. However, for the most part, it’s reliable.
What do I think about the scalability of the solution?
We have different business units. Each business unit performs a different activity. I work for cybersecurity and around the installation of the endpoint security product. However, we also have the red team that performs penetration tests. We also have a business unit related to the cloud infrastructure. Then there are people that are working directly on security. There are maybe 200 people, maybe more, that work with this solution.
We tend to work with medium to large organizations.
It's very specific for large or medium customers. However, it depends also on the type of business of the customer. The customer can be small, however, if the business is very important, then maybe the DLP solution is also needed for smaller organizations.
It is absolutely scalable.
How are customer service and support?
If we're talking about the classic product, we found that technical support usually had good skills and sound knowledge when we open a service request. In the case of solid core, which is a very specific product, we note that the support of McAfee doesn't have skill with that product, however, it's normal as the distribution on the market of this typical product is not so vast.
Which solution did I use previously and why did I switch?
I have experience with some Trend Micro and Symantec products for the endpoints.
All three vendors adopt the classical techniques for malware interception, and then the digital senior too. There’s also new functionality with the EDR. Maybe McAfee and Symantec have bigger data centers with global threat intelligence and are more advanced instead of Trend Micro. However, the solutions are all basically the same. That said, McAfee is a unique vendor in that it can give one console for our product.
How was the initial setup?
For me, it's not complex. We have more than six years of experience with McAfee. Each vendor needs to perform the installation. However, the systems are the same for all vendors. When we need to perform a new installation or upgrade, then the problems are mostly the same for each vendor.
It only takes about six hours to implement the product.
I’d rate it a three out of five in terms of the ease of implementation. How difficult it might be is related to the technician's skill that performs the installation. For the first time, it might be a bit more complicated. Once you understand McAfee, however, and you’re well-versed in the product, it’s not a problem.
The solution doesn’t require any maintenance.
What about the implementation team?
We provide implementation services to our clients.
What was our ROI?
We’ve seen that, especially when we deployed the last protection to the customer, with new EDR functionality and DLP functionality, the customer is happy about the time dedicated to analyzing the incidents. That time is very reduced now since the product now can automate a lot of things that, in the past, the analyst would have to do manually.
What's my experience with pricing, setup cost, and licensing?
In terms of the price, it's different for a government user.
The price on the market for one endpoint with all the protection needed is at least 25 euros. It depends on the product that we need to install, however.
The number of endpoints can impact the price. If we try to sell 1000 endpoints compared to more than 1000, the price can change.
When we sell the protection solution, we also sell the service of the security operation center. Then, our team also can manage the infrastructure of protection for the customer.
The price is moderate for the market. I’d rate it a three out of five in terms of affordability.
What other advice do I have?
We are a platinum partner of McAfee.
We’re using the latest version of the solution.
It is on-premise. However, it is also connected to the cloud as the McAfee solution, when we work in the EDR console, is cloud-connected to the on-premise console with the intelligence on the cloud.
The product is excellent. However, it is very complex to implement from scratch. Therefore, it’s good to have a partner that can assist you and help you with the setup.
I’d rate the solution eight out of ten.
Which deployment model are you using for this solution?
Hybrid Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Amazon Web Services (AWS)
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner