Skip to content

Human-Led MDR vs Automated MDR: Why the Analyst Difference Matters

Human-led MDR vs automated MDR comparison infographic

Your MDR provider says it monitors your environment 24/7. Fine. Now test that claim. At 2 AM on a Tuesday, when an attacker abuses legitimate admin tools and slips past the initial rule set, who actually investigates? A trained analyst, or a scripted runbook that already missed the compromise on the way in? We work with SMBs across the Nordics and Europe at Falconer Security, and the single factor that most reliably separates “threat caught” from “threat missed for three weeks” is the gap between real human-led MDR and automation-only MDR with a human answering machine attached.

The 2025 Gartner Market Guide for Managed Detection and Response defines MDR as “remotely delivered, human-led, turnkey, modern SOC functions.” That phrasing is deliberate, and Gartner put “human-led” in there because too many vendors had stopped doing it. The rest of this post is about why the distinction matters, what fully automated MDR actually misses, and how to evaluate providers on the analyst layer they actually deliver rather than the one they claim.

What human-led MDR actually means

In a human-led MDR service, trained security analysts actively triage, investigate, and respond to threats in your environment. Automation handles the grinding work, which means data collection, correlation, and the first pass of filtering. Analysts make the judgement calls. Is this suspicious activity a real attack? What is the attacker trying to do? How should we respond, and what are we willing to break to do it?

This is not the same thing as “we have analysts on staff.” Plenty of vendors have analysts somewhere in the building without having them anywhere near the detection workflow. Human-led MDR means analysts sit inside the detection and response loop. They review escalated alerts, run proactive hunts for threats that automated rules missed, and make decisions based on context machines cannot read off a log.

Key distinction: Human-led MDR does not mean analysts do everything manually. It means automation accelerates analysts, and analysts make the decisions that matter. The best MDR services combine both, using AI for speed and human judgement for accuracy.

Microsoft’s own Defender Experts for XDR service illustrates what this looks like when implemented properly. Per Microsoft Learn documentation, the service uses “a combination of automation and human expertise” to triage incidents, with experts running detailed investigations and giving actionable managed response recommendations to SOC teams.

What automated MDR looks like in practice

Automated MDR leans primarily on detection rules, machine learning models, and predefined playbooks to identify and respond to threats. When an alert triggers, the system follows a scripted workflow. It enriches the alert with threat intel, scores it, and either auto-remediates or opens a ticket.

For known, predictable threats that model works fine. Commodity malware gets contained quickly. Brute-force attempts get blocked. Known-bad IP addresses get rejected at the edge. The problem is everything else, which is to say most of what actually matters.

Where automation breaks down

  • Living-off-the-land attacks: Attackers using PowerShell, PsExec, or legitimate admin tools to move laterally look identical to normal IT operations. Automated rules either miss them entirely or generate so many false positives that real attacks get buried.
  • Business email compromise (BEC): Small changes in email forwarding rules or OAuth app consent do not trigger automated alerts because the individual actions are technically legitimate. Analysts recognise the pattern because they understand the business context.
  • Novel attack techniques: The CrowdStrike 2026 Global Threat Report found that AI-enabled attacks surged 89% year-over-year, with average breakout times down to 29 minutes. Automated rules built for yesterday’s techniques miss tomorrow’s variations. Analysts adapt in real time.
  • Alert fatigue and noise: Automation generates alerts. Without analysts filtering signal from noise, security teams drown. We routinely find that default Sentinel detection rules generate far more noise than actionable intelligence.

Human-led MDR vs automated MDR: side-by-side comparison

Capability Human-Led MDR Automated MDR
Alert triage Analyst reviews context, determines real vs. false positive Rule-based scoring, auto-classification
Threat hunting Proactive hypothesis-driven searches for hidden threats Scheduled queries only, limited to known patterns
Novel attack detection Analysts recognise unusual behaviour even without matching rules Misses attacks that don’t match predefined signatures
Response decisions Context-aware: analyst weighs business impact before acting Follows playbook: may over-isolate or under-respond
False positive rate Lower: analysts filter noise before escalation Higher: automated scoring has limited context
Detection tuning Continuous: analysts adjust rules based on real-world findings Periodic: tuning depends on vendor update cycles
Business context Analysts learn your environment, users, and normal operations Limited to metadata and predefined asset classifications
Scalability Constrained by analyst capacity, but expertise improves accuracy Scales easily across large environments

Why Gartner emphasises the human element

The 2025 Gartner Market Guide for MDR services makes the position clear: MDR must stay human-led. AI supports analysts. AI does not replace them. Gartner projects that by 2028, 50% of MDR findings will include threat exposures (up from around 20% today), and that kind of contextual analysis is not something automated systems can deliver on their own.

Rapid7 put it more bluntly in their analysis of the Gartner Guide: “AI equals assistance, not autonomy.” The emphasis is on agentic AI models that enrich alerts, draft response paths, and filter noise. Analysts still make the final call.

Why is the analyst layer so load-bearing? Because attackers adapt faster than automated rules, and they know it. The CrowdStrike 2026 Global Threat Report puts breakout times at 29 minutes. The investigation and response window is too narrow for ticket-based workflows but still too consequential to hand to scripts that might isolate your CFO’s laptop during a board meeting over what turns out to be a false positive.

The real cost of the analyst gap

Pick an MDR provider with weak analyst coverage and the consequences show up on a spreadsheet. The IBM Cost of a Data Breach Report 2025 pegged the global average breach cost at $4.44 million, and organisations using security AI and automation reduced that cost significantly. The catch: that reduction came from AI plus analysts, not AI alone. Automation on its own, with nobody directing it, creates blind spots that look exactly like coverage until they don’t.

The ISC2 2025 Cybersecurity Workforce Study confirms a persistent global shortage, with 33% of organisations citing budget constraints as the primary driver. Building an in-house SOC with experienced analysts is rarely on the table for SMBs. That is exactly why the quality of analysts inside your MDR provider’s SOC matters more than any single feature on their platform.

What Falconer Security sees in practice: When we inherit environments from automation-heavy MDR providers, we consistently find untuned detection rules, unreviewed alert backlogs, and threats that persisted for weeks because automated systems classified them as low-severity. The technology was running. Nobody was watching.

What to look for in a human-led MDR provider

Not every provider claiming “24/7 analyst coverage” delivers the same thing. Five questions that separate real human-led MDR from marketing copy.

1. Ask about analyst-to-customer ratios

One analyst covering 200 customers is automation with human oversight bolted onto escalations. Genuine human-led MDR needs ratios where analysts can actually learn your environment. The question to ask, verbatim: how many customers does each analyst support, and can you prove it?

2. Demand transparency on response actions

A real human-led provider can show you what analysts did during an investigation. The queries they ran, the evidence they reviewed, and why they reached the response decisions they did. If the output you get is automated alert summaries and nothing else, the human layer is cosmetic.

3. Check for proactive threat hunting

Scheduled queries are automation. Hypothesis-driven hunts based on emerging intelligence are the human-led part. Ask how many threat hunts they ran in the last quarter and what they found. Vague answers mean the hunting is not actually happening, whatever the service description says.

4. Evaluate detection engineering capabilities

Does the provider write custom detection rules for your environment, or do you get the same generic rule set as every other customer? Custom detection engineering is one of the clearest indicators of genuine human-led MDR. Generic rules catch generic threats and miss the specific attack patterns targeting your industry and infrastructure.

5. Verify NIS2 and compliance alignment

For EU organisations, NIS2 Article 21 mandates specific incident handling and reporting capabilities. Your MDR provider should walk you through how their analyst workflows map to those requirements, not just point at an audit trail from automated logging. The directive text is on EUR-Lex for reference.

How human-led MDR works with Microsoft Sentinel

If you run Microsoft environments, pairing Microsoft Sentinel (cloud-native SIEM) with human-led MDR is the strongest security operations model available. What follows is how that actually plays out on an engagement.

Sentinel collects and correlates security data from across your Microsoft 365, Azure, and Entra ID environment. Automated rules handle the first layer of detection. Then human analysts take over. They review escalated incidents, hunt for threats the rules missed, tune detection logic to reduce noise, and respond to confirmed attacks with actions that factor in business impact.

That combination also answers the fundamental limitation of Sentinel on its own. I have written about it before. A SIEM without analysts is a data collection tool, not a security solution. The platform generates alerts. Analysts decide which alerts are real threats and take action.

Our managed Sentinel offering is built around dedicated analysts who learn each client’s environment, write custom KQL detection rules, and run regular threat hunts. That is the practical implementation of human-led MDR in a Microsoft-native environment.

When automated MDR makes sense

There are cases where fully automated MDR is the right answer. For an organisation with very limited budget and no existing security monitoring, automated MDR is meaningfully better than nothing. It gives you baseline coverage against commodity threats like known malware, brute-force attacks, and basic phishing. That is real protection.

But if you handle sensitive data, operate under regulatory requirements like NIS2, or face anything resembling targeted threats, automated MDR on its own leaves gaps that show up in breach reports. The question is not “can we afford human-led MDR?” The question is whether you can afford the consequences of the gaps automation-only leaves behind.

Frequently asked questions

What is the difference between human-led MDR and automated MDR?

Human-led MDR places trained security analysts at the centre of threat detection and response. Analysts actively triage alerts, investigate suspicious activity, hunt for hidden threats, and make response decisions based on business context. Automated MDR relies primarily on detection rules, machine learning, and predefined playbooks to handle alerts without consistent human review.

Why does Gartner recommend human-led MDR?

The 2025 Gartner Market Guide for MDR explicitly defines MDR as “human-led, turnkey, modern SOC functions.” Gartner emphasises that AI should support analysts rather than replace them, because advanced threats require contextual judgement that automated systems cannot reliably provide.

How do I know if my MDR provider is truly human-led?

Ask about analyst-to-customer ratios, request examples of actual investigation reports (not automated summaries), and verify that the provider runs proactive threat hunting. Genuine human-led MDR providers can point to specific threat hunts conducted, custom detection rules written, and investigation narratives showing analyst decision-making.

Can automated MDR detect living-off-the-land attacks?

Automated MDR struggles with living-off-the-land attacks because these techniques use legitimate system tools like PowerShell and PsExec. The individual actions look normal to automated rules. Human analysts catch these attacks by recognising patterns of behaviour that are technically legitimate but operationally suspicious in context.

Is human-led MDR relevant for NIS2 compliance?

Yes. NIS2 Article 21 requires organisations in essential and important sectors to implement cybersecurity risk management measures, including incident handling capabilities. Human-led MDR provides the investigation, analysis, and reporting capabilities NIS2 demands, while automated MDR may fall short of the incident response depth the directive requires.