Managed detection and response (MDR) has emerged as a disruptive force in the managed security services market over the past decade, but there are crucial differences among vendors. The latest Forrester Wave report breaks down the key factors to look for when selecting an MDR vendor.

MDR is a managed security service that typically uses a combination of human expertise and automation technologies to provide 24/7 monitoring and analysis of IT infrastructure for signs of malicious activity. It can be used to “rapidly detect, investigate and respond to unauthorized and/or suspicious activity; offer assurance that adversaries have not gained access via threat hunting; and recommend actions to improve overall security posture,” according to an earlier Forrester report.

As the MDR market enters the next stage of maturity, vendors are facing the complex challenge of scaling their services for a broader customer base and a larger suite of services — “going from hundreds to thousands of customers and from a few services to many,” analysts noted in the Forrester Wave report.

Based on those trends, the analysis firm recommended MDR customers look for providers that:

1. Offer actual response capabilities without requiring automation 

The report noted that some MDR vendors require automation for any vendor-performed response action, but only “assist” customers in non-automated actions. Human expertise still holds a significant value in understanding the threats. “Restricting response to automated actions does help reduce the cost of delivering the service to customers but lets down customers that are unable — or unready — to automate,” they wrote.

2. Conduct threat hunting with defined criteria across various data sources 

While some vendors tout "automated threat hunting," analysts argue this is merely another term for analytics. “Real threat hunting requires a systematic approach to creating a hypothesis with clear success criteria and establishing a threshold at which the hunt is complete.”

3. Provide data federation

The latest innovation that drives detection and investigations in MDR is data federation. This approach interacts with data that MDR vendors never ingest and enables using data wherever it’s stored. “Customers save money because they avoid paying for multiple points of ingest, and providers get more data they can use during investigations,” the report noted.

Forrester named Expel, CrowdStrike, Red Canary as leaders

In the Forrester Wave report, the firm used 23 criteria to evaluate top MDR vendors.

It identified Expel, CrowdStrike and Red Canary as leaders; Secureworks, Rapid7, eSentire, Binary Defense, SentinelOne and Arctic Wolf as strong performers; BlueVoyant, ReliaQuest and Deepwatch as contenders; and IBM as a challenger.

Forrester categorized its evaluation criteria into three high-level categories: current offering, strategy and market presence. The first category encompasses aspects such as threat hunting and intelligence, case management, analytics, extended detection and response (XDR) and managed detection, investigations and response. The strategy category includes product vision, market approach, planned enhancements and partner ecosystem. The last one reflects each vendor's revenue and number of customers.

MDR is gaining momentum

CrowdStrike President Michael Sentonas told SDxCentral in an earlier interview that the company had been seeing managed security services gain traction and more large companies asking for help due to the economic downturn.

In addition, the industry is facing a talent shortage with an estimated gap of 3.5 million workers. Therefore, many companies are turning to third-party service providers to manage their security capabilities.

“A lot of organizations are looking to outsource the management of their security capabilities to third parties that bring great tools, great skilled resources that respond to incidents and bad things happening in their environments very quickly [and] keep them safe,” Tom Etheridge, CrowdStrike's chief global professional services officer, said.

Etheridge also said the macroeconomic impact has led many organizations to consolidate their vendors and reduce the overall cost of owning and operating cybersecurity tools in their environment. MDR services can help in all of those areas, as well as by decreasing the number of tools and agents running on an organization's endpoints.