Endpoint protection.
Detect, respond, manage.
Endpoint protection shields notebooks, PCs, servers and mobile devices from malware, ransomware and stolen credentials. We rely on Microsoft Defender for Business for endpoint detection and response and on managed detection and response from Arctic Wolf, combined with patch management and central device management. Consulting, rollout and operations come from DEVACON.
Five layers,
one protection concept.
Prevention and hardening
Devices are set up to a fixed standard: encryption, firewall, application and device control, attack surface reduction rules. What an attacker cannot execute, nobody has to detect.
Endpoint detection and response with Microsoft Defender for Business
Microsoft Defender for Business monitors the behaviour of processes, files and network connections on every device, detects attacks that classic virus scanners miss and isolates affected devices. For customers with Microsoft 365 Business Premium, Defender for Business is already part of the licence.
Managed detection and response from Arctic Wolf
Arctic Wolf monitors endpoints, network and cloud services around the clock from its security operations centre, triages alerts and initiates the response to an incident, together with us as your point of contact. No alert is left waiting overnight or over the weekend.
Device and patch management
With Microsoft Intune we manage Windows, macOS, iOS and Android devices centrally: policies, compliance, updates for operating system and applications in planned windows. Unpatched vulnerabilities are the most common entry point, so patching is part of the product.
Email protection, awareness and backup with Hornetsecurity
Most attacks on endpoints start with an email. Hornetsecurity filters phishing, malware and spoofed senders, trains employees with simulated attacks and backs up Microsoft 365 so that data can be restored after an incident.
Operations and reporting
We set up the solution, look after it in daily operations and report regularly on detected threats, patch status and open items. The scope is stated in the maintenance contract, not in the small print.
From inventory
to monitored operations.
A typical sequence. Existing protection solutions are replaced in stages so that no device is unprotected in between.
- Step 1
Inventory
Which devices, operating systems and licences exist, what protection runs today, where updates are missing. On request as an IT security infrastructure check.
- Step 2
Concept
Selection of the building blocks: Defender for Business, Arctic Wolf MDR, Intune, Hornetsecurity, matched to licences, sites and protection needs.
- Step 3
Pilot
One group of devices is migrated, policies are verified, false positives reduced, the reporting paths with Arctic Wolf rehearsed.
- Step 4
Rollout
All devices are migrated in stages, legacy solutions uninstalled, users informed.
- After that
Operations
Monitoring, patches, reports and regular reviews as part of the maintenance contract.
Frequently asked questions
about endpoint protection.
Is the built-in Windows antivirus not enough?
The basic protection in Windows detects known malware. Endpoint detection and response with Microsoft Defender for Business goes further: it evaluates behaviour, detects attacks without a known signature and can isolate devices. Who evaluates the alerts and responds is the second question, and that is what managed detection and response from Arctic Wolf is for.
What exactly does Arctic Wolf do?
Arctic Wolf runs a security operations centre that analyses the telemetry of your endpoints, network and cloud services around the clock. In the event of an incident, the team gets in touch, assesses the situation and coordinates the response with us. You do not need to build a security team of your own.
We have Microsoft 365 Business Premium. What are we missing?
Business Premium includes Defender for Business and Intune, in other words the tools. They only become effective through configuration and through someone who evaluates alerts. We set up both and, on request, add Arctic Wolf for monitoring and Hornetsecurity for email, awareness and backup.
Does this also work for servers and mobile devices?
Yes. Windows servers are included just like Windows PCs, macOS devices and smartphones running iOS or Android. Which devices are protected to what extent is defined in the concept.
What does endpoint protection cost?
That depends on the number of devices, the existing licences and the desired scope of monitoring. After the inventory you receive a quote with a clear scope of services.
Endpoint protection for your devices.
We take stock of your environment and propose a protection concept.