Services / Continuous Operations
Managed Detection & Response
Round-the-clock cyber threat detection, investigation, and response, run by security analysts who watch every alert.
The problem
Your EDR generates alerts. They arrive in a channel that nobody watches after 6pm, and nobody is qualified to say whether a given alert is a false positive or the first hour of an intrusion. Meanwhile the auditor is asking who monitors security events, and the honest answer is nobody in particular.
The method.
Establish coverage and telemetry quality first
Detection is only as good as its inputs. Before monitoring begins we verify agent coverage against the asset inventory, and confirm that the sources an investigation needs are flowing: endpoint telemetry, identity and sign-in logs, cloud control-plane logs across all regions, VPN and remote access, and critical SaaS audit logs. Blind spots are named up front rather than discovered during an incident.
Tune detections to the environment
Out-of-the-box rules produce alert fatigue, and alert fatigue produces missed intrusions. Rules are tuned to your estate (developer machines run strange binaries legitimately, your CI system authenticates from odd places, your admins do use PowerShell) and mapped to MITRE ATT&CK so coverage gaps are visible rather than assumed.
Triage with human analysts, around the clock
Alerts are triaged by an analyst against the environment context, not auto-forwarded. Each escalation reaches you with a verdict, the evidence, the affected assets and a recommended action, not a raw alert ID and a link to a console you would have to learn to read.
Respond within a pre-agreed authority
Containment actions are agreed in advance and written down: which hosts may be isolated without a call, which accounts may be disabled, which actions always require your approval, and who is authorised to give it at 3am. This is negotiated before the first incident, because during an incident it costs hours.
Produce the compliance evidence as a by-product
Monitoring coverage, alert volumes, mean time to triage, mean time to contain, and incident records with timelines and corrective actions. These are exactly what ISO 27001 A.8.15/A.8.16 and the SOC 2 monitoring criteria require, and what cyber insurers ask for at renewal.
What is Managed Detection and Response?
Managed Detection and Response is an outsourced service in which analysts monitor an organisation's security telemetry around the clock, triage alerts, investigate genuine threats, and take pre-agreed containment actions. It differs from a monitoring tool in that a human decides whether an alert matters, and from a traditional SOC in that response authority is agreed in advance rather than limited to raising a ticket.
Does ISO 27001 or SOC 2 require security monitoring?
Yes. ISO 27001:2022 Annex A requires monitoring activities and event logging, and the SOC 2 Common Criteria require the monitoring of system components and the detection of anomalies. Both expect evidence that monitoring actually operated (coverage figures, alert handling records and incident timelines), not merely that a tool was purchased.
What telemetry does MDR need to be effective?
Endpoint detection telemetry across the full estate, identity provider sign-in and audit logs, cloud control-plane logs in every account and region, remote access and VPN logs, and audit logs from business-critical SaaS. Coverage gaps in these sources are the single biggest determinant of whether an intrusion is caught, which is why coverage is verified before monitoring starts rather than after.