SEP2: Building a Detection-First Agentic SOC

SEP2 runs a 24/7 MDR service across more than 70 customers, from AI-native startups to legacy public sector estates. By automating detection engineering with Spectrum during its build phase, SEP2 cut rapid-response rule deployment time by 66% and doubled its deployed detections with no additional headcount.

5 min read
Spectrum
SpectrumLinkedIn

Most agentic SOC programs start at response. SEP2 started at detection.

During the early build phase of its agentic Security Operations Centre, SEP2 partnered with Spectrum to automate detection engineering across its managed service. Mark McDaid, SEP2's Head of Alliances and GTM, sat down with Spectrum CEO Meny Har to talk about what that changed — for SEP2's analysts, and for the customers behind them.

Two numbers came out of it:

  • A 66% reduction in the time it takes to get rapid-response detection rules deployed.
  • Double the deployed detection rules across the customer base, with no additional headcount.

A managed service with no typical customer

SEP2 was running 24/7 MDR for more than 70 customers before the partnership began: across a variety of customer profiles and sizes.

"We've got some incredibly modern, bleeding-edge, brand new digital-native startup customers, looking at AI logs and all kinds of modern things. And then we have a number of public sector, potentially more slow-moving customers as well that still expect us to be able to detect and deal with those more legacy tools and legacy logs."

Mark McDaid, Head of Alliances and GTM, SEP2

Detection engineering across that range is not one job repeated 70 times. Every estate reads different telemetry, runs different tooling, and cares about different things — which is exactly why shipping the defaults doesn't work.

Tuning was a bottleneck

Before Spectrum, everything that made SEP2's service good was incredibly bespoke and manual. Tuning rules, standing up new rapid detections, rolling coverage for a novel attack across a customer base are all expensive in terms of engineering hours.

That put SEP2 in the position every growing managed service recognizes: the only lever for more coverage was more people.

"Whenever we bring on new customers, it's not feasible for us to add human resource and bring in more analysts every time. We need to build scalable systems internally."

Mark McDaid

Response metrics were the wrong focus

SEP2 tracks the standard industry set — mean time to detect, acknowledge, respond. Mark's point is not that those are wrong. Instead, they force the business to focus on metrics that come after the most important layer: detections.

"We believe that if the detection engineering or the detection rules are broken, then how quickly you respond to an alert isn't really relevant. You're just using bad data."

Mark McDaid

A fast response to the wrong alert and a fast response to an alert that never fired both score well...but both leave the customer exposed.

Double the detections, same team

Automating the detection layer moved SEP2's constraint off headcount.

"We were able to double the number of detection rules that we're able to deploy across a customer base with no additional resource internally, and we're able to reduce the time taken to deploy rapid-response rules by 66% — and that's in a relatively short time working with Spectrum."

Mark McDaid

The compounding effect shows up per vertical. When a novel threat lands in one industry, SEP2 is able to apply their learnings more quickly across all of their customers in that industry.

"If we see a novel new threat across a vertical like retail, we can start deploying these things and actually proving to our other retail customers that they're already protected against those things as soon as we've seen them — much more quickly than we would have been able to do previously."

Mark McDaid

Human in the loop, by design

SEP2 has been building its agentic SOC strategy for a couple of years, and the sequencing was deliberate: get the foundation right before automating the response on top of it.

"There's a common misconception that response is the most important thing in reducing the time taken to get to a particular outcome. But if you don't have the foundations correct, and you don't focus on what's important to the customers around what we're detecting, then you're in a position where you're working with bad data and the outcome is going to be irrelevant."

Mark McDaid

The other half of that strategy is that the automation assists analysts rather than replaces them.

"A core foundation of our agentic SOC strategy is human in the loop. We want to be working with technology that's going to be an assistant for our analysts as opposed to replacing anybody, and Spectrum's a perfect example of that. At the end of the day, it's providing a more fulfilling role for them, because it's removing a lot of those manual tasks they were previously working on."

Mark McDaid

Analysts who trust their alerts chase far fewer false negatives, and get to root cause faster.

Clear ROI

SEP2's investment had a clear, measurable return for them. They have reduced the time it takes to deploy rapid-response rules by 66%, while doubling deployed detection rules across their customer base.

"The impact on the team and the value that we've seen has been enormous, and something that's really easy for us to quantify and to prove."

Mark McDaid


If your detection estate is the layer holding back everything you've built on top of it, talk to us.

Quotes are lightly edited from the recorded interview for readability. The full conversation is above.