Episode 223

How to Tell If Your MDR Provider Will Actually Stop an Attack

September 1, 20261 hr 43 mins

You signed a contract for managed detection and response. You assumed that meant somebody would step in and stop an attack while it was happening. For a lot of MDR providers, what you actually bought is guided remediation. They find the incident, tell your team what to do, and hand it back to you to execute. That distinction is the entire reason you’re paying for this instead of running it yourself, and most buyers don’t find out which one they signed for until they’re the one on the call at 2am being asked what to do next.

Miles Lowry, Senior Territory Manager at eSentire, has sold cybersecurity from every seat in the market, VAR, Nutanix, Rubrik, and eSentire, and he walks through the one question that exposes the gap before you sign. This conversation also covers where the same blind spot shows up everywhere else in a typical MDR evaluation. Buyers send RFPs to eighteen vendors and get eighteen generic capability dumps back instead of a real fit assessment. Rules of engagement quietly change depending on whether the compromised machine belongs to your CEO or your help desk.

It also gets into DLP requests that get approved without anyone defining what they’re actually trying to stop, and security licensing already sitting in your Microsoft contract that almost nobody has turned on. The buyers with the best MDR outcomes never send a broad RFP at all. Miles names the one question he says he’d ask first if he were sitting on the buyer’s side of the table.

Know the answer before it’s 2am and someone’s waiting on you to decide.

Want the exact test to run against your own contract? Read the full breakdown: https://itbroker.com/blog/mdr-provider-response-questions

Find Your Situation

  • Your CISO or security lead has been in the seat under two years, and you’re not sure if that’s a coincidence. Jump to 21:44
  • You sent an RFP to eighteen vendors, and now you’re buried in decks that all say the same thing. Jump to 26:35
  • You can’t get the budget to build the security program you’re actually expected to deliver, and you know it. Jump to 31:14
  • You’ve never checked whether a breach on your watch creates personal liability for you, not just the company. Jump to 40:53
  • A vendor asked how much data you generate before you’d even deployed anything to measure it. Jump to 42:36
  • You’ve never actually asked your MDR provider whether they act on their own or call you first. Jump to 55:31
  • Nobody on your team could name, right now, who gets called first if your CEO’s laptop gets hit tonight. Jump to 57:25
  • Someone asked for a DLP tool and you’re not sure anyone can say what it’s actually supposed to stop. Jump to 1:10:43
  • You’ve never tested whether your MDR provider can actually act without you, or whether you’d only find out during the incident. Jump to 1:18:16
  • You’re paying for Microsoft E5 and you have no idea if the security features in it are actually turned on. Jump to 1:25:53

Chapters

  • 26:35 Who is actually answering the RFP you think you wrote
  • 31:14 Why CISOs use a vendor to share the blame when something goes wrong
  • 40:53 Why most CISOs at one conference had personal liability insurance
  • 42:36 Why “how much data do you have” is a trick question
  • 55:31 The real MDR test: alert versus response
  • 57:25 Your CEO’s laptop, and who’s actually authorized to isolate it
  • 1:00:46 Who belongs in the room on the buyer’s side and almost never is
  • 1:10:43 The DLP request nobody asked for and nobody can explain
  • 1:18:16 The one question to ask before you sign
  • 1:25:53 Paying for Microsoft E5 security licensing you never turned on

What We Mentioned

  • eSentire
  • CrowdStrike (Falcon Complete)
  • Sentinel One
  • Fortinet
  • Palo Alto Cortex
  • Microsoft Defender, Sentinel, and Entra
  • Nutanix
  • Rubrik
  • Veeam
  • Gartner
  • NIST CSF
  • Log4j
  • Tenable

About Miles Lowry

Miles Lowry is Senior Territory Manager at eSentire, where he works directly with security leaders on managed detection and response. He’s spent 14 years in enterprise technology sales, moving through VAR, Nutanix, Rubrik, and now eSentire, giving him a rare, direct view into where buyers get MDR wrong before they ever sign.

LinkedIn: https://www.linkedin.com/in/cloud-ai-expert/ Company: https://esentire.com

About Signed

Signed is the podcast for buyers in a market built for sellers. Host Max Clark, CEO of ITBroker.com, sits down with CIOs, CFOs, operators, and founders who’ve lived inside real enterprise tech deals. New episodes weekly at itbroker.com/podcast.

If you’re in the middle of a real tech decision and want someone in your corner, book an intro call at itbroker.com. Buy tech without regret.