Managed detection and response (MDR) is a cybersecurity service in which external security specialists continuously monitor an organisation's systems, investigate suspicious activity, hunt for hidden threats and help contain or remediate confirmed attacks.
MDR combines security software with human analysts. The provider works as an extension of the organisation's security team and may provide 24/7 monitoring without requiring the organisation to build and staff its own security operations centre.
Managed Detection and Response at a Glance
| Aspect | What MDR provides |
|---|---|
| Primary purpose | Detect, investigate and respond to cyber threats |
| Main operators | External security analysts supported by automation |
| Typical coverage | Endpoints, identities, cloud services, networks, email and other connected telemetry |
| Core activities | Monitoring, alert triage, threat hunting, investigation, containment and remediation |
| Response model | Guided response or provider-led response, depending on the contract |
| Best suited to | Organisations without 24/7 security coverage or with overloaded internal teams |
| Important limitation | MDR does not replace patching, access controls, backups or security governance |
How Does Managed Detection and Response Work?
MDR usually follows a continuous detection and response process:
- Collect security data from systems such as endpoint protection platforms, identity services, cloud environments, networks and security logs.
- Prioritise alerts by filtering false positives and identifying activity that may indicate a genuine attack.
- Investigate incidents to establish what happened, which systems or accounts are affected and how serious the threat is.
- Hunt for related activity that automated alerts may have missed.
- Contain and remediate the threat by isolating a device, stopping malicious files or restricting application execution.
- Identify the root cause and recommend changes that could reduce the chance of a repeat incident.
The process varies by provider. Microsoft describes MDR as a service that includes incident triage, investigation, threat hunting and either direct response or guidance for the customer's team.
Alert Monitoring and Prioritisation
Security tools can generate a large number of alerts, and many do not represent real attacks. MDR analysts review those alerts, connect related events and rank incidents by likely severity and business impact.
This gives internal teams fewer low-value notifications to review. The aim is not to create more alerts. It is to find the alerts that need investigation or action.
Threat Hunting
Threat hunting is the search for suspicious activity that has not triggered a conventional security alert.
An MDR team may look for signs of compromised accounts, unusual privilege escalation, lateral movement, malware persistence or suspicious activity across cloud and endpoint environments. This work separates a full MDR service from a monitoring service that only processes incoming alerts.
Investigation and Response
When analysts confirm a likely incident, they assess its scope, timeline and impact. Depending on the agreement, the MDR provider may:
- Isolate a compromised device
- Stop or quarantine a malicious file
- Restrict an application from running
- Disable or restrict a compromised account
- Block known indicators of compromise
- Remove persistence mechanisms
- Guide the customer's IT team through remediation
- Provide an incident report and root-cause analysis
Response authority is an important contract detail. Some providers notify the customer and recommend actions. Others can take approved containment and remediation actions directly.
What Is the Difference Between MDR and EDR?
Endpoint detection and response (EDR) is a security technology, while managed detection and response is a managed service that uses security technologies and human expertise to investigate and respond to threats.
| EDR | MDR |
|---|---|
| Software that monitors endpoint activity | A service operated by security specialists |
| Focuses mainly on computers, servers and other endpoints | May combine endpoint, identity, cloud, network and other telemetry |
| Generates detections and provides investigation tools | Reviews detections, hunts for threats and manages response |
| Requires internal staff to operate effectively | Provides external analysts and operational expertise |
| May not include 24/7 human coverage | Commonly offers continuous monitoring, subject to the provider's service model |
An organisation can use EDR without MDR. However, an EDR deployment may provide limited value when nobody has the time or expertise to investigate alerts and respond to confirmed threats.
What Is the Difference Between MDR, SIEM and XDR?
These terms refer to different parts of a security operations model:
- MDR, or managed detection and response, is the people-and-process service that monitors, investigates and responds to threats.
- SIEM, or security information and event management, is a platform that collects and analyses security data from multiple sources.
- XDR, or extended detection and response, connects detection and response capabilities across several security domains.
- EDR focuses mainly on endpoint activity.
- MSSP, or managed security services provider, is a broader category that may include firewall management, vulnerability management, compliance support, network monitoring and other services.
A security platform supplies technology. MDR supplies an operational service around that technology. An MDR provider may use EDR, SIEM, XDR, security orchestration and threat intelligence platforms as part of its service.
What Are the Benefits of MDR?
MDR can provide continuous security operations when an organisation lacks the staff, coverage or expertise to run them internally.
24/7 Security Coverage
MDR can provide continuous monitoring and access to security analysts when an organisation does not have its own round-the-clock security operations team. This can help smaller security teams, distributed businesses and organisations working across multiple time zones.
Faster Investigation and Containment
MDR can reduce the time between an alert, an investigation and a response. Acting sooner may limit an attacker's ability to move between systems, increase privileges or access sensitive data.
NIST places detection, response and recovery within a wider cybersecurity risk-management process. Detection identifies suspicious events, response limits their effect and recovery restores affected capabilities.
Access to Specialist Expertise
MDR gives organisations access to analysts who investigate a broad range of security incidents. This can help when an internal IT team lacks dedicated threat-hunting, digital forensics or incident-response experience.
Reduced Alert Fatigue
MDR analysts separate routine alerts from incidents that require attention. Internal teams can then spend less time reviewing every security notification manually.
Security Team Augmentation
MDR can support an internal security team rather than replace it. An organisation might use the provider for continuous monitoring and initial response while its own staff handle architecture, governance, risk and complex remediation. Microsoft describes its MDR service as augmenting, rather than automatically replacing, a customer's security operations centre.
What Are the Limitations of MDR?
MDR strengthens detection and response, but it does not provide a complete cybersecurity programme.
An MDR provider cannot analyse systems it cannot see. The service may also have limited effect when an organisation has weak identity controls, unpatched software, excessive privileges or inadequate backups. Business decisions that depend on detailed operational knowledge also remain with the customer unless the contract assigns them to the provider.
Important limitations include:
- Incomplete visibility: The provider can analyse only the data sources connected to the service.
- Unclear response authority: Some contracts require customer approval before containment actions.
- Limited technology coverage: A plan may focus on one vendor's security products or selected workloads.
- Shared responsibility: The customer remains responsible for security policies, asset management, patching, backups and business continuity.
- Provider dependency: The organisation relies on the provider's analysts, tools, processes and escalation procedures.
NIST's cybersecurity framework treats detection and response as part of a wider lifecycle that also includes identifying risks, protecting systems and recovering from incidents. MDR covers part of that lifecycle. It does not remove the need for the other functions.
Who Should Use Managed Detection and Response?
MDR is usually a good fit for an organisation that lacks continuous security coverage or cannot operate its security tools effectively.
Typical reasons to consider MDR include:
- No 24/7 security operations centre
- Too few security analysts to investigate alerts consistently
- EDR, SIEM or XDR tools without enough staff to operate them
- A need for threat hunting or incident investigation expertise
- Employees, systems or customers in multiple regions
- An existing security team that needs extra capacity
- No clearly defined escalation and incident-response process
MDR may be unnecessary when an organisation already has a mature internal security operations team with round-the-clock monitoring, effective threat hunting and tested incident-response procedures. It may still use an MDR provider for specialist expertise or additional coverage during periods of high demand.
What Should You Check Before Choosing an MDR Provider?
Start by checking what the provider monitors, what its analysts do and which response actions the contract allows.
- Coverage hours: Confirm whether monitoring is genuinely 24/7 and whether analysts work continuously or only during business hours.
- Telemetry coverage: Check support for endpoints, identity systems, cloud platforms, email, network devices, SaaS applications and other important systems.
- Human involvement: Ask how analysts investigate alerts and how much of the service depends on automation.
- Response authority: Confirm which actions the provider can take without approval, such as isolating a device or disabling an account.
- Service-level agreements: Review response times, escalation rules and communication requirements.
- Threat hunting: Establish whether proactive hunting is included or charged as an additional service.
- Incident reporting: Check whether reports include evidence, affected assets, timelines, root cause and recommended remediation.
- Integration requirements: Confirm which security products, log sources and cloud services the provider supports.
- Data handling: Review data retention, access controls, privacy obligations and the location of security data.
- Exit process: Understand how the organisation can retrieve its data and move away from the provider.
Pricing varies by provider. Quotes commonly depend on the number of protected assets, the amount and type of telemetry, the security platforms involved, monitoring requirements and whether the provider can perform remediation.
A low price may not represent a lower overall cost if the service excludes the data sources or response actions needed during an incident.
Bottom Line
MDR is worth considering when an organisation has security tools but lacks the people, time or expertise to operate them continuously.
Before signing a contract, confirm four things: what the provider monitors, how it investigates threats, which response actions it can take and how quickly it must act. Those details determine what the service will do during a real incident.