How CentrexIT Closed Critical Security Gaps & Scaled Analyst Efficiency with Wirespeed ADR

CentrexIT is built on a simple belief: Technology should work for people, not the other way around. For the past 24 years, the San Diego-based managed service provider (MSP) has delivered managed IT services, cybersecurity tools, and AI-enabled solutions designed to help organizations operate more efficiently, reduce risk, and grow with confidence.
Vendor selection is a rigorous process of technical due diligence for centrexIT leadership. They aren't looking for check-the-box security. They demand force multipliers that allow their analysts to stay proactive, a finely tuned technology stack where every piece of software earns its place by reducing friction, not adding to it.
Operational Friction: The Ceiling of Legacy MDR
Scaling managed security for more than 60 clients, centrexIT found its existing managed detection and response (MDR) solution was beginning to create the very friction it sought to avoid. The traditional, human-led triage model was creating a persistent human bottleneck.
The integration between its existing MDR provider and centrexIT’s ticketing system was one-way and imprecise. Every security event triggered a "zombie” ticket in its professional services automation (PSA) software, regardless of its validity. Instead of hunting genuine threats, security analysts were spending valuable time performing administrative triage on alerts.
“We immediately saw results within a two-week trial. Wirespeed was able to detect things our current MDR completely missed.” — Josh Hohbein, Manager of Cybersecurity and Automation, centrexIT
This lack of precision extended into the production environment. Because the MDR provider relied on static file hashes for exclusions, it failed to recognize the MSPs legitimate remote management tools. This triggered a recurring cycle of false positives, where the MDR would inadvertently isolate centrexIT’s own servers, causing unnecessary downtime for clients and emergency fire drills for the technical team.
The friction wasn't limited to the security operations center (SOC). The centrexIT team found themselves dedicating hours every month to auditing inaccurate billing statements and fighting for corrected invoices. Furthermore, the MDR provider’s reporting APIs were notoriously unreliable. With half of the endpoints frequently failing, it became a manual, multi-hour struggle for the MSP to produce the high-fidelity detection reports their clients expected.
Technical Pivot: Evaluating Wirespeed ADR
When centrexIT began evaluating Wirespeed, they weren't simply looking for an incrementally faster version of their current service. The team needed a system that could handle detection and containment at machine speed, freeing their analysts for higher-value work.
During a 14-day evaluation, Wirespeed Automated Detection & Response (ADR) surfaced four critical security gaps that its current MDR provider had completely missed:
Silent Block Persistence | Wirespeed identified a malicious program that was making persistent call-outs. While the client’s endpoint agent was successfully "blocking" the individual attempts, the legacy MDR ignored the activity because the threat hadn't executed. Wirespeed’s unified tool correlation saw the repeat behavior pattern across the stack, identifying the root-cause program and allowing centrexIT to uninstall the threat rather than just monitoring a recurring block. |
MFA & Conditional Access Bypasses | Wirespeed surfaced successful logins that were being denied by conditional access policies. While the legacy MDR did not log these as actionable events because "access was denied," Wirespeed documented that a threat actor possessed a valid password. This allowed centrexIT to proactively reset credentials before the actor could find a gap in the MFA or VPN. |
Shadow Telemetry Failures | In multiple instances, Wirespeed pulled telemetry from both the endpoint detection and response (EDR) tool and endpoint management service into a single view. The legacy MDR provider was purportedly integrating these sources, but in practice was failing to surface the cross-tool activity that Wirespeed used to confirm the invisible gaps. |
Behavioral Identity Gaps | The legacy MDR provider failed to distinguish between malicious actors and centrexIT’s own administrative tools. While the legacy tool saw “activity" and isolated servers, Wirespeed used behavioral call-outs to verify the source. This demonstrated Wirespeed’s ability to identify who was acting, whereas the legacy provider only saw what was happening, leading to unnecessary production downtime. |
Automated Solution: Moving From Detection to Resolution
For centrexIT, identifying existing MDR gaps was only half the battle. The true test was whether Wirespeed ADR could close these gaps without introducing more manual work for their analysts. The evaluation confirmed that Wirespeed wasn't just a more sensitive alarm, but a true resolution engine.
To solve the recurring production downtime, Wirespeed helped centrexIT build a custom behavioral exclusion for its remote management tools. In just 15 minutes, the MSP was able to move away from the legacy hash-based logic that had failed them for months. Wirespeed identified the specific, authorized behavior of the MSP team, allowing for zero-interruption service.
Combined with a parent-child architecture, centrexIT finally achieved the single pane of glass view it desired. Changes made at the parent level filtered down instantly, and analysts no longer had to port between different client dashboards to understand a threat.
Business Impact: Reclaiming the SOC
Wirespeed has helped eliminate the human bottleneck for centrexIT. By shifting the burden of triage from the SOC team to the platform, the MSP has replaced the "zombie" tickets that once plagued the service desk with high-fidelity incidents that Wirespeed triaged or contained in milliseconds. The MSP is now making better use of its full technology stack and reallocating work where it’s needed.
We’re getting back 30+ analyst hours every week and can be more proactive, rather than just closing tickets all day. With our legacy MDR, it’s just busy for the sake of being busy." — Josh Hohbein, Manager of Cybersecurity and Automation, centrexIT
Before Wirespeed, centrexIT was too busy fighting its legacy MDR noise to address a backlog of alerts in its configuration management tool. By reclaiming 30+ hours of analyst airtime every week, the MSP has been able to reinvest resources into the security posture of its clients, move into proactive vCISO consulting, and begin deep-tier hardening that had previously been sidelined by manual ticket management.
Strategic Future: Scaling with Confidence
The move to Wirespeed ADR replaced administrative drag with a scalable relationship. Accurate billing and a reliable, API-first reporting engine allowed centrexIT to deliver the transparent, high-fidelity reports its clients expect without the multi-hour manual struggle.
"The fidelity is so much higher. Now, if we get a ticket, we know we actually need eyes on it. We’ve blown our old operational efficiency out of the water. I trust the detection, and I trust the containment." — Josh Hohbein, Manager of Cybersecurity and Automation, centrexIT
By removing the operational ceiling of legacy MDR, centrexIT has built the capacity to support its clients with greater precision and focus than ever before. The transition to Wirespeed shows that in a modern threat landscape, the best security tool isn't the one that sends the most alerts, but the one that provides the most resolution.
LIGHTNING-FAST SPEED. LASER PRECISION.
Wirespeed Automated Detection & Response
Start your free 30-day trial >






