Managed Detection and Response (MDR) is a managed cybersecurity service where a specialist security team continuously monitors your systems, detects threats, investigates suspicious activity, and responds to security incidents on your behalf.
If you’re being sold MDR as your cyber security strategy, someone isn’t telling you the whole story.
There’s a trend in our industry that’s starting to concern me.
Buy an MDR service – DONE
Deploy an EDR agent – DONE
Tick the cyber security box.
Job done.
Except… it isn’t.
MDR is an important capability. We recommend it ourselves, but here’s the uncomfortable truth:
An attacker doesn’t care whether you’ve bought an MDR licence.
They’ll target whatever gives them the easiest route into your business. This can be:
- via a compromised Microsoft 365 account.
- A click on a phishing email.
- A reused password from a breach three years ago.
- Sensitive data accessed with legitimate credentials.
- A poorly configured cloud application.
- An employee with excessive privileges.
None of those problems are solved simply because an endpoint is being monitored.
That’s because businesses aren’t attacked through one product. They’re attacked across multiple fronts.
At J2, we simplify cyber security into five areas every organisation relies on:
- Users
- Data
- Machines
- Internet
Those are also the five areas cyber criminals target every single day, in increasing volumes, with new AI enabled tools.
If you’re only monitoring one of them, you’re not building cyber resilience, you are only looking at one part of the problem.
The cyber security industry has become very good at selling products.
EDR, MDR, XDR, NDR, CDR – every month there’s another acronym.
Business owners don’t buy acronyms, they buy confidence.
They want the confidence that someone will see an attack before it becomes a crisis, the confidence that someone is watching when they’re asleep, the confidence that if a criminal compromises an identity, creates malicious inbox rules or starts accessing sensitive data, somebody notices. Somebody acts.
That’s cyber resilience. Not because it’s another product, because it’s a joined-up capability.
So many in the industry sell that one view and tell them everything is going to be ok. Perhaps they do not know the actual risk because they are not cyber security specialists but IT people who read some pretty brochures.
The future of cyber security isn’t buying more tools. It’s making all of your security work together.
I’d be interested in your view.
Do you think too much of the industry still sells individual security products when businesses actually need a complete cyber resilience strategy?