Manages the tooling
A managed security service provider runs your security products and keeps them healthy. Alerts are forwarded to you. Working out what they mean, and what to do, stays with your team.
What lands on your desk: an alert.
Most MDR ends with a notification and a recommendation. Ours ends with a verdict: what happened, how far it went, what was ruled out, and the evidence behind all of it. Average time to an L1 verdict is 3m 30s.
Every provider in this market detects. The difference is what happens in the hours after, and how much of it lands back on your desk.
Managed detection and response means somebody else runs the whole arc: watching the estate, working out what an alert actually means, deciding whether it matters, and doing something about it inside limits you set. If any of those steps comes back to you as homework, what you bought was monitoring with a better name.
It also means the detections themselves are somebody’s standing job rather than a deployment task. A rule tuned once at onboarding and never revisited is a rule quietly going out of date while the estate changes around it.
They are not the same thing, and the difference is not marketing. It is who does the work when something fires.
A managed security service provider runs your security products and keeps them healthy. Alerts are forwarded to you. Working out what they mean, and what to do, stays with your team.
What lands on your desk: an alert.
Managed detection and response takes the alert and finishes the job: investigates it, reaches a verdict, and responds inside the limits you set. The escalation that reaches you is a decision, not a task.
What lands on your desk: a verdict, with evidence.
A staffed security operations centre delivered as a service: the people, the procedures and the platform, rather than a capability bolted onto tooling you already own.
What lands on your desk: the same, plus the operation behind it.
We are the second and the third, and here they are the same operation. The distinction worth caring about is not the acronym on the contract, it is whether what reaches you is an alert or an answer.
An alert arriving here is not classified and filed. It is worked through a nine-stage investigation against a triage procedure our own analysts wrote, and it does not close until a completeness gate has audited it for evidence gaps.
The identities, devices and addresses in the alert are resolved to the real objects in your directory, and the Fusion agent asks early whether this might belong to something wider.
The steps the matched procedure calls for, run in parallel, each gathering evidence with its own scoped set of tools.
The completeness gate audits the work for gaps, generates the steps that would fill them, runs those and reassesses. It is a loop, not a checkpoint.
Policy and your own decision templates reach close or escalate. The report, the timeline, the closing statement and the notification follow.
The gap between something happening and you hearing about it is where trust in a security service is won or lost.
Not a hedge, and not a limitation. It is a deliberate split, and it is the same split at four in the morning as at four in the afternoon.
Autonomy is configurable per agent and per tenant. Where the line sits is your decision rather than a property of the product, and it is agreed before anything runs.
The specialisms underneath this pillar. All of them land in the same 24/7 operation, on the same platform, with the same people accountable.
A service where somebody else watches your estate, investigates what fires, reaches a verdict and responds inside limits you set. The test is what reaches you: an alert to work means you bought monitoring, a verdict with evidence means you bought detection and response.
An MSSP manages your security tooling and forwards you alerts; working out what they mean stays with your team. MDR finishes the job, so what reaches you is a decision rather than a task. The two are often sold under the same word.
Average time to an L1 verdict is 3m 30s and to an L2 verdict 7m 50s, both measured across our own SOC. Both clocks start when a signal reaches us, not when an analyst opens it or a ticket is assigned.
We act, inside limits agreed at onboarding. The Response Agent builds the containment plan, proposes each action, and holds anything high-impact for human approval. Every step declares the exact tools it may use, and every action is recorded with the reason it was allowed.
No. Microsoft Sentinel is the one thing we need you to have, because it is the correlation engine everything runs on. There is no second SIEM to license and no data duplicated elsewhere. For the rest of your estate we build the tooling to fit.
A senior analyst, by name. Every customer-facing decision is reviewed and approved by one before it reaches you, and that is the default on the managed service rather than an upgrade. The full reasoning behind any verdict is on the record.
An hour with a SOC analyst: we run it end to end, show the evidence behind the verdict, and set the autonomy dial where you would set it. Your scenarios, not a canned demo.