• Discover the key findings from the 2026 Leadership Compass on MDR
• Learn how the MDR market is evolving
• Understand the capabilities that distinguish MDR leaders
• Explore the role of AI, identity, automation, and exposure management in MDR
• Find out what criteria to use when evaluating MDR providers
Cyber threats continue to target organizations across endpoints, networks, cloud environments, identity systems, and connected devices, while many security teams still struggle with skills shortages, operational complexity, and the challenge of maintaining effective 24x7 monitoring and response. In this environment, Managed Detection and Response (MDR) has evolved beyond managed alert handling into a broader security operations function that combines validated detections, contextual investigations, coordinated response, identity-aware analytics, and ongoing posture improvement.
Don’t miss the opportunity to join Senior Analyst Warwick Ashford for an informative webinar in which he will provide an overview of the KuppingerCole Leadership Compass on MDR 2026. He will explore how the MDR market is changing, the key findings of the report, the capabilities that now define leadership, and the criteria used to evaluate vendors. He will also discuss market drivers, delivery models, outcome-focused service expectations, and the increasing importance of identity protection, automation, integration, and exposure management in modern MDR.
Who Should Attend:
This webinar is designed for IT security leaders, security operations professionals, CISOs, security architects, and IT decision-makers responsible for threat detection, incident response, security operations strategy, and MDR evaluation. It is also relevant for organizations assessing how to strengthen resilience through managed security services, automation, identity-aware detection, and improved response capabilities.
Hello, and welcome to this webinar entitled Redefining MDR from Alert Handling to Outcome‑Focused Security Operations. I'm Warwick Ashford, a Senior Analyst at KuppingerCole Analysts, and I'm delighted that you've joined me on this rather warm day to share some insights from research into one of the most important security markets in 2026, and that's MDR. What makes this market so important is that MDR is no longer just about outsourced monitoring or alert handling.
My research shows that MDR has matured into a broader security operations function that brings together detection, investigation, response, identity monitoring, exposure management, and measurable operational outcomes. That matters because most organizations are under pressure from every direction at once. There are more threats, more complexity, more cloud, more identity risk, and not enough skilled people to run security operations at the level that is now required.
So, the key question is no longer do we need MDR. I think the real question is what kind of MDR will actually improve resilience. In this webinar, we will walk through what the 2026 KuppingerCole Leadership Compass on MDR tells us about how the market is changing, what separates the leaders from the challenges, and what buyers should do differently as a result.
So, I've got quite a lot to share with you today, but before we dive into the content, let's go through some housekeeping points. As you can see, there's no need to worry about audio controls. You are muted centrally, and we'd like this webinar to be as interactive as possible, so I will be asking two poll questions.
So, please participate, and we can have a look at the results later. And then we'll finish up with a Q&A session, and so this is your opportunity to ask any burning questions you may have, and you don't have to wait until the end. You can just ask your questions at any time by going to the questions tab in the Livestorms control panel, and that should be on the bottom right-hand side.
And also, don't worry about taking detailed notes, because we're recording the webinar, and the video and the slide deck will be made available for download in a day or two. Now, to run through the agenda, MDR in 2026 is a much broader and more strategic market than it was even a short time ago. This Leadership Compass helps us to understand both where the market is now, and how organizations should evaluate providers going forward.
First, we'll have a look at an overview of the MDR market, why MDR matters now. Next, we'll look at some of the insights from the research, what has changed, moving on to some key findings and recommendations, and finishing up with a Q&A session. But let's get right to it and talk about where we are in 2026. The MDR market, in my view, has crossed the line. If your provider still talks about monitoring, rather than measurable improvements in detection speed, response quality, and reduced exposure, you're buying yesterday's model.
That's because MDR is no longer defined by alert handling, and it's not just about monitoring either, although round-the-clock threat monitoring is a key component. MDR is becoming an operating model for security operations. That changes how providers compete, and how customers should evaluate them. Buyers should be evaluating MDR services not on features, but on outcomes. You should be asking questions like, is the current or prospective MDR provider reducing risk, or just reducing dashboard noise? Can any MDR offering still call itself modern without identity-centric analytics?
And considering MDR now includes exposure management, automation, and co-managed responses, are you still evaluating vendors with an outdated checklist? By the end of this webinar, hopefully you will have a clear understanding of how MDR has evolved, a practical view of what defines leadership in 2026, and a better idea of how to evaluate MDR providers against your own requirements. So why does MDR matter now? The reality is, of the modern world, is that organizations face persistent threats across infrastructure, applications, cloud, identity systems, and connected devices.
But many still can't operate effective round-the-clock security operations internally. MDR matters because it fills that operational gap. Traditional monitoring models struggle because enterprise environments have become highly distributed and diverse, spanning endpoints, networks, cloud workloads, applications, identity systems, also OT and IoT, not to mention all those remote workers. Organizations face rising attack volumes, increasing cloud adoption, identity-centric attacks, and growing complexity, while many lack the skilled staff required to maintain continuous monitoring.
Traditional siloed tools cannot provide the unified visibility and telemetry correlation that's needed across these diverse environments. Now there are, in fact, five main drivers of the demand or need for MDR services, starting from the bottom.
There are, of course, the persistent cyber threats that face just about every business, driving the need for security operations 24-7. Then many organizations simply do not have the cybersecurity teams with enough people and skills to deal with the cyber onslaught. This challenge is exacerbated by the fact that many organizations are increasingly using cloud-based services, which has increased the attack surface significantly.
Next, identity is now one of the key attack vectors, so organizations need the capabilities to detect and respond to identity risks. And then literally on top of all that is the growing number of regulations that organizations need to comply with, many of which require organizations to demonstrate their ability to be resilient in the face of cyber threats. Leading MDR services are designed to meet those needs.
And in order to do so, MDR has evolved from managed alert handling into a service model focused on validated detections, contextual investigations, coordinated response, and continuous improvement of security posture. I think the ability to work with organizations to improve their cybersecurity capabilities on an ongoing basis as the threat landscape changes is one of the key benefits and hallmarks of leading MDR services.
And part of that evolution has been the incorporation of capabilities from XDR, SOAR, ITDR, CTEM, and ASM, often with SIEM as the underlying data and correlation layer, creating a unified operational model that integrates detection, investigation, response, exposure management, and compliance support. That convergence is reshaping the market, and increasingly just about every element is supported by some form of AI.
When it comes to required capabilities, the essentials include 24 by 7 monitoring, validated detection, multi-domain telemetry correlation, threat hunting, automation, SIEM and SOAR integration, and strong reporting. The key features of modern MDR then are, one, validated detection, which means MDR must reduce alert noise by confirming which signals are the ones that you should actually be paying attention to and require action.
Two, contextual investigation, which means providers need to correlate endpoint, network, cloud, identity, and application telemetry to understand the full scope of an incident. Three, coordinated response, which means MDR must support fast containment and remediation, not just alert escalation. And fourth, continuous posture improvement, which means MDR services must help customers reduce future risk through exposure management, tuning, threat hunting, and actionable remediation guidance. For more details on the required capabilities, please have a look at the 2026 Leadership Compass on MDR.
Now the four key features that I've just been talking about translate into four main use cases, and those are, one, continuous detection and monitoring. Now this refers to the need for round-the-clock visibility across endpoints, networks, cloud identity, applications, and connected devices where internal teams often lack capacity.
Two, validated detection and contextual investigation. Now this refers to the need to reduce alert noise by correlating telemetry and giving security teams actionable findings rather than just raw alerts.
Three, coordinated response and containment. Now this refers to the need to improve cyber resilience by enabling faster containment, remediation, and response decisions across complex environments. Now as I said at the European Identity and Cloud Conference EIC in Berlin in May, resilience should be the overall goal. This is your organization's ability to prepare for, withstand, respond to, and most importantly, recover from cyber incidents while continuing to operate critical business operations. And fourth, exposure management and posture improvement.
Now this refers to the need for organizations to identify weaknesses, prioritize remediation, and improve defenses continuously as the threat landscape changes. And perhaps a fifth and overarching use case would be compliance and obviously compliance reporting.
Next, we have a look at the latest leadership compass, but first a poll question for you to answer. So time to get your brains engaged. And the question is this. What is the biggest challenge you would like MDR to address?
Is it one, reducing alert fatigue and improving SOC efficiency? Two, accelerating threat detection and incident response?
Three, addressing skill shortages and expanding security expertise? Or four, improving visibility across cloud endpoint network and identity environments? So please make your selection now on the polls tab in the control panel. And don't forget you can ask a question at any time by going to the questions tab which is right next door. And we'll look at the poll results and your questions towards the end of this webinar.
We now move on to the next section of this webinar to look at the 2026 MDR leadership compass based on briefings with 13 MDR vendors and their responses to a very detailed questionnaire that covers nine key areas. And these are internal security, functionality, deployment, interoperability, usability, innovation, market strength, ecosystems, and financial strength.
Now, in addition, this leadership compass looked at seven other capabilities that are reflected in a spider chart for each one of the vendors. But we'll look at an example of that later. If you are interested in our research methodology, there is a link in the report and you can get more information on that. So the participating vendors in the report represent the breadth of the modern MDR market, ranging from specialist MDR providers and endpoint security platform vendors to global managed security service providers, channel focused suppliers, and regional cybersecurity specialists.
They vary in size, geographic reach, service maturity, delivery models, technology ownership, and obviously their target customer profile. So just to be clear, one of the main aims of the leadership compass is to help end user organizations understand the market, to find out what services are available, and to identify which ones best meet their needs. From this research, it is clear that MDR has become a unified security operations function, integrating detection, investigation, response, and exposure management across multiple telemetry domains.
This is a much bigger mission than traditional outsourced monitoring.
And so in addition to the basics such as 24 by 7 monitoring and incident response, mature MDR providers typically deliver things like validated detection rather than alert forwarding, correlation of endpoint network cloud and identity telemetry, threat hunting, both human-led and automated, AI-assisted investigations, incident containment isolation, SOAR-driven response automation, which is a key element, identity-centric monitoring, which is becoming increasingly important, exposure management and vulnerability prioritization, which is about risk management and also improving overall risk and security posture.
Integration with SIEM and other security tools, which is essential, and comprehensive reporting, dashboarding, and customer collaboration. These capabilities move MDR beyond basic monitoring into outcome-based security operations. In the context of MDR, coordinated investigations combine automated analytics with human analyst validation. MDR providers correlate activity across multiple telemetry sources, they investigate alerts in context, they validate detections, and they determine whether containment is required.
This approach reduces false positives and alert fatigue, it improves detection quality, it lowers operational noise, and it accelerates the mean time to detect and the mean time to respond. End-user organizations are increasingly differentiating based on outcomes. Buyers now want measurable improvements in detection and response efficiency, containment quality, and security posture.
Now, as I've already mentioned, identity is central. Unsurprisingly, the importance of identity in the context of security is now well established. In response to the fact that identity has become a primary attack vector, MDR providers are MDR providers are increasingly adding identity-centric analytics, monitoring for anomalous access, and credential misuse detection. We also see that AI has moved from experimentation to an operational layer.
Vendors are applying ML, UWeber, and increasingly LLM-based Gen AI to accelerate triage, investigations, threat hunting, and reporting, but the better providers still keep detection and response grounded in validated telemetry and human oversight. Some vendors have even introduced quality assurance processes around the AI, which I think is great.
Hopefully, more providers will do the same in future. So, MDR customers should expect transparency around how AI influences detections, recommendations, and automated actions. Buyers should always try to distinguish between genuine operational improvements from AI and the marketing claims that tend to be overstated in terms of the autonomous security capabilities.
Now, MDR is becoming proactive. Another element of the evolution of MDR is the shift from reactive defense to proactive improvement. Exposure management, continuous assessment, attack surface insights, and vulnerability prioritization are expanding MDR beyond reactive response into ongoing posture improvement.
So, by continuously assessing and improving security posture rather than only responding to incidents, MDR helps organizations reduce risk, strengthen defenses, and improve operational resilience over time. As you know, I mentioned the importance of resilience a little bit earlier.
So, it's worth noting that co-managed MDR has also become a mainstream delivery model. Customers increasingly want shared visibility into investigations and some control over response decisions, while still delegating a large part of the operational burden to the MDR provider. This hybrid operating model allows organizations to be as involved as much as they can or want to be, while still retaining access to external expertise and technological support. Integration and interoperability is another key area to highlight. Integrations, specifically custom connectors, are a top requirement.
Vendors that provide specific connectors have scored more highly in this report than those who rely on APIs. Interoperability between MDR services and existing cyber security tools is very important, because organizations need unified visibility across distributed environments and existing security investments for effective detection and response. For this report, the key integration areas that we looked at included EPDR and XDR, NDR, SOAR, SIM, DLP, CSPM, ASM, and PAM.
And finally, before we look at the results of the comparative analysis and leadership, I'd like to highlight some of the innovative capabilities that increasingly shape that leadership. These include LLM-based analyst assistance, CTEM and ASM, OT and IoT support, AI transparency, co-managed SOC models, and behavioral identity risk scoring, which evaluates the likelihood that an identity, account, or session is compromised or being misused. In this report, all of the MDR solutions evaluated included user behavior analytics. 92% of them included LLM-based summaries of alerts and investigations.
Just over half included deceptions or honeypot technologies and continuous threat exposure management, while around a third included breach and attack simulation and attack surface management. But I expect that this will increase in future, especially ASM. And so time now for another poll question to get you involved, which you can answer again on the polls tab of the Livestorm control panel. And the question is, which MDR capability is most important to you? Is it identity-centric threat detection and response, ITDR?
Two, human-led threat hunting and incident response expertise? Three, security automation and AI-assisted investigations?
Or four, the ability to integrate with existing security tools and workflows? Please record your answers now and we'll look at the results a little later. And now for the final section of this presentation, we'll look at some of the results of the 2026 MDR Leadership Compass. And anyone familiar with the Kupinger Coal Analysts Leadership Compass will know that we look at leadership in four categories, product, market, innovation, and overall. Product leadership is based on the presence and completeness of required features. For more detailed information, please have a look at the report.
Market leadership is an amalgamation of the number of customers and their geographic distribution, the size of deployments and services, the size and geographic distribution of the partner ecosystem, as well as the financial health of the participating vendors. Innovation leadership is based on the evaluation of innovative features recently added, together with the vendor's history in innovation. And finally, overall leadership reflects how vendors balance product strengths, innovation, and market presence.
If you'd like to see the product, market, and innovation leadership charts, you'll have to read the report, I'm afraid, which I encourage you to do. But if you look closely at the overall leadership chart on the right, you can see who the innovation and product leaders are among the vendors that we evaluated, and you can get a good idea of their relative market strength, which is reflected in the size of the bubbles.
You can see the overall leaders in red, and what's striking is that these vendors are not all winning in exactly the same way, but they all show a strong combination of product capability and innovation. The leaders share several characteristics, mature MDR execution, a high pace of innovation, broad telemetry coverage, strong integration capabilities with customer security tools, flexible managed and co-managed operating models, and meaningful AI support for analysts, strong response automation and orchestration capabilities, and strong alignment to identity and cloud realities.
However, not every end user organization needs a leading MDR service. Leadership status is useful, but it's not a substitute for selection. Choosing the right MDR service for your organization depends on your organization's size, skills, expected growth, needs, and of course, budget. As mentioned earlier, in addition to the leadership charts, we also provide a spider chart as part of the write-up for each of the participating vendors.
Now, here is an example of one of those spider charts, which, as you can see, provides a rating for each one of the vendors across seven dimensions, over and above the standard areas of security deployment, interoperability, and usability. So, for the MDR leadership compass this year, we looked at coverage, cloud and container support, obviously detection capabilities, response capabilities, and then also threat intelligence, customer and admin support, and compliance, which includes vendor certifications and compliance reporting capabilities.
So, now buyers can use these spider charts to see which vendors are strong in the areas that are of greatest importance to their organizations. And so, in summary, the MDR market is expanding beyond monitoring and alerts, and is rapidly evolving into full spectrum operations. MDR is becoming increasingly identity-centric. It is accelerating the adoption of AI-driven security, and it is shifting to proactive risk reduction. And in choosing an MDR service provider, security leaders should prioritize integration with their existing security stack.
They should evaluate identity threat detection as a core requirement. They should assess exposure management capabilities, and they should validate all AI capabilities through proof of concept testing to ensure that it behaves the way the MDR providers claim that it does, and in the way that the end-user organization would like it to. Before we move on to the questions, there are three key points I'd like to leave you with.
First, MDR is no longer simply outsourced monitoring or alert handling. It has evolved into a broader security operations function that brings together detection, investigation, response, exposure management, identity monitoring, automation, and reporting.
Second, buyers should evaluate MDR providers on measurable outcomes, not just feature lists. The important questions are whether the service improves detection speed, response quality, containment effectiveness, visibility, and security posture.
And third, the strongest MDR providers are those that can integrate with a customer's existing security stack. They can address identity as a core attack vector. They can use AI in a transparent and human validated way, and help organizations reduce risk continuously over time. That means that the right MDR provider is not simply the one with the strongest leadership position or the longest list of capabilities.
For you, it's the provider that best fits your organization's environment, maturity, skills, risk profile, and operational requirements. And now it's time to look at the poll results. And if I can just go to the polls tab, let me see how the voting went. And I don't seem to see any results in the poll section. I'll just submit a vote and see if it makes a difference.
Okay, right, that worked things up. So it seems that identity-centric detection and response tied with a security automation and AI-assisted investigations when it came to which MDR capabilities were the most important to you. Only 11% said the ability to integrate with existing security tools.
Well, that's interesting. I have a feeling that that's going to probably be more important when you're making the purchasing discussion, or decision rather, because obviously the more it integrates with your existing stack, the better it's getting, the more value you're going to get out of your existing stack. Interestingly enough, there doesn't seem to be any votes for human-led threat hunting and incident response expertise. That's interesting.
Okay, so the second poll question was, what is the biggest challenge you would like MDR to address? And so the biggest chunk there was accelerating threat detection and incident response, and I guess that's no surprise. Time is of the essence these days and certainly MDR will do that. Reducing alert fatigue and improving SOC efficiencies.
Only 20%, I would have thought that would be a bit higher. I would have thought that most of you would have found alert fatigue one of the biggest challenges that you guys are facing.
So yeah, that's quite interesting. I would have expected to be able to hire that. And only 10% said addressing skill shortages and expanding security expertise. And also another 10% for improving visibility across cloud and endpoints and so on.
Yeah, so kind of not quite as high as I would have expected on the other options, but yeah, interesting to see that accelerating threat detection response is kind of really the area that you wanted to focus on. Okay, and so now we will go to the questions in the questions tab and see what questions we have there.
Okay, so far we only have one question. Don't be shy. As I said at the beginning, we'd like to make this as interactive as possible, so we can only do that if you guys ask for questions. And so the first question is, how do we know whether an MDR provider is improving security outcomes, not just handling alerts? Ask for evidence. Ask for evidence of measurable improvements in detection efficiency. Get them to show how it goes up from where you were to where it goes with their help. Ask for evidence of the improvements in response speed, containment quality, and posture enhancement.
A modern MDR provider should show how it reduces alert noise, how it validates detection, how it accelerates containment, and how it improves security posture over time through the transparent reporting and evidence-based metrics. So get them to prove it, and that's why I said doing a proof of concept is important.
Most vendors will allow you to try before you buy, and I think it's a good idea, and then you can prove it in your environment, because they can make as many claims as they like, but proving it in your environment, I think, is the best way to ascertain whether it's going to be good for you. We have another question here. How do we know whether an MDR provider is improving security outcomes, not just handling alerts?
Oh, wait, was that? Oh, that was the first question.
Sorry, I beg your pardon. Next question, the new question, is should identity threat detection now be a mandatory MDR requirement?
Yes, I think it should. As I said earlier, identity has become a primary attack vector, so MDR should include identity-centric analytics, credential misuse detection, anomalous access monitoring, and alignment with ITDR. If identity telemetry is weak or optional, the service may not reflect current enterprise attack patterns. I think here the bottom line is organizations evaluating MDR should assess not only endpoint and network visibility, but also the provider's ability to detect and respond to identity-based attacks. We have another question. That's great.
Is the goal to get a single tool that provides all capabilities? If an integrated set of tools, will there be an overlap? Will there be overlapping AI functions?
Well, MDR is a service, right, so you're kind of going to have a dashboard of sorts, and this is going to be the one area that you're going to be able to do everything together. So, you know, in the brave new world of AI that we have now, some organizations are thinking about, well, should we be using this in our security operations? But already MDR providers are doing that. They're already doing that. They're doing it successfully, and most of them are doing it in a very responsible way, and I think that's when you come to buy these services, you need to get them to demonstrate that.
But, you know, rather than having to pioneer it yourself and have to kind of avoid all the pitfalls, to me this is kind of one of the biggest benefits of MDR, is that you don't have to go through all that pain. You're just getting the intelligence that is being delivered, and you're getting the automated responses that are being delivered, obviously set up in, you know, so in a way it's kind of that it's a security operations environment.
So, if you mean that into a single tool, I guess that's what it is. It's a single environment role in a single tool, because that's what they're providing, and, you know, you can then decide how, to what degree you want to run it yourselves, and to what degree you just want to hand over to the MDR provider.
So, hopefully that answers that question. I don't know if we have any more questions. Just give a few minutes to see if anybody comes up with another question, and no more questions, I don't think.
All right, well then, if we haven't got any more questions, I think we can move on. So, included in the slide deck are some links to related research for you to have a look at, including the 2026 MDR Leadership Compass that we've been talking about today, and the Companion Buyer's Compass, which sets out the challenge, the solution, and the top use cases in more detail, as well as selection criteria, architectural and pre-deployment considerations, and questions to ask vendors, and some recommendations.
I would also like to take this opportunity to remind you that, in addition to our research on a wide range of topics, Keeping a Coal Analyst hosts a number of conferences, webinars, and networking events through the year, and we also offer advisory services, and if you'd like to get more information on how our advisory services could help your organization with your identity and cybersecurity goals, just follow the QR code.
And our next event is our Identity Fabric Impact Day in Cologne, Germany, on the 9th of December, and if you would like more information on that, again, just follow the QR code. So, thank you so much for joining me today. I hope you found it thought-provoking and, above all, useful.
And so, from me and the webinar team here at Keeping a Coal Analyst, it's goodbye until next time.
See All Locations
See All Locations