Lucas Molefe | Cybersecurity Expert | ESET Southern Africa | mail me |
At the start of 2024, a finance worker in Hong Kong at a multinational firm joined what appeared to be a routine video call with senior leadership.
The call included people who looked and sounded like the company’s UK-based CFO and other executives. However, AI-generated deepfakes had created these individuals. As a result, the employee authorised several transfers to different bank accounts worth around $25 million.
This incident shows that AI is no longer a theoretical threat. Instead, cybercriminals actively weaponise it to automate fraud and create highly convincing scams. Artificial Intelligence (AI) is described as a driver of one of the fastest transformations the cybersecurity industry has ever seen.
Today, attacks unfold at machine speed. Consequently, malicious actors now operate far faster and more efficiently than before. This shift forces organisations to rethink long-standing assumptions about how attacks start, spread and can be mitigated.
The business case for MDR
Managed Detection and Response (MDR) transforms cybersecurity from a reactive function into a continuous and intelligence-driven capability.
At its core, MDR combines advanced threat detection technology with human expertise. Instead of simply generating alerts, MDR providers actively monitor environments around the clock, investigate suspicious activity and respond to incidents in real time.
When you think about the number of threats the average organisation faces each week, having a solution that monitors and protects your environment 24/7 is a must for CIOs and CEOs who want to sleep easily at night.
With a prevention-first cyber strategy like MDR, organisations aim to stop attacks before they infiltrate systems or cause damage. Instead of relying mainly on detection and response after a breach, organisations focus on blocking attacks early. As a result, MDR dramatically reduces the time between intrusion and containment.
This speed matters because attackers cause greater damage and disruption when organisations fail to detect them quickly. In addition, MDR helps businesses strengthen resilience against increasingly sophisticated cyber threats.
MDR helps businesses address skills shortages
One of MDR’s biggest advantages is access to scarce skills. According to the World Economic Forum, the global cybersecurity talent shortage could reach 85 million workers by 2030. Given these realities, many organisations cannot build a fully staffed 24/7 security operations centre.
By providing on-demand analysts, threat hunters and incident responders, MDR helps businesses overcome the cybersecurity skills shortage without the cost and complexity of hiring in-house experts.
Furthermore, MDR helps businesses gain immediate access to specialised expertise without long recruitment cycles or significant operational overheads.
The need for speed in cybersecurity
MDR also delivers the speed organisations need for effective incident containment. When a cyber incident happens, the board is typically less focused on the technical details of the attack. Instead, directors worry more about possible financial loss, reputational damage and regulatory penalties. These risks increase the longer the breach goes undetected and uncontained.
Boards and business executives want to restore operations as quickly as possible, he explains. For example, a major mining operation or manufacturing facility can lose millions of rands in revenue after only a few hours of downtime. Therefore, organisations that detect and contain attacks faster can reduce downtime more effectively and protect their reputations.
In cybersecurity, time is the ultimate currency. By turning cybersecurity into a continuous service instead of a collection of tools, MDR empowers organisations to stay ahead of attackers. At the same time, MDR helps businesses protect assets, operations and reputations in a world where every second counts.
