MDR Has To Stop Mopping The Floor

Threat Talks infographic

Find Threat Talks on

A CISO got breached and could not say how it happened. No entry point, no list of what left. He paid the ransom blind. So he bought MDR, and the next time he had the full picture: who clicked, which data was accessed, when it left the building. Same outcome.

Detection done well is a mop. It tells you how big the puddle is, in high resolution, after the fact.

Lieuwe Jan Koning, Co-founder & CTO at ON2IT, recorded this one on the floor at RSA Conference with Nicholai Piagentini, Technical Enablement Engineer at ON2IT and twenty years in the Bay Area security market. Nicholai has watched vendor after vendor put an M in front of whatever they already sold. The result is a category where the letters no longer tell you what you are buying. If MDR is on your shortlist this year, this is the conversation to have before the contract, not after.

What you’ll learn

 

  • The M is negotiable. For many vendors, managed means logs get collected, not that an experienced human acts on them.
  • Every vendor skins MDR as their own product. EDR, NDR, XDR and DDR all get the same label, so scope quietly shrinks to whatever they already sell.
  • Your log bill is priced as hot storage. Vendor data lakes keep everything searchable, so you pay top rate per terabyte with no path to warm or cold.

Your cybersecurity experts

Lieuwe Jan Koning

Co-Founder and CTO
ON2IT

Nicholai Piagentini

Nicholai Piagentini

Technical Enablement Engineer
ON2IT

Episode details

Buyers walk the expo floor with a clear mental model of what MDR does. One place to send every security-relevant log. Enrichment and analysis on top. An extension of the SOC. Clear remediation, ideally automated. A data lake to look back through. Five jobs bundled into one term. Nicholai’s point is that no single vendor delivers all five, and the ones who come closest do it only inside their own ecosystem.

The reason is commercial, not technical. A vendor can consume any log you send it, that is what a SIEM does. What it cannot do profitably is give a competitor’s telemetry the same enrichment and analysis it gives its own. Every hour spent making a rival’s endpoint logs shine is an hour that does not create a reason to replace that endpoint. So cross-vendor support exists, but at lower fidelity. The demo looks seamless because the demo runs on the vendor’s own stack. Nicholai’s test is blunt: push an external log in on purpose and watch whether the platform stitches it to anything meaningful.

Storage is where the bill escapes. The industry already solved tiering years ago, with hot, warm and cold at wildly different price points. Pipe your logs into a vendor data lake and that solution disappears. Everything has to stay searchable, so everything stays hot, and you buy it through your MDR contract rather than direct from a storage provider. Then you discover you generate more logs than the ROI model assumed. Ask whether tiering exists at all before you commit to a retention number.

Which leaves the question the episode ends on. The CISO with full forensic visibility got breached again anyway. Detection and response, done well, tells you exactly how you lost. That is worth something, but it is cleanup, not prevention. Lieuwe Jan and Nicholai park the fix for a follow-up episode on where MDR goes next.

Three questions for any vendor conversation, before the contract:

  • In practice, what does your platform do with a log it did not create?
  • Ask for that demo on a competitor’s telemetry. Is there tiered storage, or does every log stay hot for the life of the contract?
  • When I escalate, who picks up, and do they know my environment?
Threat Talks infographic

Get your Hacker T-shirt

Join the treasure hunt!

Find the code within this episode and receive your own hacker t-shirt for free.

9 + 5 =

Christmas Hacker