Deepwatch is a managed detection and response provider. Rather than selling a product a customer installs and operates, it delivers security monitoring as a service: telemetry from the customer's endpoints, network, cloud accounts and identity systems is ingested into a managed detection platform, detection content is maintained against it, and analysts triage what fires around the clock, escalating the alerts that represent real activity and handling or directing containment when something is confirmed.
The detection stack is built around a managed SIEM — Splunk in many deployments — with integrations to endpoint detection and response tools, network sensors, firewalls, cloud provider logs and identity providers. Around that sits the service layer that customers actually interact with: a portal for alerts, cases and reporting, an assigned delivery team who learn the environment, agreed escalation paths, and service levels for acknowledgement and response.
What matters for a customer-side team is that MDR is a shared responsibility model, not an outsourcing of security. The provider cannot detect what it is not sent, cannot tune out false positives without context about your business, and in most engagements cannot take containment actions your change process has not authorised. The work that determines whether a Deepwatch engagement succeeds is largely done on the customer side: deciding what telemetry to onboard, supplying asset and business context, agreeing what constitutes an escalation, staffing the response end, and reviewing detection coverage against the threats that actually apply.
Why this skill matters now
Building a twenty-four-hour security operations capability in house is out of reach for most organisations. Genuine round-the-clock coverage needs roughly a dozen analysts across shifts before anyone has written a single detection rule, and the market for experienced detection engineers is thin at any price. Managed detection and response exists because that arithmetic does not work for the majority of organisations that still need continuous monitoring.
At the same time, cyber insurance requirements, customer security questionnaires and regulatory expectations have converged on continuous monitoring and demonstrable incident response as baseline conditions. Signing an MDR contract satisfies that on paper, which is precisely where the risk sits: an organisation can be paying for monitoring while sending incomplete telemetry, ignoring escalations outside business hours, and having never tested the handover between the provider and its own responders.
The skill that is genuinely short, therefore, is not operating a vendor console. It is being a competent customer of a security service — knowing what to onboard and in what order, reading detection coverage against a framework rather than trusting a coverage claim, triaging and challenging escalations, running the response steps that only you can run, and holding the service to measurable outcomes at a review rather than accepting a dashboard of alert counts.