MDR, Security Operations, AI/ML

Transforming MDR: How AI challenges and strengthens protection services

A human supervisor manages a staff of robots in a security operations center.

Managed detection and response services (MDR) offer something that many small and medium-sized businesses (SMBs) struggle to build themselves: around-the-clock cybersecurity monitoring backed by experienced security analysts.

The problem for SMBs is economics. Maintaining a high level of expertise and a robust cybersecurity infrastructure can be expensive, which makes sophisticated MDR and its underlying extended detection and response capabilities accessible only to enterprises or large businesses that can afford it.

AI is now changing that. Even as AI increases the need for sophisticated defenses, it can automate enough security work so that MDR services are attainable for smaller organizations.

In a recent white paper, ESET describes AI-powered SOC technology as having the potential to make enterprise-grade protection "more affordable and accessible."

"AI-powered SOCs can automate significant portions of cybersecurity workflows, helping to relieve experienced human analysts from alert fatigue and enabling them to focus on the highest-priority strategic issues," says the white paper.

Why in-house security programs often have trouble keeping up with AI

The widespread adoption of AI pressures SMBs from inside and out. Employees are introducing generative AI and autonomous agents into business processes, sometimes without IT oversight, while attackers can use AI to improve social engineering, discover vulnerabilities and scale phishing, scams and other malicious activity.

Autonomous systems also expand the attack surface because they can access data, invoke services and perform business-critical tasks, often with few guardrails. The associated risks may range from sensitive-data leakage to compromised AI components and agents operating outside their intended scope.

Keeping pace with the rapid development of AI, in which new technologies and concepts are widely adopted seemingly every month, also requires expertise and constant attention that smaller security teams may lack.

How AI-driven responses enable MDR to expand its user base

ESET's PROTECT MDR services use AI to ingest endpoint telemetry, correlate activity, cluster related events and filter noise, while its Live AI technology can investigate incidents, recommend remediation and provide a way to isolate affected resources.

This lets human experts concentrate on ambiguous and high-priority threats rather than manually processing every alert. The key is not replacing analysts with AI but making those analysts more efficient.

ESET's redesigned PROTECT portfolio illustrates the resulting service model. PROTECT Premium provides autonomous MDR response supervised by security experts 24/7, while Ultimate adds live access to threat hunters plus threat analysis and remediation. Both are available starting at 10 seats, a significant departure from the traditional enterprise-only MDR model.

How integrated AI security and guided onboarding reduce complexity and operational burdens

Yet affordability will matter little if MDR is too complicated for a small IT team to deploy and operate. That's why integration is part of the value proposition.

ESET is building AI Agent Security, Behavioral Monitoring and Conversation Security into its PROTECT portfolio rather than requiring customers to assemble separate products. Endpoint, AI workload, cloud, identity and other protections are similarly available through one platform and console.

Guided MDR onboarding is intended to reduce setup complexity and implementation risk. Optional packages can add email protection, MFA, vulnerability and patch management, awareness training and a cyber warranty, extending MDR toward a broader resilience service.

AI is raising the security stakes for SMBs, but it can also make affordable defenses that were previously available mainly to enterprises. By automating correlation, investigation, triage and response, MDR providers can spread scarce human expertise across more customers without eliminating expert supervision.

This hybrid model combining machine speed with human judgment may ultimately be AI's most consequential contribution to MDR. It not only makes security operations faster but puts sophisticated 24/7 protection within reach of organizations that could never afford to build their own SOCs.

An In-Depth Guide to AI

Get essential knowledge and practical strategies to use AI to better your security program.
Paul Wagenseil

Paul Wagenseil is a custom content strategist for CyberRisk Alliance, leading creation of content developed from CRA research and aligned to the most critical topics of interest for the cybersecurity community. He previously held editor roles focused on the security market at Tom’s Guide, Laptop Magazine, TechNewsDaily.com and SecurityNewsDaily.com.

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds