Service reference

Get 24/7 managed detection and response without building a SOC

A security operations team watches your environment around the clock, hunts what your tools miss, and contains confirmed threats rather than emailing you about them.

Clear scope · friendly support · practical advice

Last reviewed

The short version

Included as standard

Everything here is covered by the agreed fee. Anything outside it is quoted in advance.

  • 24/7/365 security operations centre monitoring
  • Endpoint detection and response across all devices
  • Network traffic analysis and anomaly detection
  • Cloud security monitoring (Azure, AWS, Microsoft 365)
  • Threat hunting by experienced analysts
  • Automated containment of confirmed threats
  • Incident response with root cause analysis
  • Monthly threat intelligence briefings

The gap between the breach and the alarm

Most businesses buy prevention. Firewalls, antivirus, email filters. Very few have anyone actively watching for the attacks that get through those tools.

And attacks do get through. Every perimeter has gaps. Every user makes mistakes. Every piece of software carries vulnerabilities. Prevention decides how often you are attacked successfully. Detection decides how long that attacker stays.

Managed detection and response closes the second gap with continuous monitoring, proactive threat hunting and fast incident response. It sits alongside cybersecurity services rather than replacing them.

What managed detection and response actually does

SOC as a service means security analysts watching your environment around the clock. Not watching dashboards — hunting for indicators of compromise, investigating anomalous behaviour, and correlating events across your endpoints, network, cloud platforms and identity systems.

When an analyst confirms a threat, they act. Malware executing on an endpoint gets that device isolated from the network: automatically where the threat is clear-cut, with analyst approval where it is not. An account showing signs of compromise gets disabled, then investigated.

You are not waiting for an alert email the next morning. For a ransomware attack, as we set out in our ransomware threat landscape guide, the gap between minutes and hours is the gap between one isolated machine and an encrypted network.

Proactive threat hunting, not just alerts

Automated detection catches known patterns. But sophisticated attackers deliberately avoid known signatures. They use legitimate tools already installed on your systems, move slowly to blend with normal traffic, and exploit zero-day vulnerabilities that no rule has been written for yet.

Our threat hunters proactively search for these stealthy intrusions. They analyse behavioural patterns, look for lateral movement indicators, investigate unusual authentication activity, and correlate weak signals that individually look benign but together indicate compromise. This human layer is what separates MDR from a tool that sends alert emails.

MDR vs EDR vs SIEM vs SOC: the difference

These four acronyms get used almost interchangeably, and the distinction matters, because buying the wrong layer leaves you with tooling nobody is watching.

What it is Who operates it What it does not do
EDR Software on endpoints that detects and can isolate malicious behaviour You Nothing outside the endpoint; nobody watches the alerts
SIEM A platform that collects and correlates logs from everything You Detects nothing on its own; needs rules, tuning and analysts
SOC A team of analysts, in-house or outsourced You or a provider Costs a minimum of three FTE to run 24/7 in-house
MDR EDR + log analytics + a 24/7 analyst team + authority to act Provider Not a replacement for backups, patching or email filtering
MSSP Traditionally alert forwarding and device management Provider Classically notifies you rather than responding itself

The practical difference between MDR and an older MSSP model is authority. An MSSP typically sends you an alert. MDR contains the threat and tells you afterwards. If a provider cannot isolate a host at 3am without waiting for your approval, you are buying monitoring, not response.

What MDR costs per endpoint

MDR is priced per endpoint or per user, per month. The UK mid-market range is wide because the term gets applied loosely.

  • Entry / tool-led MDR: £6–£12 per endpoint/month. Usually one vendor’s EDR with a shared analyst pool.
  • Full MDR with log ingestion: £15–£30 per endpoint/month. Covers identity, cloud and email telemetry, not just endpoints.
  • In-house 24/7 SOC: £350,000+ per year in salary alone. Genuine round-the-clock cover needs five or six analysts, not three.

For a 50-person firm, full MDR lands between roughly £750 and £1,500 per month on those rates. Weigh that against a single ransomware incident. Note too that most cyber insurers now price MDR into their premiums, so part of the cost comes back through reduced insurance.

Five questions to ask any MDR provider

Five questions will tell you what a provider is actually offering:

  1. “Will you isolate a compromised host without calling me first?” If no, it is monitoring. Get the pre-authorised action list in writing.
  2. “Is your SOC staffed by analysts at 3am on a Sunday, or is it follow-the-sun with a skeleton shift?” Ask where the analysts physically are.
  3. “What telemetry do you ingest beyond endpoints?” Identity (Entra ID) and email are where modern attacks actually start. Endpoint-only MDR misses business email compromise almost entirely.
  4. “What is your contractual mean time to respond, and what happens if you miss it?” An SLA with no remedy attached is difficult to rely on.
  5. “Who owns the data if we leave?” Log retention and portability matter for both investigations and regulators.

What MDR does not cover

Worth setting out clearly, so you can plan the other layers around it. MDR detects and responds to intrusions. It does not:

  • Replace backups. If ransomware detonates, recovery still depends on tested, immutable backups.
  • Patch your systems. Detection is not remediation of the underlying vulnerability.
  • Stop the phishing email arriving. That is email security and awareness training.
  • Fix identity architecture. If everyone is a domain admin, MDR will detect the compromise faster and still have to watch it spread.

MDR is the layer that assumes the others will occasionally fail. It is not a substitute for them.

FCA and DORA monitoring duties, evidenced

For financial services firms in scope of FCA operational resilience or DORA, monitoring and incident evidence may form part of the wider programme. MDR can produce useful detection, response and reporting records, while your compliance advisers determine whether the complete set of obligations has been met.

You also get monthly threat intelligence briefings written for the financial services sector, including hedge funds and wealth managers. They cover emerging attack techniques, campaigns aimed at your sector, and what to strengthen next — so you stay current without tracking the threat landscape yourself.

Last reviewed , and maintained by the Nerdster engineering team.

Tell us what would make IT easier

Share what is causing problems or taking up time. Our London team replies during business hours.

We respond within 2 hours during business days. Your data is handled per our privacy policy.

Contact details

0330 043 7414

Mon-Fri 8am-6pm

[email protected]

We reply within 2 hours

71-75 Shelton Street

Covent Garden, London WC2H 9JQ

IT assessment

A review of your IT, your security posture and your compliance readiness, free of charge.

  • 30-minute consultation call
  • Infrastructure & security review
  • Compliance gap analysis
  • Custom recommendations report

What you get from us

Stay covered outside office hours

Attackers do not work business hours. The SOC monitors your environment around the clock, including weekends and holidays, with pre-agreed authority to isolate a compromised host rather than wait for you to wake up.

Get the depth of a full security team

Running a SOC in-house means five or six analysts, a SIEM platform and threat intelligence feeds before you detect anything. You get all of it as a service, and your written SLA sets out what we owe you.

Hear about threats, not noise

Security tools generate thousands of alerts. Analysts investigate and triage them, so your team hears about confirmed threats that need a decision rather than a queue of false positives.

FAQ

Frequently asked questions

What is the difference between MDR and traditional antivirus?

Antivirus detects known malware signatures. MDR combines advanced endpoint detection, network monitoring, cloud security, and human analysts who actively hunt for threats and respond to incidents. It catches sophisticated attacks that antivirus misses entirely.

Do we need MDR if we already have EDR?

EDR is a technology. MDR is a service that includes EDR plus human analysts who monitor, investigate, and respond 24/7. EDR without skilled people watching it is like having a burglar alarm with nobody listening.

How does the SOC communicate with us during an incident?

During a confirmed incident, your designated contact receives an immediate phone call and email with details of the threat, containment actions taken, and recommended next steps. We also provide a full incident report within 48 hours.

What data does the MDR service collect?

The service may collect endpoint telemetry, network flow data, authentication logs and cloud activity logs. Data locations, subprocessors and retention depend on the agreed platform and service, and are documented before deployment so your advisers can review them.

Can MDR help with regulatory compliance?

MDR can provide monitoring, incident records and response evidence that support relevant FCA, DORA or certification work. It does not make an organisation compliant by itself; scope and any remaining requirements need to be assessed with your legal, compliance or certification advisers.