Back to glossary

MDR

2 min read

In security operations, MDR is managed detection and response: a service in which a provider supplies the analysts, the process and usually the tooling to monitor a client’s estate and act on what they find. It is bought instead of building a round-the-clock team, and what distinguishes it from older monitoring is the mandate to respond.

July 29, 2026
Compartir:

How it works

The provider deploys or adopts sensors, most often their own endpoint agent plus connectors to identity, mail, network and cloud sources, and runs their own detection content over the resulting telemetry. Their analysts triage around the clock, investigate what survives triage, and either escalate to the client or take agreed containment actions directly, such as isolating a host or disabling an account.

The boundary with its neighbours is a matter of what is being bought. EDR and XDR are technology; a SOC is an internal function; MDR is that function delivered as a service. A provider will typically operate their own platform, which is why the choice tends to come with a technology decision attached.

What goes wrong

Read the mandate before the datasheet, because the word response covers very different arrangements. Some contracts permit the provider to isolate a host at three in the morning without asking; others require the provider to telephone somebody who may not answer. The second arrangement is monitoring with a faster escalation path, and pricing it as response is how clients end up believing an intrusion would be stopped when in fact it would be reported.

The second issue is context. A provider does not know which of your servers runs payroll, which maintenance window is in progress or which administrator is expected to be working at that hour, so without a maintained asset picture their prioritisation is generic. Escalations arrive as technical descriptions rather than as business events, and the client is left to convert one into the other.

The third is coverage. The service is scoped to the sources under contract, and an attacker who operates entirely in an unmonitored plane, typically a cloud control plane or a mail platform that was left out to save money, is outside it by design.

Where this shows up in an audit

The measurable question is what the provider actually did, and an adversary exercise answers it with timestamps: when we were first visible in telemetry, when the provider raised it, what they escalated and what they contained. Clients are frequently surprised by the middle number rather than the first. We also test the plane that was left out of scope, because that is where the gap between the contract and the expectation lives.

¿Quieres ver cómo trabajamos en Asperis Security?

Agenda 30 minutos con uno de nuestros especialistas. Revisamos tu stack y te decimos qué conviene probar primero.