Service
Managed detection and response
The difference between owning security tooling and being defended by it is whether somebody reviews what it reports. MDR is the review: continuous human attention on the alerts your endpoints generate, with pre-agreed authority to contain something at three in the morning without waiting for a call back.
Alert review
24 / 7
by people, not just software
An unreviewed console satisfies a compliance checkbox. It does not stop an incident.
Three things that get called the same thing
These terms are used interchangeably in sales conversations and they describe genuinely different levels of protection.
| Approach | What it does | Who responds |
|---|---|---|
| AntivirusMisses anything new or fileless | Matches files against known bad signatures | None |
| EDR tooling aloneAlerts nobody reviews are not a control | Records behaviour and raises alerts | You, eventually |
| MDRCosts more than tooling alone | Records behaviour, alerts reviewed by people 24 by 7 | The provider, within minutes |
What happens when something fires
Containment first, investigation second. The order matters, because an hour spent understanding an incident is an hour it continues to spread.
| Action | Timing |
|---|---|
| Isolate the endpointDevice cut from the network but still reachable for investigation | Immediate |
| Disable the accountStops lateral movement using stolen credentials | Immediate |
| Kill the processHalts encryption or exfiltration in progress | Immediate |
| Block the destinationCuts command and control traffic at the firewall and DNS | Immediate |
| Preserve evidenceMemory and log capture before anything is rebuilt | During |
| Notify youA named person is called, not emailed | Immediate |
Agree the authority in advance
The most valuable conversation in setting this up has nothing to do with technology. It is deciding, while nothing is on fire, what a provider may do without asking.
- Isolating a single endpoint, almost always granted as standing authority
- Disabling a user account, usually granted with immediate notification
- Blocking a destination at the firewall, usually granted
- Taking a server offline, usually requires contact first
- Initiating a restore, always requires a decision from your side
Why the middle of the night matters
Attacks are timed deliberately. Encryption is commonly triggered on a Friday evening or over a public holiday, on the reasonable assumption that nobody will look at a console until Monday.
A twelve hour head start is the difference between one isolated workstation and an environment that needs rebuilding from backup. That gap is the entire commercial argument for continuous review, and it is why the cheapest version of this service, which is tooling with alerts sent to your inbox, delivers so much less than it appears to.
Common questions
Answered before you ask.
Is this different from the endpoint protection in our Microsoft licence?
The tooling may well be the same. What differs is whether anybody is watching it. A capable endpoint platform generates alerts continuously, most of them benign, and the value only appears when someone with the experience to tell the difference reviews them promptly. Businesses of this size rarely have anyone rostered to look at a security console at two in the morning, which is precisely when the interesting alerts arrive.
Who has the authority to isolate our machines?
That is agreed in advance and written down. Most businesses grant standing authority to isolate a device and disable an account during a suspected active incident, because waiting for approval at three in the morning costs more than a false positive does. Actions with wider business impact, such as taking a server offline, normally require contact first. The point is that the decision is made calmly in advance rather than during the event.
How many alerts will we actually hear about?
Very few. The overwhelming majority of alerts are resolved without any contact because they are benign or automatically handled. You hear about the ones requiring a decision or an action from your side. A provider forwarding every alert to you has not filtered anything and has effectively handed the work back while charging for it.
Does MDR replace our other security controls?
No, it sits behind them. Multi factor authentication, patching, email filtering and segmentation prevent incidents. MDR assumes something will get through anyway and shortens the time between that happening and somebody noticing. Deploying detection while leaving prevention thin is the wrong order, which is why identity and patching come first in an engagement.
Related
What sits alongside this.
Cybersecurity services
Endpoint detection, email security, monitoring and user training.
Cybersecurity risk assessment
Vulnerability scanning, penetration testing and a prioritised findings register.
Security awareness training
Phishing simulation and short, frequent training that changes behaviour.
Backup and disaster recovery
Immutable backups with tested restores and a defined recovery window.
What is included in managed IT services
A line by line scope, including the exclusions most contracts hide.
Find out what your current tooling is missing.
The assessment reviews what security tooling you already own, what it is reporting, and whether anyone is reading it.