What Is MDR (Managed Detection and Response)?

Related problems: Nobody watching security alerts at night or on weekends; Too many alerts from our security tools and no one to triage them; Can't hire or afford a 24/7 security team; Cyber insurer asking who monitors our endpoints

Managed detection and response (MDR) is a security service in which an outside team watches your environment around the clock, investigates suspicious activity and responds to real threats, either by taking pre-authorized containment actions itself or by guiding your team through them. It combines detection software, usually endpoint detection and response (EDR) at a minimum, with analysts who decide which alerts matter and respond to them. For companies that can’t staff their own 24/7 security operation, MDR is the most common way to get one.

At a glance

  • MDR is a service, not a product: people, process and technology delivered by a provider for a monthly fee.
  • Coverage starts with endpoints and often extends to identity, email, cloud and network data, depending on the provider and tier.
  • Analysts triage alerts and hunt for threats; depending on the service, they either take pre-authorized containment actions (such as isolating a device) or advise your team, which then acts.
  • Response usually stops at containment or guidance; deep forensics and recovery are often a separate incident response engagement.
  • Pricing is typically per endpoint or per user, with extra charges varying by data source and data volume.

What problem it solves

Security tools generate alerts constantly. Most are harmless, some are urgent, and attacks often happen at night or on weekends when no one is looking. A mid-sized company with a small IT team usually can’t hire, train and retain enough security analysts to cover every hour of every day, and alerts that sit unread until Monday are how a single compromised laptop turns into a company-wide ransomware event.

MDR closes that gap. The provider’s analysts review alerts as they arrive, separate real threats from noise, and act within minutes or hours rather than days. It also gives you access to people who see attacks across many customers and know what current threats look like, which is hard to build internally. Cyber insurers increasingly ask whether endpoints are monitored around the clock, and MDR is a common way to answer yes.

How it works

Telemetry. The provider collects activity data from your environment. At minimum this is an EDR agent on laptops and servers; broader services also pull in identity provider logs, email security, firewall and cloud platform data. Some providers require their own EDR tool, while others work with the one you have.

Detection and triage. Detection rules and analytics flag suspicious behavior. Analysts investigate each alert, add context from other data and threat intelligence, and decide whether it is a real incident. Many providers also do proactive threat hunting, looking for signs of attackers that didn’t trigger an alert.

Response. For confirmed threats, a provider with your pre-approval takes containment actions such as isolating a device from the network, ending a malicious process, disabling an account or resetting its sessions, and notifies you with what happened and what to do next. Some services only advise and leave the action to you; others act directly. That difference matters more than almost anything else in the contract.

Reporting and escalation. You get incident reports and regular summaries. Serious incidents are escalated to your contacts and, if needed, to an incident response team for investigation and recovery.

When it matters for buyers

  • When you have no one watching after hours. If alerts go to an inbox nobody checks on weekends, MDR is the usual fix.
  • When cyber insurance renews. Insurers increasingly ask about EDR, 24/7 monitoring and incident response readiness, and answers can affect coverage and premium.
  • When you already own EDR or a SIEM but nobody acts on them. Tools without people produce alerts, not outcomes.
  • When comparing providers. The words “detection” and “response” mean very different things across contracts; scope, authority and exclusions decide value.
  • When you grow quickly. New sites, acquisitions and remote staff add devices and accounts faster than an internal team can monitor.

Questions to ask vendors

  • Which data sources are included (endpoint, identity, email, cloud, network), and what costs extra?
  • Do you require your own EDR tool, or can you work with ours?
  • What containment actions will you take without calling us first, and can we customize that list?
  • What are your response times for critical alerts, and how are they measured and reported?
  • Where does your response stop, and are incident response hours included or sold separately?
  • Who are the analysts, where are they located, and do we get a named contact?
  • How do you report on what you saw and did each month?
  • If we leave, what data and detection history do we keep?

How it differs from EDR, XDR and a SOC

Endpoint detection and response (EDR) and extended detection and response (XDR) are technologies: software that collects data and gives you tools to detect and respond. MDR is a service, people operating that kind of technology for you. A security operations center (SOC) is the security monitoring function itself, whether you build it in-house or buy it; MDR is one of the most common ways to outsource it. MDR also differs from incident response (IR), the whole process you own, and from an incident response retainer, which puts investigators on call for the deeper work after a serious incident. See our managed detection and response overview, and our comparisons of MDR vs EDR and MDR vs XDR.

Frequently Asked Questions

Is MDR the same as EDR?
No. Endpoint detection and response (EDR) is software that records and acts on activity on your devices. MDR is a service: people who watch that software's alerts, and often other sources, around the clock and act on them. Most MDR services either supply an EDR tool or work on top of one you already own.
What is the difference between MDR and an MSSP?
A managed security service provider (MSSP) traditionally manages security devices and forwards alerts, leaving much of the investigation to you. MDR focuses on detecting threats, investigating them and responding, either by acting directly where you have authorized it or by telling your team exactly what to do. The line has blurred, as many MSSPs now sell MDR, so compare what each contract actually commits to.
Does MDR replace our IT team or MSP?
No. MDR handles detection and first response for security threats. Your IT team or MSP still patches systems, manages users and does the fixing and rebuilding after an incident, and you still own business decisions.
How is MDR priced?
Usually per endpoint or per user per month, sometimes with additional charges for the volume of log data ingested, extra data sources such as cloud or network, or incident response hours beyond what is included. Pricing models vary widely, so compare quotes on the same scope.
Does MDR include incident response?
It includes some response, but how much varies. Some providers take containment actions themselves, such as isolating a device or disabling an account, where you have pre-authorized them; advisory-only services tell you what to do and leave the action to your team. Full incident response, including forensic investigation and recovery, is often sold separately or as a limited block of retainer hours. Ask exactly where the provider's work stops.

You Don’t Need Another Sales Call. You Need an Answer.

30 minutes. No pitch. Just an honest conversation about where you are, what you need, and whether working together makes sense.

We use your details to set up and prepare for the call, and send the newsletter only if you ask for it. Privacy policy.