
MDR to IR Handoffs: Stick The Landing
Source: YouTube · SANS Digital Forensics and Incident Response · published Aug 15, 2025 · 29:21
Forrester analysts Jess Burn and Jeff Pard identify that process gaps, undefined severity definitions, and poor communication protocols—not technology—are the primary causes of delayed response and wasted time in MDR-to-IR handoffs 0:00.
Key Takeaways:
• Undefined severity definitions and documentation gaps create regulatory, insurance, and operational risks during escalation 1:05
• Organizations must implement a formal severity matrix to define incident scope, data impact, and necessary stakeholders for timely legal and executive involvement 2:10
• MDR providers should maintain business-as-usual monitoring, assist with containment, and conduct threat hunts, but must never independently wipe systems or run parallel IR investigations 4:30
• IR teams must provide specific indicators of re-entry to MDR post-incident to ensure effective continuation of environmental protection 6:15
• Security leaders should prioritize process governance and inclusive tabletop exercises over tool investments to prevent administrative delays 3:30
The speakers conclude that effective incident management requires rigorous process definition, clear communication protocols, and frequent practice with all involved parties to bridge the gap between MDR and IR teams.
Sources:
- 0:10 Introduction of analysts Jess Burn and Jeff Pard
- 1:05 Overview of MDR-IR handoff issues and escalation problems
- 2:10 Importance of a formal severity matrix for incident scope and stakeholders
- [3:30](https://www.youtube.com/watc
Generate CPE Credits
Generate a professional CPE document from this video's transcript.
Estimated credit: 0.5 CPE hours
Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.
Topic: Incident Response. Commonly maps to: Security Operations, Security Assessment and Testing. Exact CISSP domains are assigned during generation.
Free account. One generation at a time, with a daily limit.
CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.
Transcript Preview
First 800 characters of the transcript
Hi everybody. So, we're the entertainment after lunch. So, welcome. Um, I don't know how to tap dance, but I'm certainly going to try right now. I'm Jess Burn. I'm a principal analyst on the security and risk team at Forester research. And one of the areas that I cover is incident response and crisis management. I also cover email messaging and collaboration security. and I've been working with forer CISO clients for gosh the better part of 13 14 years now starting as an adviser on our security and risk council. So I write for the role of the CISO along with Jeff um with a particular focus on security talent management hiring training and retention of security staff. Jeeoff I'll let you introduce yourself. >> Yeah, so Jeff Pard here. I'm a vice president and principal analyst on a security…