TL;DR: Market consolidation, platform packaging pressure, and AI hype are reshaping MDR buying decisions, according to Expel, while identity threats already account for over half of its investigations, per its interview with Justin Bajko. The real question is not whether AI can replace analysts, but how teams preserve control, flexibility, and detection quality as vendors bundle more capabilities into rigid platforms.
NHIMG editorial — based on content published by Expel: an interview with Justin Bajko on MDR strategy, AI hype, and market change
Questions worth separating out
Q: How should security teams evaluate MDR providers when platformization is increasing?
A: Teams should evaluate whether the MDR provider can preserve control fidelity across identity, cloud, endpoint, and application signals.
Q: Why do identity threats change the way SOCs should work?
A: Identity threats shift investigations upstream because attackers often abuse accounts, tokens, or privilege before triggering traditional malware indicators.
Q: What do security teams get wrong about GenAI in the SOC?
A: They often assume the model reduces the need for analyst judgment.
Practitioner guidance
- Test MDR platforms against environment-specific use cases Ask providers to demonstrate how they handle your highest-value identity, cloud, and application scenarios, not just generic alert triage.
- Map identity telemetry into SOC playbooks Ensure authentication anomalies, privileged account activity, token misuse, and service-account behaviour are explicit inputs to investigation and escalation playbooks.
- Separate AI assistance from AI autonomy in procurement Require vendors to show exactly which tasks are assisted by AI and which still depend on human review.
What's in the full article
Expel's full interview covers the operational detail this post intentionally leaves for the source:
- How Expel thinks about AI-assisted detection engineering inside its analyst workflow
- The company's view on platform packaging, customer choice, and MDR market consolidation
- Justin Bajko's comments on why identity threats now dominate a large share of investigations
- The product-led service model Expel says it is building across Workbench and Ruxie
👉 Read Expel's interview on AI-led MDR, platformization, and market consolidation →
AI-led MDR and platformization: what do security teams do now?
Explore further
Platformization is changing security operations from feature selection to control preservation. When vendors bundle more capabilities into fewer packages, the hidden question is whether the customer can still enforce the controls they actually need. That matters in MDR because detection engineering, analyst workflows, and identity telemetry are not interchangeable. The programme risk is vendor convenience diluting operational fit, so practitioners should judge platforms by control fidelity, not bundle size.
A question worth separating out:
Q: How can organisations tell if MDR and identity governance are working together?
A: Look for identity-driven alerts that are resolved with clear ownership, timely escalation, and measurable reduction in repeat investigations caused by stale access or poor privilege scoping. If SOC and IAM teams operate separately, the organisation usually sees slower containment and more recurring identity-related cases.
👉 Read our full editorial: AI-led MDR platformization is reshaping SOC strategy choices