Security

Pargo Networks to Restructure Around MDR This Year, Expand 'SOC Service' Business

IT DAILY ·

권영목 파고네트웍스 대표. (사진: 김병주 기자)

✦ AI Summary

Pargo Networks plans to overhaul its business structure within the year and expand from an MDR-centered model to SOC service (SOC as a Service).

The company officially launched three services centered on its own security operations platform, DeepACT: DeepACT DEFENSE, DeepACT ATTACK, and DeepACT Detection-Engineering.

It is pushing a structure in which AI handles repetitive analysis and detection rule writing, while security specialists focus on risk judgment and response prioritization.

Pargo Networks will overhaul its business structure within the year. Since 2017, the company has built up MDR operations capabilities, and based on that foundation, it plans to expand beyond its existing support for client threat detection, analysis, and response into broader security operations support.

The expanded scope of support will include pre-attack risk validation and the upgrading of detection systems. The restructuring direction is to broaden the focus from MDR to SOC service (SOC as a Service), and the scope of SOC service is support for the overall security operations of companies.

The reorganization of security operations will be carried out in a way that AI handles repetitive analysis and detection while security specialists focus on risk assessment and response. Through this, the company aims to change the structure of its security operations support.

On the 1st, Pargo Networks CEO Kwon Young-mok held a press briefing at Grand InterContinental Seoul Parnas in Gangnam-gu, Seoul, and said it would continue using the term MDR until the end of December this year. He added that, as a short-term plan, the company will evolve into an SOC service provider from the perspective of threat detection and response.

The company officially launched three services centered on its own security operations platform, DeepACT, that day. The newly released services are DeepACT DEFENSE, DeepACT ATTACK, and DeepACT Detection-Engineering. DeepACT DEFENSE handles risk validation from a defensive perspective, DeepACT ATTACK handles risk validation from an attacker's perspective, and DeepACT Detection-Engineering handles the upgrading of detection systems.

Information gathered across these three areas is linked into a single security operations process. Through this, the company has established a structure that connects defensive validation, attacker-perspective validation, and detection-system enhancement around DeepACT.

Among them, DeepACT DEFENSE is a blue team service operated on the basis of the client's security environment, including EDR, NDR, and XDR. The service performs 24-hour threat detection, analysis, and response, and includes functions for delivering alerts and response measures. It also judges the actual severity of threats, determines response priorities, and has expanded its service scope in the direction of carrying out necessary blocking and isolation measures.

Pargo Networks inspects vulnerabilities and identifies risks that should be addressed first through DeepACT ATTACK, a red team service that first targets enterprise infrastructure and checks in advance for weak points from an attacker's perspective. DeepACT ATTACK combines attack surface management (ASM), AEV, AI red teaming, and dark web intelligence, and is equipped to verify whether discovered vulnerabilities can actually be linked to attacks and to validate attack paths.

DeepACT Detection-Engineering then uses global threat intelligence such as Google Threat Intelligence (GTI), SentinelLabs, and CrowdStrike Falcon Intelligence, along with frontier AI, to automate the process of discovering new threats and turning them into actual detection rules. In this process, newly identified IOC and attack techniques are handled and converted into detection logic for use in the client's security solutions, while confirmed attack paths and threat information produced by DeepACT ATTACK are also reflected in threat hunting and detection engineering.

The three services operate in an integrated manner, using threat hunting and detection-engineering results in the DeepACT DEFENSE detection and response system. Pargo Networks plans to use this to build a cyclical structure that runs from risk validation before an attack occurs to the detection and response of actual threats.

Pargo Networks said on the 1st that it held a press briefing and that CEO Kwon Young-mok announced the launch of three services centered on its own security operations platform, DeepACT. In its DeepACT-based service plan, the company is first deploying AI to repetitive and standardized security tasks, and it identified repetitive analysis and the writing of detection rules as areas for AI use.

As an example, the company said that while a traditional analyst needed about 2 hours for threat hunting, the AI and detection-engineering use case reduced threat hunting to about 5 minutes. It also said that in analyses linking multiple pieces of malware, it is verifying time savings of 60% to 70% compared with the previous process.

However, the company said that security analysts still take part in the final threat determination. It also said that it applies Human-in-the-loop intervention during the stage of reviewing enterprise work environments and context, including threats related to critical systems.

CEO Kwon said that roughly 70% of work in specific areas is handled by AI, while roughly 30% involves team intervention. He added that AI's role is large-scale data analysis and handling repetitive work, while security specialists are responsible for analyzing threat context and actual impact, as well as determining response priorities.

Pargo Networks cited a bottleneck in security operations caused by growing volumes of alerts and threat data analysis as customer numbers and security products increased, and it used that as the backdrop for expanding AI use. CEO Kwon said that as AI use became fully underway in the first half of this year, the focus of security operations shifted from the number of detections to detection speed, judgment accuracy, and actual response capabilities.

Pargo Networks' main target customers are companies that lack their own security operations staff. CEO Kwon identified its core customer base as companies with annual revenue of KRW 500 billion to KRW 5 trillion.

Among these core customers, there are many cases in which the SOC staff size is 3 to 5 people, and at most around 10 people. For that reason, he said, a small SOC team bears the burden of handling compliance and actual threat response at the same time.

Pargo Networks has more than 300 client companies. The company is designing new services based on existing customer needs, and DeepACT ATTACK is cited as an example of a new service under design. The scope of design covers functions and business models.

Pargo Networks is expanding overseas hubs for 24-hour operations, and in June it established a Toronto, Canada branch and MDR center. It then said it plans to dispatch 4 domestic MDR staff members there on September 5 and to operate a 1- to 3-year rotational work system. The company intends to run a 24-hour in-house response system by linking weekday shifts on both sides using the time difference between Korea and Canada.

Meanwhile, after the August acquisition by LG Uplus, Pargo Networks will continue maintaining its existing business, and it will also keep its plan to launch DeepACT after the acquisition. It said the existing business will proceed as originally planned, and the launch of the DeepACT platform will also proceed as originally planned.

CEO Kwon said that the acquisition terms included internalizing Pargo Networks' MDR capabilities within LG Uplus and strengthening security. He also said there would be no change in the company name and no outward change in his position as CEO. In addition, he explained that there are currently no discussions about dispatching LG Uplus personnel to Pargo Networks and no discussions about changing management positions.

CEO Kwon said that security operations will not immediately reach a fully autonomous stage. He said the current operating model is moving toward expanding the scope of AI processing, but that security specialists will continue to judge risk context and decide whether to respond.

He then defined Autonomous SOC as AI independently carrying out security operations judgment and response, and said Autonomous SOC is expected to become a reality in 2 to 4 years. He added that AI will not replace existing analysts, but it can significantly reduce the time needed for current tasks, and accordingly analysts should focus on more important decision-making and upgrade their roles.

Source: IT DAILY · Kim Byung-ju
Original: https://www.itdaily.kr/news/articleView.html?idxno=241333

References

This article was produced with the help of an automated content generation algorithm.


Source: IT DAILY

View original

This article was summarized and organized by BizCrush based on the original article from IT DAILY. For exact quotations and full details, please refer to the original article.