Which of these best describes your operating model and capability to respond to threats and incidents? (select only one)
We are lacking good visibility of our estate to detect threats
We have visibility but we are not actively acting on all alerts
We get reactive alerts from our tooling and act on all alerts
We get reactive alerts from our tooling and act on all alerts. We also proactively hunt threats in our estate
We get reactive alerts from our tooling and act on all alerts. We also proactively hunt threats in our estate. We are using playbooks and automation to support incident management