MDR and AI: Why Expertise and Data Sovereignty are Crucial

Author
Estelle Ouhassi
Published
05. October 2026

Share article

AI accelerates attack activity and increases the pressure on cyber defence teams to make decisions. Managed Detection & Response (MDR) condenses a wide range of security signals into relevant attack patterns and clear actions that need to be taken. AI brings speed, human expertise underpins sound decision-making, and data sovereignty strengthens trust. This article shows how that interplay enables effective and transparent cyber defence.

The current cybersecurity landscape is making it increasingly difficult for security professionals to detect attacks early and classify them correctly. AI-powered reconnaissance, exploit generation, and lateral movement within compromised environments are now part of the operational reality. At the same time, “Living-off-the-Land (LOTL)” techniques—which involve the misuse of legitimate system tools—along with cloud-based infrastructures and automated attack chains, make detection more difficult.

Incident response practices also demonstrate just how complex classification has become. Attacks regularly cross the boundaries between local systems, cloud services, and identities. Only when cyber defense brings together relevant endpoint, network, identity, cloud, and application data do the connections along an attack chain become significantly more apparent.

This brings a key challenge into focus: The sheer volume of detected signals alone says little about the actual threat. Security professionals have less and less time to assess a potential attack, evaluate the risk and determine the necessary response.

How does AI in MDR support informed Security Decisions?

AI in MDR aggregates security signals from various sources and reveals connections that individual alerts do not show. AI analyzes large volumes of data, enriches information, groups related alerts, and prioritizes risks. It can also construct initial attack stories that structure potential attack scenarios. Attack stories thus link individual signals into a coherent hypothesis about the course and potential scope of an attack. AI can also suggest next steps for analysis.

A simple scenario illustrates just how relevant this contextualization is: A suspicious login, a newly configured email rule, and an unusual process on an endpoint device—when viewed in isolation—do not yet provide a clear picture. When MDR brings these events together, the pattern of a potential account takeover begins to emerge.

AI shortens the path from individual signals to a prioritized big picture. Experts use this context to assess the situation earlier and weigh their options for action. This creates a “decision advantage.”

However, a quickly generated overall picture alone does not provide a solid foundation for security-critical decisions.

Human-AI Teaming: AI Analyzes, Experts Decide

Human-AI teaming combines the speed of machine analysis with human judgment. AI prepares analyses and courses of action: experts evaluate hypotheses, take the organizational context into account, and decide on escalation, communication, and response. Critical response measures are carried out either after approval by experts or within clearly defined rules.

This division of labor also transforms day-to-day operations in the SOC. Manual queries, switching between different consoles, or piecing together individual pieces of information consume valuable analysis time. AI and automation reduce this manual effort. Experts focus more on validation, contextualization, quality assurance, and customer communication.

Trust in this collaboration also requires that the handling of sensitive security data remain controllable and traceable.

Security Telemetry Makes Data Sovereignty a Security Issue

Security telemetry can reveal identities, systems, permissions, vulnerabilities, and critical business processes. It includes, for example, login events, endpoint activities, network connections, and cloud and email logs. Anyone using AI in MDR must therefore be able to track what data it processes, for what purpose, for how long, and where.

Requirements for data sovereignty, governance, and compliance determine the appropriate operating model for LLM data processing. Depending on the specifications, processing may take place within the EU or in Switzerland. For particularly stringent data locality requirements, dedicated AI hardware in Switzerland may also be an option.

The technical environment is thus tailored to the respective regulatory and company-specific requirements. “AI by Design” embeds this principle directly into the architecture: data minimization, purpose limitation, secure data flows, auditability, guardrails, and human oversight are taken into account from the very beginning. This makes it possible to determine what data the AI uses, for what purposes, and where human oversight remains necessary.

What Sets Trustworthy MDR with AI Apart

The key is the interplay of AI, human expertise, and a controlled approach to handling sensitive security data:

  • AI drives speed: It aggregates security signals, reveals correlations, and prepares prioritized courses of action.

  • Human expertise ensures sound decision-making: Experts validate results, provide the business context, and take responsibility for security-critical decisions.

  • Data sovereignty builds trust: “AI by Design” and appropriate operating models ensure controlled and traceable processing of sensitive security data.

This combination of speed, expertise, and control creates a solid foundation for decision-making, enabling you to identify relevant threats earlier and take targeted action. What matters most is not only what MDR delivers, but also how and where security-critical data is processed. Our experts will help you tailor MDR to your requirements for cyber defense, data sovereignty, and compliance.

Explore the SOC of the Future

Deep Dive: MDR with AI in Cyber Defense Practice

How is AI transforming Managed Detection & Response, and what matters most when implementing it? In the full technical article and interview, Michael Stampfli, Head of Cyber Defense Services & Operations at InfoGuard, delves into the connections between AI-powered analysis, human expertise, and data sovereignty.

The technical article and interview provide a well-founded perspective from the field of cyber defense and demonstrate how MDR supports rapid and transparent security decisions, even under increasing pressure to make decisions.

To the feature article and interview

 

Caption: AI-generated image

Table of Contents
    Share article