Managed detection and response is a service, not a product. It is a team of analysts watching your estate around the clock, usually using detection tooling you already own or licence through them, with a mandate to act at three in the morning without waiting for you to wake up. That single distinction explains why this market confuses buyers so badly: MDR sits on the same quote as antivirus, EDR and SOC-as-a-service as though all four were interchangeable line items, when three of them are things and one of them is people.

The confusion has a price. Organisations routinely pay for endpoint tooling that nobody reads, or budget for an in-house security operations centre they cannot staff, while the actual gap — someone competent looking at the alerts out of hours — stays open. Successive editions of the UK Government’s Cyber Security Breaches Survey have found that only a minority of businesses have any formal incident response plan, and the Verizon Data Breach Investigations Report continues to show intrusions that ran for days before anyone noticed. Neither statistic is a tooling problem. Both are an attention problem, which is the specific thing cybersecurity services are meant to solve.

This guide separates the four properly. It covers what an MDR contract actually includes beyond the licence, what antivirus still stops and where it goes blind, why unmonitored EDR behaves like a flight recorder, what a 24/7 SOC really costs to staff, and how the four compare on coverage, price, speed and response authority. It then gets practical: how to choose by company size and sector, what to ask a provider before signing, and which mistakes reliably waste the budget. It is written to sit alongside an existing IT security programme rather than replace it.

What Managed Detection and Response Actually Buys You

managed detection and response vs edr antivirus soc b stacked translucent hex plates

Strip away the marketing and managed detection and response is three things bundled together: a detection platform, a staffed rota that watches it, and a contractual right to intervene on your systems. Remove any one of those and you have bought something else.

The three components that define an MDR contract

The platform is usually EDR or XDR, sometimes with a SIEM behind it, and it is frequently the same product you could licence directly. The rota is the expensive part — analysts covering nights, weekends and bank holidays, with escalation paths and named responsibilities. The mandate is the part buyers most often negotiate away and most often regret: without pre-agreed authority to isolate a host or disable an account, your provider becomes a very well-informed telephone service.

Detection engineering is the component nobody sells

Every serious managed detection and response provider maintains its own detection content — rules, behavioural analytics and hunting queries that sit on top of whatever the vendor ships by default. That content is tuned against what they see across their whole client base, which is the genuine economy of scale in the model. A single mid-market business will never write, test and retire detections at that rate, and the out-of-the-box ruleset alone is not where the value is.

What “response” means, and what it does not

Response in most contracts means containment: isolating an endpoint from the network, killing a process, suspending an account, blocking a hash. It rarely means full forensic investigation, legal notification, rebuilding servers or negotiating with an extortion group. Read the definition in the contract rather than the one on the website, because the gap between “we respond” and “we contain and hand over” is where the 4am argument happens. A managed detection and response engagement should say plainly which actions the provider takes unilaterally, which need your sign-off, and how long they will wait for it.

Antivirus: The Layer You Still Need and Should Stop Overrating

managed detection and response vs edr antivirus soc c upright magnifying lens over cubes

Antivirus — or next-generation antivirus, as most of it now is — remains a sensible baseline control. It is also the layer buyers most often mistake for a complete security posture.

How signature and heuristic detection works

Classic antivirus matches files against known-bad signatures. Modern engines add heuristics, machine learning classifiers and behavioural blocking, which materially improved the hit rate against novel malware. Enforcement happens locally on the device, decisions are made in milliseconds, and nobody has to be awake for it to work. That autonomy is exactly why it scales cheaply to every laptop you own.

What antivirus genuinely stops

Commodity malware, drive-by downloads, malicious attachments, opportunistic ransomware droppers and the long tail of automated attacks. That is not a trivial list — it is most of the volume most organisations face, and running without it is indefensible. Cyber Essentials treats malware protection as one of its five technical controls precisely because the baseline still works. Nobody buying managed detection and response should be removing it.

Where antivirus goes blind

It struggles badly with anything that is not a malicious file. An attacker who signs in with a stolen password, uses PowerShell and legitimate administrative tooling, moves laterally with valid credentials and exfiltrates data through a permitted cloud service never presents antivirus with a file to judge. That pattern — living off the land — is now the dominant shape of serious intrusions, and it is precisely the gap that managed detection and response exists to close.

EDR vs Managed Detection and Response: Data Without Watchers

managed detection and response vs edr antivirus soc d watchtower cylinder glowing ring

Endpoint detection and response records what happens on a device: processes, command lines, network connections, registry writes, parent-child relationships. It is a genuinely powerful data source, and it is the foundation almost every MDR service is built on.

What EDR records that antivirus never sees

EDR keeps a timeline. When an alert fires, you can walk backwards to the initial access, see which account was used, which binary spawned which child process and what it touched. That is the difference between “we deleted a file” and “we know how they got in and what they reached”. For device management and forensic purposes it is transformative.

The alert volume problem

A few hundred endpoints will generate a steady stream of detections, most of which are benign — a developer running an unusual script, an administrator using a remote tool, an installer behaving oddly. Someone has to decide which is which. Vendors quote suppression and auto-resolution rates, but the residue that needs human judgement is still measured in daily events, not weekly ones, and it does not arrive at convenient times.

Unmonitored EDR is an expensive flight recorder

This is the single most common failure mode in mid-market security. The licence is bought, the agent is deployed, the console is opened enthusiastically for a fortnight, and then it is opened again after an incident — where it faithfully reproduces the entire attack that nobody was watching. The data was perfect. The attention was absent. Buying managed detection and response on top of the same tooling changes nothing about the telemetry and everything about whether it is read.

SOC: A Team and a Process, Not a Product

managed detection and response vs edr antivirus soc e five blank blocks rising row

A security operations centre is the in-house version of the same answer: your own analysts, watching your own tooling, on your own rota. Where it is viable it is excellent, because nobody understands your environment better than people who work in it.

What an in-house SOC actually requires

Analysts across three shifts, a tier-two escalation capability, a detection engineer to write and maintain content, a manager, a SIEM or data lake with the ingest licensing that implies, threat intelligence feeds, playbooks, and a quality process to stop alert fatigue quietly hollowing the whole thing out. It is a department, not a hire — which is precisely the comparison managed detection and response is asking you to make.

The 24/7 staffing arithmetic is the real barrier

Covering every hour of every week takes roughly 4.2 full-time equivalents for a single seat once you account for holidays, sickness, training and attrition. Two-person coverage means eight to nine analysts before you have hired anyone senior. In a market where experienced detection analysts are scarce and mobile, the recruitment problem is usually harder than the budget one — which is why the managed detection and response market exists in the shape it does.

Co-managed and hybrid models

The most common mature answer is not either/or. A small internal team owns business hours, context, tuning and the relationship with the business; a provider owns nights, weekends and surge capacity. That hybrid keeps institutional knowledge in-house while buying the coverage that is uneconomic to staff, and it is where most organisations with an existing incident response capability end up.

Managed Detection and Response vs EDR vs Antivirus vs SOC Compared

managed detection and response vs edr antivirus soc f single hourglass on plinth

Laid side by side, the four stop looking like competitors and start looking like a stack with one obvious hole in the middle.

DimensionAntivirus / NGAVEDRIn-house SOCMDR
What it isSoftware on the deviceTelemetry platformYour team plus toolingTheir team plus tooling
Primary jobBlock known-bad filesRecord and alertInvestigate and respondInvestigate and respond
Who watches itNobody — it is automaticYou, if anyoneYour analystsProvider analysts
Out-of-hours coverAutomated onlyNone by defaultOnly if you staff itContracted 24/7
Catches stolen credentialsNoRecords it, may alertYes, if watchedYes
Takes containment actionAutomatic, file-levelManual, by youYesYes, per contract
Ramp-up timeDaysWeeks9–18 months4–8 weeks
Cost shapeLow per seatModerate per seatHigh fixed headcountModerate subscription
Fails whenNo file is involvedNobody reads the consoleYou cannot recruitScope or authority is too narrow

Reading the table without buying all four

Antivirus and EDR are tooling decisions. SOC and managed detection and response are the same operational decision answered two different ways — build the watching capability or rent it. You need a tooling answer and an operational answer, not four separate purchases.

The layers stack, they do not compete

Nearly every serious posture ends up as antivirus enforcing at the device, EDR providing the telemetry, and either a SOC or a managed detection and response provider supplying the humans. The genuine either/or is only ever in that last column, and the coverage matrix below shows why the first three columns cannot cover for it.

Attack behaviourAntivirus aloneEDR unmonitoredEDR plus MDR
Known malware executableBlockedBlockedBlocked
Phishing to credential theftMissedLogged, unreadDetected and contained
PowerShell living-off-the-landMissedAlerted, unreadInvestigated
Lateral movement, valid accountsMissedLogged, unreadDetected
Ransomware staging at 02:00PartialAlerted, unreadContained in minutes
Cloud and identity abuseMissedOut of scopeCovered if in scope
Insider data stagingMissedLogged, unreadDetected by behaviour

What Managed Detection and Response Costs Against an In-House SOC

Price is where the decision usually resolves, and the comparison is only honest when the in-house column includes everything, not just salaries.

The in-house SOC line items nobody budgets

Two analysts do not equal coverage. A genuine round-the-clock rota needs eight or more, plus a SIEM licence priced on ingest volume that grows every time you onboard a new log source, plus intelligence feeds, plus the detection engineering time to keep content current. Then add recruitment cost, ramp time before the team is productive, and the replacement cycle when an analyst leaves for a specialist provider.

Illustrative annual cost, 250-endpoint UK business (modelled, not quoted)
In-house 24/7 SOC, eight analysts plus SIEM £420k
Co-managed: two analysts plus out-of-hours service £180k
Full MDR service including platform £75k
EDR licences only, nobody watching £22k

What MDR pricing actually looks like

Most providers price per endpoint, per user, or per ingested data volume, with a floor. Per-endpoint pricing is the easiest to forecast and the easiest to game — a low headline rate often excludes identity, email and cloud coverage, which is where a large share of real incidents now begin. Compare managed detection and response quotes on scope first and unit price second, or you will compare two different services.

Cost lineIn-house 24/7 SOCMDR service
Analyst salaries and on-callEight or more FTEIncluded in subscription
Detection platformLicensed by youBundled or bring-your-own
SIEM ingest and retentionGrows with log volumeUsually capped in contract
Threat intelligenceSeparate subscriptionIncluded
Detection engineeringDedicated headcountAmortised across clients
Time to operationalNine to eighteen monthsFour to eight weeks
Key-person riskHighContractual

Where the break-even sits

Below roughly 750 to 1,000 endpoints, managed detection and response is almost always cheaper than genuine round-the-clock in-house cover, and it is available in weeks rather than a year. Above that, and particularly in regulated or high-target sectors, a hybrid model starts to win on control and context even where it loses on headline price.

Response Speed: Where Managed Detection and Response Pulls Ahead

Coverage tables settle what each model can see. Speed settles what it is worth, because the damage curve in a modern intrusion is steep and most of it happens after the first alert and before the first human response.

Dwell time is the metric that matters

The interval between initial compromise and detection determines almost everything downstream: how many accounts are taken, whether backups are reached, whether exfiltration completes. Ransomware operators frequently move from access to encryption inside a single working day, and often overnight deliberately. Antivirus does not measure dwell time because it never sees the intrusion. Unmonitored EDR measures it retrospectively.

Illustrative median time from intrusion to detection (modelled)
Antivirus only 21 days
EDR reviewed in business hours 9 days
In-house SOC, business hours only 4 days
24/7 managed detection and response under 1 day

Why three in the morning is the whole argument

Attackers time destructive stages for when nobody is available. An alert raised at 02:14 and read at 09:00 is not detection, it is archaeology. This is the single strongest argument for managed detection and response over any model that quietly assumes someone will notice, and it is the reason out-of-hours cover deserves more scrutiny in the contract than the detection technology does.

Containment authority changes the arithmetic

Detection speed is worthless without a corresponding right to act. A provider who detects in four minutes but must reach a named contact before isolating a host inherits your response time, not theirs. Pre-authorised containment for a defined set of actions — isolate endpoint, disable account, block hash — turns minutes of detection into minutes of containment.

Illustrative share of endpoint alerts receiving human triage (modelled)
EDR, no monitoring service 8%
Internal IT team, business hours 34%
In-house SOC 71%
MDR provider 96%

How to Choose Between Managed Detection and Response and the Alternatives

The right answer varies more with your staffing and obligations than with your industry. Four profiles cover most mid-market cases.

Under fifty staff with no security specialist

Buy antivirus and EDR through a managed provider and take a managed detection and response service on top. Building anything internal is not a budget question at this size, it is an availability question — you will not keep a security analyst busy or interested, and you certainly will not cover nights. Bundling it with existing managed IT services usually gives the cleanest accountability, because the same party owns both the estate and the detection.

Fifty to 250 staff with a lean IT team

This is the sweet spot for MDR. You have enough estate to be worth attacking, enough complexity to generate real alerts, and an IT function already fully occupied keeping the business running. Managed detection and response gives you the rota without the recruitment, and it lets your own people stay on infrastructure rather than triaging alerts they were not hired to interpret.

Two hundred and fifty staff and above with compliance obligations

Consider a hybrid. Keep a small internal capability for context, tuning, risk decisions and evidence, and contract the out-of-hours watch. Frameworks are broadly indifferent to who does the work provided it is documented and effective — the same logic that governs Cyber Essentials Plus vs ISO 27001 scoping decisions applies here.

Regulated, high-target or EU-facing organisations

Financial services, healthcare, critical suppliers and anyone inside the scope of NIS2 compliance face explicit expectations about detection, response and reporting timelines. Here the question is rarely whether to have a watch function, only how much of it is yours. Whichever route you take, the notification clocks are legal obligations rather than best practice, so verify that your managed detection and response contract can actually feed them.

ProfileSensible answerWhy
Under 50 staff, no specialistNGAV plus EDR plus MDRNo viable internal rota at any budget
50–250 staff, lean ITMDR, identity and email in scopeReal alert volume, no spare capacity
250+ with compliance loadHybrid: internal days, MDR nightsKeeps context, buys coverage
Regulated or high-targetHybrid with contractual reportingStatutory notification clocks
1,000+ endpoints, mature teamIn-house SOC plus surge supportBreak-even favours building

What to Ask a Managed Detection and Response Provider Before Signing

Proposals in this market look alike. The differences live in scope, authority and evidence, and they surface only if you ask directly.

Scope questions

Which endpoints, servers, identity platforms, email tenants and cloud accounts are covered, and what is explicitly excluded? Is the price per endpoint, per user or per gigabyte ingested, and what happens when volume grows? Does coverage include your Microsoft 365 tenant, given how many intrusions now start there — the pattern set out in this business email compromise response plan is the common one.

Authority and response questions

Exactly which actions will you take without contacting us? What is the escalation path at 03:00 on a Sunday, and who holds the pager? What is your contractual time to acknowledge, to triage and to contain, and what happens commercially when you miss it? Ask for the last quarter’s actual figures against those targets, not the targets themselves.

Evidence and reporting questions

What do we receive after an incident, and in what form? Can we get the raw telemetry, or only your summary? Does the reporting satisfy an auditor, an insurer and a regulator? A managed detection and response provider that cannot produce a defensible incident record is selling reassurance rather than assurance.

Tooling, tuning and exit questions

Do you use our EDR licences or yours, and who owns the detection content built during the engagement? How is tuning handled, and who decides what gets suppressed? If we leave, what do we keep — historical data, detections, playbooks — and how long does transition take? Providers who bundle their own platform can be excellent, but they also make leaving harder, and that should be priced in rather than discovered later.

Mistakes That Waste a Managed Detection and Response Budget

Most disappointing engagements fail in one of a small number of ways, and all of them are decided before the contract is signed.

Buying MDR to compensate for missing basics

No detection service repairs unpatched internet-facing systems, absent multi-factor authentication, universal local administrator rights or untested backups. It will simply watch those weaknesses be exploited, faster and in more detail than before. Fix the hygiene first — a sound security baseline still outperforms an expensive watch function bolted onto a weak estate.

Withholding the authority to act

Signing a 24/7 service and then requiring an email approval before any containment converts the whole thing into a notification service at premium pricing. If the fear is business disruption, define a graded action list rather than removing authority entirely.

Leaving identity, email and cloud out of scope

Endpoint-only coverage is the cheapest quote and the most common regret. Credential attacks, token theft and mailbox rule abuse leave few endpoint traces, so an endpoint-only managed detection and response contract can run perfectly while an attacker works entirely inside your tenant.

Treating the monthly report as the outcome

The deliverable is reduced dwell time and contained incidents, not a slide deck. Review the service against response metrics and closed findings, and keep a live picture of your own exposure through routine threat intelligence and vulnerability work rather than waiting to be told.

Never testing the service

Run a purple-team exercise or a controlled simulation within the first quarter. Confirm the alert fires, the analyst calls, the escalation path works out of hours and the containment action lands. An untested managed detection and response service is an assumption with an invoice attached.

Managed Detection and Response: Frequently Asked Questions

Is MDR just outsourced EDR monitoring?

Partly, but the better services go well beyond watching one console. They correlate endpoint telemetry with identity, email and cloud signals, run proactive threat hunts, maintain their own detection content and take contracted containment action. A provider that only forwards EDR alerts with a covering note is selling monitoring, not managed detection and response.

Do we still need antivirus if we buy MDR?

Yes. Antivirus or NGAV is the enforcement layer that blocks commodity threats automatically and locally, without waiting for a human. Managed detection and response is the investigation and response layer above it, not a replacement for it. Removing the baseline to fund the service is a false economy, and most certification schemes expect malware protection regardless.

Can our IT provider deliver this, or do we need a specialist?

Many managed IT providers deliver strong MDR, either directly or through a specialist partner, and having one accountable party for the estate and the detection is a genuine advantage. What matters is the substance: a real 24/7 rota, defined containment authority and published response metrics — not whether the badge on the invoice says security.

How long does onboarding take?

Typically four to eight weeks for a mid-market estate: agent deployment, log source connection, baseline tuning to suppress normal behaviour, and agreement of the response playbook. Expect a noisy fortnight while the environment is learned. Any managed detection and response provider promising full value on day one has not tuned anything.

Will it reduce our cyber insurance premium?

It frequently helps. Insurers increasingly ask specifically about EDR deployment, out-of-hours monitoring and documented response capability, and a managed detection and response contract answers all three credibly, improving both terms and insurability. Treat premium reduction as a welcome side effect rather than the business case.

What happens if the provider misses an incident?

Read the liability and service credit terms carefully, because credits are usually capped at a fraction of monthly fees and no provider indemnifies you against breach losses. This is exactly why response metrics, testing and retained evidence matter — they let you judge performance continuously rather than argue about it afterwards.

References