The gap between the breach and the alarm
Most businesses buy prevention. Firewalls, antivirus, email filters. Very few have anyone actively watching for the attacks that get through those tools.
And attacks do get through. Every perimeter has gaps. Every user makes mistakes. Every piece of software carries vulnerabilities. Prevention decides how often you are attacked successfully. Detection decides how long that attacker stays.
Managed detection and response closes the second gap with continuous monitoring, proactive threat hunting and fast incident response. It sits alongside cybersecurity services rather than replacing them.
What managed detection and response actually does
SOC as a service means security analysts watching your environment around the clock. Not watching dashboards — hunting for indicators of compromise, investigating anomalous behaviour, and correlating events across your endpoints, network, cloud platforms and identity systems.
When an analyst confirms a threat, they act. Malware executing on an endpoint gets that device isolated from the network: automatically where the threat is clear-cut, with analyst approval where it is not. An account showing signs of compromise gets disabled, then investigated.
You are not waiting for an alert email the next morning. For a ransomware attack, as we set out in our ransomware threat landscape guide, the gap between minutes and hours is the gap between one isolated machine and an encrypted network.
Proactive threat hunting, not just alerts
Automated detection catches known patterns. But sophisticated attackers deliberately avoid known signatures. They use legitimate tools already installed on your systems, move slowly to blend with normal traffic, and exploit zero-day vulnerabilities that no rule has been written for yet.
Our threat hunters proactively search for these stealthy intrusions. They analyse behavioural patterns, look for lateral movement indicators, investigate unusual authentication activity, and correlate weak signals that individually look benign but together indicate compromise. This human layer is what separates MDR from a tool that sends alert emails.
MDR vs EDR vs SIEM vs SOC: the difference
These four acronyms get used almost interchangeably, and the distinction matters, because buying the wrong layer leaves you with tooling nobody is watching.
| What it is | Who operates it | What it does not do | |
|---|---|---|---|
| EDR | Software on endpoints that detects and can isolate malicious behaviour | You | Nothing outside the endpoint; nobody watches the alerts |
| SIEM | A platform that collects and correlates logs from everything | You | Detects nothing on its own; needs rules, tuning and analysts |
| SOC | A team of analysts, in-house or outsourced | You or a provider | Costs a minimum of three FTE to run 24/7 in-house |
| MDR | EDR + log analytics + a 24/7 analyst team + authority to act | Provider | Not a replacement for backups, patching or email filtering |
| MSSP | Traditionally alert forwarding and device management | Provider | Classically notifies you rather than responding itself |
The practical difference between MDR and an older MSSP model is authority. An MSSP typically sends you an alert. MDR contains the threat and tells you afterwards. If a provider cannot isolate a host at 3am without waiting for your approval, you are buying monitoring, not response.
What MDR costs per endpoint
MDR is priced per endpoint or per user, per month. The UK mid-market range is wide because the term gets applied loosely.
- Entry / tool-led MDR: £6–£12 per endpoint/month. Usually one vendor’s EDR with a shared analyst pool.
- Full MDR with log ingestion: £15–£30 per endpoint/month. Covers identity, cloud and email telemetry, not just endpoints.
- In-house 24/7 SOC: £350,000+ per year in salary alone. Genuine round-the-clock cover needs five or six analysts, not three.
For a 50-person firm, full MDR lands between roughly £750 and £1,500 per month on those rates. Weigh that against a single ransomware incident. Note too that most cyber insurers now price MDR into their premiums, so part of the cost comes back through reduced insurance.
Five questions to ask any MDR provider
Five questions will tell you what a provider is actually offering:
- “Will you isolate a compromised host without calling me first?” If no, it is monitoring. Get the pre-authorised action list in writing.
- “Is your SOC staffed by analysts at 3am on a Sunday, or is it follow-the-sun with a skeleton shift?” Ask where the analysts physically are.
- “What telemetry do you ingest beyond endpoints?” Identity (Entra ID) and email are where modern attacks actually start. Endpoint-only MDR misses business email compromise almost entirely.
- “What is your contractual mean time to respond, and what happens if you miss it?” An SLA with no remedy attached is difficult to rely on.
- “Who owns the data if we leave?” Log retention and portability matter for both investigations and regulators.
What MDR does not cover
Worth setting out clearly, so you can plan the other layers around it. MDR detects and responds to intrusions. It does not:
- Replace backups. If ransomware detonates, recovery still depends on tested, immutable backups.
- Patch your systems. Detection is not remediation of the underlying vulnerability.
- Stop the phishing email arriving. That is email security and awareness training.
- Fix identity architecture. If everyone is a domain admin, MDR will detect the compromise faster and still have to watch it spread.
MDR is the layer that assumes the others will occasionally fail. It is not a substitute for them.
FCA and DORA monitoring duties, evidenced
For financial services firms in scope of FCA operational resilience or DORA, monitoring and incident evidence may form part of the wider programme. MDR can produce useful detection, response and reporting records, while your compliance advisers determine whether the complete set of obligations has been met.
You also get monthly threat intelligence briefings written for the financial services sector, including hedge funds and wealth managers. They cover emerging attack techniques, campaigns aimed at your sector, and what to strengthen next — so you stay current without tracking the threat landscape yourself.