
Threat Talks - Your Gateway to Cybersecurity Insights
MDR Has To Stop Mopping The Floor
A CISO got breached and could not say how. No entry point, no list of what walked out, nothing to take to the board. He paid the ransom blind. Then he bought MDR. The next time, he had all of it. Who clicked, which data was touched, when it left. He still got breached. So what did the M in MDR actually buy him? Lieuwe Jan Koning, Co-founder & CTO at ON2IT, sits down at RSA Conference with Nicholai Piagentini, Technical Enablement Engineer at ON2IT and twenty years deep in the Bay Area security scene, to separate what MDR vendors pitch from what MDR delivers. Buyers think MDR is one product. It is five jobs: collect the logs, enrich them, put an experienced human in the loop, remediate, and keep it all retrievable. Most vendors do two of them well, and only inside their own stack. Three questions tell you which two. All three are in the episode, and in the description below. Timestamps (00:00) - The MDR reality check: expectation versus practice (01:33) - What buyers think they are buying (03:35) - Single pane of glass, and why nobody has one (06:40) - Why no vendor is paid to support a competitor's logs (07:42) - Log retention: when everything becomes hot storage (11:06) - Three questions to ask every MDR provider (13:20) - Data sovereignty: who operationally controls your logs (15:02) - The future of MDR, and why detection alone is cleanup (15:36) - The CISO who saw everything and still got breached The three questions In practice, what does your platform do with a log it did not create? Ask for the demo on a competitor's telemetry, not your own. Is there tiered storage, or does every log stay hot for the life of the contract? When I escalate, who picks up: someone who knows my environment, or someone reading an LLM's answer back to me? Key topics covered What "managed" means to different MDR vendors, and why a human in the loop is rarely part of the deal Why EDR, NDR, XDR and DDR all get reskinned as MDR, and what that does to scope The economics of vendor data lakes: every log priced as hot storage, with no tiering to warm or cold Commercial incentives that keep cross-vendor log support shallow, and how to test for it before you buy Data sovereignty and jurisdiction as a procurement requirement, not a European footnote Related ON2IT Content & Referenced Resources: Threat Talks: https://threat-talks.com/ ON2IT Zero Trust as a Service: https://on2it.net/ AMS-IX: https://www.ams-ix.net/ams Subscribe block Subscribe to Threat Talks and turn on notifications for deep dives into the world's most active cyber threats and hands-on exploitation techniques. Follow and Support our channel! ► YOUTUBE: / @threattalks ► SPOTIFY: https://open.spotify.com/show/1SXUyUE ... ► APPLE: https://podcasts.apple.com/us/podcast ... Receive your Threat Talks T-shirt https://threat-talks.com/ ️ Explore the Hack's Route in Detail ️ https://threat-talks.com ️ Threat Talks is a collaboration between @ON2IT and @AMS-IX






