Report an Incident Become a Partner Careers Contact
Book a Demo
The practice · detection & response

Managed detection and response,
with the investigation already done.

Most MDR ends with a notification and a recommendation. Ours ends with a verdict: what happened, how far it went, what was ruled out, and the evidence behind all of it. Average time to an L1 verdict is 3m 30s.

Alert → verdict24x7x365
INSignal from your Microsoft estateclock starts
L1Triaged, enriched, deduplicated3m 30s
L2Investigated, scope established7m 50s
GATEAudited for evidence gapsreassessed
RESPContainment inside your limitson approval
L3Senior analyst signs the verdictdefault
What MDR actually covers

Detection is the easy half.
Response is what you are buying.

Every provider in this market detects. The difference is what happens in the hours after, and how much of it lands back on your desk.

Managed detection and response means somebody else runs the whole arc: watching the estate, working out what an alert actually means, deciding whether it matters, and doing something about it inside limits you set. If any of those steps comes back to you as homework, what you bought was monitoring with a better name.

It also means the detections themselves are somebody’s standing job rather than a deployment task. A rule tuned once at onboarding and never revisited is a rule quietly going out of date while the estate changes around it.

  • Monitoring across the Microsoft estate you already run, without a second SIEM to license.
  • Investigation on every alert, not on the ones somebody had time for.
  • A verdict with the evidence attached, and a senior analyst accountable for it.
  • Containment planned and executed inside limits you agreed at onboarding.
  • Detection content reviewed, backtested and tuned as a standing job.
MDR, MSSP and SOC as a service

Three terms
the market uses interchangeably.

They are not the same thing, and the difference is not marketing. It is who does the work when something fires.

MSSP

Manages the tooling

A managed security service provider runs your security products and keeps them healthy. Alerts are forwarded to you. Working out what they mean, and what to do, stays with your team.

What lands on your desk: an alert.

MDR

Owns the outcome

Managed detection and response takes the alert and finishes the job: investigates it, reaches a verdict, and responds inside the limits you set. The escalation that reaches you is a decision, not a task.

What lands on your desk: a verdict, with evidence.

SOC as a service

The whole operation

A staffed security operations centre delivered as a service: the people, the procedures and the platform, rather than a capability bolted onto tooling you already own.

What lands on your desk: the same, plus the operation behind it.

We are the second and the third, and here they are the same operation. The distinction worth caring about is not the acronym on the contract, it is whether what reaches you is an alert or an answer.

How our SOC handles an alert

Signal in.
Signed-off verdict out.

An alert arriving here is not classified and filed. It is worked through a nine-stage investigation against a triage procedure our own analysts wrote, and it does not close until a completeness gate has audited it for evidence gaps.

  1. 01

    Establish what we are looking at

    The identities, devices and addresses in the alert are resolved to the real objects in your directory, and the Fusion agent asks early whether this might belong to something wider.

  2. 02

    Investigate it properly

    The steps the matched procedure calls for, run in parallel, each gathering evidence with its own scoped set of tools.

  3. 03

    Refuse to accept it too early

    The completeness gate audits the work for gaps, generates the steps that would fill them, runs those and reassesses. It is a loop, not a checkpoint.

  4. 04

    Decide, then hand it over

    Policy and your own decision templates reach close or escalate. The report, the timeline, the closing statement and the notification follow.

See the nine stages, named

What you see, and when

Live, not
a monthly PDF.

The gap between something happening and you hearing about it is where trust in a security service is won or lost.

As it happens
Your incidents, verdicts and service performance are live in the portal. Not a report assembled at month end from a queue nobody watched.
When it escalates
A notification from the SOC mailbox, routed to the right people for you and for that incident type, with every send recorded against the investigation.
On every incident
A full investigation report with the evidence attached, an escalation write-up where it escalated, a closing statement in plain English, and a draft notification for your stakeholders.
Month on month
Detection coverage and your Threat Attack Profile sharpen as the landscape shifts, and the service review says what changed rather than restating the SLA.
Where the AI works, and where a person does

The agents do the volume.
People own the consequence.

Not a hedge, and not a limitation. It is a deliberate split, and it is the same split at four in the morning as at four in the afternoon.

Carried by the agents

  • Triage, enrichment and deduplication on every alert as it lands
  • Investigation to a verdict, with the timeline and blast radius
  • Correlation across incidents, alerts and entities
  • Threat hunting on a schedule and in response to new intelligence
  • Detection engineering, backtested before anything is deployed
  • The report, the closing statement and the draft notification

Held by people

  • Sign-off on every customer-facing decision, by default
  • L3, and anything policy cannot settle
  • Approval of high-impact response actions
  • Human-led incident response
  • Where the autonomy dial is set, agreed with you
  • The relationship, by name, with a defined escalation path

Autonomy is configurable per agent and per tenant. Where the line sits is your decision rather than a property of the product, and it is agreed before anything runs.

Everything in this practice

The rest of
detection and response.

The specialisms underneath this pillar. All of them land in the same 24/7 operation, on the same platform, with the same people accountable.

Questions

Detection and response, answered.

What is managed detection and response?

A service where somebody else watches your estate, investigates what fires, reaches a verdict and responds inside limits you set. The test is what reaches you: an alert to work means you bought monitoring, a verdict with evidence means you bought detection and response.

How is MDR different from an MSSP?

An MSSP manages your security tooling and forwards you alerts; working out what they mean stays with your team. MDR finishes the job, so what reaches you is a decision rather than a task. The two are often sold under the same word.

How quickly do you reach a verdict?

Average time to an L1 verdict is 3m 30s and to an L2 verdict 7m 50s, both measured across our own SOC. Both clocks start when a signal reaches us, not when an analyst opens it or a ticket is assigned.

Will you take action, or just tell us?

We act, inside limits agreed at onboarding. The Response Agent builds the containment plan, proposes each action, and holds anything high-impact for human approval. Every step declares the exact tools it may use, and every action is recorded with the reason it was allowed.

Do we need to replace our SIEM?

No. Microsoft Sentinel is the one thing we need you to have, because it is the correlation engine everything runs on. There is no second SIEM to license and no data duplicated elsewhere. For the rest of your estate we build the tooling to fit.

Who is accountable for a wrong call?

A senior analyst, by name. Every customer-facing decision is reviewed and approved by one before it reaches you, and that is the default on the managed service rather than an upgrade. The full reasoning behind any verdict is on the record.

See it on your own alerts

Bring us an alert type
that wastes your week.

An hour with a SOC analyst: we run it end to end, show the evidence behind the verdict, and set the autonomy dial where you would set it. Your scenarios, not a canned demo.