Blog · Managed Security · July 12, 2026 · By Mike Parker

The Business Case for MDR (in Numbers a CFO Accepts)

Security pitches fail in the finance office because they arrive as fear. Here's the case for managed detection and response in the CFO's native language: staffing arithmetic, breach economics, and predictable spend.

Every CFO has sat through the security pitch with the hooded figure on slide two. Most have learned to tune it out — not because the risk isn't real, but because "be afraid" isn't a line item. So let's make the case for managed detection and response the way a finance leader would actually evaluate it: what the capability is, what it costs to build versus rent, and what the downside scenario costs when nobody's watching.

What you're actually buying

MDR is a staffed capability, not a software license: a 24/7 security operations center (SOC) that watches your endpoints, identities, and network; investigates the alerts; and — the part that matters — acts. Isolates the infected laptop at 3 a.m. Kills the hijacked session. Disables the account before the attacker finishes reconnaissance. The deliverable isn't alerts. It's containment, measured in minutes.

Option A: build it. (Bring a calculator.)

The build-it-yourself math is unforgiving, and it starts with a number that surprises people: 168. That's how many hours are in a week. One analyst covers 40 of them. Staffing a single around-the-clock monitoring seat therefore takes four people before anyone takes a vacation, gets sick, attends training, or quits — in practice, a rotation of about five, plus someone senior to run it. That's the payroll before you buy the detection stack, the log platform it feeds, and the retention those analysts will fight for in a market that bids security talent up relentlessly.

For an enterprise, that math is a department. For a 50-person company, it's a non-starter — the payroll for the rotation alone would rival the entire IT budget. Which is why the honest version of "we handle security in-house" at most SMBs is: one very tired IT person reads the alert queue when they can. Detection that sleeps isn't detection; the intrusions that hurt don't happen during business hours — they're timed for when nobody's at the console.

Option B: rent it. (This is the entire pitch.)

MDR prices the same capability per user or per endpoint, monthly. The provider spreads the SOC's fixed cost — the rotation, the tooling, the detection engineering — across hundreds of clients, and each client pays a predictable operating expense that scales with headcount. Time-to-capability is weeks of onboarding instead of quarters of hiring. And accountability lives in a contract with response commitments, not in a job description you hope to fill by Q3.

The downside scenario

What "nobody was watching" costs

The CFO's question is expected loss. Here's the published data behind the estimate.

$11.5M

average cost of a U.S. data breach — a record high

IBM Cost of a Data Breach 2026

247

days on average to identify and contain a breach — eight months of an intruder inside

IBM Cost of a Data Breach 2026

88%

of SMB breach incidents involve ransomware or extortion — vs. 39% at large orgs

Verizon DBIR 2026

Reading those numbers like a CFO

No, your breach wouldn't cost $11.5 million — that average, from IBM's Cost of a Data Breach 2026 study, skews toward large enterprises. But every component of it scales down and lands on a smaller balance sheet with less cushion: downtime while systems are rebuilt, incident-response and legal fees, notification obligations, the insurance retention, customers who quietly leave, and the premium hike at renewal. For plenty of small companies, two weeks of frozen operations is the catastrophic scenario.

The 247-day figure is the one that should genuinely bother a finance leader: that's the average time to identify and contain a breach, per the same IBM study. Eight months. The entire economic argument for MDR lives in that window — an intrusion caught in the first hour is an incident report; the same intrusion discovered in month six is a company-defining event. And per the Verizon DBIR 2026, when smaller organizations do get breached, 88% of the time it's the ransomware-and-extortion variety — the kind with downtime and a demand letter attached. Detection speed isn't a technical metric. It's the variable that decides which invoice you get.

So the CFO frame is straightforward: MDR is a modest, predictable monthly spend that collapses the expensive variable — dwell time — toward zero, priced at a fraction of one bad month. It also reads as risk management to the people who grade you on it: cyber insurers now effectively require 24/7 detection and response for decent terms (we covered what carriers demand separately), and client security questionnaires ask the same questions.

The questions a CFO should ask any MDR provider

  1. Who acts, and on what authority? Can your analysts isolate a machine or kill a session themselves, or do you email us and hope? "Alert-only MDR" is a contradiction in terms.
  2. What's covered? Endpoints only, or identities and cloud sign-ins too? (Most modern intrusions start with a login, not malware.)
  3. What are the response commitments? In writing, in the contract.
  4. What happens during a real incident? Is response included or billed hourly at 2 a.m. rates?
  5. What does reporting look like? A monthly summary a board member could read, or a log dump?
  6. What's the exit? Contract length, notice period, fees. (Ours: one-year initial term, then month-to-month with 60 days' notice and no exit fees — confidence in a service is easiest to judge by how easy it is to leave.)

MDR is the center of our managed cybersecurity service, it layers onto internal IT teams through co-managed IT, and the numbers are on the pricing page where a CFO can model them.

The breach math is published. The staffing math is arithmetic. MDR is what it looks like when a CFO runs both.

Quick answers

MDR economics, answered plainly

What is the difference between EDR and MDR?

EDR is software — an endpoint detection and response platform that watches devices for malicious behavior and raises alerts. MDR is the service wrapped around it: analysts watching those alerts around the clock, investigating them, and acting — isolating an infected machine, killing a hijacked session, disabling a compromised account. EDR without someone watching it is a smoke detector in an empty building.

We already have an MSP. Isn't this covered?

Often not. Traditional managed IT keeps systems running — patching, backups, helpdesk — which is different work from security monitoring and response. The clarifying questions: who reviews our security alerts at 2 a.m. on a Saturday, and what are they authorized to do without waking anyone? If the honest answer is "nobody" or "send an email we read Monday," you have IT management, not detection and response.

What does MDR cost for a small business?

It is typically priced per user or per endpoint, monthly, so it scales with headcount and reads as predictable operating expense. We publish our numbers rather than hiding them behind a quote form: our Secure IT plan, which includes the 24/7 SOC and MDR alongside full managed IT, is $250 per user per month. Whatever provider you evaluate, insist on pricing you can model in a spreadsheet.

Do we still need MDR if we carry cyber insurance?

Yes — they do different jobs. Insurance transfers part of the financial loss after an incident; it does not detect or contain anything. Carriers know this, which is why their questionnaires increasingly ask about 24/7 monitoring and response capability before quoting. In practice the two reinforce each other: MDR shrinks the incident, insurance absorbs the residue, and the premium reflects both.

Do small companies really get targeted?

The data says smaller organizations are where the worst attack type concentrates. Per the Verizon DBIR 2026, 88% of breach incidents at small and mid-sized businesses involved ransomware or extortion, versus 39% at large organizations. Attackers automate; the size of your logo is not a control.

Run the numbers on your own environment

A free 30-minute assessment with the owner — what 24/7 detection and response would cover in your business, and what it would cost. Bring the CFO.

Book a Free 30-Minute IT Assessment