Join our Newsletter — 33% off our NHI Course

Notifications
Clear all

AI-led MDR and platformization: what do security teams do now?


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 18936
Topic starter  

TL;DR: Market consolidation, platform packaging pressure, and AI hype are reshaping MDR buying decisions, according to Expel, while identity threats already account for over half of its investigations, per its interview with Justin Bajko. The real question is not whether AI can replace analysts, but how teams preserve control, flexibility, and detection quality as vendors bundle more capabilities into rigid platforms.

NHIMG editorial — based on content published by Expel: an interview with Justin Bajko on MDR strategy, AI hype, and market change

Questions worth separating out

Q: How should security teams evaluate MDR providers when platformization is increasing?

A: Teams should evaluate whether the MDR provider can preserve control fidelity across identity, cloud, endpoint, and application signals.

Q: Why do identity threats change the way SOCs should work?

A: Identity threats shift investigations upstream because attackers often abuse accounts, tokens, or privilege before triggering traditional malware indicators.

Q: What do security teams get wrong about GenAI in the SOC?

A: They often assume the model reduces the need for analyst judgment.

Practitioner guidance

  • Test MDR platforms against environment-specific use cases Ask providers to demonstrate how they handle your highest-value identity, cloud, and application scenarios, not just generic alert triage.
  • Map identity telemetry into SOC playbooks Ensure authentication anomalies, privileged account activity, token misuse, and service-account behaviour are explicit inputs to investigation and escalation playbooks.
  • Separate AI assistance from AI autonomy in procurement Require vendors to show exactly which tasks are assisted by AI and which still depend on human review.

What's in the full article

Expel's full interview covers the operational detail this post intentionally leaves for the source:

  • How Expel thinks about AI-assisted detection engineering inside its analyst workflow
  • The company's view on platform packaging, customer choice, and MDR market consolidation
  • Justin Bajko's comments on why identity threats now dominate a large share of investigations
  • The product-led service model Expel says it is building across Workbench and Ruxie

👉 Read Expel's interview on AI-led MDR, platformization, and market consolidation →

AI-led MDR and platformization: what do security teams do now?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 18527
 

Platformization is changing security operations from feature selection to control preservation. When vendors bundle more capabilities into fewer packages, the hidden question is whether the customer can still enforce the controls they actually need. That matters in MDR because detection engineering, analyst workflows, and identity telemetry are not interchangeable. The programme risk is vendor convenience diluting operational fit, so practitioners should judge platforms by control fidelity, not bundle size.

A question worth separating out:

Q: How can organisations tell if MDR and identity governance are working together?

A: Look for identity-driven alerts that are resolved with clear ownership, timely escalation, and measurable reduction in repeat investigations caused by stale access or poor privilege scoping. If SOC and IAM teams operate separately, the organisation usually sees slower containment and more recurring identity-related cases.

👉 Read our full editorial: AI-led MDR platformization is reshaping SOC strategy choices



   
ReplyQuote
Share: