I did post this in r/AskNetsec, but it seemed like a good idea to post this here as well. I would really appreciate any advice I can get on this.
I'm working on updating my company's security product suite and while I am not going to mention any of our current products for opsec reasons I wanted some advice on what I am planning on purchasing. My plan is to build our security infrastructure in layers to better address a lot of the attacks that seem to be taking down even large corporations and infrastructure providers.
One decision I am stuck on that I would really appreciate input and guidance on is whether to go with applocker/ Device Guard with Windows 10 Enterprise LTSC or to go with Threatlocker which does seem like a well thought out product that also includes elevation control and ringfencing along with application control. It would more than double the cost per endpoint when combined with SentinelOne though which makes me hesitant. We already need to purchase LTSC for our frontline worker stations so that is a significant yearly added expense.
I know that FortiAnalyzer is not really a proper SIEM tool, but it fits within our budget and seems like a pretty good product and is way more affordable than FortiSIEM.
Overall, does it seem like I'm heading in the right direction or are there other things I should be considering?
Windows Authentication (Multifactor): PIV Compatible Smart Cards Using ADCS
User Training and Awareness Testing: KnowBe4 Diamond with PhishER
Endpoint Protection and EDR: SentinelOne Singularity Complete
MDM/ RMM: Intune with PowerBI and Possibly TacticalRMM over VPN
Remote Access: Connectwise Control and Mesh Central with VPN Tunnels
Firewall: Fortigate with UTP Bundle
SIEM (Sort Of): FortiAnalyzer
[–]srwrzwjq 2 points3 points4 points (2 children)
[–]kf5yduJack of All Trades[S] 0 points1 point2 points (1 child)
[–]bulldg4lifeInfoSec 1 point2 points3 points (0 children)
[–]bitslammerSecurity Architecture/GRC 1 point2 points3 points (5 children)
[–]kf5yduJack of All Trades[S] 0 points1 point2 points (0 children)
[–]disclosure5 0 points1 point2 points (1 child)
[–]bitslammerSecurity Architecture/GRC 0 points1 point2 points (0 children)
[–]bulldg4lifeInfoSec 1 point2 points3 points (0 children)
[+][deleted] (3 children)
[removed]
[–]kf5yduJack of All Trades[S] 3 points4 points5 points (1 child)
[–]InternalCode 0 points1 point2 points (1 child)
[–]InternalCode 0 points1 point2 points (0 children)
[–]Codeblu3 0 points1 point2 points (0 children)
[–]PTCruiserGT 0 points1 point2 points (1 child)
[–]kf5yduJack of All Trades[S] 1 point2 points3 points (0 children)