Managed detection and response (MDR) is a security service in which an outside team watches your environment around the clock, investigates suspicious activity and responds to real threats, either by taking pre-authorized containment actions itself or by guiding your team through them. It combines detection software, usually endpoint detection and response (EDR) at a minimum, with analysts who decide which alerts matter and respond to them. For companies that can’t staff their own 24/7 security operation, MDR is the most common way to get one.
At a glance
- MDR is a service, not a product: people, process and technology delivered by a provider for a monthly fee.
- Coverage starts with endpoints and often extends to identity, email, cloud and network data, depending on the provider and tier.
- Analysts triage alerts and hunt for threats; depending on the service, they either take pre-authorized containment actions (such as isolating a device) or advise your team, which then acts.
- Response usually stops at containment or guidance; deep forensics and recovery are often a separate incident response engagement.
- Pricing is typically per endpoint or per user, with extra charges varying by data source and data volume.
What problem it solves
Security tools generate alerts constantly. Most are harmless, some are urgent, and attacks often happen at night or on weekends when no one is looking. A mid-sized company with a small IT team usually can’t hire, train and retain enough security analysts to cover every hour of every day, and alerts that sit unread until Monday are how a single compromised laptop turns into a company-wide ransomware event.
MDR closes that gap. The provider’s analysts review alerts as they arrive, separate real threats from noise, and act within minutes or hours rather than days. It also gives you access to people who see attacks across many customers and know what current threats look like, which is hard to build internally. Cyber insurers increasingly ask whether endpoints are monitored around the clock, and MDR is a common way to answer yes.
How it works
Telemetry. The provider collects activity data from your environment. At minimum this is an EDR agent on laptops and servers; broader services also pull in identity provider logs, email security, firewall and cloud platform data. Some providers require their own EDR tool, while others work with the one you have.
Detection and triage. Detection rules and analytics flag suspicious behavior. Analysts investigate each alert, add context from other data and threat intelligence, and decide whether it is a real incident. Many providers also do proactive threat hunting, looking for signs of attackers that didn’t trigger an alert.
Response. For confirmed threats, a provider with your pre-approval takes containment actions such as isolating a device from the network, ending a malicious process, disabling an account or resetting its sessions, and notifies you with what happened and what to do next. Some services only advise and leave the action to you; others act directly. That difference matters more than almost anything else in the contract.
Reporting and escalation. You get incident reports and regular summaries. Serious incidents are escalated to your contacts and, if needed, to an incident response team for investigation and recovery.
When it matters for buyers
- When you have no one watching after hours. If alerts go to an inbox nobody checks on weekends, MDR is the usual fix.
- When cyber insurance renews. Insurers increasingly ask about EDR, 24/7 monitoring and incident response readiness, and answers can affect coverage and premium.
- When you already own EDR or a SIEM but nobody acts on them. Tools without people produce alerts, not outcomes.
- When comparing providers. The words “detection” and “response” mean very different things across contracts; scope, authority and exclusions decide value.
- When you grow quickly. New sites, acquisitions and remote staff add devices and accounts faster than an internal team can monitor.
Questions to ask vendors
- Which data sources are included (endpoint, identity, email, cloud, network), and what costs extra?
- Do you require your own EDR tool, or can you work with ours?
- What containment actions will you take without calling us first, and can we customize that list?
- What are your response times for critical alerts, and how are they measured and reported?
- Where does your response stop, and are incident response hours included or sold separately?
- Who are the analysts, where are they located, and do we get a named contact?
- How do you report on what you saw and did each month?
- If we leave, what data and detection history do we keep?
How it differs from EDR, XDR and a SOC
Endpoint detection and response (EDR) and extended detection and response (XDR) are technologies: software that collects data and gives you tools to detect and respond. MDR is a service, people operating that kind of technology for you. A security operations center (SOC) is the security monitoring function itself, whether you build it in-house or buy it; MDR is one of the most common ways to outsource it. MDR also differs from incident response (IR), the whole process you own, and from an incident response retainer, which puts investigators on call for the deeper work after a serious incident. See our managed detection and response overview, and our comparisons of MDR vs EDR and MDR vs XDR.
