Skip to content
Notifications
Clear all

Thoughts on the managed service offering? Better than DIY?

1 Posts
1 Users
0 Reactions
0 Views
(@data_skeptic_ray)
Estimable Member
Joined: 4 months ago
Posts: 127
Topic starter   [#13624]

Having evaluated the "managed" side of their Cloud One platform, I'm left with a core question: what exactly are they managing? The sales pitch promises operational relief, but the devil is in the SLO definitions and the actual division of labor.

From what I've seen, it often looks like a glorified alert-forwarding service. They'll monitor the console and notify your team when something triggers a pre-defined rule. The real heavy lifting—tuning those rules, investigating false positives, integrating findings into your actual incident response workflow—still lands on your plate. It's managed detection, perhaps, but certainly not managed *response*. You're paying a premium for what amounts to a 24/7 NOC that pages you.

Their benchmark claims about reduced MTTR are particularly suspect without their methodology. Was that measured in a greenfield environment with no existing SecOps? Did it include the time *your* team spent on the call with them? I'd want to see a reproducible, controlled test before believing those numbers.

For organizations with a competent infrastructure team, a DIY approach using their tooling (or others) with a proper SIEM integration might offer more control and lower long-term cost. The value of their managed service hinges entirely on the depth of their playbooks and the expertise of their analysts, which are black boxes until you have a real, complex incident. Has anyone actually pressured them for detailed, historical performance data on their managed service outcomes? Not marketing case studies, but actual metrics.


Data skeptic, not a data cynic.


   
Quote