Managed security is changing. Customers still need providers to monitor alerts and respond to active threats, but they also want help finding exposed assets, understanding attack paths, and fixing the underlying weaknesses that could lead to an incident.
Optiv has expanded and renamed its MDR service, bringing Google Security Operations, Wiz, and agentic AI into a broader managed security offering.
Optiv Agentic Security Operations, formerly Optiv MDR, is designed to connect threat detection with exposure management and remediation. AI agents will take on parts of alert review, triage, and investigation, while Optiv practitioners validate findings, guide response, and oversee remediation.
Remediation at the center of the service
Google SecOps, Wiz, and AI-assisted investigations are already available through several managed security providers. Optiv says the difference lies in the range of technologies it supports and the workflows it can build across them.
Ben Spencer, product director at Optiv, told MSSP Alert, “Scale and breadth. Many companies offering their AI SOCs are focused solely on detection and response, or are taking telemetry in from just a select few integrations, that’s really focused. Optiv, as a leader in advise, deploy, and operate — and with our wide bench — is doing more. We have capabilities with other technologies, and we’ve built workflows for those other technologies that we do out of agentic security operations that other companies are not able to take advantage of. Furthermore, Optiv Agentic Security Operations is focused on remediating security threats, not just responding, and being able to remediate the root cause.”
Google SecOps handles detection and investigation
Google Security Operations provides the main detection and investigation layer. It brings together security telemetry, analytics, and Google Threat Intelligence to help Optiv identify and investigate activity across customer environments.
AI agents can review alerts, gather related information, and push higher-priority risks to Optiv’s analysts. Practitioners remain responsible for validating the findings and deciding how the organization should respond. The model could cut down the time analysts spend moving between tools and rebuilding an incident timeline. That matters when security teams are managing large alert volumes across complex environments.
Wiz adds cloud exposure and attack-path data
Wiz expands the service beyond active threat detection. Wiz Cloud identifies vulnerabilities, cloud misconfigurations, and attack paths. Wiz Code looks for risks in code and continuous integration and continuous delivery pipelines, while Wiz Defend provides cloud detection and response.
Optiv plans to bring that information into its agentic workflows so an analyst can see the exposure behind an alert, the assets involved, and the potential business impact.
“Wiz allows us to do a couple of things: One, take advantage of Wiz’s top-class capabilities in the cloud defense space, allowing us to have better viability and the capability to understand misconfigurations and vulnerabilities in cloud architecture, and use that understanding to remediate those security concerns. Two, Wiz allows us to begin offering governance capabilities to help secure agentic workloads in the cloud. Optiv Agentic Security Operations is intended to allow us to support remediation across a client's wider tech stack, and is not limited solely to Wiz or Google Security Operations, but it will heavily depend on integrations and client environments,” Spencer said.
The governance piece adds another use case. As companies deploy more AI agents in cloud environments, they need to understand what those agents can access, what actions they can take and how their activity is monitored. Wiz gives Optiv a way to bring those workloads into the same view as other cloud assets and exposures.
Optiv is still building the packages
Optiv is working on how it will package detection, exposure management, and remediation. The company is also looking at how findings from exposure management and continuous penetration testing tools can feed into the service.
“Optiv is building out packages and has integrations with this sort of service and products that offer them. We’re working closely with Horizon3.ai and other partners around exposure management and continuous pen testing, and we are excited to use Agentic Security Operations as the foundation to discover and remediate threats found with those tools,” Spencer said.
The Horizon3.ai relationship points to how Optiv could connect continuous security testing with managed remediation. A penetration test or exposure assessment may find a weakness, and Agentic Security Operations could then help prioritize the issue, assign the work, and track whether it was fixed.
MSSP and channel partner opportunity
Optiv may also work with other MSSPs and channel partners when an engagement calls for it, although the company has not laid out a formal partner model for the service.
“It’s more about offering the best and most trusted security solutions to our clients, while delivering real-time and real-world results. We’ll work with MSSPs and channel partners where it makes sense and when it aligns with the needs of our clients, our partners, and the business — all with the goal of data-driven results and mutual success,” Spencer said.
Partners will want to know whether Optiv plans to support referral, resale, subcontracting, or joint delivery arrangements. MSSPs that already manage Google SecOps or Wiz will also need clarity around customer ownership and the division of service responsibilities. There may be room for partners with regional reach, specialized skills, or existing customer relationships. Clear boundaries will be needed when both Optiv and another provider are involved in monitoring, investigation, or remediation.