Episode
218

Playbook: Buying MDR Without Getting Burned

July 28, 2026

Six months before the largest retail breach in U.S. history, Target's threat detection system worked exactly as it was supposed to. It caught the attack. It fired five separate alerts. Then nothing happened, because the system could watch, but it couldn't act.

That gap between detecting a threat and stopping it is where most MDR contracts fail their buyers. Max Clark recently evaluated a well known provider for ITBroker's own portfolio and found the same gap hiding under the brand name: full "Manage Detection and Response" on paper, watch and email in practice. He breaks down why that one distinction decides whether you're protected or just informed, and the exact questions that expose which one you actually bought.

Find Your Situation

  • Our provider says they offer MDR. How do I know if they can actually stop an attack, or just tell me about it? → Jump to 12:45
  • Our dwell time metric keeps improving. Is that actually good news? → Jump to 05:45
  • Should we build a 24/7 internal security team instead of outsourcing to MDR? → Jump to 08:00
  • We bought security tools and I'm not sure they're actually deployed correctly. What should I check? → Jump to 09:15
  • What does real data say about self managed security versus paying for real MDR? → Jump to 11:30

The Playbook

  • 01:30 The three questions almost nobody asks before they sign
  • 03:00 Why watch and notify is the same as having no SOC at all
  • 04:00 Why attackers now move faster than your team can respond
  • 05:45 Why falling dwell time isn't the win the industry sells it as
  • 07:00 Why 40% of security alerts never get investigated
  • 08:00 The real math behind staffing a 24/7 security operation
  • 09:15 Shelfware and the deployment gap nobody owns
  • 10:15 The default setting question, and why opinionated vendors are the safer choice
  • 11:30 What real cyber insurance claims data proves about self managed EDR vs. real MDR
  • 12:45 The exact questions that cut through the brochure

Resources Mentioned

  • CrowdStrike breakout time research, the source behind this episode's attacker speed data.
  • Mandiant dwell time research, the source behind the dwell time and ransomware-specific recovery figures.
  • A real cyber insurance ransomware claims study, the source behind the recovery time and claim size comparison.

About Signed

Signed is the podcast for buyers in a market built for sellers. Playbooks are the solo format, 10 to 15 minutes, one trigger, one specific play. New episodes weekly at itbroker.com/podcast.

Transcript

Max Clark (00:00)

They could see, but they couldn't touch. They could tell you the house was on fire. They could not pick up a hose.

clock didn't shrink because we got better at catching them. It shrank because they got better at finding what's valuable and monetizing it fast.

A powerful tool with nobody to truly wield it didn't just underperform. On recovery, it did worse than having less because it manufactured a feeling of protection that wasn't

This is signed to the podcast for buyers and a market built for sellers. I'm Max Clark, CEO of ITbroker.com. Today's playbook is about one of the most consequential things a company will buy and one of the easiest to buy badly: Manage Detection and Response, or MDR, or Manage SOC, a security operations center you rent instead of build.

I just sat through an evaluation of a provider with a very big name in this industry, a name you'd recognize. They wanted into our portfolio. And what I found underneath the brand was alarming. They were selling MDR, but when you looked at what they actually did, it was detection and notification. Watch and tell you, nothing more. And I want to walk you through why that is that why that one distinction is the whole game. Let's get into it. And start here because the whole industry is built to make you forget it.

Cybersecurity is about people as it is about tooling. The vendors sell you the tool, the dashboard, the AI, the threat feed, and the tool matters, but the tool is maybe half of it. The other half is three questions almost nobody asks before they sign. Who is watching? Who is taking action? And what is the default? That third one, what's the default, is the most important question in the entire purchase. And it's the one buyers almost never ask. I'll come back to it because it's where the real money and the

Real risk live. For now, just hold all three. Who watches, who acts, what's the default? Every failure in this category traces back to one of them. Back to that provider I evaluated. On the brochure, manage detection and response. In practice, they'd watch your environment and when something looked wrong, they'd send you a notification. That was it. Zero bidirectional integration with your security tools. They could see, but they couldn't touch. They could tell you the house was on fire. They could not pick up a hose.

In practice, that's the same thing as having no sock at all. Think about what actually has to happen during an attack. Something malicious fires, somebody has to investigate. Is it real or is it noise? Somebody has to decide what to do. And then somebody has to do it. Isolate the machine, kill the process, disable the account, pull the device off the network. Whatever. If your MDR provider stops at, we'll send you an email and then every one of those steps still lands on your internal team at two in the morning on a holiday weekend while the clock is running.

That is exactly what happened to Target. The external eyes worked, the handoff to the people who could act broke, and the gap between detecting and doing is where almost everyone gets burned. Here's why this is worse today than it has ever been. Speed. CrowdStrike tracks something called breakout time, how long it takes an attacker once they're in to move from the first machine out across the rest of your network. In 2021, that number was about 98 minutes. In their 2026 report, the average is 29 minutes.

The fastest breakout they recorded was 27 seconds. And in one case, data started leaving the building four minutes after the attacker got in. Four minutes. Most companies can't get the right people onto a call in four minutes, let alone investigate and contain a live intrusion. So if your security model is the vendor notices, emails us, and then our team logs and figures out what to do, you've already lost. The notification arrives, the attacker is three rooms deeper into your house.

Now here's a number the industry waves around as good news, and I want to reframe it for you. Dwell time. The gap between when an attacker gets in and when they're discovered has collapsed. A decade ago, the median was over 200 days. Today Mandiat puts it around two weeks. For ransom more specifically, it's about five days. Sounds like a win, right? We're catching them faster, but we're mostly not. Look at why that number fell. The fastest shrinking category is breaches where the attacker tells you in a ransom note.

The medium there is five days, and it's not because your defense has spotted anything. It's because the attacker finished the job and popped up asking for money. The clock didn't shrink because we got better at catching them. It shrank because they got better at finding what's valuable and monetizing it fast. The window between breaking and real damage used to be months. Now it's days, sometimes minutes. A service that only watches and notifies was already too slow for the old clock. Against this one, it isn't even in the game.

So why does the Human Capacity to Act fail so reliably? Two reasons the noise and the math. Start with the noise. The average enterprise security operation gets thousands of alerts a day across dozens of tools, and more than half are false positives. Survey after survey finds the same thing. Roughly 40% of alerts are never investigated at all. And in one 2025 study, 61% of security teams admitted they had ignored an alert that later turned out to be a real incident. That's the target story again, just at industry scale.

The detection usually isn't what fails. What fails is the human capacity to act on what the detection found. Here's something I do when I sit down with a new IT team. I ask them to show me the email folder where all their security alerts pile up. And I'm not doing it to catch them being negligent. I'm doing it to make a point. That folder has thousands of unread messages in it. These are good people. They're not lazy. They simply do not have the time to even attempt to keep up with the fire hose of noise that modern security tooling generates.

Your IT team is already saturated with actual IT work. Keeping the business running, the tickets, the projects, the migrations. Asking them to also be a 24-7 security operation on top of that isn't a stretch gold. It's physically impossible. And here's the math that proves it. To cover one seat around the clock, one person watching 247-365, you need about seven full-time employees. Do the math. A week has 168 hours. A person works 40. So just for the raw hours, you're over four people.

Then advocation, sick days, training, and the rule that you never stand a lone analyst on a 3 a.m. shift and no backup, and you land at six or seven. And that's for one seat, not a team, not a bench of specialists across different kinds of threats, one chair filled around the clock. Hiring those people, training them and keeping them in a market with a multi-million person talent.

Hiring those people, training them, and keeping them in a market with a multimillion person talent shortage where everyone is fishing for the same hires is brutally hard and brutally expensive. This is the entire reason professional 24-7 MDR exists: to cut through the noise, surface the handful of events that actually matter, investigate them, and take action at a scale no single company your size can staff for. You're not buying alerts. Alerts are abundant and worthless. You are buying.

Decisive action on the handful that matters. And done right with a real contract and a real SLA behind it that runs less than the loaded cost of a single full-time hire per thousand employees. We negotiate hard, so our clients do better than that. But even at market rate, you're getting an entire around the clock operation for less than one analyst you couldn't reliably hire, anyways. Let me widen the lens because this connects to a problem bigger than just MDR.

A staggering amount of security gets bought and never actually works. Not because the product is bad, because nobody owned getting it deployed, configured, and finished. The research is brutal. One report found the average enterprise runs around 45 security tools and uses fewer than half of them on a given day. Another found 71% of organizations admit most of their security tools are underutilized. Roughly a fifth of the software companies pay for is pure shelfware, bought, never deployed, and misconfiguration.

Tools installed but left on default settings or available but never actually turned on is one of the most common ways attackers get in. Here's a through line: a half-deployed security tool isn't neutral. It's worse than nothing because it makes you feel protected when you're not. And the reason these deployments stall is almost always the same. No clear ownership. The vendor assumes the customer will finish it. The customer assumes the vendor handled it. So it sits there, half configured on defaults. Nobody chose on purpose.

Which brings me back to that third question. What's the default? When you turn the service on, what does it actually do out of the box before you touch anything? Does it isolate a compromised machine automatically or wait for a human to click yes? Who chose that setting? You or an onboarding script three years ago? The default is what protects you on the worst night of the year when nobody's watching and nobody's awake to make a decision. If you don't know your defaults, you don't know what you bought. So what should good look like?

Your MDR provider should be flexible, but they should also be opinionated. And I want to be specific because opinionated vendor sounds like a red flag and it's actually the opposite. Most companies are not cybersecurity experts. That's the whole reason you're outsourcing this in the first place. So when a provider has no point of view, when they just say, just tell us how you want it configured and we'll do whatever you say, that's not flexibility. That's abdication. They're handing the hardest expert decisions back to the customer who already admitted they're not the expert.

A good provider tells you how the program should be designed to actually work. They have defaults you believe in. They'll push back on you. They care whether the deployment gets finished because they own the outcome, not just the alert. Flexible enough to fit your environment, opinionated enough to tell you when you're about to make a mistake. That combination is rare and it's exactly what you should be screening for. If all this still sounds like my opinion, let me give you the receipts. And they come from the one party with no incentive to be wrong about the risk.

The insurers paying the claims. A study of real cyber insurance ransomware claims broke the victims out by what security they actually had in place. The results are stark. Companies running self-managed EDR, a strong detection tool but operated in-house, had a median recovery time of 55 days and a median claim of around $500,000. Company with a real MDR service, median recovery of three days, median claim of about $75,000.

Sit with that gap. Same class of attack. The difference isn't the tooling. EDR is a capable tool. The difference is that one group had experts operating it around the clock and acting, and the other had the tool sitting on top of a saturated internal team. 55 days versus three, half a million dollars versus 75,000. And here's the kicker that ties this whole episode together. And that same data, the self-managed EDR group, actually recovered slower than companies with only basic no-frills endpoint protection.

A powerful tool with nobody to truly wield it didn't just underperform. On recovery, it did worse than having less because it manufactured a feeling of protection that wasn't real. That's the entire thesis of this episode. Sitting in an insurance actuary spreadsheet. Detection is a tool, protection is people acting on it. Okay, so you're evaluating a provider. Here are the questions that cut through the brochure. Write these down. When an event happens, walk me through exactly what takes place.

Not the marketing version, the literal sequence. Who investigates, who decides on the remediation, who executes it?

Can you take action or only notify? This is the one that exposed the provider I just evaluated. Ask it flat out. Can you isolate a host, kill a process, disable an account, pull a device off the network yourselves without waiting on my team? If the answer is we notify and you act, you're buying detection and praying for protection. Do you have bi directional integration with all my security tooling? The EDR on my endpoints, my email security gateway, my SASE and network layer.

Bidirectional means they can both see it and control it. One direction is a smoke detector, two directions is a sprinkler system. When speed is the entire game, are you designed for it? Or are there approval steps and limitations baked in? That guarantee that you'll be too slow to matter when it counts. What are the defaults? Who set them? And what happens automatically with no human in the loop? Who owns getting this fully deployed and confirmed working in writing? Because if everybody owns it,

Nobody owns it. Every one of those is the same question wearing different clothes. When it matters, will somebody actually act? That's the thing you're buying, not the watching, the acting. And here's where I'll land it. The reason this category is so easy to buy badly is the same reason every category on the show is easy to buy badly. It's built for the seller. The seller wants to sell you the tool because the tool is the easy, scalable, high margin part. The watching, the deciding, the acting, the owning of the deployment, that's the hard part.

The expensive part, the part that actually protects you. And a lot of providers have quietly figured out they can charge you for protection while only delivering detection because most buyer can't tell the difference until the worst night of the year when they find out the hard way. You don't have to be the one that finds out the hard way. Ask questions. Make them show you what happens after the alert. And if you want somebody independent in the room with you, when you do, somebody whose only job is to make sure you're buying protection and not a very expensive smoke detector.

That's what we do at itbroker dot com. This was a signed playbook. Buy tech without regret. I'll see you next time.

Related Solutions

No items found.