3. When Does It Make Sense to Keep Security Operations Internal?
Building an in-house security team is a significant undertaking, requiring an investment in both people and technology. Many enterprises have already made those investments and may be disinclined to reverse course. But an MDR service can also work in concert with your internal team, serving as an additional set of eyes and expand your coverage without continuing to expand your SOC. In addition, businesses that handle unusually sensitive data, work in a tightly regulated industry, or operate specialized technology must always think carefully about how, or whether, to bring on third parties.
4. Can a Hybrid Model Deliver the Best of Both Worlds?
In a hybrid model, the organization maintains an in-house team that determines security strategy, manages vendors, and provides deep subject-matter expertise on the technologies supporting the business. This team may work only during normal business hours. The MDR provider provides 24/7 monitoring and response services to handle the day-to-day operations of the security infrastructure. It escalates to the in-house team when necessary but handles routine work on its own.
This is a common approach for enterprises because it acts as a force multiplier, enabling your team to focus on specialized work that delivers the most value to your business. It also serves as a steppingstone for organizations moving their work to an internal team over time.
5. How Should Businesses Evaluate MDR Providers?
You’ll want to go beyond the slick marketing materials and learn how the MDR service actually operates. The best way to do this is to track down a customer and talk through the service they’re receiving. Begin by understanding the onboarding process for new clients. You’ll want to know what to expect as the MDR provider deploys and tunes their technology in your environment. Then get a sense of the day-to-day service offering. What will you hear from the service on a routine day without emergencies? What happens when something goes wrong in your environment? What are the procedures for when it really hits the fan? How will the MDR service scale up to support your organization during a critical incident?
You should also carefully review the financial terms of the contract. How will the cost of the service change as your organization changes in size or scope?
