Skip to content
Article

AI just reopened a question your peers thought was closed: who runs their detection.

By DoGood Team · July 2, 2026

Member Signal

The Member Signal is DoGood’s weekly peer-intelligence briefing for the member network. This issue went to members on July 2, 2026, and appears here lightly edited for the web.

The Signal

This month two currents in the network ran into each other. One is a cluster of members re-shopping managed detection, several of them unhappy with the response times they get from their current provider. The other is AI pressure landing squarely on the SOC. Where the two meet, AI has become the reason detection contracts get reopened, not just the reason budgets grow.

A finance CISO is evaluating an AI-powered managed-detection service and wants to measure the improvement over the current provider, line by line. Another finance CISO has put SIEM and XDR platforms up for review to lift detection while cutting operational complexity. A business-services CISO running a hybrid managed-detection model says that as the team moves toward AI, the current strategy no longer feels on par. Same trigger, different seats.

A year ago, “we have MDR” closed the conversation. Now it opens one. The question your peers are asking is not whether they are covered. It is whether what covers them is keeping pace with how fast the other side is moving.

From the Network

“We are looking at expanding our detection and response capabilities to include AI and I’m curious how this solution could help augment that.”

Divisional Senior Vice President, Insurance

“We want to explore how an autonomous, AI-driven platform can help us automate security actions and remediate risky employee behaviors in real time, scaling our security operations without interrupting daily workplace productivity.”

Chief Information Security Officer, Education

Two seats, one instinct. The moment AI enters the picture, the detection stack stops being settled infrastructure and turns back into a live decision.

Top Open Priorities

“We’re evaluating AI-powered MDR solutions to improve threat detection and response. I’d like to assess Daylight’s AI capabilities, analyst model, integrations, automation, and measurable improvements over our current MDR approach.”

Chief Information Security Officer, Finance

“We currently utilize a hybrid model with external MDR active. However as we are approaching AI, the strategy seems to not be onpar with our currrent model”

Senior Vice President & CISO, Business Services

Working on either of these? These are live asks in the network.

One is measuring an AI-native provider against the incumbent. The other is admitting the incumbent no longer keeps pace. Same conclusion from two directions: the detection contract is back in play.

New to the Network

Eighteen senior IT and security leaders joined the DoGood network in June. The senior cohort included:

Title Company
Senior Vice President, Information Security Bank of America
Chief Information Security & Privacy Officer Western Carolina University
Vice President & Chief Information Officer Denison University
Chief Information Officer Rite-Hite Corporation
Chief Technology Officer 3Z Brands
Chief Technology Officer Compass International
VP, Cyber Security Technology Bank of America
Senior Director of IT Sonder

The June cohort skews toward education, banking, and construction, and it tilts senior: CISOs, CTOs, and VPs of information security.

Member Spotlight

Nitin Agarwal, Wayne Memorial Hospital. This week the network is shopping AI-powered detection vendors. Nitin Agarwal has a rule for exactly that moment. He runs IT as CIO of a 120-bed rural hospital where every dollar has a conversation attached, and he judges a vendor by one test, put plainly in his DoGood spotlight: “They’re not a contract. They’re my partners.” He is just as deliberate on AI procurement, warning that the terms that matter most are the ones buried deep in the contract.

Read his full story →

Deep Dive: Detection & Response

Twenty-one member submissions touched detection and response in the last 90 days. The dominant pattern is not a coverage gap. It is dissatisfaction with the incumbent, and AI is the accelerant.

Where activity is concentrated

Replacing a managed provider is the largest piece. Most of the detection submissions are about swapping or re-bidding an existing service, not standing one up for the first time. The reasons named are consistent: slow response times, an MSP that cannot keep up, a strategy that feels behind as AI arrives. One hospitality IT director wants out over response time alone. One construction-sector CIO is planning the move off the incumbent while still under contract into 2027. A finance CISO is now measuring an AI-powered provider against the current MDR approach, capability by capability.

Folding AI into detection is the second cluster. Members are not asking whether to add AI. They are asking who does it well. An insurance leader wants to expand detection and response to include it. An education CISO wants an autonomous platform that automates response and remediates risky behavior in real time.

SIEM scale and cost is a smaller thread. A few members are re-examining SIEM on economics, per-user pricing and the cost of scaling, while weighing XDR and around-the-clock SOC monitoring on the side.

What your peers are buying

Booked meetings and active evaluations over the last month. Vendor, then buyer title and industry:

Vendor Activity
Daylight (AI-powered MDR) CISOs, Finance & others · Jun–Jul
Arctic Wolf (MDR) CIOs · late May–June
Red Canary (MDR) CISO / Deputy CISO · July; one construction CIO re-shopping away

The Red Canary line is the tell: winning the meeting is not the same as winning the renewal.

What’s still open

A managed provider members actually want to keep. No one named an incumbent they were happy with. The re-shopping is driven by service quality, response time above all, and no alternative has pulled ahead as a clear front-runner. The category is in motion with no default winner.

Detection that is AI-native, not AI-added. Members asking to “include AI” are describing a want, not a product they have chosen. That seat is open for whoever can show autonomy that holds up at the moment the AI hands a case back to a human.

If your MDR renewal is more than two quarters out, do not wait for it to start the evaluation. Pull your last quarter of escalations and measure one number: median time from alert to a human analyst actually taking action. That figure, not the autonomy percentage on the datasheet, is what your peers are switching over. Make your next vendor conversation answer to it.

The Context

The headlines are catching up to what the network already knew.

The detection vendors are rebuilding around exactly the pressure your peers described. In the last few months CrowdStrike launched an agentic managed-detection service that lets AI agents triage and respond at machine speed, and Sophos now reports its AI closing 52% of managed-detection cases end to end, acting in 89 seconds from case to response. Gartner still puts autonomous SOC agents at 1 to 5% adoption today, genuinely early, but projects 60% of SOC work shifts to AI within three years. The finance CISOs putting AI-powered MDR up for evaluation this week are reading the same signal the vendors are now betting the category on.

Bottom Line

The vendors are competing on how much the AI closes on its own. Your peers are quietly re-shopping on the part the datasheets bury: what happens in the small share the AI hands back, because that handoff is exactly where the response-time complaints already live.

What to Do About It

Before your next detection review, pull one metric from the last 90 days: median time from alert to a human analyst taking action. Carry that number into every MDR and SOC conversation, including with your current provider, and make every autonomy claim answer to it. The distance between the demo and that number is your real evaluation.

Build pipeline you can actually follow up on.