Managed Detection and Response
The MDR Services described herein are subject to the License and Services Agreement located at https://www.cybereason.com/license-agreement, unless the customer receiving the services (“Customer”) has executed a different license and services agreement, in which case the executed version shall supersede, (the “Agreement”). In the event of any conflict between the terms hereof and the Agreement, the terms hereof shall control.
Cybereason shall provide those services listed below subject to the terms of the Agreement, provided that in the event of any conflict between the terms hereof and the Agreement, the terms hereof shall control. Customer’s order of MDR Services shall be specifically designated in the applicable Quote.
All MDR Services will be provided in accordance with the Cybereason MDR: GSOC MDR Service Definition (“Service Definition”) which includes further detail and is provided by Cybereason upon request. Cybereason reserves the right to update the contents of the Service Definition at any time. All Customers who subscribe to notifications will be informed of material changes with advance notice. For the avoidance of doubt, authorization and direction from Customer for active remediation or any security service under the MDR Services shall be obtained in writing and in accordance with the applicable notification provisions of the Agreement, or as otherwise agreed to by the parties in writing.
Onboarding: Customer will be onboarded into MDR Essentials by Cybereason, and once onboarding has been completed, an automated email will be sent to Customer by Cybereason confirming completion of onboarding and commencement of Monitoring phase as defined this Service Description and the Service Definition.
Monitoring
Cybereason shall monitor and triage malops by leveraging its Software Platform and provide remediation recommendations.
Tasks in this stage (“Monitoring”) will include:
Monthly Reports
Each MDR customer will receive a standard monthly report. This report is aimed at providing an overview of the Customer’s environment and Malop activity that was seen within the previous calendar month. Cybereason reserves the right to update the contents of the Monthly Reports to provide enhanced metrics for reporting.
For avoidance of doubt, the Cybereason MDR Service is bound to the activities of triage, investigation and analysis of a malop within the Cybereason Software Platform and, as such, is not within the scope of Incident Response services, such as, but not limited to, determining initial infection vector, professional services consulting, crisis management, digital forensics, advanced analysis, malware analysis, external log analysis, threat intelligence research, vulnerability research, root cause analysis and guided disaster recovery. Incident Response services will require a separate Professional Services Statement of Work as detailed above.