GlossarySOC and monitoring

MDR

Short answer

MDR (Managed Detection and Response) is a service in which an external security team monitors an organisation's systems, investigates alerts and responds to threats on its behalf, using detection tools such as EDR or XDR.

What an MDR service includes

An MDR provider deploys or operates detection technology, usually EDR or XDR, reviews the alerts it generates, investigates suspicious activity, hunts for threats that tools did not flag, and takes response actions such as isolating a device or disabling an account. The customer receives reports and is contacted when a decision is needed.

MDR vs EDR

EDR is the technology. MDR is the service of people who watch and act on what that technology detects. Buying an EDR without anyone reviewing its alerts leaves most of its value unused.

MDR vs SOC

An MDR is a type of outsourced SOC focused on detection and response. A broader SOC service may also cover log management with a SIEM, vulnerability monitoring and compliance reporting.

What to check with a provider

Coverage hours, which response actions the provider can take without asking, response times, and how incidents are escalated and reported.

Related terms

Keep reading on this topic

Continuous monitoring and response: EDR, SIEM, 24/7 SOC operations, detection engineering and incident handling.

Go to the topic hub