KNOWLEDGE — FUNDAMENTALS

MDR — Managed Detection and Response

MDR describes a service model in which an external provider supplies not only detection technology but also its operation: alerts are reviewed by the provider's analysts, assessed and passed to the customer.

In some arrangements this is combined with authority to intervene directly. MDR is therefore an operating model rather than a technology.

The distinction is between a tool and a service. A detection system shows what is happening. An MDR provider looks at it on the customer's behalf, decides what matters and gets in touch when something needs doing. Organisations without a security team, and without the intention of building one, are buying that work.

A SOC is the organisational unit that performs this work, whether run internally or externally. MDR is the purchased version of it, usually with contractual response times. NDR, SIEM and EDR are the tooling such a service runs on. An MDR offering may use the same technology as an organisation running it in-house; the difference is who holds responsibility.

MDR makes sense where continuous coverage is required and cannot be staffed internally. Worth noting: the provider needs access to security-relevant data to do this, frequently within their own environment. Organisations with requirements about where processing happens should establish this early.

AEGYS is not an MDR provider. The products deliver visibility into the network and into exploitability, with correlation and priority attached. Ongoing operation is handled by partners working on the same platform. The separation is deliberate: AEGYS does not run a SOC and takes on no on-call obligation.

On how tooling and operation can sensibly be divided:

Reviewing network data