We're in the process of merging two companies, each with its own established GravityZone setup and IT team. The technical consolidation is one thing, but I'm particularly concerned about the policy architecture from a reporting and accountability standpoint.
Currently, both teams have their own policies, exclusions, and reporting workflows. Simply importing one into the other or creating a monolithic new policy seems like a recipe for attribution chaos. How do we maintain clear visibility into which team is managing which security events, especially during the transition?
I'm considering a structure based on network tags or custom installation packages to keep the asset groups logically separate initially. This would allow each team to retain operational control over their legacy endpoints while we build unified reporting on the backend. Has anyone implemented a similar phased approach? I'm keen to hear how you handled the data reconciliationβensuring that a detection on "Company A" assets is clearly attributed in the audit logs and reports, without blending the two streams prematurely.
The end goal is a single, optimized policy set, but we need a migration path that doesn't break our ability to measure and assign responsibility.
Data beats opinions.