We use Sysdig Secure to gain visibility into our runtime workloads. We use a whole bunch of security tools to scan our images before they get deployed into our production clusters. We needed a tool to give us runtime visibility and threat detection.
By implementing Sysdig Secure, we were trying to see any gaps. When an image is running, we wanted to see if any high or medium-scale vulnerabilities were picked up during the scanning and were running in a live workflow. We understood that we had a gap there. If there was a threat for us, we wanted to make sure that we knew and that we could scan our environment for any zero-day threats or vulnerabilities in general.
The main benefit for me personally is being able to articulate the ever-growing, dynamic, and constantly changing landscape. Just today, in a management leadership call, I was able to demonstrate that although we are solving a lot of these vulnerabilities, we are picking up new vulnerabilities each and every day. It allows me to articulate the importance of information security with actual real-time data.
Sysdig's runtime insights help us detect and respond to threats that are happening in real-time. We can look at Sysdig dashboards or run reports to see precisely what happens in our runtime environment. A good use case of this was that when zero-day vulnerabilities came out, we could scan our environment to see if the vulnerabilities apply to any of our production workloads.
Sysdig Secure helps us prioritize issues and distribute work. We are a small company, so we do not have multiple security or dev teams. We have two or three guys on my team. Having the ability to focus on critical vulnerabilities is crucial. It does not make sense to prioritize low-level threats when we have limited time.
We do not use live threat investigation features as much as we would like because of different priorities, but it is something that we do use. Over time, it shows us whether we are putting the right effort into resolving issues. For example, when we look at the dashboard scene over a 30-day period, we can see whether the critical vulnerabilities are increasing or decreasing. It lets us know whether we are on the right track.
We are currently using agentless scanning. Deploying it onto our cluster has enabled us to get full visibility into what is running on our cluster.
Sysdig provides us with the contextual awareness we need to create an immediate incident response strategy. It provides links to the threat and explains the threat and the resolution possible. It equips us with the right information to make a decision on whether to address the threat immediately or take a risk in terms of deploying remediation.
Sysdig has not enabled us to reduce the number of security tools we use. We were not using anything before Sysdig, and after choosing Sysdig, we did not have a need to look at anything else.
Sysdig has not helped reduce external SOC costs. We are a very small business, so we do not have the budget for an external SOC. However, it has definitely alleviated the pressure to look for one and to source an external SOC. We have a project history to look at a virtual SOC and leverage tools that we do have, and Sysdig is a part of that. There is definitely a saving there because we have not had the need to go out and look for an external SOC.
Sysdig has helped reduce the percentage of workloads that have security exposures that put the organization at risk. It has reduced the workload, mainly from an understanding of where we can assign work to cover the most ground in terms of resolving vulnerabilities.
The most valuable feature is the level of support that we get. Our solutions or customer success representative is very valuable. I see them as an extension of our security team. In terms of the product itself, it is able to very clearly give us where we are in terms of security and threats in the environment.
Reporting can definitely be better. Live dashboards should be configurable for a longer period of time rather than 30 days. Being able to go back in time to compare six months ago to today would be valuable.
We have used Sysdig Secure for a few years. We have probably gone through two renewals.
It has been extremely stable. We have never had any issues with it. I would rate it a ten out of ten for stability.
I would rate it a ten out of ten for scalability. We have not had any issues. It has not been slow or anything like that.
We have approximately 25 people using this solution. They are from the engineering team and the DevOps team.
I would rate their customer service an eight out of ten purely because I have it in a proactive manner. I meet our solutions engineer every fortnight, so I usually do not require support at all.
We were not using any similar solution previously.
It was extremely straightforward. We just installed the agent, and then we could see the dashboard light up. It took a few hours.
It is deployed on the cloud. The cloud deployment is at one location, but the agent is installed at multiple locations.
One person was involved in its deployment.
We have definitely seen an ROI time-wise and resource-wise. I feel that I have an extension to our security team with this service. It gives us a lot of visibility that we would not have otherwise. It has saved 50% of an information security professional.
I am always going to say that it could be a little bit cheaper. I do feel that it is a little bit on the expensive side.
If you have the right approach to resolving vulnerabilities, it is an extremely useful tool. It is not useful if you plan to just have it deployed and not take action on any of the vulnerabilities.
I would rate Sysdig Secure a nine out of ten. If it has better reporting capabilities to visualize trends over time, it will be a more complete product.