Using the Swiss Cheese model as a framework for defense in depth, this post explains how layered log sources and detection rules across endpoint, identity, cloud, and network domains create resilient security coverage. It walks through how to build a threat model per asset type, select the most valuable log sources when budget is constrained, and evaluate MDR providers using metrics like cost-per-detection, detection noise, and true positive rates. Asset-based vs. ingestion-based MDR pricing models are compared, with a scoring framework provided to help organizations choose the right vendor.

10m read timeFrom rapid7.com
Post cover image
Table of contents
The Swiss Cheese modelWhat are the “holes” of the cheese slice?How do we know what log sources and detections we need?Cheese with a complex flavor is nice, overly complex MDR pricing is notComparing solutions
46 Impressions