By NHI Mgmt Group Editorial TeamDomain: Cyber SecuritySource: ExpelPublished November 17, 2025

TL;DR: Market consolidation, platform packaging pressure, and AI hype are reshaping MDR buying decisions, according to Expel, while identity threats already account for over half of its investigations, per its interview with Justin Bajko. The real question is not whether AI can replace analysts, but how teams preserve control, flexibility, and detection quality as vendors bundle more capabilities into rigid platforms.


At a glance

What this is: This is an interview-driven analysis of MDR market consolidation, platformization, and AI use in security operations, with identity threats emerging as a major investigation driver.

Why it matters: It matters because SOC, IAM, and security leaders are being pushed to reassess where analyst-led services, embedded detections, and identity telemetry belong in their operating model.

👉 Read Expel's interview on AI-led MDR, platformization, and market consolidation


Context

MDR buying decisions are being shaped by platform consolidation, packaging rigidity, and the limits of one-size-fits-all security operations. For security leaders, the issue is not simply which vendor has more features, but whether the delivery model preserves visibility, control, and response quality across a changing threat surface. Identity telemetry sits inside that discussion because many modern investigations begin with account abuse, token misuse, or privileged access signals rather than classic malware alone.

The article frames a familiar security market pendulum. Customers want simplification, but they also need flexibility when workloads, identities, and attack paths do not fit a rigid bundle. In practice, that means the SOC model, the IAM programme, and the NHI governance layer increasingly overlap, because detection, identity, and response now operate as one operational loop rather than separate buying categories.


Key questions

Q: How should security teams evaluate MDR providers when platformization is increasing?

A: Teams should evaluate whether the MDR provider can preserve control fidelity across identity, cloud, endpoint, and application signals. The key test is not package breadth, but whether the service still supports customer-specific detections, tuning, escalation paths, and evidence collection without forcing a rigid operating model.

Q: Why do identity threats change the way SOCs should work?

A: Identity threats shift investigations upstream because attackers often abuse accounts, tokens, or privilege before triggering traditional malware indicators. That means SOCs need IAM, PAM, and NHI telemetry embedded in triage, not treated as a separate governance function. If identity signals are weak, the SOC sees abuse later and responds with less context.

Q: What do security teams get wrong about GenAI in the SOC?

A: They often assume the model reduces the need for analyst judgment. In practice, GenAI reduces reading and writing time, but the analyst still owns interpretation, prioritisation, and escalation. If the team uses the model to replace verification, it will amplify mistakes instead of reducing workload.

Q: How can organisations tell if MDR and identity governance are working together?

A: Look for identity-driven alerts that are resolved with clear ownership, timely escalation, and measurable reduction in repeat investigations caused by stale access or poor privilege scoping. If SOC and IAM teams operate separately, the organisation usually sees slower containment and more recurring identity-related cases.


Technical breakdown

Platformization in MDR: why packaging changes operational risk

Platformization in MDR is the shift from specialised services toward bundled security suites with standardised packaging, shared integrations, and broader feature sets. That can simplify procurement, but it also creates governance friction when customers need tailored response paths, niche detections, or tighter identity coverage. The core risk is not the platform itself. It is the loss of control over how detection content, analyst workflow, and escalation logic map to the customer’s actual environment. Practical programmes must test whether a bundled model still supports the identity and workload signals that drive real investigations.

Practical implication: validate that any MDR platform can preserve environment-specific detections and identity telemetry, not just broad coverage claims.

AI in the SOC: augmentation works better than replacement

AI in security operations is most defensible when it reduces analyst friction, accelerates triage, and improves detection engineering rather than claiming to replace human judgment. Expel’s interview reflects a broader industry pattern: the market is crowded with AI SOC messaging, but trust remains limited where autonomous decision-making meets high-stakes investigation. The important distinction is between vendor efficiency and customer security outcomes. A system that makes an analyst faster is useful only if it also improves containment quality, alert fidelity, and investigation depth.

Practical implication: assess AI features against investigation quality, false-positive reduction, and analyst decision support, not against automation claims alone.

Identity telemetry is becoming a primary SOC signal

Identity telemetry is increasingly central because adversaries often exploit credentials, sessions, tokens, and privilege pathways before triggering conventional endpoint or network alerts. When identity threats become the lead signals in more than half of investigations, the SOC is no longer operating on a malware-first model. That changes how detections, escalations, and response playbooks should be tuned. IAM and NHI governance now influence incident quality directly, because poor lifecycle controls or weak access scoping can turn routine authentication events into investigation drivers.

Practical implication: align SOC detections with IAM and NHI lifecycle controls so identity events are investigated with the same priority as endpoint alerts.


NHI Mgmt Group analysis

Platformization is changing security operations from feature selection to control preservation. When vendors bundle more capabilities into fewer packages, the hidden question is whether the customer can still enforce the controls they actually need. That matters in MDR because detection engineering, analyst workflows, and identity telemetry are not interchangeable. The programme risk is vendor convenience diluting operational fit, so practitioners should judge platforms by control fidelity, not bundle size.

AI SOC messaging is being pulled by market demand, but practitioner trust still depends on human-led operations. The article reflects a broader truth in SOC modernization: AI is most useful when it amplifies analysts, not when it replaces them rhetorically. In practice, high-value security operations still require judgment around context, privilege, and escalation. The field should therefore treat human-led, AI-supported MDR as the current operating baseline, not a transition state to fully automated response.

Identity threats are now a core security-operations signal, not a side channel. Expel’s comment that identity threats lead more than half of investigations shows how access abuse, credential misuse, and privileged activity shape SOC workload. That is a governance problem as much as a detection problem, because weak identity lifecycle controls increase investigative noise and real attacker opportunity. Security teams should treat IAM, PAM, and NHI governance as upstream SOC controls.

Detection quality will become the differentiator as MDR markets consolidate. If every vendor claims platform breadth and AI assistance, the practical discriminator shifts to whether detections stay tuned to the customer’s real environment. That includes identity-specific telemetry, environment-specific response logic, and clear ownership for tuning. This is where NIST CSF 2.0 and NIST SP 800-53 become useful reference points for governance and control mapping.

Named concept: identity-led MDR. This is the operating model where identity events, not only endpoint or malware alerts, shape the first investigative move. The implication is that identity hygiene, least privilege, and lifecycle governance become security operations inputs rather than separate IAM tasks. Teams that do not build for identity-led MDR will continue to miss the earliest signs of abuse.

What this signals

Identity-led MDR is becoming the practical operating model for modern SOCs. As more investigations begin with identity signals, teams need their SOC, IAM, and PAM owners to share a common triage model. That means authentication, privilege, and lifecycle events should be visible in the same workflows that handle endpoint and cloud alerts, with clear escalation paths into response.

The market is also signalling that AI will be judged on analyst augmentation, not on autonomy claims. For practitioners, that means procurement should focus on evidence quality, tuning effort, and how quickly the service can adapt to identity-heavy threats. The organisations that benefit most will be those that treat identity telemetry as a core detection input rather than a separate governance report.

Detection engineering will matter more as MDR services consolidate. If packaging gets broader and more rigid, the teams that retain security value will be the ones that insist on custom detections, identity-aware playbooks, and measurable response quality. That is consistent with NIST Cybersecurity Framework 2.0 thinking, especially where govern and detect must stay aligned.


For practitioners

  • Test MDR platforms against environment-specific use cases Ask providers to demonstrate how they handle your highest-value identity, cloud, and application scenarios, not just generic alert triage. Validate whether detections can be tuned without forcing your team into rigid packaging choices.
  • Map identity telemetry into SOC playbooks Ensure authentication anomalies, privileged account activity, token misuse, and service-account behaviour are explicit inputs to investigation and escalation playbooks. This closes the gap between IAM visibility and SOC action.
  • Separate AI assistance from AI autonomy in procurement Require vendors to show exactly which tasks are assisted by AI and which still depend on human review. Score the workflow on containment quality, analyst confidence, and false-positive reduction rather than marketing labels.
  • Re-evaluate identity ownership across SOC and IAM teams Define who tunes identity detections, who owns privileged access alerts, and who resolves lifecycle issues when an alert reveals stale access. Shared ownership prevents investigation delays and reduces handoff failure.

Key takeaways

  • MDR consolidation is not just a buying trend, it is a control-design issue that affects how well security teams can preserve fit, tuning, and response quality.
  • Identity is now a primary SOC input, because access abuse and privilege misuse often surface before conventional malware or endpoint indicators.
  • AI should be evaluated as analyst augmentation in MDR, with success measured by investigation quality, not by claims of human replacement.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

MITRE ATT&CK address the attack and risk surface, while NIST CSF 2.0, NIST SP 800-53 Rev 5 and NIST AI RMF set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0DE.CM-1SOC monitoring and identity telemetry are central to the MDR discussion.
NIST SP 800-53 Rev 5AU-6MDR quality depends on analysis and response tied to auditable events.
NIST AI RMFGOVERNAI-assisted SOC tooling needs clear accountability and oversight.
MITRE ATT&CKTA0006 , Credential Access; TA0004 , Privilege EscalationIdentity abuse is the investigation pattern driving this article's SOC focus.

Map identity alerts to ATT&CK credential-access and privilege-escalation tactics to sharpen detections.


Key terms

  • Platformization: The process of expanding a product into a broader integrated platform with shared data, logic, and workflows. In security terms, platformization concentrates authority and integrations, which can improve visibility but also increase the blast radius of a compromised credential or over-scoped role.
  • Product-led service: A product-led service is a delivery model where software capabilities and human expertise are combined as one operating offering. In security operations, it means the service is built around engineered workflows, embedded tooling, and measurable outcomes rather than analyst time alone.
  • Identity-led MDR: Identity-led MDR is an operating model where authentication, privilege, token, and lifecycle signals are treated as first-class security operations inputs. It recognises that many attacks begin with identity abuse, so the SOC and IAM programmes must work as one response loop.
  • Detection Engineering: The discipline of designing, testing, and maintaining detection logic so it remains useful against real attacker behaviour. It covers telemetry selection, rule quality, false-positive management, and the operational workflow needed to keep alerts actionable.

What's in the full article

Expel's full interview covers the operational detail this post intentionally leaves for the source:

  • How Expel thinks about AI-assisted detection engineering inside its analyst workflow
  • The company's view on platform packaging, customer choice, and MDR market consolidation
  • Justin Bajko's comments on why identity threats now dominate a large share of investigations
  • The product-led service model Expel says it is building across Workbench and Ruxie

👉 Expel's full interview adds more detail on AI strategy, customer packaging pressure, and identity-led investigations.

Deepen your knowledge

The NHI Foundation Level course, the industry's only accredited NHI security programme, covers NHI governance, secrets management, and machine identity security. It helps practitioners connect identity controls to wider security operations and lifecycle decisions.
NHIMG Editorial Note
Published by the NHIMG editorial team on August 20, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org