Do Human Work Podcast: Rethinking Cybersecurity's Foundations — WATCH NOW

Legacy MDR is a Fraction of What You Need

Ask a security leader why they are leaving their MDR provider, and you will rarely hear that the provider was bad. You hear something worse: it did exactly what we bought it to do, and what we bought turned out to be a fraction of what we needed.

That is not a vendor problem. It is a model problem, built in from day one. It just never made it into the contract.

Legacy MDR is people-led. A shared bench of analysts works your alerts from playbooks, and the only way to add capacity is to hire. Alert volume grows at machine speed. Hiring does not.

What "legacy MDR" means

Managed detection and response means an outside provider watches your environment around the clock, investigates alerts, and acts on the ones that matter. It exists because 24/7 coverage takes five to six full-time analysts who are expensive, hard to hire, and harder to keep.

Legacy MDR is that model delivered the original way: human analysts working a shared queue from playbooks written in advance. For years it was the only way to get continuous coverage without building a SOC, and it was a fair trade.

Then alert volume exploded. Analyst supply did not.

Reason one: most of your alerts never get investigated

A shared bench has fixed hours. Your environment generates more alerts than those hours can absorb. So the provider filters: rules, thresholds, and severity tiers decide what a human sees. The rest are closed, suppressed, or never opened.

Nobody is cutting corners. It is the only way the math works. Your coverage ends wherever someone else drew the line, and you have probably never seen where that is.

Most teams find out during an incident, when they go looking for the alert that should have caught it and find it auto-closed at 2am.

Ask your provider what share of your alerts get a documented human investigation. Then ask what happens to the rest.

Reason two: you paid for answers and got homework

An escalation should end an investigation. Too often it starts yours.

The ticket arrives with a severity, some enriched fields, and a recommended action. What is missing is the reasoning: what was queried, what was ruled out, why this verdict. So your analyst reopens the case, re-pulls the context, and reaches their own conclusion.

You paid for an investigation. You got an alert with extra metadata.

Measure time to conclude, not time to acknowledge: how long until your team has a verdict it will act on without redoing the work. Providers report acknowledgment time because it flatters them.

Reason three: two years in, it still does not know your environment

Legacy MDR runs the same generic detection content across every customer. That is what makes it economical. It is also why the same false positive shows up every month.

Your build server does things that would be alarming anywhere else. Your finance team travels. Your developers run attacker tools for legitimate reasons. A shared bench cannot hold that context for every customer, so it either escalates the same benign activity forever or tunes it out and misses the real thing.

Your analysts learn which escalations to ignore on sight. That knowledge lives in their heads, not in the service you are paying to hold it.

Reason four: they keep the receipts

Ask what happens to your investigation history when the contract ends. Usually, it stays with the provider.

Years of reasoning about your environment, which alerts were benign and why, is the most valuable thing a managed service produces. If you cannot take it with you, every switch resets you to zero, and the longer you stay, the more leaving costs.

You cannot audit it either. When a regulator or your board asks why an alert was closed eighteen months ago, "the provider said it was benign" is not an answer.

Reason five: the bill grows, the coverage does not

Legacy MDR is priced per endpoint, per user, or by data volume, with response and threat hunting sold as upgrades.

Every one of those meters grows on its own. You hire, migrate a workload, or add a log source for compliance, and the bill goes up without anyone deciding to buy anything. Coverage stays flat, because paying more for the same shared bench does not create more analyst hours.

For growing companies, the price increase and the coverage complaint land in the same renewal. That is usually when the switching conversation starts.

Five signs you have outgrown the model

  1. You cannot get a straight answer on coverage. If a provider will not say what percentage of alerts get investigated, the number is not one they want you to hear.
  2. Your team reinvestigates most escalations. Track it for a month. If analysts redo more than a third, you are paying twice.
  3. The same false positive keeps coming back. Still escalating your backup job after two years is not a service that learns.
  4. Nobody can explain a closed alert from last quarter. Reasoning that cannot be retrieved is reasoning you do not own.
  5. Your renewal is growing faster than your headcount. When the meter outruns the business, the pricing works for the provider, not for you.

One or two is normal. Four or five is structural, and switching to another provider in the same model will just reproduce it.

What teams move to

Most teams leaving legacy MDR still want a managed service, and they should. Plenty of organizations have no business staffing a 24/7 SOC. The problem was never outsourcing. It was capacity that scaled with hiring, which forced the filter that broke everything else.

The fix is a service where AI agents do the front-line investigation instead of analyst hours. Coverage stops depending on bench size, so every alert gets investigated, not a filtered slice. Escalations arrive with the reasoning attached, because agents show their work by default. And the service learns your environment, because holding context is a software problem, not a staffing one.

Humans do not leave the picture. They move up to the decisions that actually need judgment, which is where your team wanted them all along.

For the underlying concepts, see our reference pages on what MDR is and what agentic security is.

How to pressure-test any provider

Test the five failure points above, not the feature list.

Get the coverage number in writing. What share of alerts get a full investigation, and how do they define "full"?

Measure time to conclude, not time to acknowledge. Run both against the same sample of your own historical alerts.

Open a closed case. Ask for the full reasoning on an alert the service resolved on its own: sources, evidence, path to verdict. If you cannot follow it, you cannot defend it.

Hand it your worst alert. Give it the one your current provider always gets wrong and watch what happens.

Price it at your size three years from now, not today, and ask which meters move.

Our MDR Evaluation Guide goes deeper, including the questions providers tend to dodge.

Where 7AI fits

PLAID ELITE is 7AI's fully managed service. AI agents investigate every alert, across every source, around the clock. Named 7AI experts stay on the loop for judgment, response, and oversight.

No rationing by bench capacity. Escalations arrive with root cause, timeline, evidence, and a recommended action already assembled. Response runs within limits you set. Every case shows its reasoning, so you can audit any verdict.

The outcome of a platform, delivered as a service, with no platform to run.

Frequently asked questions

Why do companies leave their MDR provider?

Usually because of structural limits in the legacy delivery model, not provider failure. The five most common reasons: only a subset of alerts receives real investigation, escalations arrive as work rather than finished conclusions, the service does not learn the customer's environment, investigative reasoning stays in the provider's console, and pricing scales with endpoint or data growth the customer does not control.

What is legacy MDR?

Managed detection and response delivered the original way: human analysts on a shared bench triaging alerts against pre-written playbooks, with capacity that scales by hiring. Its coverage is bounded by how many analyst hours the provider can staff.

How much of my alert volume does MDR actually investigate?

It varies by provider and is rarely published. Because a shared bench has fixed hours, services filter alerts by rule, threshold, and severity before a human sees them. Ask any provider what percentage of alerts receive a documented investigation, and what happens to the rest.

Is switching MDR providers worth it?

It depends on whether the problem is the provider or the model. If escalation quality or responsiveness is the issue, another provider may help. If the issue is coverage, repeated false positives, or price outpacing growth, switching providers within the same people-led model tends to reproduce the same outcome.

What should I measure when evaluating MDR?

Time to conclude rather than time to acknowledge, the share of alerts receiving full investigation, whether escalations require your team to redo the work, whether the service learns environment-specific context, and whether investigative reasoning is auditable and portable. Test all of it against your own historical alerts rather than a sample report.

Does an AI-delivered service still include human experts?

Yes. Agents handle the front-line investigation volume, and people stay on the loop for judgment calls, response decisions, and oversight. The change is what humans spend their time on, not whether humans are involved.