Managed Detection and Response (MDR)

MDR delivers 24/7 detection and active response as an outcome on the provider's own platform, and it trades at higher multiples than traditional managed security. On Aug 1, 2025, Zscaler completed its acquisition of Red Canary for ~$675M announced, recorded at $651.4M — 4.62× the $141M of ARR the acquirer later disclosed it contributed, a software-like multiple for a "services" business — with Zscaler citing agentic AI plus human expertise as the rationale.

Other transactions across an 18-month run followed the same logic: Sophos closed Secureworks (Feb 2025); Arctic Wolf closed its purchase of BlackBerry's Cylance assets (Feb 3, 2025, ~$160M total — ~$80M cash at close + ~$40M deferred + ~5.5M shares), turning an endpoint engine into Aurora Endpoint Security; and LevelBlue absorbed Trustwave's cloud-native MDR (closed Aug 19, 2025). The pattern: MDR is the slice of services that trades like software, so platforms either buy their way into a 24/7 response outcome or build one — because MDR combines the recurring-revenue stickiness of services with the gross margin of a product.

What MDR is: the outcome, not the tooling

MDR sells an outcome: 24/7 detection of threats and active response — containment, isolation, remediation — delivered on the provider's own platform and telemetry, with a team of analysts doing the threat-hunting and the hard investigation a tool can't. The contrast with the classic MSSP (04a) is central: an MSSP manages the customer's devices and hands over an alert; an MDR provider detects and responds on the customer's behalf on a stack it controls. That single shift — from "we'll watch your tools" to "we'll deliver the security result on our platform" — is what gives MDR its better economics: the provider's platform leverages each analyst across many customers (higher gross margin, ~65–75% vs. an MSSP's ~45–60%), and the offering is sticky because it's an outcome the customer can't easily re-insource. MDR is, in effect, "SOC-as-a-service" productized — and it grew up inside the MSSP category before turning around to eat it from above.

The named-player map (four archetypes)

MDR providers cluster into four archetypes, each associated with a different acquirer and multiple:

1. Scaled independent pure-plays — the IPO/strategic-exit candidates. - Arctic Wolf — Aurora open-XDR platform (200+ integrations); the largest independent, Evolution-backed, ~$4.4B last private valuation, >$300M ARR (estimate; likely higher), repeatedly described as IPO-ready (CEO publicly "not in a hurry"). Bought Cylance (Feb 2025) to add an owned endpoint engine — the "control your own telemetry" move. In Aug 2026 it repositioned Aurora explicitly as an agentic SOC, reporting more than 10 trillion events processed and more than 200,000 investigations run weekly, with over 60% of cases autonomously closed, and pricing it on flat, unlimited-ingestion terms against the metered pricing common in AI security — a direct test of whether the agentic SOC expands MDR margin or becomes a commoditized feature (see 04c). - eSentire, Expel (Forrester Wave Leader, SaaS-style MDR), Deepwatch, Critical Start, Huntress (SMB-native, channel-led; passed $250M ARR at 65% YoY growth in July 2026, protecting more than 270,000 businesses — the largest independent scaled below the enterprise tier, see 07g).

2. Product-platform managed tiers — MDR as an attach to a software platform (highest margin, hardest for independents to compete with on price). - CrowdStrike Falcon Complete, Microsoft Defender Experts (XDR), Palo Alto Unit 42 + Cortex (MDR via Cortex XDR), Rapid7 MDR, SentinelOne Vigilance/MDR, Sophos MDR (now carrying Secureworks' Taegis). These are the disintermediation threat to independents: the customer gets "managed" from the vendor it already runs.

3. Platform acquirers building a SecOps managed motion. - Zscaler (Red Canary, ~$675M announced / $651.4M accounted, closed Aug 1, 2025) — bolting a top-tier MDR brand and analyst bench onto a SASE/zero-trust platform to enter security operations. - Sophos (Secureworks, Feb 2025) — Taegis XDR + Counter Threat Unit, TB-owned; one of the largest MDR rosters in the market. In July 2026 Sophos consolidated its portfolio under Sophos Fusion, an AI-native defense system that evolves Sophos Central on an open architecture and embeds the Taegis analytics engine across endpoint, network, identity, email, and cloud, with 500+ third-party integrations — the first full product integration of the Secureworks asset. Sophos reports its own operations resolve 52% of cases without human intervention at an 89-second average automated response time; a Next-Gen SIEM tier (long-term retention, compliance reporting) is scheduled for general availability on August 15, 2026, and a shadow-AI-visibility add-on (Sophos AI Defense) launched in early access. (Sophos, Jul 2026 · SiliconANGLE, Jul 15 2026)

4. Carrier / GSI / IR-led managed. - LevelBlue (Trustwave's MDR + Alert Logic managed services), Verizon, Mandiant (Google), Kroll, IBM, Accenture, Bitdefender, Red Sift at the IR-and-enterprise end. - The carrier half of this archetype was until recently a category with no members. That changed on Aug 19 2026, when Munich Re agreed to acquire At-Bay at a $575M enterprise value; At-Bay sells At-Bay Stance MDR alongside its cyber policies, so a reinsurer now owns an MDR product outright rather than partnering for one (11, 24a). The economics differ from every other archetype on this page. A platform sells MDR to protect attach rate and a services firm sells it for margin; a carrier that also underwrites the insured buys it because a shortened or avoided incident reduces a loss it would otherwise pay itself. That basis is not available to a strategic or sponsor buyer of the same asset, so an MDR comp set that mixes carrier buyers with vendor and services buyers mixes two pricing logics — the same dividing line drawn for cyber consulting at AXA XL–S-RM on 24a.

How the value is migrating: platforms absorb the leading MDR brands

MDR consolidation: the scaled brands get absorbed Independent MDR brand → its acquirer (2025) Red Canary Secureworks (Taegis) Trustwave MDR Cylance (endpoint) Zscaler · $651M · 4.6× ARR Sophos (TB) LevelBlue Arctic Wolf (~$160M) Largest remaining independents: Arctic Wolf (IPO-track), eSentire, Expel, Deepwatch, Huntress, Critical Start Product-platform managed tiers (Falcon Complete, Defender Experts, Cortex, Rapid7 MDR) compete from above
2025's MDR absorption: the scaled brands moved into platforms, leaving a thinner set of large independents led by Arctic Wolf. Sources: Zscaler completes Red Canary (Aug 1, 2025); Arctic Wolf closes Cylance (Feb 3, 2025); LevelBlue–Trustwave (Aug 19, 2025).

The Red Canary comp is the one every MDR founder and sponsor will now cite, and the acquirer's filing has since given it a firmer basis than the announcement did. Zscaler's FY2026 Form 10-K records total purchase price consideration of $651.4M — all cash, reconciling from $749.5M of assets acquired less $98.1M of liabilities assumed, and 3.5% below the ~$675M announced. Against the $141M of ARR Zscaler subsequently disclosed Red Canary contributed (12a), the comp on the accounted figure is $651.4M / $141M ≈ 4.62×, against 4.79× on the announced value — the same denominator, 0.17 turns apart. The allocation is consistent with what was being bought: goodwill $545.4M (84% of the price), identified intangibles $162.5M — customer relationships $90.8M on a seven-year life, developed technology $61.1M on five, trademarks $10.6M — and $72.7M of deferred revenue written down to fair value, a reminder that a services book's contracted revenue is re-measured downward at close and does not carry across at its pre-deal value. A further $20.2M of restricted stock sits outside consideration as post-combination compensation (Zscaler FY2026 Form 10-K). The multiple sits between services and software because the buyer paid for an outcome-platform-plus-analyst-bench it could leverage with agentic AI, not for billable hours — a thesis Zscaler productised on Sep 9 2026 as Zscaler Agentic SOC, with the Red Canary bench named as a component of the product (04c). That is the prize the whole category is chasing — and the reason Arctic Wolf's owned-telemetry move (buying Cylance) matters: an MDR that controls its own endpoint/sensor data captures more of the value than one reselling someone else's platform, which both lifts its margin and widens its strategic-buyer set.

Below the named players: the tier that consolidates itself

The absorption pattern above describes what happens to MDR brands large enough for a platform to want. It does not describe the larger population beneath them — regional and mid-market providers with no national brand, no owned telemetry and no realistic path to a strategic buyer's balance sheet. That tier consolidates, but on different terms, and September 2026 produced two prints that show how.

The buyers are sponsor-backed operators, not strategics, and the capital is often debt. On Sep 16 2026 two managed-detection transactions were announced. Quorum Cyber acquired Ontinue from EQT Mid Market Europe, and CyberMaxx acquired Avertium from Sunstone Partners, the latter having closed five days earlier on Sep 11. Neither disclosed consideration and neither party in either deal reports revenue, so no multiple is derivable from either and none is asserted. What is disclosed is the funding structure on the CyberMaxx side: Periscope Equity invested in 2021 and Comvest Credit Partners provided a credit facility in 2025 that has funded the acquisition programme. A levered sponsor-backed operator buying from another sponsor prices against its own cost of capital and its ability to underwrite synergies it will execute itself — not against the public comparables that set the Red Canary mark. This is the mechanical reason the same asset class shows a wide multiple dispersion depending on which tier of buyer is transacting.

Hold periods here run long, and that shapes who is selling. Avertium was assembled by Sunstone Partners in May 2019 from the simultaneous purchase of three firms — Terra Verde Security, TruShield and Sword & Shield Enterprise Security — and sold in September 2026, a holding period of roughly seven years and four months. A growth-equity platform held two to three years past a conventional exit window is not usually a seller of choice, and a sale to a levered mid-market consolidator rather than to a strategic or a larger sponsor is consistent with that. The same reading applies to Ontinue, separated from Open Systems in 2023 and sold in 2026 to a services buyer after its sibling SASE business had already gone to a different acquirer in 2024.

What is bought is adjacency, not scale in the same activity. CyberMaxx sells continuous detection and response; Avertium sells assessment, security architecture, governance-risk-compliance advisory and penetration testing. The stated logic is holding a mid-market customer across the full sequence from first assessment through continuous defence, which is a wallet-share argument rather than a cost-synergy one. Combining a recurring managed book with a project-based advisory book also mixes two revenue qualities, and the blended multiple a future buyer applies will sit below what the managed book alone would earn — the same effect visible in the Optiv ACT carve-out on 11, where a services platform separated project work from recurring work rather than combining them.

Both September consolidations in this tier sit inside the Microsoft security ecosystem. Quorum Cyber and Ontinue both build on the Microsoft stack; Avertium is a Microsoft Security Solutions Partner with capability across Defender, Sentinel, Entra, Purview, Intune and Copilot. Consolidating within one vendor ecosystem raises utilisation of a single skill base and a single toolchain, which is where the margin improvement in a services combination actually comes from. It also concentrates the combined entity's exposure to that vendor's pricing, packaging and managed-tier strategy — the same platform tier identified in archetype 2 above as the structural competitor to independents.

The consequence for the category's comp set, measured rather than asserted. Of the 12 managed-security and security-services acquisitions logged for 2026 on 11, 11 disclose no consideration — 91.7% — and exactly one is priced: Munich Re's $575M enterprise value for At-Bay. That single priced observation comes from the carrier archetype, whose economics archetype 4 above identifies as unavailable to a strategic or sponsor buyer, because a reinsurer that also underwrites the insured is buying avoided loss rather than revenue. The category's only 2026 price mark is therefore set by the buyer type least representative of the rest of it.

The practical inference follows directly. A comparable-transaction analysis of this category assembled only from priced deals rests on one observation drawn from a buyer universe most assets here will never reach, while the other eleven transactions — the ones actually representative of how the tier trades — contribute nothing to it. Valuation in this part of the market is consequently governed by the buyer's own cost of capital and underwriting of self-executed synergies, not by an observable multiple; the absence of marks is a structural feature of a privately funded, privately held tier rather than a temporary gap in the record.

The bear case

The bull case: MDR is the high-margin, sticky, fast-growing answer to the SOC talent shortage, validated by software-like exit multiples. Three counterweights. First, the product platforms compete from above and may win the mid-market on bundling: when CrowdStrike, Microsoft, and Palo Alto can attach a managed tier to the platform the customer already runs, the independent MDR's price umbrella erodes and its differentiation narrows to "vendor-neutral" — a real but shrinking edge. Second, the agentic SOC may commoditize the analyst bench that justifies the premium (04c): if AI agents do L1/L2 investigation at near-zero marginal cost, then "24/7 human-led response" loses scarcity value, and MDR pricing power compresses toward software gross margins without software's scalability — squeezing the in-between players. Third, MDR ARR may not be as software-grade as the multiple implies: response work carries real labor and incident-driven variability, gross retention depends on SLA performance, and a string of misses can churn an "outcome" contract faster than a tool subscription. Falsifiable test: watch whether a large independent MDR (most plausibly Arctic Wolf) reaches the public markets at a software-grade multiple and holds it, or whether the remaining independents are all absorbed pre-IPO (like Red Canary, Secureworks, Trustwave) while the product platforms take the mid-market — in which case "MDR is a durable independent category" weakens to "MDR is the managed tier every product platform must own."

→ Cross-references: Service Providers, MSSP, The Agentic SOC, Endpoint, SecOps & SIEM, Deals & Comps, Valuation, Operator Economics.


Updated 2026-10-04 19:34 UTC · © El Dorado Capital · el-doradocapital.com · Market intelligence for informational purposes only; not investment advice.