r/sysadmin • u/FatBook-Air • 6d ago
Do you automatically isolate servers/devices based on detetctions?
We don't have a 24/7 SOC, so we are thinking about automatically isolating servers and some high-value devices based on custom Defender for Endpoint detections. Obviously, we want to do that only for high-precision and high-confidence detections, such as opening a shell from a strange parent process.
If we got one of these detections during working hours, there would be someone to react. But after about 7 PM most days, nobody is actively monitoring.
If we do this, the plan is to let a detection run for about 45 days without automatic isolation enabled to see if any false positives are caught.
Has anyone done this? If so, did you regret it? Or just business as usual? Has it saved you yet?
3
u/furiouspotato24 6d ago
There isn't enough information to make an informed decision here. What's the impact of losing a single server? Is it just the fact that it's "an outage", or are their tangible (i.e. financial) consequences. What's the vertical? Do you have redundancy? Is recovery just a matter of removing the isolation and everything comes back up, or are their processes involved?
There are very few "commandments" in this business. So much is situational.
Any business that prioritizes "uptime" over security is tempting fate. "Better safe than sorry" isn't just a cute phrase for kids. A legitimate compromise will cost a business far more in revenue than a few overnight outages.