Skip to content
UnifiedONE — Community Protection Intelligence
Threat Intelligence

What Is MDR, and When Does a Business Need It?

MDR is human-led, round-the-clock detection and response delivered as a service. What it covers, how it differs from EDR, MSSP and SOC as a service, and the seven triggers that mean your business now needs it.

Sher Khatak22 min read
Share
Ring of 24 hour segments with the late night band highlighted in gold, showing the hours when most ransomware is deployed and detection coverage is thinnest

Published 21 August 2026. Figures are drawn from the 2026 Sophos Active Adversary Report, the 2026 Verizon Data Breach Investigations Report, IBM’s Cost of a Data Breach Report 2026, the 2025 ISC2 Cybersecurity Workforce Study and Gartner’s Market Guide for Managed Detection and Response Services.

Most security tools work perfectly at three in the morning. The problem is that nobody is reading them.

Sophos analysed 661 incident response and managed detection cases handled between November 2024 and October 2025, across 70 countries and 34 industries. In that dataset, 88.10% of ransomware was deployed outside the victim’s normal working hours. The four busiest hours for attacks of every kind were 23:00 to 03:00 in the target’s local time, accounting for 37.1% of them, and the four quietest all fell between 06:00 and noon. Attackers are not keeping unsociable hours by accident. They are working the hours when your response is slowest.

That finding is the clearest argument for managed detection and response, and it is also the sharpest test of whether your organisation needs it. This guide covers what MDR is, what separates it from the products and services it gets confused with, and the specific conditions under which buying it is the right decision. It also covers the conditions under which it is not.

Short answer: MDR is an outsourced service that watches your security telemetry around the clock, investigates what matters, and takes action to contain a threat rather than simply emailing you about it. A business needs it once it owns detection tooling nobody monitors outside office hours, once an incident would have to be handled by people who already have other full-time jobs, or once an insurer, regulator or customer starts asking for evidence of continuous monitoring.

What is MDR?

MDR stands for managed detection and response: a service in which an external team monitors your environment continuously, investigates suspicious activity, and either contains the threat directly or directs your team through containment. Gartner, in its Market Guide for Managed Detection and Response Services (Pete Shoard, Andrew Davies and Angel Berrios, 1 October 2025), frames it as remotely delivered, human-led, turnkey security operations functions whose end product is disruption and containment rather than notification.

Four properties do the defining work. Strip any one out and what remains is something else wearing the label.

  1. Human-led. Analysts engage with your data every day. Gartner is explicit that automation-first and AI-branded offerings are not the same service, however capable the tooling.
  2. Continuous. Cover is genuinely around the clock, including the hours in which most ransomware is actually deployed.
  3. Turnkey. The provider brings the detection content, the tuning and the process. You are not being sold a platform to operate yourself.
  4. Ending in containment. There is a contractual commitment to act, not merely to inform.

That last point is where the market gets untidy. Gartner counted well above 600 providers describing themselves as MDR at the time of that research, and warned that technology-first offerings which never deliver human-led response are misaligned with what buyers think they are purchasing. The acronym is not a specification. The contract is.

What an MDR service actually does

The work divides into seven functions, and the difference between providers usually shows up in the last three rather than the first four. Monitoring is the easy part to sell and the cheap part to deliver. Deciding, acting and evidencing are where a service either earns its fee or does not.

Diagram showing many raw security signals narrowing through triage to a small number of investigations and finally to one confirmed containment decision
The value is not in producing signals. It is in closing them.
Function What it means in practice What its absence looks like
Continuous monitoring Endpoint, identity, email, cloud and network telemetry watched every hour of every day Alerts queue overnight and get triaged the next morning
Triage Someone decides which signals are real before they reach you Your team investigates everything, or quietly investigates nothing
Investigation An analyst establishes scope: which accounts, which hosts, how far it reached You know a machine alerted, not what happened
Threat hunting Deliberate search for activity that no existing rule has caught You only ever find what your detections already knew about
Containment Isolating a host, disabling an account, revoking a session, killing a process You receive an email and act on it whenever you next look
Response guidance A named person walks your team through eradication and recovery You improvise during the worst week of your year
Reporting Evidence of what was seen, what was decided and what was done You cannot answer the insurer, the auditor or the regulator

MDR vs EDR, MSSP and SOC as a service

EDR is a product you own, MDR is a service that operates one. The four models are routinely marketed as if they were interchangeable, and they are not. The useful way to separate them is to ask a single question of each: when an alert fires at 03:00 on a Sunday, whose job is it?

Model What you are buying Who acts on the alert Usual pricing basis
EDR or XDR A product: sensors, detection content, a console Your team, whenever it next looks Per endpoint or per user licence
MSSP Management of security devices, plus broad monitoring across the estate Usually you, after a notification or a ticket Per device or per service tier
SOC as a service An operated security function, frequently running on tooling you already own Shared, and defined in a runbook Per data volume or per seat
MDR An outcome: detection through investigation to containment The provider, within a contracted response time Per endpoint, per user or per identity

Two practical notes. First, a real MDR service can sit on top of tooling you already licence, so this is not automatically a decision to replace your stack. Second, the boundary between SOC as a service and MDR is genuinely blurred, and vendors on both sides know it. Judge the contracted response commitment rather than the category name.

Why the hours matter more than the tools

The gap that decides most incidents is not a detection gap, it is a staffing gap that only exists between roughly 18:00 and 08:00. Three independent 2026 datasets converge on this, and each measures a different part of the same clock.

Measure 2026 figure Source
Ransomware deployed outside normal working hours 88.10% Sophos Active Adversary Report 2026
Attacks occurring between 23:00 and 03:00 local time 37.1% Sophos Active Adversary Report 2026
Data exfiltration occurring outside working hours 78.85% Sophos Active Adversary Report 2026
Median time from intrusion to reaching Active Directory 3.4 hours Sophos Active Adversary Report 2026
Average eCrime breakout time, initial access to lateral movement 29 minutes, fastest observed 27 seconds CrowdStrike Global Threat Report 2026
Detections involving no malware at all 82% CrowdStrike Global Threat Report 2026

Read together, these numbers describe a specific failure mode. An attacker signs in with a valid credential at 23:40 on a Friday, so no malware fires and no file is quarantined. They are in the identity directory before 03:00. Encryption or exfiltration follows before anyone reaches a desk on Monday. Every stage was visible in telemetry that your tools were dutifully recording. The 82% malware-free figure matters here too: if your detection strategy still assumes a malicious file to catch, the most common intrusion of 2026 produces nothing to catch.

This is the same argument our guide to ransomware prevention reaches from the other direction: detection without a response capability at 03:00 on a Sunday is just a log file.

When does a business need MDR? Seven triggers

The decision is rarely about company size, and almost always about coverage, competence and obligation. Each trigger below is written as something you can check this week rather than a description of a persona.

  1. You own detection tooling that nobody watches out of hours. This is the most common trigger by a distance. Licences for endpoint and identity detection are widely deployed. Rotas that read them at 02:00 are not.
  2. Your incident response plan names people who have other full-time jobs. If the plan’s first responder is also responsible for the ERP migration, you have a document rather than a capability.
  3. The shift arithmetic does not work. A week contains 168 hours and one analyst works about 40 of them, so a single seat covered continuously needs at least 4.2 people before you allow for holiday, sickness, training or handover. In practice it is five or six, for one seat, at one tier.
  4. Identity is your real attack surface. Sophos found 67% of incidents rooted in identity attacks, with multi-factor authentication missing in 59% of cases. Identity attacks produce no file to quarantine, so they need someone reading sign-in behaviour, not an antivirus verdict.
  5. Someone external now asks for evidence. A tender, an insurer’s questionnaire, a NIS2 obligation or an enterprise customer’s security review. The question is no longer whether you own a tool, but whether you can show what it detected and what happened next.
  6. You have already had an incident that took days to understand. The cost of the last one is the most reliable business case for the next one, and the scoping delay is usually the expensive part.
  7. Your business runs when your IT team does not. Manufacturing shifts, healthcare, logistics, hospitality, retail trading hours, or simply operating across time zones. The gap between business hours and operating hours is exactly where the 88% lands.

Two or more of these being true is a reasonable threshold for a serious evaluation. One of them being true, on its own, may be cheaper to fix directly.

What the evidence says about MDR outcomes, honestly

Monitored environments are found faster than unmonitored ones, and the measured gap is days rather than hours. The Sophos dataset is unusually useful here because one firm reports on both its emergency incident response engagements and its MDR customers, using the same definitions.

Case origin Median dwell time
All cases 3.00 days
All-cause incident response cases 5.00 days
All-cause MDR cases 2.00 days
Non-ransomware incident response cases 6.00 days

That comparison deserves a caveat that vendors rarely add. It is not a controlled trial. Emergency incident response cases arrive precisely because something has already gone badly wrong, often at organisations with little or no monitoring in place, so the two populations are not equivalent. The defensible reading is narrower than the marketing one, and still worth having: environments somebody is watching get found sooner, and the difference is measured in days of attacker access.

IBM’s Cost of a Data Breach Report 2026, covering more than 600 breached organisations across incidents between March 2025 and February 2026, supplies the counterweight. Mean time to identify and contain rose to 247 days, up from 241 and reversing five consecutive years of improvement. Breaches running past 200 days cost an average of $5.65 million against $4.32 million for those resolved sooner. Breaches discovered by an organisation’s own security team were closed in roughly 209 days, about five weeks faster than average.

That last figure gets quoted as proof that in-house beats outsourced. It is not evidence of that. IBM is comparing how a breach was discovered, not who was employed to discover it. The realistic alternative to internal discovery is not an MDR provider but a customer complaint, a regulator’s letter or a leak site, and those routes are the slowest and most expensive of all. The finding is about having someone looking, not about whose payroll they sit on.

The workforce number that no longer exists

For a decade, MDR was sold on the cybersecurity workforce gap. That number is no longer published, and the reason matters more than the number did. ISC2’s 2025 Cybersecurity Workforce Study, released on 4 December 2025 and based on a record 16,029 practitioners, dropped the global workforce gap estimate entirely. Respondents in both 2024 and 2025 said consistently that their binding constraint is skills rather than headcount.

The replacement figures are blunter. 95% reported at least one skill need, up five points. 59% called those needs critical or significant, up from 44% the previous year. 88% had already experienced at least one significant security consequence attributable to a skills shortage, and 69% had experienced more than one. Separately, 33% said they lacked the resources to staff their teams adequately and 29% said they could not afford people with the skills they needed.

This reframes what MDR is for. It is not a way to buy bodies you failed to hire. It is a way to rent a narrow competence, available at a specific hour, that is expensive to build and harder still to retain once built. That is a more honest business case, and a more durable one.

When you do not need MDR yet

MDR bolted onto an environment with no inventory, no MFA and no log retention produces alerts you cannot act on, at a price you will resent. There are four situations in which the money is better spent elsewhere first.

  • You do not know what you own. Without a reliable asset and identity inventory, coverage gaps are invisible to both you and the provider. Onboarding will surface this anyway, expensively.
  • Basic identity controls are absent. If MFA is not enforced on administrators, remote access and email, close that first. It is cheaper than any service and it removes a large share of what the service would otherwise be paid to detect.
  • You keep almost no telemetry. Sophos reported that cases with missing telemetry doubled year on year, driven substantially by firewall appliances shipping with seven days of log retention, and in some cases twenty four hours. Nobody can investigate what was never recorded.
  • You already run genuine round the clock cover. If your gap is detection engineering or tuning rather than hours, buy that. Paying an MDR provider to duplicate a rota you already staff is a poor trade.

The first three are foundation work rather than detection work, which is why posture and configuration control belong underneath the detection layer rather than beside it.

What MDR does not do

Every MDR contract has a boundary, and the boundary is where most disappointment lives. Four limits are worth writing down before you sign anything.

It does not patch anything. Sophos measured a median of 322 days between a vendor advisory being published and exploitation being observed. A window that wide is not a detection problem, it is a remediation problem, and no monitoring service closes it for you.

It does not fix your configuration or your identity hygiene. A provider can tell you that a legacy authentication protocol is being abused. Turning it off remains yours.

It has explicit scope exclusions. These are normal and they are specific. Microsoft’s own service, Defender Experts for XDR, documents that incidents categorised as compliance, data loss prevention or custom detections, and those affecting IoT, iOS or Android devices, sit outside the service. Ask every provider for the equivalent list, in writing.

It does not transfer accountability. You can outsource the work and the hours. Under NIS2 the responsibility for managing cybersecurity risk stays with the organisation and its management body, and a regulator will ask you, not your supplier, what happened.

How to choose an MDR provider

Six questions separate a genuine service from a monitoring product with a service-shaped price. All six are answerable in a first call, and the quality of the answer tells you more than any feature matrix.

Ask this Why it decides the outcome
Will you contain, or only notify me? Remote containment beyond alerting is what separates MDR from managed monitoring. Get the permitted actions listed explicitly.
What response time is contracted, measured from what event? Rapid response is not a commitment. Time to acknowledge, time to investigate and time to act are three different clocks.
Which humans engage with my environment daily, and in which time zones? MDR is defined as human-led. A follow-the-sun rota and an autonomous triage engine are not the same purchase.
Whose tenant, whose detections, and what leaves with me? Detection content tuned to your environment over two years is an asset. Establish at signing whether you keep it.
What is explicitly out of scope? Every provider has exclusions. Only some volunteer them.
What evidence do I get for an insurer, auditor or regulator? Reporting is the deliverable you will use most often and evaluate least during procurement.

What MDR costs, and how to compare like with like

Published per-endpoint prices span more than an order of magnitude, so a single headline figure would mislead you. What does not vary is the arithmetic on the alternative, and that is the comparison worth making.

A week has 168 hours. One analyst covers roughly 40 of them. Continuous cover of a single seat therefore needs at least 4.2 people before any allowance for annual leave, sickness, training, handover or attrition, which is why real rotas run to five or six people for one seat at one tier. A credible internal function needs more than one tier. Set against that, the relevant question is not whether MDR costs more than a salary, but whether it costs more than the coverage you currently do not have.

Four cost lines are routinely missed at evaluation and routinely painful later.

  • Onboarding and tuning. Usually a separate charge, and the period during which the service is least effective.
  • Telemetry ingestion and retention. Especially where a SIEM sits underneath, and especially during an incident, when volumes spike precisely when you cannot negotiate.
  • Incident response. Establish whether hands-on-keyboard response during a major incident is included or sold as a separate retainer. The answer varies widely.
  • The counting unit. Per endpoint, per user and per identity produce very different bills for the same organisation. Model your own numbers rather than the example in the proposal.

MDR, NIS2 and cyber insurance

Two external forces are turning continuous monitoring from a good idea into a documented requirement: regulatory reporting deadlines and insurance underwriting. Both care about evidence rather than intent.

Under Article 23 of the NIS2 Directive, in-scope entities owe a competent authority an early warning within 24 hours of becoming aware of a significant incident, and a fuller notification within 72 hours. There is a subtlety here that vendor material regularly gets wrong. The clock starts when you become aware, so slow detection does not by itself breach the deadline. It does something worse. It extends the period in which an attacker operates unobserved, and it leaves you assembling a 72-hour notification from telemetry that has already rolled off your retention window.

If you are unsure whether those duties reach your organisation, our two-minute NIS2 applicability check settles it quickly, and Who does NIS2 cover, and what you actually have to do covers the obligations that follow. Our NIS2 overview maps the directive onto the controls involved.

Cyber insurers have moved their bar in steady increments: tested backups, then multi-factor authentication, then endpoint detection, and now increasingly proof that alerts reach a human at any hour rather than the next working morning. Renewal questionnaires have shifted from attestation towards evidence, which is why the ability to produce current, board-ready evidence on request is becoming as commercially useful as the detection itself.

MDR in a Microsoft environment

If your organisation runs Microsoft 365, you are almost certainly already generating the telemetry an MDR service needs, and quite possibly paying for it twice. Defender for Endpoint, Defender for Office 365, Defender for Identity, Defender for Cloud Apps and Entra ID Protection produce the identity and endpoint signal where modern intrusions appear first, and Microsoft Sentinel can hold the rest.

One clarification is worth making explicitly, because the assumption behind it is widespread and expensive. Microsoft’s own managed service, Defender Experts for XDR, is licensed and sold separately from Microsoft 365 E5. Owning E5 gives you the tooling and the telemetry. It does not give you anyone watching them at 02:00. Organisations frequently discover this during an incident rather than during procurement.

That gap between owning the signal and operating it is the practical case for a layer that turns Sentinel, Defender, Intune and Entra ID signals into one validated decision across every tenant, rather than another console for someone to not be watching. You can see how the detection and response platform applies that to an existing Microsoft estate without replacing any of it.

Why shared defence changes the arithmetic

The same tradecraft hits many organisations in sequence, which means the second target is attacked with indicators the first one already produced. Sophos observed 51 distinct ransomware brands in its 2026 dataset, of which the five largest accounted for 51% of all deployments. Verizon’s 2026 report, drawing on more than 31,000 incidents and over 22,000 confirmed breaches across 145 countries, found third parties involved in 48% of breaches, up from 30% a year earlier. Attackers are reusing infrastructure, tooling and supplier relationships at scale.

Network diagram of connected organisations where one investigated attack becomes a validated detection for every other member
One organisation sees the attack first. Everyone else gets the protection before it arrives.

Defending against reused tradecraft one organisation at a time means every member pays for the same investigation separately. That is the reasoning behind UnifiedONE’s shared defence intelligence: an attack investigated once in one member environment becomes a validated detection for every other member, usually within minutes. The same weekly breakdown of what attackers actually did to Microsoft environments is published openly in The Repeat.

How that is packaged depends on who carries the operational load: managed service providers running many tenants, smaller organisations without a dedicated security team, or enterprises that already run a SOC and need coverage rather than replacement.

Frequently asked questions

What does MDR stand for in cybersecurity?

MDR stands for managed detection and response. It is a service, not a product: an external team monitors your security telemetry continuously, investigates what looks genuinely suspicious, and contains confirmed threats or directs your team through containment. The defining feature is that the provider is obliged to act, not just to notify.

What is the difference between MDR and EDR?

EDR is endpoint detection and response software: sensors, detection logic and a console that you own and operate. MDR is the human service that operates detection tooling on your behalf, usually across identity, email and cloud as well as endpoints. Many organisations buy EDR, deploy it properly, and then discover that nobody is reading it after 18:00.

Is MDR the same as a SOC?

A security operations centre is the function. MDR is one way of sourcing it. An in-house SOC gives you full control and deep business context but requires enough analysts to staff a continuous rota across several tiers. MDR gives you the coverage without the rota, at the cost of some context, which good providers close through onboarding and a named contact.

Do small businesses need MDR?

Size is the wrong test. The right test is whether anyone is watching outside office hours and whether an incident would land on someone who already has another full-time job. Small organisations face the same ransomware affiliates as large ones, and 88.10% of ransomware is deployed outside working hours, which is exactly when a small team is least able to respond.

Can MDR replace my IT team?

No, and a provider that implies otherwise is describing a different service. MDR covers detection, investigation and containment. It does not patch systems, harden configuration, manage identities or run your helpdesk. It also does not transfer accountability: under NIS2 the responsibility for managing cybersecurity risk stays with your organisation and its management body.

How long does MDR onboarding take?

Expect the service to be least effective in its first weeks. Sensors have to be deployed to full coverage, log sources connected, detections tuned to your environment, and response permissions agreed so the provider can actually act. Ask any provider what proportion of your estate they expect to be covered at 30 days, and what happens to alerts during the gap.

Does MDR satisfy cyber insurance requirements?

Frequently, but only where it includes contracted response commitments and genuine round the clock cover, and only where you can evidence coverage across servers as well as laptops. Insurers have moved from asking whether a control exists to asking for proof of what it detected and what happened next. Read the questionnaire against the contract before assuming the two match.

In short

  • MDR is human-led, continuous detection and response delivered as a service, ending in containment rather than notification. Gartner counted well above 600 providers using the label, so judge the contract rather than the acronym.
  • The case for it is a clock, not a product gap: 88.10% of ransomware is deployed outside working hours, 37.1% of attacks fall between 23:00 and 03:00, and average breakout time is now 29 minutes.
  • Monitored environments are found faster. Sophos recorded a median dwell time of 2.00 days across MDR cases against 5.00 days across incident response cases, though the two populations are not directly comparable.
  • The workforce gap argument has been retired. ISC2 stopped publishing the figure in 2025 because the binding constraint is skills, not headcount, with 59% now reporting critical or significant skill needs.
  • Fix inventory, MFA and log retention first. MDR watching an environment with seven days of firewall logs cannot investigate what was never recorded.
  • Owning Microsoft 365 E5 gives you the telemetry, not the watchers. Microsoft’s own MDR service is licensed separately.

Sources

  1. Sophos X-Ops, Nowhere, man: The 2026 Active Adversary Report, February 2026, based on 661 incident response and MDR cases handled between 1 November 2024 and 31 October 2025 across 70 countries and 34 industries. Retrieved 20 August 2026.
  2. Verizon, 2026 Data Breach Investigations Report, May 2026. Retrieved 20 August 2026.
  3. IBM Security, Cost of a Data Breach Report 2026, July 2026, based on more than 600 breached organisations, incidents between March 2025 and February 2026. Retrieved 20 August 2026.
  4. CrowdStrike, 2026 Global Threat Report, 24 February 2026. Retrieved 20 August 2026.
  5. ISC2, 2025 ISC2 Cybersecurity Workforce Study, 4 December 2025, based on 16,029 respondents. Retrieved 20 August 2026.
  6. Gartner, Market Guide for Managed Detection and Response Services, Pete Shoard, Andrew Davies and Angel Berrios, 1 October 2025. Subscription report.
  7. Microsoft, What is Microsoft Defender Experts MDR, Microsoft Learn. Retrieved 20 August 2026.
  8. European Union, Directive (EU) 2022/2555 (NIS2), Articles 20 and 23. Retrieved 20 August 2026.

Written by

Sher Khatak

UnifiedONE

Newsletter

Get the next one in your inbox.

A useful read once a month. No spam.

See it in action

See it in action.

Turn one validated threat into protection for your whole community. Start free, or book a walkthrough with our team.