Decoding NOC, SOC, EDR, XDR, and SIEM for Dealership Cyber Tools

Automotive Risk Management Partners

Key takeaways

  • The updated FTC Safeguards Rule has a compliance deadline of June 9th, prompting dealerships to evaluate cybersecurity vendors and tools.
  • EDR (endpoint detection response) software is a common baseline tool used to protect individual devices on a network.
  • XDR is the newer generation of threat detection and remediation technology, replacing the older MDR platforms that some vendors still use.
  • A SOC (security operations center) monitors dealership IT infrastructure and identifies potential threats from the internet as they come in.
  • A NOC (network operations center) takes threats identified by the SOC and handles the more in-depth remediation process.
  • Some cybersecurity vendors only provide threat identification without remediation, so dealerships should understand exactly what is included in any package they purchase.

Summary

Meeting the updated FTC Safeguards Rule deadline of June 9th means choosing cyber security tools and vendors, and that process comes loaded with acronyms that are easy to confuse: EDR, MDR, XDR, SIEM, NOC, and SOC. EDR (endpoint detection and response) software is now standard across the industry. MDR and XDR both identify and remediate threats, with XDR being the newer technology replacing the older MDR approach; a SIEM tool works alongside these to log and organize activity. The SOC, or security operations center, monitors a dealership's IT infrastructure and identifies threats from the huge volume moving across the internet daily, while the NOC, or network operations center, takes what the SOC flags and handles the deeper remediation work.

For a dealership evaluating providers, the practical takeaway is that not every package covers the same ground. Some vendors stop at threat identification using older MDR technology and never get into full remediation, while others, including this provider's current setup using XDR with a SIEM tool, cover both sides. Before signing or renewing a cyber security contract, dealership leadership should understand exactly which pieces, EDR, SOC monitoring, NOC remediation, are actually included, since gaps between identification and remediation directly affect how well a store is protected and how well it can demonstrate Safeguards Rule compliance.

Transcript

Safeguards Rule deadline and cyber acronym overload

You know, I'm talking to you today given the upcoming deadline for the Safeguards Rule, or the update to the Safeguards Rule that's coming June 9th, and many of you are out there trying to figure out how you're going to solve the whole cyber security piece and how you're going to attack this. And I'm sure that, being the IT aficionados that most of us are, you're getting hit with a number of these acronyms: NOC, SOC, EDR, XDR, SIEM. And I wanted to kind of give a little clarification to it, because as you're going through your research and you're trying to decide who you want to do business with or how you're going to solve this dilemma, it's kind of nice to at least have an understanding of what you're looking at and what really all this means.

EDR, MDR, and XDR explained

So EDR, which is an endpoint detection response software or platform, is very commonplace. Everybody's going to be using that. If you look at MDR and XDR, those are the platforms that are used in the whole process of identifying threats and remediating those threats. MDR is the older technology, the XDR is the newer technology. So you'll see some of the companies out there today are probably still using MDR. We currently use the XDR platform with a SIEM tool.

SOC: monitoring and threat identification

So in this whole cyber security world, there's basically two different functions. You've got the network operations center, or the NOC, and then you've got the security operations center, or the SOC. Now, the SOC basically is the monitoring process, or the monitoring center, for the internet, or the infrastructure of your IT functions in the dealership. The SOC basically is there to man it, or to log everything and to recognize or identify threats as they come in. And this could be, you know, there's hundreds of thousands of threats running throughout the internet on a daily basis. So the SOC obviously has a list of certain threats that they are aware of that exist out there. They identify those, they remediate some of that, they get into basically the whole process of managing what's coming in, the information or the threats or the potential threats that come into the infrastructure.

NOC: remediation of identified threats

You've got the NOC, the network operations center, that's structured in a way to where it's going to take those identities, or whatever is identified through the SOC, and it's going to either help to assist the SOC in identifying those potential threats, and then it can get into the more in-depth and more involved remediation processes of remediating any of those threats that have come in.

Evaluating vendor packages and coverage gaps

So you've got a couple of different acronyms and things that you really got to look at when you're looking at all of this. Some companies are only going to provide half of this piece. They're only going to give you up to maybe the point of identifying the threats without the remediation. They're going to use an MDR instead of the XDR. XDR is the newest technology they're going to be using. Everybody pretty much is probably using some sort of SIEM tool or software platform that they use to attach to help create the logs and everything else that they've got.

Getting assistance choosing or reviewing a vendor

So when you're going through all of this, you need to make sure that you understand the packages that you're buying, understand what you're looking at, and obviously take your time in viewing that. One of the things that we will do is, if you have signed up with someone else, you know, we're not in this just for the monetary gain of all of it. Obviously, we're not here for our health either, but by the same token, if you need assistance, maybe you've contracted already with a company and you just want to make sure that everything's protected, give us a call. We'll be more than happy to talk to you and kind of walk you through some of that just to assist you in that. And then, if at some point in the future you decide to do business with us, that's great.

So, you know, if you need anything, or if you have any questions, the website, the phone number, everything's right here on the screen. Give us a call, we'll be there to talk to you. Thanks.

Questions this video answers

What is the difference between a SOC and a NOC?

The SOC, or security operations center, monitors the dealership's IT infrastructure and internet activity to identify potential threats. The NOC, or network operations center, takes what the SOC identifies and either assists in identifying threats further or performs the more in-depth remediation of those threats.

What is the difference between EDR, MDR, and XDR?

EDR is endpoint detection response software used commonly to protect devices. MDR is an older platform used in identifying and remediating threats, while XDR is the newer technology that has largely replaced it. Some companies still use MDR instead of upgrading to XDR.

Why should dealerships understand these cybersecurity acronyms right now?

With the updated FTC Safeguards Rule deadline of June 9th approaching, dealerships are researching how to handle cybersecurity and are being hit with terms like NOC, SOC, EDR, XDR, and SIEM. Understanding what these mean helps dealers evaluate vendors and know exactly what they are buying.

What should a dealership check before buying a cybersecurity package?

Dealerships should make sure they understand what is included in the packages they are buying, since some companies only provide threat identification without remediation, or use older MDR technology instead of the newer XDR platform with a SIEM tool.

Covered in this video

  • FTC Safeguards Rule
  • Endpoint Detection Response (EDR)
  • Extended Detection and Response (XDR)
  • Managed Detection and Response (MDR)
  • Security Operations Center (SOC)
  • Network Operations Center (NOC)
  • Security Information and Event Management (SIEM)