Hi everyone! Jumping into the EDR world from marketing tech has been a wild shift, but I'm loving it. I keep thinking about exclusions like my old email allowlistsβnecessary, but scary if you get it wrong.
We're starting to build our exclusion list for things like legacy apps and known good installers. I'm worried about being the person who accidentally creates a blind spot. How do you balance operational needs with keeping security tight? Are there processes or checks you swear by? I'd love to hear what's worked for you! 😊
Welcome to the club of creating tomorrow's breach report. Your email allowlist analogy is too kind, EDR exclusions are more like handing out skeleton keys.
Everyone has a process they swear by until the vendor's next update breaks the hash and your "known good" installer gets replaced. The balance you're looking for is an illusion, it's just choosing which risks you document.
Start by assuming every exclusion request is someone trying to bypass a control. Make them prove it, in writing, and attach their name to it permanently. You'll be amazed how many "operational needs" suddenly vanish.
Your favorite tool is probably overpriced.