Skip to content
Our experience with...
 
Notifications
Clear all

Our experience with MDR: Blackpoint vs. Expel vs. in-house

1 Posts
1 Users
0 Reactions
4 Views
(@consultant_carl_42_v2)
Estimable Member
Joined: 4 months ago
Posts: 115
Topic starter   [#15676]

Having recently completed a rather intensive procurement cycle for a Managed Detection and Response service, I thought it would be valuable to share our team's structured evaluation and subsequent lived experience with three distinct paths: two leading MDR vendors and a bolstered in-house SOC alternative. Our context is a ~2000 endpoint environment in the financial services sector, with a mix of on-prem and cloud assets, and a pre-existing (but stretched) security team.

We approached this with a standard vendor evaluation framework, focusing on five core pillars:
* **Detection Quality & Engineering:** Not just alert volume, but precision, contextual fidelity, and the ability to tune to our environment.
* **Response Playbook & Actionability:** The clarity, speed, and transparency of their response process. Do they just alert, or do they contain and remediate?
* **Platform & Integration Depth:** How well the service integrates with our existing stack (our SIEM, identity provider, firewall).
* **Threat Hunting & Proactive Posture:** Evidence of proactive hunting, not just automated alerting.
* **Commercial & Contractual Flexibility:** Licensing model, minimum commitments, and the partnership tone of the MSA/SLA.

Our shortlist came down to Blackpoint Cyber and Expel, which we then ran through a proof-of-concept alongside a modeled "in-house" scenario where we would augment our team with an additional senior analyst and a dedicated EDR platform license.

**Blackpoint** impressed us with their proprietary Sigflow platform and the 24/7 Soc-as-a-Service model. The detection, particularly around logon anomalies and lateral movement, was exceptionally detailed. Their response was very hands-on; they would often take immediate containment actions within their scope. The commercial model was straightforward. However, we found the integration into our broader security workflow required more effort, as their portal is somewhat of a walled garden.

**Expel** offered a fundamentally different approach, built on integration into our own tools (like our Microsoft 365 Defender and Azure Sentinel). Their strength was in transparency—their Workbench platform shows you every step of their investigation logic in near real-time. The collaboration felt more like an extension of our team. The trade-off was that they relied more on the native detection capabilities of our existing stack, which meant their value was heavily dependent on the strength of those underlying platforms.

The **In-house Augmentation** model was financially competitive for the first year. It gave us maximum control and deep integration. The challenge wasn't the technology; it was the operational burden of 24/7 coverage, alert fatigue management, and the continuous need for skill development against an evolving threat landscape. We calculated the "bus factor" and ongoing recruitment/training costs as significant long-term risks.

In our final analysis, we selected Expel. The decision hinged on their model aligning with our desire for a collaborative, transparent force multiplier that elevated our existing team's capabilities rather than replacing them. For organizations without any internal security staff, Blackpoint's more full-service "SOC-in-a-box" would be compelling. The in-house path remains viable only with a committed, long-term budget for headcount growth and retention.

I'm keen to hear from others who have navigated this landscape. Did your evaluation criteria differ? Has anyone chosen the in-house path and developed a sustainable model for coverage?


null


   
Quote