The tools produce the alerts; the centre decides what they mean. An analyst on the first tier looks at each alert, checks it against the known false positives, and either closes it, enriches it with context, or escalates it. The second tier investigates the escalations, pulling logs from the SIEM, telemetry from the endpoints and history from the identity provider to decide whether something is really happening and how far it reaches. The third tier hunts: it looks for what the detections missed, writes new ones, and takes the hardest cases. Around them sit the engineers who keep the tooling running and the detections current, and above them sits the incident response process that takes over when a case is confirmed.
- Tier one: triage. Volume, speed, and a good list of what to ignore. The role with the highest turnover in the industry.
- Tier two: investigation. Reading logs across sources, forming a hypothesis, confirming or discarding it.
- Tier three: hunting and detection engineering. Finding what the rules missed and turning it into a rule.
- Engineering: the SIEM, the endpoint platform, the automation that handles the routine so analysts handle the rest.
- Management: the metrics, the shift pattern, the escalation to incident response, and the argument for budget.
Around the clock is the expensive part. Covering every hour of the year with at least two people who can do this work needs a team of ten or more, plus the tooling, plus the training, and the alerts do not arrive politely during office hours. Managed detection and response providers sell exactly that coverage, watching many customers' telemetry from one centre, and for most organisations below a few thousand staff the honest comparison is between a provider's shared team and an internal team that will be understaffed at night. The certifications that lead into this work, the vendor-neutral analyst paper and Microsoft's operations exam, both describe the tier-two skills: read the query, say what it returns, decide what it means.
What to keep in house even when you outsource
The provider watches; someone inside has to act. Containment on your systems, the decision to disable an executive's account or take a service offline, the knowledge of which server is the payroll system and which is a test box, and the ownership of the response plan cannot be bought from outside. A managed service with nobody inside who can act on its calls is an expensive way to be told about a breach.
