We hear it on a lot of first prospect calls: “We already have someone watching this.”
It's usually true. There is a person. They're competent, they care, and they do look at the consoles. On a good day they see several. But that carries an assumption worth dissecting, which is that the job is defined as ‘watching’.
We put that question to practitioners on our own podcast last year. Three of them, from three segments with nothing in common, described the same failure from different angles. We've linked each episode where their comments come up.
None of them were describing someone who wasn't trying.
The technology director of a Texas school district described how she got the job: "I came in from the classroom to become IT. I don't have a degree in cybersecurity."
That isn’t a knock. It's often the case in mid-market IT, and anyone who has staffed a small team knows it. The person watching your security consoles probably isn’t steeped in cyber, still owns everything from the phone system to the printers, and is watching security telemetry in the gaps between the work they were actually hired to do.
So when a buyer says someone is watching, the honest translation is: someone checks when they can, alongside their other job, during business hours, from the tools they happen to have open.
That’s a real capability. It isn’t nothing. It’s just not the same thing as detection, and the difference shows up in three specific places.
Districts like hers get hit over holidays. Not by coincidence. Attackers know school staffing thins out over winter and summer break, and they time accordingly.
Think about that, as it’s not exclusive to K-12. Your staffing calendar is knowable from outside. School calendars are published. Manufacturing shutdowns are published. Fiscal year end, the week of Thanksgiving, the Friday before a long weekend, the fact that nobody senior is looking at a console at 2am on December 26. None of that is a secret.
An attacker choosing when to move is not stopped by having someone good. They're choosing the hours when that someone is asleep or away, and those hours are most of them. One person covers roughly a quarter of the week. The rest of the week is exposed by math, not negligence.
The CIO of a NYSE-listed tanker operator has the extreme version of a problem most organizations face.
He described the problem plainly. There's no cybersecurity specialist aboard a ship. Visibility into the onboard network is limited. Detecting a breach in real time is hard. By the time anyone finds out, it can already be too late.
A ship is a branch office - just one that moves - staffed by people with demanding jobs that aren't IT, connected intermittently. He can't station an analyst on every vessel. As he stated, "I cannot put a human there to do that."
Of course most organizations don't run tankers. Most organizations did, however, spend the last few years scattering their endpoints across houses, coffee shops and airports, and the effect isn’t that different. The school district version: once a Chromebook goes home, your firewall rules and DNS filtering stop being the control you thought they were. The device is still yours. The traffic no longer passes anything you own.
So the watcher can be attentive, awake, and looking at the right screen, while the activity happens somewhere that the screen never showed. That failure has nothing to do with effort.
This is the part that changed how we talk about the objection.
The CRO of a vCISO firm described testing an internal SOC build that had cost $9-10 million. He ran a test against it. It missed the alerts his team generated. He had to fail it.
$9-10 million is not a person glancing at a console between help desk tickets. That is a funded, staffed, purpose-built internal security operation. And it still failed a basic test of whether it would notice something happening.
If watching were the function, money would solve it. The money was there. It didn't.
Which suggests the problem is not the quantity of attention. It's that attention and detection are simply different jobs, and the second one doesn't scale by adding more of the first.
Three things a person at a console structurally can’t do, no matter how many you hire:
That's the work. Watching is what you do when you don't have a system covering these bases.
The vCISO firm CRO said it well: "An alert is an alert whether it happens at a credit union or a not for profit."
That's why detection outsources well. The techniques are the same across all customers. An attacker moving laterally through Active Directory looks the same in a bank and a school district, so the pattern library, the tuning, and the analyst hours all generalize across customers. You get the benefit of everything learned across every other environment.
The inverse is also true. Anything specific to your business doesn’t generalize and shouldn’t leave. Which systems can be taken offline in the middle of a shift? Which vendor has access to what and why? Which application was built by someone who left in 2019? Who has authority to disconnect a device during a school day?
Outsourcing detection doesn't outsource responsibility either. You still own your environment. In most engagements, you or your MSP still execute the response (unless of course your MXDR provider can take that on, Gradient Cyber can). What changes is that you're deciding with validated findings instead of with an alert queue.
We published a set of four requests for auditing whether an MXDR service is actually working: coverage, detections, response, and tuning records for the last ninety days. Those apply to an in-house function too. Run them against whoever is watching your environment today, yourself included.
And run them against us. The vCISO firm CRO said one more thing worth repeating, about providers who deploy with gaps: "I don't understand how a deployment could have intentional blind spots in the network. I have a moral problem with it."
He's right, and the test is simple. Ask what percentage of your assets are actually monitored, then check it against something independent like your DHCP lease count or your switch port inventory. A provider with blind spots suffers the same weaknesses as a person who is just watching. They're just more expensive.
Is this an argument that our IT person isn't good enough? Of course not. Every failure described here happened to people who were competent and paying attention. The issue is that detection requires continuous coverage, cross-domain correlation, and validation before escalation, and none of those are things a person does by being a diligent ‘watcher’.
Can't we just buy better tools? Tools produce alerts. Someone still has to correlate them across sources, decide which are real, and act. Adding a tool usually adds volume to the queue your person is already behind on. The gap is operational, not a missing product.
We have a SOC on paper. Does that change the answer? It depends on whether it has been tested. The $9-10M investment above existed on paper too. Generate some activity you'd expect to be caught and see whether anyone tells you about it. Of course, do it in a controlled manner, with your leadership informed.
What if we only have endpoint coverage today? Then coverage is the first thing to measure. Ask what share of your identity, network and SaaS activity is in scope. An endpoint-only service can be excellent inside its own scope - but still leaves the majority of your attack surface unobserved.
What does Gradient Cyber actually do differently here? Quorum AI correlates telemetry across endpoint, network, identity, SaaS and cloud. What reaches you is a validated finding, not a raw alert. Every SitRep holds the supporting evidence, a severity, and prioritized actions.
The objection is usually right about the person and wrong about the job. Someone is watching. The question worth asking in the next budget conversation is not whether you have somebody, but what you'll be able to produce if a regulator, an insurer, or your board asks what happened in your environment over the last ninety days.
If the answer is "we'd have to go look," there’s your gap. It was never about how hard anyone was watching.