Knowledge Hub · Security

What happens when Sophos MDR detects a threat in a FirstNet-managed environment?

Managed Cybersecurity Services · Answered by FirstNet Technology Services

Short answer

Sophos MDR analysts spot the threat and send an alert to FirstNet's support desk. FirstNet's Incident Response team then works with you to contain the threat, fix the cause and recover.

In detail

Sophos MDR is the 24/7 security operations layer: its analysts hunt for threats and flag suspicious activity. The steps after a detection:

  • Detection: Sophos MDR analysts find suspicious activity in your telemetry.
  • Alert: Sophos notifies FirstNet's support desk.
  • Response: FirstNet's Incident Response team contacts the people you nominated.
  • Containment and remediation: FirstNet works with you to contain the threat and deal with the cause, following the agreed playbook.
  • Recovery: systems return to normal. Where Druva backup is in place, clean data can be restored.

During onboarding, you agree an incident response runbook with FirstNet. It sets how alerts arrive, who steps in and which remediation playbook applies. If you use Sophos endpoints and a Sophos firewall, Security Heartbeat can also isolate a compromised device automatically.

FirstNet does not run its own SOC. The Premium support tier extends incident response to on-site remediation support where it applies.

Source: FirstNet Managed Cybersecurity Services service page →

Didn’t answer your question?

Call