Guide

Cyber Security

The security domain holds the strategy and the operations that carry it out. It opens with Zero Trust, which is the strategy the rest of this library implements and is not a product anybody can sell you: what it actually is, where the idea came from and where it takes you, what it changes about the working day for the people signing in and the people running the estate, and an honest reading of the market beyond Microsoft. The second series turns to detection and response bought rather than built, and reads the managed market by the architecture each provider actually runs rather than by where it sits on somebody’s ranked list.

Zero Trust

4 articles

MDR

12 articles
MDR 1Start here
Anchor

Managed Detection and Response: Buying Operators, Buying a Stack, or Both

The MDR question is not which provider is best. It is whether you are buying a second security stack, operators for the one you already own, or a provider who replaces the layer your security data lives in, and who holds the authority to act inside your tenant.

MDR 2
Doctrine

Arctic Wolf: The Concierge and the Open Platform

The name that comes up first in most mid-market conversations, and the reason is the delivery model rather than the technology. The platform question and the delivery question have different answers, and the second one gets less scrutiny than it deserves.

MDR 3
Doctrine

Microsoft Defender Experts: The First-Party Answer

Microsoft operating Microsoft is the baseline case every other provider is implicitly priced against. What Defender Experts declines to cover is the fastest way to work out what you actually need from anyone else.

MDR 4
Doctrine

CrowdStrike Falcon Complete: The Second Stack, Fully Operated

The most complete version of the buy-a-second-stack answer, and the most architecturally consequential provider in this series for a Microsoft estate. CrowdStrike now sits inline in the Entra authentication flow, which makes it a second policy decision point in front of the one you built.

MDR 5
Doctrine

Huntress: Operating the Licenses You Already Own

What does an organisation with Business Premium, no security staff and a few hundred endpoints actually do? Huntress operates the Microsoft licences you already hold rather than selling a replacement for them, and that constraint has produced some of the most practical engineering in this series.

MDR 6
Doctrine

Expel: Authority With Guardrails

The purest expression of the operate-your-stack model: no agent, no platform to adopt, judgement sold against the tooling you already run. Expel has also done the best job in this market of writing down what its analysts may do and what happens when it goes wrong.

MDR 7
Doctrine

Red Canary Under Zscaler: When Your Zero Trust Vendor Owns Your SOC

Red Canary was the reference implementation of vendor-neutral managed detection until Zscaler bought it in August 2025. That transaction turns a straightforward evaluation into a question about what happens when your zero trust enforcement vendor also holds your detection contract.

MDR 8
Doctrine

Critical Start: The Only Service Level With a Clock and a Remedy

Critical Start publishes what nobody else in this market does: a response time with a defined start, a defined stop, and service credits when they miss. Plus the known-good registry that makes resolving every alert economically possible, and the question you should ask about it.

MDR 9
Doctrine

Palo Alto Unit 42 Managed XSIAM: Buying a Security Data Platform With Operators Attached

Palo Alto is the mirror image of the endpoint replacement. They leave your Defender agents alone and replace the layer above, which makes this a security data platform decision wearing a managed service label.

MDR 10
Doctrine

What the Contracts Actually Say: Authority, SLAs, Overlap, and the GenAI Claim

Eight providers, one set of questions, and the answers do not line up the way the marketing suggests they should. Where the real differences sit, which published numbers mean anything, what an E5 organisation ends up paying for twice, and how to run an evaluation that produces a decision.

MDR 10.1
Build sheet

Build Sheet: MDR Readiness in Your Own Tenant

A managed detection provider inherits your logging gaps on the day they onboard. Establish what your tenant actually produces and retains before you take a single vendor demonstration, so the evaluation compares providers rather than measuring your own instrumentation.

MDR 10.2
Build sheet

Build Sheet: The Evaluation Scorecard and Proof-of-Value Plan

Most MDR evaluations are decided by a demonstration and a reference call, which between them test the vendor sales engineering and their choice of referee. A scorecard you can defend to a board, and a provider-neutral proof-of-value plan that measures what actually comes back.