enterprisesecuritymag

Enterprise Security Magazine

Secureworks
The Ultimate Line of Defense in a New Era of Cyber Threats

Wendy K. Thomas, President and CEO, SecureworksWendy K. Thomas, President and CEO
As IT infrastructures continue to grow in complexity within enterprise ecosystems, organizations are striving to create and maintain a cyber security framework to achieve effective cyber resilience. And with expanding attack surfaces, sophisticated threats, and more importantly, a large pool of point security solutions present in the infrastructure, the path to true cyber resilience is fraught with challenges. While point solutions can be effective for specific use cases, these discrete solutions often fail to fight adversaries at scale in a complex and highly dynamic cloud-native environment. Wendy K. Thomas, President and CEO of Secureworks, compared this scenario to a person buying a treadmill and automatically expecting to be healthier as a result. "Buying security products that react independently won't make any organization safe because they fail to provide visibility into the entire technology infrastructure," she says. The scenario gets more complex in the case of multi-vector attacks, where cybercriminals deploy threats across multiple entry points. This highly sophisticated approach may even go undetected as independent security solutions restrict visibility, which significantly impacts the efficiency and efficacy of security operations.

In this scenario, how can organizations improve their overall security posture?

Secureworks has the answer. A global leader in cybersecurity, Secureworks offers Taegis XDR, a cloud-native security analytics solution for Extended Detection and Response (XDR), built on 20+ years of real-world threat intelligence and research. The solution unifies multiple security products and enables customers to outpace and outmaneuver adversaries with precision. With Taegis XDR, organizations gain comprehensive visibility and control over their endpoints, network, and cloud environments. "We provide clients the holistic visibility they need to keep their assets secure," said Wendy.

Taegis combines automated detection, containment, and response capabilities with industry leading threat intelligence and incident response insights to improve security operations for customers. Even when security features— including passwords, multi-factor authentication, and patches fail— Taegis serves as the ultimate line of defense by proactively detecting backdoor cyber activities and containing them quickly. Such an approach enables customers to create a security perimeter, preventing cybercriminals from extracting the data through sophisticated methods, including ransomware.

Secureworks built Taegis as a cloud-native solution, complementing the customer’s existing infrastructure by correlating events from multiple security tools. More importantly, by covering a customer’s entire environment and reducing their total cost of ownership, the Taegis platform allows customers to maximize ROI quickly.

For Security Operations Professionals by Security Operations Professionals

Secureworks began its XDR journey as one of the leading managed security service providers in the market, protecting organizations across an expanding attack surface with complex risks, threats, and vulnerabilities. The company’s security operations professionals developed their own tools to provide visibility across enterprise environments, as well as to automate relevant security operations workflows. From there, they saw an opportunity to empower customers and the broader security community with these capabilities.


Buying security products that react independently won't make any organization safe

"Taegis was fundamentally an XDR platform before XDR was a thing," said Wendy. And today, with annual recurring revenue of over $100 million, Taegis has evolved into a trusted XDR platform for companies.

Cyber Security Management Made Simple

Secureworks delivers its XDR solution through three offerings: Taegis XDR, Taegis ManagedXDR, and Taegis VDR.

As a platform, Taegis XDR allows customers to take security into their own hands and transform the way their in-house security teams detect, investigate, and respond to threats.

According to Wendy, security teams of all sizes are overwhelmed by today’s expanding attack surfaces. Even large enterprises are impacted by the shortage of skilled and experienced staff who can proactively respond to threats. Taegis ManagedXDR directly addresses these challenges. As a managed security service delivered through the Taegis security analytics platform, Taegis ManagedXDR includes threat hunting and incidence response. While providing this service, Secureworks completely manages the technology and allows clients to collaborate with them fully.

Additionally, Secureworks provides a suite of consulting services, including incident management and response services to help customers both understand and respond to incidents, threats, attack techniques, and vulnerabilities. "Last year alone, our company undertook more than 1,400 incident response engagements," said Wendy. Secureworks synthesizes this information into new analytics and detectors to continuously improve the Taegis platform based on our deep understanding of the threat landscape.

Yet another takeaway of Taegis ManagedXDR is its ability to hunt for threats proactively in the customer’s environment. Customers can opt into different tiers of threat hunting as part of ManagedXDR, or perform threat hunting themselves using Taegis XDR directly.

Taegis VDR, on the other hand, is delivered as a part of Secureworks' efforts to automate and simplify vulnerability management. The solution can automatically identify and prioritize vulnerabilities for intelligent remediation. Unlike traditional vulnerability scanning and patching software, Taegis VDR patches the gaps in the customer’s environment by understanding the risk posed by vulnerabilities and the potential exploitability of the assets.

Fostering Collaboration in the Security Landscape

Secureworks knows that a single company alone cannot win the battle against cybercriminals. Organizations of all sizes and maturity levels are struggling with the difficulty of attracting and retaining security talent, while facing the growing security risks to their business. There are many managed technology services providers that have a need to provide integrated security services, as it is a natural adjacency for them, but they need a jump start. As such, Secureworks is helping to accelerate the development of security talent on a broader level by offering a Managed Security Services Providers (MSSP) program that takes everything Secureworks has learned and accomplished in its 20+ year history as a leading MSSP and provides it to partners, enabling them to deliver the same capabilities.

The program provides partners with the ability to deliver MDR (Managed Detection and Response) services on top of the Taegis XDR platform. Partners can leverage the experience of Secureworks' analysts who command expertise in all XDR capabilities for comprehensive coverage, detection, and response. In order to ensure the quality of its partners' services, Secureworks offers training and certificates upon onboarding.

The MSSP program allows Secureworks to address the skills gap—a problem that’s been looming over the cybersecurity landscape for a long time — with a unique approach. With several training and education programs to improve the skills and augment the operational excellence of its customers, Secureworks enables security professionals to work with confidence. Additionally, within the platform, MSSP providers are able to take advantage of Secureworks’ continuously updated threat intelligence and investigation capabilities built on 20 years of best practices to work more efficiently.

A Customer-Centric Approach

Even though security is one of the critical investment areas for every company today, many shy away from implementing a holistic security solution due to the unaffordable pricing structure. For that reason, Secureworks has made its solution cost-effective, offering a predictable pricing structure to customers based on the number of endpoints and includes 12-months of data storage in the base price. This allows customers to run an effective security program, that scales with their needs.

"We will stay with our customers in the fight against cybercriminals every day and help them improve their security postures"

Many customers have reaped the benefit of these measures. In one instance, a professional services firm struggling with malware in its infrastructure approached Secureworks for assistance. The cost associated with setting up and managing the SIEM was extremely high for the customer, as they had distinct security needs. After understanding the customer's challenges, Secureworks stepped in and deployed Taegis XDR. The platform helped the customer successfully automate and expand their threat detection capabilities with real-time updates via the cloud. The real benefit was yet to come: the customer could enhance the security posture of their infrastructure without employing a separate team. In a nutshell, Secureworks helped the customer close all the doors to attacks with just a third of the cost that it had been paying earlier.

Such success stories stem from Secureworks' technological prowess and experience in addressing the complex security challenges of its customers. In fact, this experience gives them a thorough understanding of repetitive workflows, investigations, alerts, security playbooks, and more. The company leverages this knowledge to enhance its platform continually.

Turning the Tides

Going forward, Secureworks wants to deepen its focus on securing human progress via innovative, battle-tested security solutions. In order to accomplish this mission, the company continues to expand its Taegis portfolio and augment the platform with new features. Recently, Secureworks introduced two products, Taegis NGAV and ManagedXDR Elite, aimed at boosting customers' cyber security resilience. While the former offers next-generation endpoint threat prevention, the latter focuses on providing continuous managed threat hunting.

Moving ahead, Secureworks plans to expand its global reach by partnering with a new generation of MSSPs. While doing so, the company wants to evolve with its customers and demonstrate their ability to stay ahead of the security game. "We will stay with our customerss in the fight against cybercriminals every day and help them improve their security postures," said Wendy.

- Russell Thomas
    November 18, 2021

Company
Secureworks

Headquarters
Atlanta, GA

Management
Wendy K. Thomas, President and CEO

Description
Secureworks' Taegis XDR platform enables customers and partners to outpace and outmaneuver adversaries with more precision. Taegis XDR acts as unified security incident detection and response platform capable of consolidating multiple security products. With Taegis, organizations can gain comprehensive visibility and control over their endpoints, network, and cloud environments. As a result, Secureworks can detect and respond to more and real threats faster

Secureworks News

Cybersecurity provider Secureworks to let go 15% of its workforce

Secureworks Inc. is implementing a workforce reduction of 15% as a strategic measure to enhance profitability and allocate more resources to its flagship cybersecurity product suite. This development was disclosed through an official regulatory filing today. This decision comes half a year following a previous round of job cuts that impacted approximately 9% of Secureworks’ workforce, equivalent to around 200 employees. The current round of layoffs is anticipated to affect roughly 300 employees.

The company aims to finalize the restructuring process within its fiscal third quarter, concluding in late October. Secureworks has estimated that this initiative will incur a charge of $14.2 million. This financial outlay encompasses costs linked to specific "real estate related cost optimization actions" as well.

Secureworks, listed on the Nasdaq, markets a range of cybersecurity products under the brand name Taegis. The primary component of this portfolio is Taegis XDR, a software platform designed to identify malicious activity across a company’s cloud environment, employee devices, and other technological assets. It also features a tool for administrators to investigate potential security breaches.

The second facet of the product suite is a tool named Taegis VDR. Using artificial intelligence, this tool scans an organization's infrastructure for vulnerabilities. It then prioritizes these security weaknesses based on their severity, enabling administrators to address the most critical issues first.

The company also offers Taegis ManagedXDR, which combines its software products with professional services. This service enables enterprises to have Secureworks handle breach attempts on their behalf and manage related tasks such as evaluating an organization's systems for potential security gaps.

This reduction in workforce by Secureworks follows two months after the company posted fiscal first-quarter results that fell short of analysts' expectations. During the three-month period ending on May 5, Secureworks reported an unexpectedly significant loss and a year-over-year decrease in revenue. However, within the same timeframe, revenue from the Taegis suite experienced a notable surge of 68%.

In the regulatory filing that communicated the layoffs, Secureworks articulated that the restructuring aligns with its strategy to "focus on the higher-value, higher-margin Taegis solutions." The company also expressed its intention to enhance margins and optimize its organizational structure for improved scalability.

For the current fiscal year, Secureworks forecasts a loss ranging from $31 million to $39 million, coupled with sales reaching up to $400 million. Conversely, the Taegis product portfolio is anticipated to achieve an annualized revenue run rate of at least $300 million.

Secureworks Continues to Deliver Enhanced Visibility and Risk Management With Akamai Partnership

Atlanta - Secureworks® (NASDAQ: SCWX), a global leader in cybersecurity, today announced a new technology partnership with Akamai, the cloud company that powers and protects life online. The alliance between the companies will empower security operations teams with the data and intelligence needed to scale secure access in an era when a work-anywhere approach has led to identity becoming the new perimeter.

In the midst of ongoing transformations in corporate work policies, employees are engaging with diverse work models, including on-site, hybrid, and remote arrangements. The widespread nature of these work models has elevated the importance of implementing zero trust principles for managing access, becoming a crucial element of enterprise cybersecurity strategies. However, security teams frequently encounter challenges in consolidating and correlating extensive access logs with their other security-related data.

To address this issue, the integration of data into Secureworks Taegis™ XDR from Akamai's zero trust, web, and API security solutions emerges as a solution that enhances transparency, introduces agility, and expedites response times. This development, announced today, underscores Secureworks' commitment to assume a prominent role as the industry's premier open XDR platform.

“Cybersecurity must enable businesses and their teams to move fast and freely. Open ecosystems that correlate and enrich data to provide enhanced context and intelligence are the bedrock of cyber resilience,” said Chris Bell, VP Alliances, Corporate Development and Strategy. “It's for this reason we're committed to building and developing the industry's most open and transparent platform. Because when security is seamless, customers thrive. We know that Akamai shares that vision and are confident that customers reap significant benefits from our partnership.”

The initial stage of the partnership has been successfully initiated, featuring the integration between Secureworks Taegis and Akamai Enterprise Application Access (EAA), a solution centered around zero trust network access (ZTNA). This integration results in the infusion of telemetry data from EAA with supplementary context derived from Secureworks Threat Intelligence. Consequently, clients possess the capacity to make well-informed choices regarding access to applications and systems. Moreover, as novel alerts are introduced, they can be cross-referenced with data spanning the entire infrastructure. This facilitates streamlined prioritization and swift, efficient responses.

“The relentless pace of the global economy requires enterprises to deploy security that does not adversely impact employee productivity. We engineer high-performing security solutions that can deliver fast and reliable employee experiences. Our partnership with Secureworks can automatically generate data that companies need to respond quickly to complex threats, coupled with rich threat intelligence to understand and mitigate risk,” said Pavel Gurvich, Senior Vice President and General Manager, Enterprise Security at Akamai.

RANSOMWARE DWELL TIME HITS LOW OF 24 HOURS

Analysis from Secureworks annual State of The Threat Report shows ransomware median dwell time has dropped from 4.5 days to less than 24 hours in a year

ATLANTA - Ransomware is being deployed within one day of initial access in more than 50% of engagements, says Secureworks® (NASDAQ: SCWX) Counter Threat Unit™ (CTU™). In just 12 months the median dwell time identified in the annual Secureworks State of the Threat Report has freefallen from 4.5 days to less than one day. In 10% of cases, ransomware was even deployed within five hours of initial access.

"The driver for the reduction in median dwell time is likely due to the cybercriminals' desire for a lower chance of detection. The cybersecurity industry has become much more adept at detecting activity that is a precursor to ransomware. As a result, threat actors are focusing on simpler and quicker to implement operations, rather than big, multi-site enterprise-wide encryption events that are significantly more complex. But the risk from those attacks is still high," said Don Smith, VP Threat Intelligence, Secureworks Counter Threat Unit.

"While we still see familiar names as the most active threat actors, the emergence of several new and very active threat groups is fuelling a significant rise in victim and data leaks. Despite high profile takedowns and sanctions, cybercriminals are masters of adaptation, and so the threat continues to gather pace," Smith continued.

The annual State of the Threat report examines the cybersecurity landscape from June 2022 to July 2023. Key findings include:

• While some familiar names including GOLD MYSTIC (LockBit), GOLD BLAZER (BlackCat/ALPV), and GOLD TAHOE (Cl0p) still dominate the ransomware landscape, new groups are emerging and listing significant victim counts on "name and shame" leak sites. The past four months of this reporting period have been the most prolific for victim numbers since name-and-shame attacks started in 2019.

• The three largest initial access vectors (IAV) observed in ransomware engagements where customers engaged Secureworks incident responders were: scan-and-exploit, stolen credentials and commodity malware via phishing emails.

• Exploitation of known vulnerabilities from 2022 and earlier continued and accounted for more than half of the most exploited vulnerabilities during the report period.

Most Active Ransomware Groups

The same threat groups continued to dominate in 2023 as in 2022. GOLD MYSTIC's LockBit remains the head of the pack, with nearly three times the number of victims as the next most active group, BlackCat, operated by GOLD BLAZER.

New schemes have also emerged and posted numerous victims. MalasLocker, 8BASE and Akira (which ranked at number 14) are all newcomers that made an impact from Q2 2023. 8BASE listed nearly 40 victims on its leak site in June 2023, only slightly fewer than LockBit. Analysis shows that some of the victims go back as far as mid 2022, although they were dumped at the same time. MalasLocker's attack on Zimbra servers from the end of April 2023 accounted for 171 victims on its leak site in May. The report examines what leak site activity actually reveals about ransomware attack success rates — it's not as straightforward as it seems.

The report also reveals that victim numbers per month from April-July 2023 were the most prolific since name and shame emerged in 2019. The highest number of monthly victims ever was posted to leak sites in May 2023 with 600 victims, three times as many as in May 2022.

Top Initial Access Vectors for Ransomware

The three largest initial access vectors (IAV) observed in ransomware engagements where customers engaged Secureworks incident responders were: scan-and-exploit (32%), stolen credentials (32%) and commodity malware via phishing emails (14%).

Scan-and-exploit involves the identification of vulnerable systems, potentially via a search engine like Shodan or a vulnerability scanner, and then attempting to compromise them with a specific exploit. Within the top 12 most commonly exploited vulnerabilities, 58% have CVE dates of earlier than 2022. One (CVE-2018-13379) also made the top 15 most routinely exploited list in 2021 and 2020.

"Despite much hype around ChatGPT and AI style attacks, the two highest profile attacks of 2023 thus far were the result of unpatched infrastructure. At the end of the day, cybercriminals are reaping the rewards from tried and tested methods of attack, so organizations must focus on protecting themselves with basic cyber hygiene and not get caught up in hype," Smith continued.

The World of Nation-State Attackers

The report also examines the significant activities and trends in the behavior of state-sponsored threat groups belonging to China, Russia, Iran, and North Korea. Geopolitics remains the primary driver for state-sponsored threat groups across the board.

China:

China has shifted part of its attention to Eastern Europe, while also maintaining a focus on Taiwan and other near neighbors. It displays a growing emphasis on stealthy tradecraft in cyberespionage attacks — a change from its previous "smash-and-grab" reputation. The use of commercial tools like Cobalt Strike, as well as Chinese open-source tooling, minimizes risk of attribution and blends with activity from post-intrusion ransomware groups.

Iran:

Iran remains focused on dissident activity, on hindering progress on the Abraham Accords, and on Western intentions towards renegotiations of nuclear accords. Iran's main intelligence services — the Ministry of Intelligence and Security (MOIS or VAJA) and the Islamic Revolutionary Guard Corp (IRGC) — both use a network of contractors to support offensive cyber strategies. The use of personas (impersonating real people or fake created people) is a key tactic across Iranian threat groups.

Russia:

The war in Ukraine remained the focus for Russian activity. This falls into two camps; cyberespionage and disruption. This year has seen an increase in the amount of patriotic-minded cyber groups targeting organizations considered adversaries of Russia. For gangs, Telegram is the social media/messaging platform of choice for recruitment, targeting and celebrations of success. The malicious use of trusted third-party cloud services is frequently incorporated into Russian threat group operations.

North Korea:

North Korea threat groups fall into two groups: cyber espionage and revenue generation for the isolated regime. AppleJeus has been a fundamental tool for North Korea's financial theft initiatives, and according to Elliptic, North Korean threat groups have stolen $2.3 billion USD in crypto assets between May 2017 and May 2023 (30% of this from Japan).

State of the Threat Report 2023

This latest State of the Threat Report is the seventh annual report from Secureworks providing a concise analysis of how the global cybersecurity threat landscape has evolved over the last 12 months. The information within the report is drawn from the Secureworks Counter Threat Unit's (CTU) firsthand observations of threat actor tooling and behaviors and includes real-life incidents. Our annual threat analysis provides a deep dive insight into the threats our team has observed on the front line of cybersecurity.

Secureworks launches Taegis IDR to tackle identity-based threats in 90 seconds

Cybersecurity companySecureworks Inc. today announced the launch of Taegis IDR, a new identity threat detection and response solution that it says takes 90 seconds to discover identity-related risks and configurations.

Secureworks Taegis IDR has been designed from the get-go to close security gaps proactively by leveraging artificial intelligence and machine learning to detect, prioritize and respond automatically to identity-based threats across an organization environment and the dark web.

The solution seeks to address a well-known issue — identity — which regularly ranks as one of the top three access vectors for ransomware. The Secureworks Counter Threat Unit has observed a 688% increase in stolen credentials offered for sale on one of the largest dark web marketplaces recently, driving the criminal ecosystem.

Taegis IDR protects against all of MITRE ATT&CK Credential Access techniques, including kerberoasting, password spraying and brute force attacks, the company says. Kerberoasting is an attack method for cracking password hashes for service accounts in Active Directory.

It also continuously scans Microsoft Entra ID environments to identify misconfigurations and security gaps to reduce identity attack surfaces and the risk of leaked or stolen credentials. The service provides full visibility into identities within 90 seconds, enabling organizations to monitor and respond to abnormal user behaviors and exposures quickly.

Additionally, Taegis IDR protects against identity-based threats by leveraging automated playbooks for immediate response actions. Through the unification of identity threat detection and response with extended detection and response, the company says, it delivers comprehensive security across an organization’s environment. “Identity is the fuel of the cybercriminal ecosystem and today we’re cutting off their supply,” said Chief Product Officer Kyle Falkenhagen.

Falkenhagen added that the service, through identity protection combined with the latest threat intelligence, AI and broad visibility across endpoints, cloud and other applications, “uncovers misconfigurations to improve identity security posture with speed and precision.”

Secureworks was previously in the news in February when it launched a new AI service that promised to reduce the workload of security analysts by over 50%. Called Threat Score, the service assesses the risk of an alert and anticipates the likelihood of a negative impact within the context of a given organization’s operations.


© 2026 Enterprise Security Magazine. All rights reserved. Headquartered in Fort Lauderdale, FL, USA.