Managed detection and response is a service, not a product. It is a team of analysts watching your estate around the clock, usually using detection tooling you already own or licence through them, with a mandate to act at three in the morning without waiting for you to wake up. That single distinction explains why this market confuses buyers so badly: MDR sits on the same quote as antivirus, EDR and SOC-as-a-service as though all four were interchangeable line items, when three of them are things and one of them is people.
The confusion has a price. Organisations routinely pay for endpoint tooling that nobody reads, or budget for an in-house security operations centre they cannot staff, while the actual gap — someone competent looking at the alerts out of hours — stays open. Successive editions of the UK Government’s Cyber Security Breaches Survey have found that only a minority of businesses have any formal incident response plan, and the Verizon Data Breach Investigations Report continues to show intrusions that ran for days before anyone noticed. Neither statistic is a tooling problem. Both are an attention problem, which is the specific thing cybersecurity services are meant to solve.
This guide separates the four properly. It covers what an MDR contract actually includes beyond the licence, what antivirus still stops and where it goes blind, why unmonitored EDR behaves like a flight recorder, what a 24/7 SOC really costs to staff, and how the four compare on coverage, price, speed and response authority. It then gets practical: how to choose by company size and sector, what to ask a provider before signing, and which mistakes reliably waste the budget. It is written to sit alongside an existing IT security programme rather than replace it.
Table of contents
- What Managed Detection and Response Actually Buys You
- Antivirus: The Layer You Still Need and Should Stop Overrating
- EDR vs Managed Detection and Response: Data Without Watchers
- SOC: A Team and a Process, Not a Product
- Managed Detection and Response vs EDR vs Antivirus vs SOC Compared
- What Managed Detection and Response Costs Against an In-House SOC
- Response Speed: Where Managed Detection and Response Pulls Ahead
- How to Choose Between Managed Detection and Response and the Alternatives
- What to Ask a Managed Detection and Response Provider Before Signing
- Mistakes That Waste a Managed Detection and Response Budget
- Managed Detection and Response: Frequently Asked Questions
- References
What Managed Detection and Response Actually Buys You
Strip away the marketing and managed detection and response is three things bundled together: a detection platform, a staffed rota that watches it, and a contractual right to intervene on your systems. Remove any one of those and you have bought something else.
The three components that define an MDR contract
The platform is usually EDR or XDR, sometimes with a SIEM behind it, and it is frequently the same product you could licence directly. The rota is the expensive part — analysts covering nights, weekends and bank holidays, with escalation paths and named responsibilities. The mandate is the part buyers most often negotiate away and most often regret: without pre-agreed authority to isolate a host or disable an account, your provider becomes a very well-informed telephone service.
Detection engineering is the component nobody sells
Every serious managed detection and response provider maintains its own detection content — rules, behavioural analytics and hunting queries that sit on top of whatever the vendor ships by default. That content is tuned against what they see across their whole client base, which is the genuine economy of scale in the model. A single mid-market business will never write, test and retire detections at that rate, and the out-of-the-box ruleset alone is not where the value is.
What “response” means, and what it does not
Response in most contracts means containment: isolating an endpoint from the network, killing a process, suspending an account, blocking a hash. It rarely means full forensic investigation, legal notification, rebuilding servers or negotiating with an extortion group. Read the definition in the contract rather than the one on the website, because the gap between “we respond” and “we contain and hand over” is where the 4am argument happens. A managed detection and response engagement should say plainly which actions the provider takes unilaterally, which need your sign-off, and how long they will wait for it.
Antivirus: The Layer You Still Need and Should Stop Overrating
Antivirus — or next-generation antivirus, as most of it now is — remains a sensible baseline control. It is also the layer buyers most often mistake for a complete security posture.
How signature and heuristic detection works
Classic antivirus matches files against known-bad signatures. Modern engines add heuristics, machine learning classifiers and behavioural blocking, which materially improved the hit rate against novel malware. Enforcement happens locally on the device, decisions are made in milliseconds, and nobody has to be awake for it to work. That autonomy is exactly why it scales cheaply to every laptop you own.
What antivirus genuinely stops
Commodity malware, drive-by downloads, malicious attachments, opportunistic ransomware droppers and the long tail of automated attacks. That is not a trivial list — it is most of the volume most organisations face, and running without it is indefensible. Cyber Essentials treats malware protection as one of its five technical controls precisely because the baseline still works. Nobody buying managed detection and response should be removing it.
Where antivirus goes blind
It struggles badly with anything that is not a malicious file. An attacker who signs in with a stolen password, uses PowerShell and legitimate administrative tooling, moves laterally with valid credentials and exfiltrates data through a permitted cloud service never presents antivirus with a file to judge. That pattern — living off the land — is now the dominant shape of serious intrusions, and it is precisely the gap that managed detection and response exists to close.
EDR vs Managed Detection and Response: Data Without Watchers
Endpoint detection and response records what happens on a device: processes, command lines, network connections, registry writes, parent-child relationships. It is a genuinely powerful data source, and it is the foundation almost every MDR service is built on.
What EDR records that antivirus never sees
EDR keeps a timeline. When an alert fires, you can walk backwards to the initial access, see which account was used, which binary spawned which child process and what it touched. That is the difference between “we deleted a file” and “we know how they got in and what they reached”. For device management and forensic purposes it is transformative.
The alert volume problem
A few hundred endpoints will generate a steady stream of detections, most of which are benign — a developer running an unusual script, an administrator using a remote tool, an installer behaving oddly. Someone has to decide which is which. Vendors quote suppression and auto-resolution rates, but the residue that needs human judgement is still measured in daily events, not weekly ones, and it does not arrive at convenient times.
Unmonitored EDR is an expensive flight recorder
This is the single most common failure mode in mid-market security. The licence is bought, the agent is deployed, the console is opened enthusiastically for a fortnight, and then it is opened again after an incident — where it faithfully reproduces the entire attack that nobody was watching. The data was perfect. The attention was absent. Buying managed detection and response on top of the same tooling changes nothing about the telemetry and everything about whether it is read.
SOC: A Team and a Process, Not a Product
A security operations centre is the in-house version of the same answer: your own analysts, watching your own tooling, on your own rota. Where it is viable it is excellent, because nobody understands your environment better than people who work in it.
What an in-house SOC actually requires
Analysts across three shifts, a tier-two escalation capability, a detection engineer to write and maintain content, a manager, a SIEM or data lake with the ingest licensing that implies, threat intelligence feeds, playbooks, and a quality process to stop alert fatigue quietly hollowing the whole thing out. It is a department, not a hire — which is precisely the comparison managed detection and response is asking you to make.
The 24/7 staffing arithmetic is the real barrier
Covering every hour of every week takes roughly 4.2 full-time equivalents for a single seat once you account for holidays, sickness, training and attrition. Two-person coverage means eight to nine analysts before you have hired anyone senior. In a market where experienced detection analysts are scarce and mobile, the recruitment problem is usually harder than the budget one — which is why the managed detection and response market exists in the shape it does.
Co-managed and hybrid models
The most common mature answer is not either/or. A small internal team owns business hours, context, tuning and the relationship with the business; a provider owns nights, weekends and surge capacity. That hybrid keeps institutional knowledge in-house while buying the coverage that is uneconomic to staff, and it is where most organisations with an existing incident response capability end up.
Managed Detection and Response vs EDR vs Antivirus vs SOC Compared
Laid side by side, the four stop looking like competitors and start looking like a stack with one obvious hole in the middle.
| Dimension | Antivirus / NGAV | EDR | In-house SOC | MDR |
|---|---|---|---|---|
| What it is | Software on the device | Telemetry platform | Your team plus tooling | Their team plus tooling |
| Primary job | Block known-bad files | Record and alert | Investigate and respond | Investigate and respond |
| Who watches it | Nobody — it is automatic | You, if anyone | Your analysts | Provider analysts |
| Out-of-hours cover | Automated only | None by default | Only if you staff it | Contracted 24/7 |
| Catches stolen credentials | No | Records it, may alert | Yes, if watched | Yes |
| Takes containment action | Automatic, file-level | Manual, by you | Yes | Yes, per contract |
| Ramp-up time | Days | Weeks | 9–18 months | 4–8 weeks |
| Cost shape | Low per seat | Moderate per seat | High fixed headcount | Moderate subscription |
| Fails when | No file is involved | Nobody reads the console | You cannot recruit | Scope or authority is too narrow |
Reading the table without buying all four
Antivirus and EDR are tooling decisions. SOC and managed detection and response are the same operational decision answered two different ways — build the watching capability or rent it. You need a tooling answer and an operational answer, not four separate purchases.
The layers stack, they do not compete
Nearly every serious posture ends up as antivirus enforcing at the device, EDR providing the telemetry, and either a SOC or a managed detection and response provider supplying the humans. The genuine either/or is only ever in that last column, and the coverage matrix below shows why the first three columns cannot cover for it.
| Attack behaviour | Antivirus alone | EDR unmonitored | EDR plus MDR |
|---|---|---|---|
| Known malware executable | Blocked | Blocked | Blocked |
| Phishing to credential theft | Missed | Logged, unread | Detected and contained |
| PowerShell living-off-the-land | Missed | Alerted, unread | Investigated |
| Lateral movement, valid accounts | Missed | Logged, unread | Detected |
| Ransomware staging at 02:00 | Partial | Alerted, unread | Contained in minutes |
| Cloud and identity abuse | Missed | Out of scope | Covered if in scope |
| Insider data staging | Missed | Logged, unread | Detected by behaviour |
What Managed Detection and Response Costs Against an In-House SOC
Price is where the decision usually resolves, and the comparison is only honest when the in-house column includes everything, not just salaries.
The in-house SOC line items nobody budgets
Two analysts do not equal coverage. A genuine round-the-clock rota needs eight or more, plus a SIEM licence priced on ingest volume that grows every time you onboard a new log source, plus intelligence feeds, plus the detection engineering time to keep content current. Then add recruitment cost, ramp time before the team is productive, and the replacement cycle when an analyst leaves for a specialist provider.
What MDR pricing actually looks like
Most providers price per endpoint, per user, or per ingested data volume, with a floor. Per-endpoint pricing is the easiest to forecast and the easiest to game — a low headline rate often excludes identity, email and cloud coverage, which is where a large share of real incidents now begin. Compare managed detection and response quotes on scope first and unit price second, or you will compare two different services.
| Cost line | In-house 24/7 SOC | MDR service |
|---|---|---|
| Analyst salaries and on-call | Eight or more FTE | Included in subscription |
| Detection platform | Licensed by you | Bundled or bring-your-own |
| SIEM ingest and retention | Grows with log volume | Usually capped in contract |
| Threat intelligence | Separate subscription | Included |
| Detection engineering | Dedicated headcount | Amortised across clients |
| Time to operational | Nine to eighteen months | Four to eight weeks |
| Key-person risk | High | Contractual |
Where the break-even sits
Below roughly 750 to 1,000 endpoints, managed detection and response is almost always cheaper than genuine round-the-clock in-house cover, and it is available in weeks rather than a year. Above that, and particularly in regulated or high-target sectors, a hybrid model starts to win on control and context even where it loses on headline price.
Response Speed: Where Managed Detection and Response Pulls Ahead
Coverage tables settle what each model can see. Speed settles what it is worth, because the damage curve in a modern intrusion is steep and most of it happens after the first alert and before the first human response.
Dwell time is the metric that matters
The interval between initial compromise and detection determines almost everything downstream: how many accounts are taken, whether backups are reached, whether exfiltration completes. Ransomware operators frequently move from access to encryption inside a single working day, and often overnight deliberately. Antivirus does not measure dwell time because it never sees the intrusion. Unmonitored EDR measures it retrospectively.
Why three in the morning is the whole argument
Attackers time destructive stages for when nobody is available. An alert raised at 02:14 and read at 09:00 is not detection, it is archaeology. This is the single strongest argument for managed detection and response over any model that quietly assumes someone will notice, and it is the reason out-of-hours cover deserves more scrutiny in the contract than the detection technology does.
Containment authority changes the arithmetic
Detection speed is worthless without a corresponding right to act. A provider who detects in four minutes but must reach a named contact before isolating a host inherits your response time, not theirs. Pre-authorised containment for a defined set of actions — isolate endpoint, disable account, block hash — turns minutes of detection into minutes of containment.
How to Choose Between Managed Detection and Response and the Alternatives
The right answer varies more with your staffing and obligations than with your industry. Four profiles cover most mid-market cases.
Under fifty staff with no security specialist
Buy antivirus and EDR through a managed provider and take a managed detection and response service on top. Building anything internal is not a budget question at this size, it is an availability question — you will not keep a security analyst busy or interested, and you certainly will not cover nights. Bundling it with existing managed IT services usually gives the cleanest accountability, because the same party owns both the estate and the detection.
Fifty to 250 staff with a lean IT team
This is the sweet spot for MDR. You have enough estate to be worth attacking, enough complexity to generate real alerts, and an IT function already fully occupied keeping the business running. Managed detection and response gives you the rota without the recruitment, and it lets your own people stay on infrastructure rather than triaging alerts they were not hired to interpret.
Two hundred and fifty staff and above with compliance obligations
Consider a hybrid. Keep a small internal capability for context, tuning, risk decisions and evidence, and contract the out-of-hours watch. Frameworks are broadly indifferent to who does the work provided it is documented and effective — the same logic that governs Cyber Essentials Plus vs ISO 27001 scoping decisions applies here.
Regulated, high-target or EU-facing organisations
Financial services, healthcare, critical suppliers and anyone inside the scope of NIS2 compliance face explicit expectations about detection, response and reporting timelines. Here the question is rarely whether to have a watch function, only how much of it is yours. Whichever route you take, the notification clocks are legal obligations rather than best practice, so verify that your managed detection and response contract can actually feed them.
| Profile | Sensible answer | Why |
|---|---|---|
| Under 50 staff, no specialist | NGAV plus EDR plus MDR | No viable internal rota at any budget |
| 50–250 staff, lean IT | MDR, identity and email in scope | Real alert volume, no spare capacity |
| 250+ with compliance load | Hybrid: internal days, MDR nights | Keeps context, buys coverage |
| Regulated or high-target | Hybrid with contractual reporting | Statutory notification clocks |
| 1,000+ endpoints, mature team | In-house SOC plus surge support | Break-even favours building |
What to Ask a Managed Detection and Response Provider Before Signing
Proposals in this market look alike. The differences live in scope, authority and evidence, and they surface only if you ask directly.
Scope questions
Which endpoints, servers, identity platforms, email tenants and cloud accounts are covered, and what is explicitly excluded? Is the price per endpoint, per user or per gigabyte ingested, and what happens when volume grows? Does coverage include your Microsoft 365 tenant, given how many intrusions now start there — the pattern set out in this business email compromise response plan is the common one.
Authority and response questions
Exactly which actions will you take without contacting us? What is the escalation path at 03:00 on a Sunday, and who holds the pager? What is your contractual time to acknowledge, to triage and to contain, and what happens commercially when you miss it? Ask for the last quarter’s actual figures against those targets, not the targets themselves.
Evidence and reporting questions
What do we receive after an incident, and in what form? Can we get the raw telemetry, or only your summary? Does the reporting satisfy an auditor, an insurer and a regulator? A managed detection and response provider that cannot produce a defensible incident record is selling reassurance rather than assurance.
Tooling, tuning and exit questions
Do you use our EDR licences or yours, and who owns the detection content built during the engagement? How is tuning handled, and who decides what gets suppressed? If we leave, what do we keep — historical data, detections, playbooks — and how long does transition take? Providers who bundle their own platform can be excellent, but they also make leaving harder, and that should be priced in rather than discovered later.
Mistakes That Waste a Managed Detection and Response Budget
Most disappointing engagements fail in one of a small number of ways, and all of them are decided before the contract is signed.
Buying MDR to compensate for missing basics
No detection service repairs unpatched internet-facing systems, absent multi-factor authentication, universal local administrator rights or untested backups. It will simply watch those weaknesses be exploited, faster and in more detail than before. Fix the hygiene first — a sound security baseline still outperforms an expensive watch function bolted onto a weak estate.
Withholding the authority to act
Signing a 24/7 service and then requiring an email approval before any containment converts the whole thing into a notification service at premium pricing. If the fear is business disruption, define a graded action list rather than removing authority entirely.
Leaving identity, email and cloud out of scope
Endpoint-only coverage is the cheapest quote and the most common regret. Credential attacks, token theft and mailbox rule abuse leave few endpoint traces, so an endpoint-only managed detection and response contract can run perfectly while an attacker works entirely inside your tenant.
Treating the monthly report as the outcome
The deliverable is reduced dwell time and contained incidents, not a slide deck. Review the service against response metrics and closed findings, and keep a live picture of your own exposure through routine threat intelligence and vulnerability work rather than waiting to be told.
Never testing the service
Run a purple-team exercise or a controlled simulation within the first quarter. Confirm the alert fires, the analyst calls, the escalation path works out of hours and the containment action lands. An untested managed detection and response service is an assumption with an invoice attached.
Managed Detection and Response: Frequently Asked Questions
Is MDR just outsourced EDR monitoring?
Partly, but the better services go well beyond watching one console. They correlate endpoint telemetry with identity, email and cloud signals, run proactive threat hunts, maintain their own detection content and take contracted containment action. A provider that only forwards EDR alerts with a covering note is selling monitoring, not managed detection and response.
Do we still need antivirus if we buy MDR?
Yes. Antivirus or NGAV is the enforcement layer that blocks commodity threats automatically and locally, without waiting for a human. Managed detection and response is the investigation and response layer above it, not a replacement for it. Removing the baseline to fund the service is a false economy, and most certification schemes expect malware protection regardless.
Can our IT provider deliver this, or do we need a specialist?
Many managed IT providers deliver strong MDR, either directly or through a specialist partner, and having one accountable party for the estate and the detection is a genuine advantage. What matters is the substance: a real 24/7 rota, defined containment authority and published response metrics — not whether the badge on the invoice says security.
How long does onboarding take?
Typically four to eight weeks for a mid-market estate: agent deployment, log source connection, baseline tuning to suppress normal behaviour, and agreement of the response playbook. Expect a noisy fortnight while the environment is learned. Any managed detection and response provider promising full value on day one has not tuned anything.
Will it reduce our cyber insurance premium?
It frequently helps. Insurers increasingly ask specifically about EDR deployment, out-of-hours monitoring and documented response capability, and a managed detection and response contract answers all three credibly, improving both terms and insurability. Treat premium reduction as a welcome side effect rather than the business case.
What happens if the provider misses an incident?
Read the liability and service credit terms carefully, because credits are usually capped at a fraction of monthly fees and no provider indemnifies you against breach losses. This is exactly why response metrics, testing and retained evidence matter — they let you judge performance continuously rather than argue about it afterwards.
References
NCSC — 10 Steps to Cyber Security
NCSC — Incident Management Guidance
NCSC — Cyber Essentials Overview
NCSC — Cyber Security Board Toolkit
NIST SP 800-61r2 — Computer Security Incident Handling Guide
NIST — Cybersecurity Framework
MITRE ATT&CK — Adversary Tactics and Techniques
CIS — Critical Security Controls