Detection & response

What is Managed detection and response (MDR)?

Definition

A service where an external team of security analysts monitors your environment 24/7, investigates alerts and takes action to contain threats, using your security tools or their own.

How it works

MDR grew out of the gap between buying security tools and having people to watch them. Endpoint, identity, email and cloud tools generate alerts around the clock, but most organisations cannot staff a team to triage them at 3am.

An MDR provider connects to those tools, filters out noise, investigates what is real and acts within limits you agree in advance, such as isolating a device or disabling an account. The difference from a traditional managed security service is response: MDR is expected to contain threats, not just forward alerts.

Key points

  • 24/7 monitoring by human analysts, not just automated rules
  • Investigation that confirms whether an alert is a real threat
  • Containment actions taken within pre-agreed authority
  • Reporting and guidance so the root cause gets fixed

Common questions

Is MDR the same as an MSSP?

Not quite. A traditional MSSP often manages devices and forwards alerts. MDR focuses on detecting, investigating and responding to threats.

Do I need to replace my tools for MDR?

It depends on the provider. Some require their own agent; others, like Touchpoint, work with tools you already own.

Talk to someone who does this every day

Questions about MDR? Our team will give you a straight answer.

Contact us