Daylight Security Opens the MDR Black Box With Detection Program Visibility

Related

Share

Managed detection and response has always run on trust. Customers hand over their telemetry, a provider promises to watch it, and the actual detection logic stays behind the curtain. Most security leaders can tell you how many alerts landed last month. Far fewer can tell you whether the program generating those alerts got any better.

Daylight Security, a managed agentic security services company, is taking aim at that arrangement. The company today announced Detection Program Visibility, a capability that lets organizations measure and improve the effectiveness of their detection programs rather than taking a provider’s word for it.

Fragmentation Is the Starting Point

The problem Daylight describes will sound familiar. Organizations accumulate security tools. Each tool ships its own detections. SIEM content grows over the years into a sprawl of rules nobody fully audits. Then a managed detection provider arrives with its own detections, typically operated as a black box.

The consequence is fragmentation. Detections live across multiple systems with no shared view. Customers find it difficult to understand what is actually being detected, where coverage overlaps, and where the blind spots sit. Nobody owns the full picture, so nobody can say whether the whole is improving.

One Model, Mapped to ATT&CK

Detection Program Visibility pulls every detection into a single place: detections from security tools, SIEM content, and the detections Daylight operates on the customer’s behalf. Daylight organizes them into a shared model and maps them to MITRE ATT&CK.

On top of that structure, the company adds operational context. Alert volume, case outcomes, verdict statistics, overlap, and coverage gaps all sit alongside each detection. A security team can see not just that a detection exists but how it behaves in production.

Hagai Shapira, CEO and co-founder of Daylight Security, framed the release as a challenge to industry norms. “Security leaders know how many alerts they receive, but they rarely know whether their detection program is actually improving,” he said. “For years, MDRs have asked customers to trust what happens behind the curtain. We believe customers should be able to see the detection program protecting them, understand how it’s performing, and continuously improve it with us. Detection Program Visibility is another step toward making managed security transparent instead of opaque.”

The Investigation Feedback Loop

Coverage maps are not new. Plenty of standalone tools will show an organization how its detections line up against ATT&CK. Daylight’s argument is that visibility alone is not the point.

Because Daylight investigates the activity these detections generate, every investigation feeds information back into the picture. The company learns which detections find meaningful threats, which create noise, which overlap, and where coverage is missing. That feedback loop is what Daylight says separates the capability from a static dashboard. It turns detection engineering from a fixed collection of rules into a measurable program that improves continuously.

Detection Program Visibility

What Changes for Customers

The practical shift is one of accountability. Under the traditional MDR model, the provider’s detection work is invisible by design. Under Daylight’s model, the customer sees the same program the provider operates, complete with performance data.

That changes the conversation between provider and customer. Instead of quarterly reports summarizing alert counts, the two sides can look at the same evidence: which detections earn their place, which need tuning, which duplicate each other, and which gaps deserve attention next. Improvement stops being an assertion. It becomes something both parties can verify.

Availability

Detection Program Visibility is available now for Daylight Managed Agentic MDR customers.

The broader question the release raises is whether opacity was ever a necessary feature of managed detection or merely a convenient one. Daylight is betting that customers, given the choice, will prefer a provider whose work they can inspect. If that bet pays off, the black box that has defined MDR for years may start to look less like a standard practice and more like a liability.

IMG 0514 2
+ posts

John Kevin Hao is a news and feature writer covering cybersecurity, technology, and business targeted for professional audiences.