

Fidelis Security
By Fidelis Security
The implementation process for Fidelis Security software typically involves several key steps, designed to ensure a smooth deployment and integration into an organization’s existing security infrastructure. The overall timeline for implementation can vary based on the complexity of the deployment but generally takes 4 to 8 weeks. Here’s a breakdown of the typical process:
A kickoff meeting is held to understand the organization's specific security needs, existing infrastructure, and goals for using Fidelis Security solutions.
The Fidelis team conducts a thorough assessment of the current environment, identifying potential gaps in security and outlining a tailored implementation plan.
The software is configured according to the organization's requirements. This includes setting up network sensors, endpoint agents, and any necessary integrations with existing security tools.
The deployment phase involves installing the software across designated endpoints and network segments. This may include configuring bi-directional traffic decryption and establishing monitoring protocols.
Comprehensive testing is conducted to ensure that the software is functioning as intended. This includes validating detection capabilities and ensuring that alerts are generated appropriately.
Users receive training sessions tailored to their roles, covering how to navigate the platform, respond to alerts, and utilize reporting features effectively.
Once testing is complete and users are trained, the system goes live. Continuous monitoring begins to ensure that all functionalities are operational.
After deployment, Fidelis provides ongoing support to address any issues that arise and to assist with further optimization of the system.
This structured approach ensures that organizations can effectively leverage Fidelis Security’s capabilities while minimizing disruption during implementation.
Fidelis Security software can be customized extensively to meet specific business needs through various means:
Tailored Configuration: Organizations can configure various settings within the platform to align with their unique operational requirements, including custom alert thresholds, reporting formats, and user roles.
Integration with Existing Tools: The software supports integration with other security tools (e.g., SIEMs like Splunk or IBM QRadar), allowing organizations to build a cohesive security ecosystem that fits their workflows.
Custom Playbooks: Users can create automated response playbooks tailored to their specific incident response processes, ensuring that actions taken during a security event align with organizational policies.
Deception Technology Customization: The deception capabilities allow organizations to design custom decoys and traps that mimic their actual environment, helping lure attackers into controlled environments for analysis.
User Roles and Permissions: Organizations can customize user access levels based on roles within the company, ensuring that sensitive data is only accessible to authorized personnel.
While specific pricing details may vary based on factors such as deployment scale and chosen features, organizations should consider several potential additional costs beyond standard licensing fees:
Setup Fees: There may be initial setup fees associated with deploying the software, which could include costs for project management, configuration services, and integration with existing systems.
Maintenance Costs: Ongoing maintenance fees may apply for updates, patches, and technical support services. These costs can vary based on the level of service agreement chosen by the organization.
Support Charges: Organizations may incur charges for premium support services beyond standard offerings. This could include extended hours of availability or dedicated support personnel for critical issues.
Training Costs: While basic training may be included in initial implementation services, additional training sessions tailored to specific user groups or advanced functionalities may incur extra charges.
Additional Module Costs: If organizations opt for advanced modules or features (e.g., enhanced deception technology), these could come with additional licensing fees.
Organizations considering Fidelis Security should engage in discussions with sales representatives to obtain a comprehensive understanding of all potential costs associated with implementation, maintenance, and support services tailored to their specific needs.
Fidelis Security provides a robust training and support framework designed to help new users effectively utilize its software. The primary training resource is Fidelis Security University, which offers a variety of training options tailored to different levels of expertise:
Online Self-Paced Courses: Users can access a range of online courses that cover fundamental topics such as technology knowledge, architecture, user interface navigation, alert creation, policy management, metadata interpretation, and rule creation for network security.
Live Training Sessions: Fidelis offers live, remote, or in-person training sessions that provide interactive learning experiences. These sessions cater to various skill levels, from beginners to advanced users.
Intermediate and Advanced Courses: Beyond foundational knowledge, intermediate courses focus on investigations, threat hunting, and advanced rule writing. These courses include practical labs, lectures, and case studies to enhance threat detection and response skills.
Certificates of Completion: Participants receive certificates upon completing courses, which can be valuable for professional development.
Educational Webinars and On-Demand Demonstrations: Fidelis hosts webinars to discuss emerging threats and best practices, along with on-demand product demonstrations to familiarize users with specific functionalities.
Fidelis Security implements several robust measures to protect data within its platform:
Data Encryption: All sensitive data is encrypted both in transit and at rest using industry-standard encryption protocols. This ensures that data remains secure against unauthorized access during transmission and while stored.
Access Controls: The platform employs strict access controls, including role-based access management (RBAC), ensuring that users have appropriate permissions based on their roles within the organization. This minimizes the risk of unauthorized access to sensitive information.
Regular Security Audits: Fidelis conducts regular security audits and assessments to identify potential vulnerabilities within its systems. These audits help maintain compliance with industry standards and best practices.
Incident Response Protocols: The company has established incident response protocols to quickly address any potential security breaches or vulnerabilities. This includes monitoring for suspicious activity and implementing corrective actions as needed.
Compliance with Standards: Fidelis adheres to various compliance frameworks (e.g., GDPR, ISO 27001) that dictate stringent data protection measures. Compliance ensures that data handling practices meet legal and regulatory requirements.
Fidelis Security releases updates regularly to enhance its software capabilities:
Quarterly Updates: Major updates are typically released quarterly, incorporating new features, enhancements, bug fixes, and security patches based on user feedback and emerging threats.
Continuous Improvement Cycle: In addition to scheduled updates, Fidelis engages in continuous improvement practices where smaller patches or hotfixes may be deployed as needed to address urgent issues or vulnerabilities discovered in between major releases.
User Notifications: Users are notified in advance about upcoming updates through email communications or in-platform notifications. This allows organizations to prepare for any changes that may affect their operations.
Fidelis Security maintains a clear policy regarding data ownership and portability, emphasizing user control and compliance with applicable regulations. Here are the key aspects of their policy:
Data Ownership: Fidelis asserts that customers retain full ownership of their data processed through its platform. This means organizations have the right to access, manage, and control their data without interference from Fidelis.
Data Portability: The company supports data portability, allowing customers to export their data in a structured format. This ensures that organizations can easily transfer their data to other systems or platforms if needed, facilitating flexibility and adaptability in their IT environments.
Compliance with Regulations: Fidelis adheres to relevant data protection regulations, such as the General Data Protection Regulation (GDPR). This includes providing individuals with rights such as access to their personal data, rectification of inaccuracies, and erasure upon request.
Data Minimization Principle: Fidelis follows the principle of data minimization, collecting only the information necessary for specific tasks. This reduces the risk of data breaches and helps maintain a sense of ownership among customers.
Security Measures: To protect customer data, Fidelis implements robust security measures, including encryption and access controls. These measures ensure that data remains secure throughout its lifecycle.
Fidelis Security offers flexible terms for scaling its services up or down based on an organization's evolving needs. Key points regarding this scalability include:
Flexible Licensing Options: Organizations can choose from various licensing models that allow them to adjust their subscriptions based on changing requirements. This flexibility enables businesses to scale their usage without incurring unnecessary costs.
Modular Features: The platform's modular architecture allows organizations to add or remove features as needed. For example, if a business grows or changes its operational focus, it can easily integrate new functionalities or discontinue those no longer required.
Support for Multiple Environments: Organizations can scale the Fidelis solution across different environments (e.g., production, development) without needing separate licenses for each environment. This simplifies management and reduces costs.
Customizable User Roles: As organizational needs evolve, Fidelis allows for adjustments in user roles and permissions within the platform. This ensures that users have appropriate access based on current business requirements.
Consultative Approach: Fidelis typically engages in consultative discussions with clients regarding scaling needs. This approach helps identify opportunities for optimization and ensures that the solutions provided align with strategic goals.
Fidelis Security has established specific terms and conditions regarding contract renewal and cancellation, which are outlined in their agreements. Here are the key points:
Automatic Renewal: Contracts for Fidelis Security products typically include an automatic renewal clause. After the initial term, the agreement automatically renews for successive one-year terms unless either party provides written notice of termination or non-renewal at least 30 days prior to the renewal date.
Support Contracts: For support services, customers must issue a purchase order (Support PO) for renewal before the expiration date to prevent a lapse in service. If a Support Contract lapses without renewal, the customer may have to pay a reinstatement fee to regain access to support services.
Pricing: Upon renewal, the terms will generally be at the then-current prices unless otherwise specified in the purchase order. This allows Fidelis to adjust pricing based on market conditions or service enhancements.
Termination by Customer: Customers can terminate the agreement by providing written notice and returning all copies of the product. Upon termination, licenses granted under the agreement are revoked, and customers must cease all use of the product.
Termination for Cause: Either party may terminate the agreement if the other party fails to cure a material breach within a specified period after receiving written notice.
Fidelis Security software meets several critical compliance standards that ensure its solutions adhere to industry regulations and best practices. Here are some of the key compliance frameworks:
General Data Protection Regulation (GDPR): Fidelis adheres to GDPR requirements governing data protection and privacy for individuals within the European Union. This includes provisions related to data processing, user consent, and data subject rights.
Federal Risk and Authorization Management Program (FedRAMP): Fidelis aims to meet FedRAMP standards for cloud services used by federal agencies, ensuring that security assessments are conducted for cloud products.
Health Insurance Portability and Accountability Act (HIPAA): For clients in healthcare, Fidelis ensures compliance with HIPAA regulations concerning the protection of patient health information.
Payment Card Industry Data Security Standard (PCI DSS): For organizations handling credit card transactions, Fidelis adheres to PCI DSS requirements, ensuring secure processing of cardholder data.
ISO/IEC 27001: The company aligns with ISO/IEC 27001 standards for information security management systems (ISMS), demonstrating a commitment to managing sensitive company information securely.