In December 2025, Kroll and CrowdStrike announced a multiyear strategic partnership to elevate MDR services worldwide. In less than eight months, Kroll migrated its global MDR client base to a unified, cloud-native platform, delivering deeper expertise, broader visibility and measurable outcomes for clients while establishing the foundation for the next generation of managed security services.
Overview
Service Line
- Kroll Managed Detection and Response
Kroll Services
- MDR on CrowdStrike Falcon® Complete Next-Gen MDR
- NG-SIEM implementation and operationalization
- Falcon Identity, Shield and Firewall
- APEX proactive resilience program
- Kroll IP on CrowdStrike AgentWorks + Falcon Foundry
- Incident response and professional services
Challenges
- Fragmented legacy EDR and SIEM environments limiting depth and consistency
- Client demand for proactive resilience, not just reactive monitoring
- Growing need to operationalize AI in production SOC environments
- Consistent depth of service at a global scale
Impact
- Unified, cloud-native security foundation on CrowdStrike Falcon
- Faster migration and onboarding — delivered at global scale
- Deeper Kroll expertise across every client environment
- Foundation for an agent-driven SOC model powered by APEX
The Challenge
The cybersecurity landscape has changed. Threats are faster, more coordinated and more consequential. Kroll’s clients needed more than reactive monitoring across fragmented tools. This shift has been confirmed by Kroll’s observations across its consulting client base. Nearly 8 in 10 breaches begin with identity compromise, and only 1 in 4 are first detected by security tooling, with the rest surfaced by people or the attackers themselves.
Kroll's previous MDR model gave clients the flexibility to choose from multiple platforms, but that breadth came at the cost of depth and speed. Detection engineering had to be replicated across five EDR platforms and three SIEM platforms, making it harder to deliver consistent expertise, scale and outcomes across a growing global client base.
Clients were asking for something different: a unified platform, proactive resilience, AI operationalized in production and measurable ROI on their SOC investments.
The broader market is moving in the same direction. Boards are demanding more proactive cybersecurity capabilities and clearer ROI justification, while early-stage AI SOC solutions raise questions about accuracy and reliability, reinforcing the need for MDR partners to be grounded in real-world experience.
Why Kroll
Kroll consolidated its MDR technology to CrowdStrike Falcon®, going deeper with a single, best-in-class technology partner to deliver a more scalable, consistent and outcome-driven service. The partnership unites Kroll's global cyber advisory and incident response expertise with CrowdStrike's AI-native platform, enabling faster, more effective detection, investigation and full-cycle remediation for clients at a global scale.
The Solution
Kroll executed comprehensive global migration of its MDR client base to the new Kroll Responder MDR service, powered by the CrowdStrike Falcon® Complete Next-Gen MDR with standardized migration engineering, NG-SIEM implementation and end-to-end deployment support delivered by Kroll's global team. This was topped by Kroll's Managed Response Ops and Incident Response services.
Key elements included:
- Migration of Kroll's global MDR client base's technology on to CrowdStrike Falcon Complete Next-Gen MDR
- NG-SIEM implementation, log-source onboarding and operationalization at scale
- Expansion into Falcon Identity, Shield, and Firewall protection
- Standardized migration engineering delivered by dedicated Kroll project management and deployment teams
- Foundation for APEX and agent-driven SOC capabilities powered by CrowdStrike AgentWorks and Falcon Foundry
The Impact
The transformation delivered what today's threat landscape demands: speed, scale and depth.
In less than eight months, Kroll migrated over 270 client environments to the modernized MDR service, reflecting the speed and operational rigor clients can expect from Kroll. Individual migrations moved just as fast: A global logistics customer moved 20,000 endpoints to CrowdStrike Falcon in two weeks, and the European operations of a global food chain migrated their SIEM in less than four days.
Clients now operate on a single, cloud-native security foundation that replaces fragmented legacy tooling with broader visibility across endpoint, identity, SIEM and cloud, backed by the full depth of Kroll's global team of MDR analysts, incident responders and cyber advisors.
They also gain the benefits of Falcon® Complete Next-Gen MDR, which delivers a 75% reduction in mean time to respond (MTTR) and resolves more than 13 million detections annually uniting expert-led operations with AI-driven automation to stop breaches with speed and precision.
Kroll's team are now the most experienced globally at deploying the modernized, agentic management security service in client environments. For clients this means more detections, visibility across 3mn endpoints and a 42% increase in MITRE coverage.
Scale of Transformation
For clients navigating a threat landscape defined by attacker speed and AI-driven risk, this is what readiness looks like: a modernized platform, deeper Kroll expertise, and a security partner engineered for the environment they operate in.
What's Next: From Modernized MDR to Proactive, Agent-Driven Resilience
Platform consolidation was the foundation. What comes next is what sets Kroll's modernized MDR service apart.
CrowdStrike is configurable, but Kroll is where the customization happens. Building on the CrowdStrike AgentWorks platform, Kroll delivers unrivaled response capabilities, including response operations, DFIR, discovery services, breach notification and resilience advisory services.
The real shift for clients is APEX, Kroll's proactive resilience program. It moves clients beyond reactive detection and response into a model designed to help them get ahead of threats, harden their environments and turn cyber posture from a defensive cost center into a business enabler.
Kroll APEX pairs Kroll's frontline incident response experience with CrowdStrike AgentWorks to introduce an agent-driven SOC model that spans the full incident lifecycle, from triage through to investigation and response. The design is grounded in Kroll's real-world incident response playbooks, not theoretical automation, and it embeds ROI measurement directly into SOC operations so that clients can see analyst time savings and efficiency gains in real time.
APEX is being built by practitioners who have delivered agentic SOC transformations across the industry. In that work, organizations have seen results such as:
- Up to ~50% reduction in manual triage effort
- ~30-40% faster investigation and response
- ~70% automation of Tier 1 and Tier 2 workflows
With APEX, Kroll isn't just adopting AgentWorks; it is helping define how agentic AI is operationalized in real SOC environments, at the scale and consistency clients need. And that means Kroll clients are among the first to benefit from what comes next in managed security.
Note:
Results reflect real outcomes from prior agentic SOC engagements across multiple organizations and environments. Actual results depend on use case selection, implementation and adoption.
Stay Ahead with Kroll
Kroll Responder
Stop cyberattacks. Kroll Responder managed detection and response is fueled by seasoned IR experts and frontline threat intelligence to deliver unrivaled response.
Cyber and Data Resilience
Kroll merges elite security and data risk expertise with frontline intelligence from thousands of incident responses and regulatory compliance, financial crime and due diligence engagements to make our clients more cyber- resilient.
CrowdStrike Partnership
Kroll’s global advisory, testing and incident response expertise, combined with CrowdStrike’s attacker speed technology, gives organizations the intelligence and operational capability to reduce risk, cost and recovery time.




