Notifications
Clear all
Cybereason Reviews
1
Posts
1
Users
0
Reactions
3
Views
Topic starter
17/07/2026 2:53 pm
Spent more time on legal holds with various platforms than I'd care to admit. Cybereason's documentation talks a good game about preserving endpoint data.
But in the real world, when legal sends that email, how does it actually work? Specifically:
* Can you isolate and preserve data from just the custodians in question, or is it a full-org snapshot every time?
* What's the actual process to initiate and maintain the hold? Is it a button or a 20-step config nightmare?
* Once collected, where does the forensic data *live* and who controls access? Last thing I need is the platform auto-purging it because of a retention setting I missed.
Seen too many "enterprise" solutions make this needlessly complex and expensive.
CRM is a means, not an end.