
Detection engineering has a measurement problem. Teams write rules, deploy them, and watch alerts arrive, but the discipline has lacked the thing every mature engineering practice depends on: a reliable way to know whether the work is getting better.
Daylight Security, the managed agentic security services company, today announced a capability aimed at exactly that gap. Detection Program Visibility helps organizations measure and improve the effectiveness of their detection programs.
Why Measurement Has Been So Hard
The obstacle is structural. Detections do not live in one system. They live in security tools, in SIEM content, and inside managed detection services. Each addition to the stack fragments the picture further.
Security tools expose their own detections, which helps. MDR providers typically do not, operating theirs as a black box. With the estate split across systems and part of it invisible, three basic questions go unanswered: what is actually being detected, where does coverage overlap, and where are the blind spots.
You cannot measure a program you cannot see. That is the whole problem in one sentence.
Building the Scoreboard
Daylight’s capability starts by making the program visible. Customers see all their detections in one place, spanning security tools, SIEM content, and the detections Daylight operates on their behalf. The company organizes them into a shared model and maps them to MITRE ATT&CK.
Then comes the measurement layer. Each detection carries operational context: alert volume, case outcomes, verdict statistics, overlap, and coverage gaps. These are the metrics detection engineering has been missing. They describe not just what exists but how it performs.
“Security leaders know how many alerts they receive, but they rarely know whether their detection program is actually improving,” said Hagai Shapira, CEO and co-founder of Daylight Security. “For years, MDRs have asked customers to trust what happens behind the curtain. We believe customers should be able to see the detection program protecting them, understand how it’s performing, and continuously improve it with us. Detection Program Visibility is another step toward making managed security transparent instead of opaque.”
The Data Source That Makes It Work
A scoreboard needs a referee. Daylight’s answer to where the quality judgments come from is investigation. The company investigates the activity these detections generate, and every investigation creates feedback on detection quality.
That feedback sorts the estate into categories that matter: detections that find meaningful threats, detections that create noise, detections that overlap, and areas where coverage is missing. Standalone visibility tools stop at showing coverage. They have no investigative process to ground quality judgments in real outcomes. Daylight’s does, which is the company’s core distinction.
From Rules to Program
The framing Daylight uses is worth dwelling on. The feedback loop, in the company’s words, turns detection engineering from a static collection of rules into a measurable, continuously improving program.
The distinction between rules and a program is the difference between artifacts and a discipline. A collection of rules is judged by its size. A program is judged by its trajectory. Is coverage expanding into the gaps? Is noise declining? Are redundant detections being consolidated? Are the detections that matter performing? These are trajectory questions. They only become answerable when the estate is unified, mapped, and measured.
Availability
Detection Program Visibility is available now for Daylight Managed Agentic MDR customers.
For the discipline of detection engineering, the release is a small argument about what the field should expect of itself. Software engineering has its delivery metrics. Reliability engineering has its error budgets. Detection engineering has mostly had alert counts, which measure volume rather than value. A scoreboard built on investigation outcomes is a step toward the kind of measurement the discipline has needed. Daylight has shipped one version of it. The teams using it will find out how much the numbers change the work.