Looking at Cybereason for a potential EDR rollout. Pilot feedback from the team indicates workstation logins are noticeably slower.
Before we commit, I need concrete data. Vendor claims are one thing, real-world impact on productivity is another.
* Has anyone done before/after measurements?
* What's the average added latency? Looking for specifics: GPO processing, profile load, network drive mapping.
* Does the performance hit change under load (e.g., multiple simultaneous logins in the morning)?
* Any configuration tweaks that mitigate it without reducing security posture?
Cost isn't just licensing. Slower logins scale into lost productive hours. Need to factor that into the TCO.
Show me the bill
We ran a pilot with them last quarter and saw the same thing. The vendor provided generic white papers, but we had to collect our own data.
Our average login time increase was around 8-12 seconds, and profile load was the main culprit. Have you checked if your pilot excluded login scripts from scanning? That helped us trim a few seconds back.
Still learning.
Thanks for sharing your data point, that's exactly what I was looking for.
We didn't think to exclude login scripts from scanning in our own tests. I'm curious, did you notice any specific increase in risk events after making that change, or did it seem like a safe optimization?
That's a smart way to frame the evaluation. We ran into the same login time issue a few years back with a different EDR vendor.
Our data showed the hit was real, but not uniform. On standard SSD-equipped machines, the extra latency was in that 8-15 second window, mostly on profile load and script execution as mentioned. On older hardware or when the management server was under heavy load during a shift change, we saw spikes up to 25 seconds. That morning rush scenario really matters.
Your point about factoring it into TCO is key. We calculated an average of 10 seconds per login, twice a day, for our frontline staff. It added up to a meaningful number in lost productive time, which gave us leverage to negotiate a more aggressive pilot price while we worked on optimizations with the vendor.
Great point about collecting your own data. Those vendor white papers can be really optimistic.
I'm glad the login script exclusion helped. That was a lifesaver in our environment too. We found the benefit was even bigger for users who had complex scripts pulling data from multiple sources.
Did you notice any difference in the impact between local profiles and roaming profiles? For us, the scan delay on roaming profiles was much more pronounced.