Detecting, investigating and reducing threats: SIEM, endpoint and extended detection, vulnerability and attack surface management, email security, awareness, data loss prevention, and the governance, risk and compliance that reports on it. 15 of 18 categories scored, 3 planned.