In cybersecurity, managed detection and response (MDR) refers to services that help organizations better understand the risks they face and improve how they identify and react to such threats. As organizations continue to shift their strategies to stay ahead, these solutions will only grow in popularity. This article outlines the Managed Security Service Provider (MSSP) opportunity around MDR, as underscored in Omdia’s recent Fortinet-sponsored report: “MSSPs and Managed Security.”
Further, when weighing options for managed security services, 53% of buyers plan to buy best-of-breed services from multiple providers instead of seeking a single provider solution, indicating that brand is an important consideration to these buyers.
These responses echo the overall drivers for choosing managed security services in general, including increased security, access to new technologies, and pre-integration of complex systems.
Author Jonathan Nguyen-Duy is VP of Field CISO at Fortinet. Read more Fortinet blogs here.
Drivers of Managed Security Service Consumption
An ever-expanding and increasingly complicated threat landscape has prompted many enterprises to outsource their cybersecurity requirements to MSSPs. Organizations use MSSPs for everything from staff augmentation and monitoring, to achieving predictable operating expenses. The enterprise survey section of Omdia’s report provides further insight into current top drivers of managed security service consumption.Survey respondents indicated that strength of security, improved performance and capacity, as well as, protection of applications and data in private and public clouds were among the strongest drivers in their decision to deploy managed security services. At present, an average of 50% of enterprise users are protected by managed security services, with 77% expected by the end of 2021.Top drivers for this change in consumption include the following:- Increase in mobility and remote working: 38%
- Cloud migration: 37%
- Increased usage of collaboration and communication tools: 36%
- Changes in volume and variety of threats: 28%
- IoT deployment: 27%
- Consolidation of security technologies and platforms: 9%
The Rising Importance of MDR
MDR services go beyond traditional MSSP offerings, enabling a better understanding of risks while also positioning enterprises to respond to detected threats more rapidly. These services combine network forensic and endpoint security tools with human analysis and automation to detect and respond to threats.Traditional MSSP offerings, in contrast, prioritize security asset management, as opposed to the deployment, management, and monitoring of security assets such as firewalls and network access controls (NAC). Adding MDR to the mix provides better protection of endpoints from malware, the ability to halt lateral threat movement, and the ability to stop internal security violations.According to the survey, the most popular managed security services currently in use are still traditional security monitoring (65%) and device management (57%). However, managed detection and response now comes in at a close third (54%), indicating that the use of MDR is on the rise.MDR From the Buyer’s Point of View
When opting for MDR, buyers have their choice of many different types of vendors, with traditional MSSPs only being one of several options. They could also choose to deploy MDR in-house with the help of proprietary software, or work with an MDR-only vendor, for example.But even buyers are aware of many benefits that come with buying MDR from an MSSP, with survey respondents indicating the following key benefits:- The solution would be fully pre-integrated: 46%
- Experienced SecOps teams: 39%
- Access to richer threat intelligence: 40%
- More telemetry because MSSPs manage many customers: 26%
- Incident response capabilities: 25%
- Already familiar with customer needs and environment: 11%
