IT Brief Australia - Technology news for CIOs & IT decision-makers
Australia
CrowdStrike named leader in IDC MarketScape MDR study

CrowdStrike named leader in IDC MarketScape MDR study

Wed, 12th Aug 2026 (Today)
Sean Mitchell
SEAN MITCHELL Publisher

CrowdStrike has been named a leader in the 2026 IDC MarketScape assessment for enterprise managed detection and response and managed extended detection and response, placing the cybersecurity company among the top vendors reviewed in the study.

The assessment covers a market that is increasingly using artificial intelligence in security operations, especially for triage, investigation, and response. CrowdStrike said the ranking reflects the performance of Falcon Complete, its managed detection and response service.

IDC said Falcon Complete uses Charlotte AI and proprietary agents to coordinate investigation and response workflows across the threat lifecycle. The research firm added that more than 10,000 daily triage decisions are made through AI workflows while maintaining validated analyst logic.

CrowdStrike said Falcon Complete currently has a median time to contain of one minute, which it defines as the time between the initial detection of a threat and the implementation of controls to contain it on an endpoint.

Market shift

The enterprise MDR segment has been evolving as customers seek services that can handle a growing volume of alerts and increasingly automated attacks. Vendors have responded by building systems that combine machine-led analysis with human oversight, particularly for structured investigation and response tasks.

In its comments on CrowdStrike, IDC highlighted what it described as proven AI with demonstrated effectiveness. It also pointed to a single-platform approach that, in its view, reduces integration overhead and operational friction for customers looking to consolidate security tools.

The report also noted the company's unified data model, which it said enables correlation across endpoint process execution, identity authentication, cloud application programming interfaces, network egress, and email chains. According to the assessment, that can help surface multi-stage attacks that may not be visible in separate detection systems.

Threat intelligence

IDC also cited CrowdStrike's Counter Adversary Operations organization as part of its assessment. According to the company, the unit tracks more than 280 adversary groups and draws on telemetry from millions of endpoints, as well as more than 100,000 hours of incident response work each year.

Those factors matter in a managed response market where buyers are weighing not just detection quality, but also the operational model behind the service. Enterprises are under pressure to reduce the number of disconnected tools in their security environments while improving incident response speed.

Austin Murphy, General Manager and Vice President of Falcon Complete at CrowdStrike, said the market is moving beyond manual processes. "Every enterprise will need agentic MDR. The volume and speed of AI-powered attacks make manual investigation unsustainable."

He said the difference between early experiments and fully operational services lies in how human expertise is built into the system. "What separates operational agentic MDR from experimentation is whether human expertise is built into the system. Every investigation our analysts run, every breach they stop, produces expert-labelled data that makes our agents more precise. That closed loop is why we believe IDC MarketScape validated CrowdStrike as an industry leader."

Competitive picture

IDC MarketScape assessments are widely used by technology buyers as one reference point when comparing suppliers. The model is designed to show the relative position of vendors in a given market by combining qualitative and quantitative criteria in a single comparative framework.

For CrowdStrike, the latest ranking supports its effort to strengthen its position in managed security services as demand grows for around-the-clock monitoring and response. The company has sought to differentiate its offering through a single-platform design, managed services, AI-based triage, and a large threat intelligence operation.

The wider market remains crowded, with established security providers and specialist MDR firms competing for enterprise budgets. Buyers are increasingly scrutinizing how much work can be automated, how quickly incidents can be contained, and whether providers can deliver visibility across endpoints, identity, cloud, and email in a single service.