The R in MDR Should Stand for Response

Every border we grew up with was one you could see on a map. The people who served knew exactly which line they were protecting. That world is gone. Today the borders that matter most are invisible, and the people crossing them never have to set foot in the country they are attacking. 

I sat down with Wilfredo Santiago of Blackpoint Cyber on Sunny’s Silver Linings, and that idea stayed with me long after we stopped recording. 

A career that started with cheating at video games

Wilfredo’s path into cybersecurity began somewhere most of us would never guess. He played a lot of video games growing up, and by his own admission he wasn’t very good at them. So he started hacking the games to make them work for him. He didn’t know it was hacking at the time. He thought it was just computer work. 

College was expensive, so at 18 he joined the United States Navy. He wanted to be a boom operator, refueling aircraft mid-air in combat zones. Then his recruiter mentioned a job that could get him stationed in Spain. He took it. He never made it to Spain. He landed at National Security Agency field sites instead, including a 100-person base in West Virginia. 

That small base turned out to be the best thing that happened to him. The people there wanted to give back to those coming up through the ranks, and Wilfredo volunteered for everything. A networking course, protocol analysis, satellite training. Send me. 

Later, as a civilian at the NSA, he spent three months at a time in different offices: malware analysis, offensive teams, defensive teams. He loved offense. But defense is what truly excited him. Putting the puzzle pieces together, understanding how we got here and which indicators we missed along the way. 

He said something I keep coming back to: you cannot defend what you don’t know how to attack. 

The assumption that SMBs will just make do

After government and a few years in the cyber threat center of a Fortune 500 financial services company in Tampa, Wilfredo joined Blackpoint. He was honest about the mindset he walked in with. He used to look at the SMB space and assume they didn’t have the resources, so they would just have to make do. 

Blackpoint changed that for him. He came to see the SMB as the heart of everything we do in the United States, and the MSPs serving them as carrying a big mission without always having the experience or resources to match. 

Here’s what matters. In his view, the MSP’s problem isn’t knowledge. It’s context and awareness, because the attack hasn’t happened to them yet. It has happened to everyone else. Hospitals. Manufacturers. Donut and praline shops. Veterinarian clinics. As Wilfredo put it, really, we’re going after the puppies now? 

He also noticed that attackers going after SMBs were loud. In enterprise and government, he was used to adversaries who moved low and slow. In the MSP space, intruders would run a thousand scripts and light up the consoles like Christmas trees. They weren’t worried about getting caught, because it’s a numbers game. If they get caught here, there are a hundred other customers to try next. 

Now picture an MSP with three to five technicians monitoring more than a hundred customers. That is an unfair fight. 

They are logging in, not breaking in

That’s the shift right there. Attackers are increasingly walking through the front door with legitimate credentials. Identity is what needs protecting, and identity security has to become more than an IT hygiene checkbox. 

His example was simple. I live in New Jersey. If my account logs in from Ohio, someone should be asking whether I’m traveling and whether there is a record of it. Continuous monitoring of identities is how you catch that. 

Then comes privilege. A client’s CEO asks for SharePoint admin in Microsoft 365, and it gets granted. Nobody realizes how much else that role can reach. Wilfredo described a company Blackpoint was monitoring where one compromised identity had the ability to push software through Intune. The attacker tried to use it to push malware to the other 400 people in the tenant. 

One identity. Four hundred machines. 

The fix has been around since the 90s. Audit permissions and apply least privilege. Give just-in-time access so people elevate when they need to and step back down afterward. Detect compromised identities fast, kill session tokens, and reset access in minutes. And protect the keys to the kingdom, the RMM and PSA credentials that can cause damage across many customers at once. 

MFA is where the work starts

Wilfredo called MFA the starting point of the finish line. When COVID pushed everyone to the cloud, sensitive workloads that once sat behind on-prem protections ended up guarded by a username and a password. Adversaries know how to hijack sessions and run adversary-in-the-middle attacks, so MFA alone won’t hold if a session is stolen. 

His answer is what he calls resilient engineering. Once you detect and respond to something, you shouldn’t have to respond to it again. If an intrusion came from a login in France and you have no business in France, write a conditional access policy that blocks France. 

He compared it to owning a home. You lock the doors. But before anyone reaches the door, your cameras already see them walking up the sidewalk. That is attack surface management. 

The R has to mean response

When I asked what sets Blackpoint apart, Wilfredo pointed to the last letter in MDR. Every booth at every vendor show says MDR. For many vendors, he said, the R means report. 

His test for MSPs: if an alert fires at 2 a.m. on a Saturday, what happens in the next 15 minutes? A report on Monday doesn’t count. 

That landed with me personally. My son volunteers with the fire department. A fire station that takes the call but has no truck to send isn’t much help to anyone. Anyone can generate alerts. The value is someone acting on them in minutes, not days. 

Security before AI first

We closed on AI governance. Wilfredo’s view is that the MSPs who get security right make it part of the sales pitch, baked into every service tier, and AI should be no different. Agents should be treated as identities. Before any AI workload goes in, ask what the use case is, and whether it’s really just automation. Read the SOC 2 Type 2 reports, and if a vendor promises zero data retention, ask them to prove it. Start with an asset inventory and a risk register, then decide how much risk you’re willing to accept. 

When you do say no to something an employee wants, offer what you can do instead. In his words, part of the job of IT is saving our employees from themselves. 

Let me bring this together. The borders are invisible now, but the mission hasn’t changed. Protect the people who depend on you. For MSPs, that means protecting the small and mid-sized businesses where American families earn their living. Wilfredo has carried that mission from the Navy to the NSA to the SMB front line, and I’m grateful he shared it with us. 

Follow my newsletter, Sunny’s Silver Linings, for more conversations like this one. 

For more content like this, be sure to follow IT By Design on LinkedIn and YouTube, check out our on-demand learning platform, Build IT University, and be sure to register for Build IT LIVE, our 3-day education focused conference, August 3-5, 2026 in Jersey City, NJ!