What to Consider about XDR for Security
Potential IT threats are constantly evolving, finding new pathways into your infrastructure and new exploits to gain access to data or systems. In the early days of computing, with dedicated server rooms and monolithic applications, attackers had to gain direct access to physical systems. As the internet became more common, attackers moved to the network and had to circumvent hardware-based protection like firewalls and routers. Now, with highly distributed environments and IT landscapes where individual employees all have devices that access company resources, there are innumerable potential points of failure.
Many layers of security have been developed to defend against potential threats – but that can introduce its own complexity. It is easy to drown in alter cascades, miss root causes, or have inadequate integration that leaves security gaps. One approach to try to mitigate those deficiencies is extended detection and response (XDR), which unifies several different security technologies within a single platform.
A Brief History of Infrastructure Security
In the early days of IT security, the focus was heavily on system-level and hardware-based security. Most security was based on access controls, malware and virus scanning, and access controls for servers and desktops, while the network was managed by firewalls and routers (and, in very advanced environments, VPNs).
Over time, these system-level protections were supported by more advanced monitoring and through aggregating logs or telemetry data to be analyzed in real-time by technologies like security information and event management (SIEM). Additionally, more robust security monitoring was developed for individual systems and services which tracked performance, running processes, file or configuration changes, and network connections to detect suspicious behavior. This endpoint-focused technology is called endpoint detection and response (EDR).
However, as both the number of IT devices ballooned and the number and types of environments shifted from physical systems alone to include cloud, virtual, and SaaS instances, the amount of data could be overwhelming for IT and security teams.
Defining XDR
eXtended Detection and Response (XDR) was designed as a way to manage security data faster and with more intelligence. There are three aspects of XDR that set it apart from SIEM or EDR: a single unified platform, analytics and cross-domain correlation, and automation. These attributes position an XDR platform to identify an attack more easily and predefine potential protective actions even before a human investigation begins.
XDR: When It Works (and When It Doesn't)
XDR is designed for security teams. Unified telemetry and analytics reduce false positives, eliminate duplicative alerts, and improve root cause analysis, which reduces alert fatigue in security analysts. This can lead to much better MTTR and reduce dwell-time for attackers and can help identify multi-vector attacks (e.g., lateral movements on the network or identity-based threats) more efficiently. Using a single platform is easier for security teams and doesn’t require a broad set of technology skills, while automation and integration can speed up the resolution process.
However, combining multiple security technologies into a single platform has some drawbacks. The implementation can be very difficult to deploy and any issues with integration or changes to data or telemetry can affect performance. Similarly, poorly tuned analytics can spike alert noise and falsely trigger investigations or automation. XDR systems tend to command a premium price, even compared to building full tech stacks of multiple vendors. And the reliance on a single vendor limits the flexibility and scope for the deployment if there are corner cases or required customization, such as specialized hardware.
One consideration that is both a pro and a con is that XDR platforms are usually designed to be run in-house, rather than as a managed service. Features like the unified platform and automated remediation are supposed to make it easier for security teams to identify, triage, and address incidents. However, running the XDR system still requires a 24/7 security operations center, so attempting to use XDR — for most organizations – requires hiring dedicated, skilled security analysts in addition to existing IT resources.
Cybersecurity Mesh Architecture: Selecting the Best Solution

A security stack is a set of capabilities, each to address a specific threat. While you can try to put everything in a single platform (the approach taken by XDR), alternatively, you can identify the best solutions, based on a variety of factors, for any specific security area and build an integrated security stack (Gartner defines this approach as a cybersecurity mesh architecture).
There are several key capabilities that can be combined that parallel the capabilities of an XDR platform:
- Endpoint detection and response (EDR), which covers detailed system-level activity and intrusion detection
- A fully staffed security operations center (SOC); with an MDR solution, the EDR technology is managed and monitored by the security services provider
- Network detection and response (NDR) to monitor real-time connections and traffic and to identify atypical patterns or behaviors
- An analytics engine, such as SIEM, for centralized log and event correlation, forensics, and detection
However, a security mesh architecture goes beyond just monitoring, and positions a more holistic approach to security:
- Hardware-based solutions such as firewalls, gateways, and zero-trust architecture
- User security awareness training
- Vulnerability management and patching
- Regular cyber risk assessments and gap analysis
- Penetration testing
- Robust authentication and access management
- Disaster recovery and incident response
While this can introduce more complexity at the beginning and potentially diffuse supply chain risk, there is a much larger benefit in being able to select the best possible technology, expand capabilities as new technologies emerge, and tailor requirements for the specific client case.
Weighing the Tradeoffs
XDR platforms have several benefits:
- Integrated automation
- Faster out-of-the-box deployment
- Centralized analytics and dashboarding, especially root cause analysis
However, all of those benefits are related to deploying and managing a system yourself. If you are not planning to hire and manage a full-time SOC and incident response team — which can be prohibitively expensive and challenging for most organizations — then those benefits are not as relevant as the potential downsides:
- Vendor lockin, both for price and for ecosystem
- Limited customization and extensibility
- Lack of specialized capabilities, especially related to networking
With a managed services provider to manage alerts and triaging, staffing, and training, then a heterogenous security stack provides benefits that directly affect the quality and resilience of your IT security:
- Flexibility
- Specialized or broader use cases
- Supply chain resilience
Simplify Your Approach to Cybersecurity
Because there are so many potential vulnerabilities, different operating environments, and difficulty managing the right levels of privilege across services, cybersecurity can become very complex – and complexity introduces even more risk.
Thrive’s mutli-layer security stack gives you the coverage that you need, across different types of threats and attack vectors. Our 24/7 security operations center and dedicated incident response teams mean that you always have a full security team available.
Find out more about our cybersecurity technology stack, and plan for how we can make your teams’ lives easier.