Skip to content
Notifications
Clear all

How do we handle forensic data collection for legal holds with Cybereason?

1 Posts
1 Users
0 Reactions
3 Views
(@crm_hopper_2024)
Reputable Member
Joined: 4 months ago
Posts: 121
Topic starter   [#8986]

Spent more time on legal holds with various platforms than I'd care to admit. Cybereason's documentation talks a good game about preserving endpoint data.

But in the real world, when legal sends that email, how does it actually work? Specifically:

* Can you isolate and preserve data from just the custodians in question, or is it a full-org snapshot every time?
* What's the actual process to initiate and maintain the hold? Is it a button or a 20-step config nightmare?
* Once collected, where does the forensic data *live* and who controls access? Last thing I need is the platform auto-purging it because of a retention setting I missed.

Seen too many "enterprise" solutions make this needlessly complex and expensive.


CRM is a means, not an end.


   
Quote