Managed Detection & Response (MDR/XDR)
Continuous monitoring, alert triage and response across endpoints, identity and cloud.
Detection tooling only works if someone is watching it and knows what to do. Our managed detection and response service monitors your endpoints, identities, email and cloud around the clock, triages alerts with analysts and responds to real threats under agreed playbooks.
The service is built on Microsoft Sentinel and Defender for organisations on that stack, and on equivalent platforms for others. You keep the data and the tooling. We provide the eyes and the hands.
- Tooling and data stay in your tenant, so you can change provider without losing history.
- Playbooks are agreed in advance, so response happens in minutes rather than after a phone call.
- The team that tests systems also tunes detection, so rules reflect how attacks actually look.
- A bank, insurer or airline with detection tooling in place and no one watching it overnight.
- A group standardising on Microsoft Sentinel and Defender across subsidiaries.
- An organisation whose insurer or regulator now expects continuous monitoring.
- Alerts pile up and the team triages them when it has time.
- A recent incident was discovered days after it started.
- Nobody is authorised to isolate a host at three in the morning.
- The security operations centre contract has ended or is under review.
What is included.
- 01
Onboarding
Log sources connected, detection rules tuned and playbooks agreed for your environment.
- 02
Continuous monitoring
Alerts triaged by analysts with escalation according to severity and time of day.
- 03
Response
Containment actions such as isolating hosts, disabling accounts and blocking indicators, within agreed authority.
- 04
Threat hunting
Regular hunts for activity that rules miss, informed by current threat intelligence.
- 05
Reporting
Monthly threat report with incidents, trends and tuning changes.
Four steps, no surprises.
- 01
Onboard
Connect sources, tune rules, agree playbooks and authority.
- 02
Monitor
Analyst triage and escalation across all hours.
- 03
Respond
Containment and investigation under agreed playbooks.
- 04
Improve
Monthly tuning, hunting and reporting.
From first meeting to steady state.
- 01Weeks 1 to 6
Onboard
Log sources connected, detection rules tuned, playbooks and authority matrix agreed.
- 02Ongoing
Monitor and respond
Analyst triage and escalation across all hours with containment under agreed playbooks.
- 03Monthly
Improve
Tuning, threat hunting, a threat report and a quarterly detection coverage review.
- Time from alert to triage and from confirmed incident to containment.
- Share of alerts closed as noise after tuning.
- Incidents detected by monitoring rather than reported by staff or third parties.
- Detection coverage against the techniques relevant to your sector.
- SOC analysts
- Detection engineer
- Incident responder
- Service delivery manager
- Onboarded detection platform.
- Response playbooks and authority matrix.
- Continuous monitoring and escalation.
- Monthly threat report.
- Quarterly detection coverage review.
MDR runs as a monthly retainer sized by users and endpoints, with a twelve-month initial term. Onboarding is a fixed-scope project of three to six weeks depending on log sources. Licensing for the detection platform stays in your name.
Incident Response Readiness & Retainer
An incident response plan, rehearsed with tabletop exercises, and an on-call retainer for when it happens.
IT ConsultingManaged IT & Support
Proactive monitoring, help desk and infrastructure management under a service level you can hold us to.
CybersecurityAttack Surface & Vulnerability Management
Continuous discovery and scanning of exposed assets with fixes prioritised by real risk.
Managed Detection & Response (MDR/XDR), in plain terms.
No. It is our default for Microsoft-centric organisations because it fits their licensing. We also operate on other platforms where that suits you better.
Whatever the authority matrix allows. Most organisations pre-approve isolating an endpoint and disabling a compromised account, with anything larger escalated to a named contact.
MDR handles detection and first response. A major incident moves to our incident response team under the retainer, with full continuity because the same people are involved.
Tuning during onboarding, continuous rule refinement and analyst triage. Your team sees confirmed incidents, not raw alerts.