The Business of Cyber Security

Managed Detection and Response (MDR)

MDR delivers 24/7 detection and active response as an outcome on the provider's own platform, and it trades at higher multiples than traditional managed security. On Aug 1, 2025, Zscaler completed its acquisition of Red Canary for ~$675M — roughly 4.8× Red Canary's ~$140M ARR, a software-like multiple for a "services" business — with Zscaler citing agentic AI plus human expertise as the rationale.

Other transactions across an 18-month run followed the same logic: Sophos closed Secureworks (Feb 2025); Arctic Wolf closed its purchase of BlackBerry's Cylance assets (Feb 3, 2025, ~$160M total — ~$80M cash at close + ~$40M deferred + ~5.5M shares), turning an endpoint engine into Aurora Endpoint Security; and LevelBlue absorbed Trustwave's cloud-native MDR (closed Aug 19, 2025). The pattern: MDR is the slice of services that trades like software, so platforms either buy their way into a 24/7 response outcome or build one — because MDR combines the recurring-revenue stickiness of services with the gross margin of a product.

What MDR is: the outcome, not the tooling

MDR sells an outcome: 24/7 detection of threats and active response — containment, isolation, remediation — delivered on the provider's own platform and telemetry, with a team of analysts doing the threat-hunting and the hard investigation a tool can't. The contrast with the classic MSSP (04a) is central: an MSSP manages the customer's devices and hands over an alert; an MDR provider detects and responds on the customer's behalf on a stack it controls. That single shift — from "we'll watch your tools" to "we'll deliver the security result on our platform" — is what gives MDR its better economics: the provider's platform leverages each analyst across many customers (higher gross margin, ~65–75% vs. an MSSP's ~45–60%), and the offering is sticky because it's an outcome the customer can't easily re-insource. MDR is, in effect, "SOC-as-a-service" productized — and it grew up inside the MSSP category before turning around to eat it from above.

The named-player map (four archetypes)

MDR providers cluster into four archetypes, each associated with a different acquirer and multiple:

1. Scaled independent pure-plays — the IPO/strategic-exit candidates. - Arctic Wolf — Aurora open-XDR platform (200+ integrations); the largest independent, Evolution-backed, ~$4.4B last private valuation, >$300M ARR (estimate; likely higher), repeatedly described as IPO-ready (CEO publicly "not in a hurry"). Bought Cylance (Feb 2025) to add an owned endpoint engine — the "control your own telemetry" move. In Aug 2026 it repositioned Aurora explicitly as an agentic SOC, reporting more than 10 trillion events processed and more than 200,000 investigations run weekly, with over 60% of cases autonomously closed, and pricing it on flat, unlimited-ingestion terms against the metered pricing common in AI security — a direct test of whether the agentic SOC expands MDR margin or becomes a commoditized feature (see 04c). - eSentire, Expel (Forrester Wave Leader, SaaS-style MDR), Deepwatch, Critical Start, Huntress (SMB-native, channel-led; passed $250M ARR at 65% YoY growth in July 2026, protecting more than 270,000 businesses — the largest independent scaled below the enterprise tier, see 07g).

2. Product-platform managed tiers — MDR as an attach to a software platform (highest margin, hardest for independents to compete with on price). - CrowdStrike Falcon Complete, Microsoft Defender Experts (XDR), Palo Alto Unit 42 + Cortex (MDR via Cortex XDR), Rapid7 MDR, SentinelOne Vigilance/MDR, Sophos MDR (now carrying Secureworks' Taegis). These are the disintermediation threat to independents: the customer gets "managed" from the vendor it already runs.

3. Platform acquirers building a SecOps managed motion. - Zscaler (Red Canary, $675M, closed Aug 1, 2025) — bolting a top-tier MDR brand and analyst bench onto a SASE/zero-trust platform to enter security operations. - Sophos (Secureworks, Feb 2025) — Taegis XDR + Counter Threat Unit, TB-owned; one of the largest MDR rosters in the market. In July 2026 Sophos consolidated its portfolio under Sophos Fusion, an AI-native defense system that evolves Sophos Central on an open architecture and embeds the Taegis analytics engine across endpoint, network, identity, email, and cloud, with 500+ third-party integrations — the first full product integration of the Secureworks asset. Sophos reports its own operations resolve 52% of cases without human intervention at an 89-second average automated response time; a Next-Gen SIEM tier (long-term retention, compliance reporting) is scheduled for general availability on August 15, 2026, and a shadow-AI-visibility add-on (Sophos AI Defense) launched in early access. (Sophos, Jul 2026 · SiliconANGLE, Jul 15 2026)

4. Carrier / GSI / IR-led managed. - LevelBlue (Trustwave's MDR + Alert Logic managed services), Verizon, Mandiant (Google), Kroll, IBM, Accenture, Bitdefender, Red Sift at the IR-and-enterprise end.

How the value is migrating: platforms absorb the leading MDR brands

MDR consolidation: the scaled brands get absorbed Independent MDR brand → its acquirer (2025) Red Canary Secureworks (Taegis) Trustwave MDR Cylance (endpoint) Zscaler · $675M · 4.8× ARR Sophos (TB) LevelBlue Arctic Wolf (~$160M) Largest remaining independents: Arctic Wolf (IPO-track), eSentire, Expel, Deepwatch, Huntress, Critical Start Product-platform managed tiers (Falcon Complete, Defender Experts, Cortex, Rapid7 MDR) compete from above
2025's MDR absorption: the scaled brands moved into platforms, leaving a thinner set of large independents led by Arctic Wolf. Sources: Zscaler completes Red Canary (Aug 1, 2025); Arctic Wolf closes Cylance (Feb 3, 2025); LevelBlue–Trustwave (Aug 19, 2025).

The Red Canary comp is the one every MDR founder and sponsor will now cite: ~$675M on ~$140M ARR ≈ 4.8×, a multiple that sits between services and software because the buyer paid for an outcome-platform-plus-analyst-bench it could leverage with agentic AI, not for billable hours. That is the prize the whole category is chasing — and the reason Arctic Wolf's owned-telemetry move (buying Cylance) matters: an MDR that controls its own endpoint/sensor data captures more of the value than one reselling someone else's platform, which both lifts its margin and widens its strategic-buyer set.

The bear case

The bull case: MDR is the high-margin, sticky, fast-growing answer to the SOC talent shortage, validated by software-like exit multiples. Three counterweights. First, the product platforms compete from above and may win the mid-market on bundling: when CrowdStrike, Microsoft, and Palo Alto can attach a managed tier to the platform the customer already runs, the independent MDR's price umbrella erodes and its differentiation narrows to "vendor-neutral" — a real but shrinking edge. Second, the agentic SOC may commoditize the analyst bench that justifies the premium (04c): if AI agents do L1/L2 investigation at near-zero marginal cost, then "24/7 human-led response" loses scarcity value, and MDR pricing power compresses toward software gross margins without software's scalability — squeezing the in-between players. Third, MDR ARR may not be as software-grade as the multiple implies: response work carries real labor and incident-driven variability, gross retention depends on SLA performance, and a string of misses can churn an "outcome" contract faster than a tool subscription. Falsifiable test: watch whether a large independent MDR (most plausibly Arctic Wolf) reaches the public markets at a software-grade multiple and holds it, or whether the remaining independents are all absorbed pre-IPO (like Red Canary, Secureworks, Trustwave) while the product platforms take the mid-market — in which case "MDR is a durable independent category" weakens to "MDR is the managed tier every product platform must own."

Cross-references: Service Providers, MSSP, The Agentic SOC, Endpoint, SecOps & SIEM, Deals & Comps, Valuation, Operator Economics.


Updated 2026-08-16 18:13 UTC · © El Dorado Capital · el-doradocapital.com · Market intelligence for informational purposes only; not investment advice.