G DATA MXDR

Product Launch

G DATA MXDR is not an off-the-shelf product. It is a security solution tailored to your IT environment. Therefore, this product cannot be purchased, installed, and used like traditional antivirus solutions.

MXDR Overview

Instead, it requires

  • an analysis of the current (as-is) state of your security concept,

  • creation of the appropriate target (to-be) concept with clear agreements

  • and a smooth transition.

PoC

Prospective customers initially have the option, as part of a Proof of Concept test phase (PoC), to check whether the concept of a Managed XDR solution fits your organization.

PoC
More information about the PoC

The Proof of Concept license includes monitoring of up to 25 devices with service level G7 for a period of two months.

The period begins from the kick-off appointment, not from contract signing.

Kick-Off

The kick-off is the first meeting of our G DATA Security Operations Team with the responsible project participants in your organization.

In this session, you will receive

  • explanations of standard configurations as well as answers to all open questions,

  • all information about the system minimum requirements,

  • a risk briefing.

In the discussion, our G DATA Security Operations Team will explain to you

  • potential risks of Exclusions,

  • non-automated responses to malicious code

  • or the exclusion of response services on certain systems.

We will clarify what Impact these points may have on response times and the resulting potential damage. A 14-day learning mode of the G DATA Agenten will be set up. For two weeks, no automated response to malicious code will be performed. After this period, you will receive information about processed sensor alerts, the end of the learning period, and that from that point onward, automated responses to detected malicious code will be executed. Response services will of course still take place during learning mode. In addition, a notification chain will be defined for the case of future Incidents.

Deployment

Deployment includes setting up a tenant (Tenant) in our system.

You will be provided with the setup file for the G DATA Agenten and access to the G DATA Web-Portal will be set up (including an extensive introduction), and your Setup ID will be communicated to you.

Onboarding

Organizations that have purchased the G DATA MXDR service receive an onboarding workshop. Exclusions are onboardings for organizations with fewer than 50 seats and service level G5, or if the service was purchased through a third party (e.g., a managed service provider). These Customers receive mail onboarding, but can additionally book the workshop (if required, please contact our sales team).
No onboarding workshop is offered for service level G3.

If you obtain G DATA MXDR through a partner of G DATA, that partner will of course receive the email for the mail onboarding.
Onboarding
More details on the onboarding workshop process

Kick-Off The kick-off appointment is the first meeting of our G DATA Security Operations Team with the responsible project participants in your organization. The following points are discussed at this appointment:

  • You will receive explanations of required or desired configurations, answers to all open questions, as well as all information about the system minimum requirements.

  • The kick-off includes a risk briefing. In the discussion, our G DATA Security Operations Team will explain to you

    • potential risks of Exclusions,

    • non-automated responses to malicious code

    • or the exclusion of response services on certain systems.

      We will clarify what Impact these points may have on response times and the resulting potential damage.
  • It will be discussed whether, and which, Exclusions should be set for monitoring by the G DATA Agenten.

  • If desired, a 14-day learning mode of the G DATA Agenten can be agreed. For two weeks, no automated response to malicious code will be performed. After this period, you will receive information about processed sensor alerts, the end of the learning period, and that from that point onward, automated responses to detected malicious code will be executed. Response services will of course still take place during learning mode.

  • You can decide whether devices should be excluded from access by the G DATA Security Analysten.

  • A notification chain will be defined for the case of future Incidents.

During the kick-off, our G DATA Security Operations Team will discuss with you which of your Endpoints we will monitor, how our responses to attacks should be performed, and where a manual analysis may be advisable instead of automated responses. Together, we will weigh the advantages and disadvantages in your specific case. In doing so, the function of systems with special relevance (especially servers) will be considered. These may include devices used by executive management (due to their special trust relevance) or domain controllers, HyperV systems, mail servers, or database servers.

After the kick-off, a summary will be created. If all points could be clarified, the individual target (to-be) concept can already be defined and deployment can be started. Otherwise, a review will be performed.

Review

During the review, all remaining open questions are clarified and documented. The final, individual target (to-be) concept is then defined here.

Deployment

Deployment initially includes setting up your tenant (Tenant) in accordance with the agreements from the kick-off (target concept) in our G DATA Cloud Backend.

Depending on the service level, you will receive, upon request, a deployment consultation from us.

You will be provided with the setup file for the G DATA Agenten and the G DATA Web-Portal (including an extensive introduction), and your Setup ID will be communicated to you.