The insurer already had a security team. Twenty people, more than 5,000 endpoints, nearly 3,000 employees to protect. It had spent a decade building its program. Then the pandemic disrupted the operation and key people left. The problem was suddenly less glamorous than catching a master criminal: how do you keep the work going when the people who know the work disappear?
In Red Canary’s published account of this unnamed Fortune 1000 mutual insurer, the answer was to buy help while keeping the internal security operations center. The customer wanted room to pursue strategic projects and dependable coverage during turnover. Cybersecurity, it turns out, has a scheduling problem as well as an adversary problem.
The useful bits / in 30 seconds
- It investigates before it interrupts. Red Canary combines connected security data, behavioral detections, analysts and supervised AI.
- It works alongside an internal team. The insurer bought continuity and capacity, rather than giving up its own SOC.
- The method is testable. Its free Atomic Red Team library lets defenders check particular detection claims.
A capable team, interrupted
The insurer considered nearly 15 managed service providers and put three through proof-of-value evaluations. According to the case study, one candidate lacked transparency and failed to improve mean time to detect. Another depended too heavily on existing alerts. Red Canary brought detection engineers, threat hunters and intelligence specialists into the evaluation.
“My team likes knowing what’s going on”
Director of information services, unnamed insurer
That modest sentence is a useful purchasing specification. A service that removes work but conceals its reasoning leaves the customer dependent on a verdict. A service that shows its investigation can also help the customer learn. Here, the team connected its endpoint detection and response telemetry and watched how the provider worked.
The lesson is to make the trial resemble the job. Ask whether the provider improves detection, exposes its evidence and survives the loss of your own experienced people. A handsome dashboard can answer none of those questions by itself.
The founders had seen this movie from space
Brian Beyer and Chris Rothe had worked on satellite-based processing systems. Those systems collected enormous quantities of data, used technology to find interesting pieces, then handed those pieces to expert analysts. Keith McCammon brought experience building security programs for defense contractors. The familiar pattern was data, selection, judgment.

The founders worked together at Kyrus before spinning out Red Canary. Their premise was that organizations could buy sophisticated endpoint tools and still lack the specialists needed to investigate what those tools saw. More observations did not automatically produce more understanding.
They also misjudged something. In an early Security Weekly interview, Beyer said they designed for customers who might refuse cloud processing. In practice, many prospective customers were already moving infrastructure into the cloud. Strong objections were rarer than expected. Customer behavior changed the assumption behind the architecture.
The business grew around a cloud service with people attached. Its stated mission is to let organizations pursue their own missions without disruption from cyberattacks. The distinctly commercial interpretation is simple: let the hospital run the hospital, while someone else watches the security evidence overnight.
An alert is a lead, not a verdict
Red Canary occupies the managed detection and response market, usually shortened to MDR. Customers connect supported security technologies. The service monitors, hunts, investigates and helps respond across endpoints, identities, cloud services and SaaS applications. Its expertise includes detection engineering, adversary behavior, threat intelligence and incident investigation.
The distinction from buying endpoint software is the investigation labor. Red Canary’s MDR product description includes more than 4,000 behavioral analytics and automated and ad-hoc threat hunts. Customizable playbooks connect response with collaboration tools, incident management and security products.
Those capabilities put it alongside alternatives such as Expel and Arctic Wolf, as well as managed offerings from endpoint vendors. The comparison should be about coverage and responsibility. Which signals enter the investigation? Which actions can the service take? What stays with your team? Red Canary’s particular case rests on its own detection work, managed investigation and integration with tools the customer already uses.
That integration matters across a varied customer base: financial services, healthcare, manufacturing, education and government all appear in its sector coverage. The 2026 Threat Detection Report describes observations across nearly 1,400 organizations. That is the scope of a research population, rather than a promise that every customer has the same needs.
The AI that needed less freedom
Red Canary’s June 2025 account of its AI development is interesting because some ideas disappointed. Early language-model classifiers gave inconsistent answers when wording changed. Customer-facing chatbots raised reliability problems. Highly autonomous agents accumulated model calls, cost and latency as they decided each successive step.
The company’s answer was to move some orchestration into deterministic code and reserve language models for suitable tasks. A fine-tuning experiment called Frank-GPT used detection engineer Frank McClain’s annotations. The useful raw material was expertise that people had bothered to write down.
Reported before-and-after bounds for its agent-assisted approach. These figures describe a company result, not a response-time guarantee for every incident.
Current AI documentation describes agents forming an initial opinion, summarizing events and compiling findings before human analyst confirmation. The operating principle is portable: automate evidence gathering, constrain the job and retain accountable review. A company needs usable data and working integrations to copy it. Missing telemetry gives both people and machines less to investigate.

The bill follows the work
This is a business subscription for managed security operations. Buyers should define the environments, integrations and response authority in their quote. A tool connection and permission to disable a user account are different contractual questions.
The adjacent products make the economics more concrete. Security Data Lake is an annual MDR add-on licensed per gigabyte stored. It retains raw logs for investigation and supports SQL search. Managed Phishing Response is licensed per email account and handles user-reported messages, including analysis and feedback. Readiness Exercises combines training, tabletops and atomic testing.
Three units hiding inside “security spend”
There is a particularly useful detail in the data lake documentation: when storage exceeds the license, ingestion continues, but over-capacity data cannot be searched or exported until capacity is increased or data is deleted. Retaining a log and being able to use it are separate matters. Put both on the procurement checklist.
The phishing service also depends on compatible infrastructure. Its setup guide specifies Microsoft Exchange or Google Workspace and a supported reporting button. An organization expecting help for disconnected systems, unrestricted automatic remediation or a different email setup should settle those requirements before purchase.
A free way to cross-examine the alarms
Atomic Red Team, publicly released in 2017, is a library of portable tests mapped to MITRE ATT&CK. It is open source and community developed. A defender can use it to exercise a particular adversary technique and observe whether the environment notices.
This is something readers can copy immediately: choose a relevant technique, review the test’s prerequisites and cleanup, run it in an authorized environment, then examine what was observed and detected. A quiet dashboard is much more persuasive when you know you gave it something to notice.
Readiness Exercises extends that habit into incident preparation. Technical tests sit alongside tabletop decisions involving security, executives, communications, legal and other business functions. A threat can be detected correctly and still produce confusion over who is allowed to act. Rehearsal makes that uncertainty visible before the emergency.
The machinery now belongs to Zscaler
Growth required capital: $34 million in 2019, followed by an $81 million Series C in 2021 led by Summit Partners. In August 2025, Zscaler completed the acquisition. Its 2025 annual filing described $675 million in cash, subject to customary adjustments, plus employee equity awards.
The rationale connects two kinds of security work: controlling access and interpreting activity. An August 2025 expanded CrowdStrike partnership connected Falcon context, Red Canary MDR and Zscaler’s zero trust platform. In September 2026, Zscaler launched Agentic SOC, with specialized agents, integrated controls and support from Zscaler and Red Canary experts.
Integration has also brought friction. Zscaler’s Q2 fiscal 2026 shareholder letter acknowledged elevated post-acquisition churn at Red Canary. Its subsequent full-year results reported $141 million in contributed annual recurring revenue. ARR is a subscription measure, not profit or recognized revenue; neither number settles whether a particular buyer will get value.
That judgment returns to the insurer’s test: can an outside operation take routine work away, show its reasoning and preserve your team’s ability to make decisions? The useful promise of Red Canary is more time for work that requires your people. The trial should prove where that time comes from.
Explore the work
Read / test / watch