Skip to content

Service

Managed detection and response

The difference between owning security tooling and being defended by it is whether somebody reviews what it reports. MDR is the review: continuous human attention on the alerts your endpoints generate, with pre-agreed authority to contain something at three in the morning without waiting for a call back.

Alert review

24 / 7

by people, not just software

An unreviewed console satisfies a compliance checkbox. It does not stop an incident.

Three things that get called the same thing

These terms are used interchangeably in sales conversations and they describe genuinely different levels of protection.

Antivirus, EDR tooling and MDR compared
ApproachWhat it doesWho responds
AntivirusMisses anything new or filelessMatches files against known bad signaturesNone
EDR tooling aloneAlerts nobody reviews are not a controlRecords behaviour and raises alertsYou, eventually
MDRCosts more than tooling aloneRecords behaviour, alerts reviewed by people 24 by 7The provider, within minutes

What happens when something fires

Containment first, investigation second. The order matters, because an hour spent understanding an incident is an hour it continues to spread.

Incident containment actions and their timing
ActionTiming
Isolate the endpointDevice cut from the network but still reachable for investigationImmediate
Disable the accountStops lateral movement using stolen credentialsImmediate
Kill the processHalts encryption or exfiltration in progressImmediate
Block the destinationCuts command and control traffic at the firewall and DNSImmediate
Preserve evidenceMemory and log capture before anything is rebuiltDuring
Notify youA named person is called, not emailedImmediate

Agree the authority in advance

The most valuable conversation in setting this up has nothing to do with technology. It is deciding, while nothing is on fire, what a provider may do without asking.

  • Isolating a single endpoint, almost always granted as standing authority
  • Disabling a user account, usually granted with immediate notification
  • Blocking a destination at the firewall, usually granted
  • Taking a server offline, usually requires contact first
  • Initiating a restore, always requires a decision from your side

Why the middle of the night matters

Attacks are timed deliberately. Encryption is commonly triggered on a Friday evening or over a public holiday, on the reasonable assumption that nobody will look at a console until Monday.

A twelve hour head start is the difference between one isolated workstation and an environment that needs rebuilding from backup. That gap is the entire commercial argument for continuous review, and it is why the cheapest version of this service, which is tooling with alerts sent to your inbox, delivers so much less than it appears to.

Common questions

Answered before you ask.

Is this different from the endpoint protection in our Microsoft licence?

The tooling may well be the same. What differs is whether anybody is watching it. A capable endpoint platform generates alerts continuously, most of them benign, and the value only appears when someone with the experience to tell the difference reviews them promptly. Businesses of this size rarely have anyone rostered to look at a security console at two in the morning, which is precisely when the interesting alerts arrive.

Who has the authority to isolate our machines?

That is agreed in advance and written down. Most businesses grant standing authority to isolate a device and disable an account during a suspected active incident, because waiting for approval at three in the morning costs more than a false positive does. Actions with wider business impact, such as taking a server offline, normally require contact first. The point is that the decision is made calmly in advance rather than during the event.

How many alerts will we actually hear about?

Very few. The overwhelming majority of alerts are resolved without any contact because they are benign or automatically handled. You hear about the ones requiring a decision or an action from your side. A provider forwarding every alert to you has not filtered anything and has effectively handed the work back while charging for it.

Does MDR replace our other security controls?

No, it sits behind them. Multi factor authentication, patching, email filtering and segmentation prevent incidents. MDR assumes something will get through anyway and shortens the time between that happening and somebody noticing. Deploying detection while leaving prevention thin is the wrong order, which is why identity and patching come first in an engagement.

Find out what your current tooling is missing.

The assessment reviews what security tooling you already own, what it is reporting, and whether anyone is reading it.

CallFree assessment