Workshop engagement compliance as-a- (NRC) with IT/Security service) staff and primary stakeholders to discuss their cybersecurity strategy and means of improvement End User one-time or n/a Cofense PhishMe, n/a n/a offered n/a n/a KnowBe4, Training ongoing LMS standalone Symbol cybersecurity Security (min. awareness 500 users) training offered directly to end users Email Security Secure Email FortiMail Mimecast MailMarshal proprietary n/a n/a offered standalone Mimecast (sold Gateway or as add-on) other product meant to detect malicious or fraudulent email content SIEM & Log a managed FortiSIEM Hosted Hosted: Fusion n/a Microsoft n/a offered standalone FortiSIEM Management solution that LogRhythm (logs (proprietary, Sentinel, Sumo (roadmap 2023) provides holistic must be ingested Microsoft Logic view of into Ntirety Sentinel) or On- customer’s environment; will Prem (Splunk, environment and not manage QRadar, correlates existing) LogRhythm); min. various data $25K MRC sources to identify threats in real time Managed combination of FortiEDR Palo Alto XDR Carbon Black, n/a Carbon Black n/a offered standalone FortiSIEM + Detection & security tools Microsoft (min. 50 (roadmap 2024) FortiEDR, Response and SOC Defender, Palo endpoints); SentinelOne (MDR) analysts used to Alto, SentinelOne; CrowdStrike, identify threats min. 250 seats Microsoft and respond to Defender (min. 25 incidents within endpoints); a customer SentinelOne environment Endpoint remote FortiEDR Palo Alto XDR n/a n/a Carbon Black NordLayer offered standalone FortiEDR, Protection management of (sold as add-on) (min. 50 FWaaS (min. 300 SentinelOne specified endpoints); (roadmap) endpoints) product CrowdStrike,
Security Matrix Page 4 Page 6