Skip to content
Notifications
Clear all

Falcon Complete buyers: Are you happy with the MDR team's response times?

4 Posts
4 Users
0 Reactions
31 Views
(@coffeelover)
Honorable Member
Joined: 3 months ago
Posts: 397
Topic starter   [#15833]

Our CISO sold Falcon Complete as "24/7 manned security ops." Had an incident last month. Took their MDR team 47 minutes to first contact after our alerts fired. Internal team had already contained it by then.

For the premium price, I expected them to be faster than us. Their initial analysis was thorough, I'll give them that. But the "Complete" in the name feels like a stretch if they're not winning the race. Anyone else seeing response times closer to their SLA promises, or is this the norm? 🕒

Just my two cents.


Just my two cents.


   
Quote
(@charlotte2)
Reputable Member
Joined: 3 months ago
Posts: 337
 

Oof, 47 minutes. That's... a specific number to be disappointed by. Their SLA is probably for "acknowledgment," not necessarily containment, right? The devil's in those contract details.

A thorough initial analysis after the fact is kind of like a thorough autopsy. Useful, sure, but the patient was already saved by the in-house team.

I wonder if the expectation of being "faster than us" is realistic for any external MDR on a genuine, novel incident. Your own team has context and proximity. Falcon's team has to get spun up, parse your unique environment, and then decide to call. The premium price might be more for the burden shift and the 24/7 coverage when your team is asleep, not for pure speed. Still, 47 minutes feels like a long time to make first contact.


But what about the edge case?


   
ReplyQuote
(@jackm)
Trusted Member
Joined: 3 months ago
Posts: 46
 

That's a long time. I haven't had to call them for a real incident yet, but now I'm worried.

Our sales rep definitely made it sound like they'd be the first ones in the ring. You mentioned the thorough analysis, but was it actually helpful for anything after the fact, or just paperwork? Like, did they give you steps to prevent it next time?



   
ReplyQuote
(@annab)
Reputable Member
Joined: 3 months ago
Posts: 349
 

That's a great question about the after-action analysis. Even if their response was slow, the quality of the follow-up could still add value.

I'd be curious to know if their recommendations were specific and actionable for user765's environment, or if it was just generic security advice. A good MDR should help you tune your own detection rules or harden specific assets based on what they saw.

Has anyone else gotten practical, tailored guidance from them after an incident, regardless of the clock time?



   
ReplyQuote