What Is MDR (Managed Detection and Response)?
MDR (managed detection and response) is a cybersecurity service that pairs a 24/7 human security team with detection technology to find, investigate, and shut down threats inside your environment. You get security-operations-grade protection without building that team yourself.
MDR is the front line of modern managed cybersecurity, giving your business a full security operations center on demand. People and software watching your endpoints, cloud, and identities around the clock, hunting for attackers and containing them before they spread. Here is what most buyers do not realize. A lot of what gets sold as MDR is really just an alert forwarder with a nicer invoice.
Every business runs on tools that generate security alerts. Firewalls, laptops, Microsoft 365, your VPN. The average small environment throws off thousands of them a week, and almost all of it is noise. The problem was never getting alerts. The problem is that nobody is awake at 2am to tell the one that matters from the 4,000 that don't. That is the exact gap MDR was built to close.
Most companies buy MDR backward. They shop on price per endpoint, sign with whoever is cheapest, and assume someone is now watching. Then something slips through at 2am on a Saturday, and they find out their provider's idea of response was emailing them a ticket. This post breaks down what MDR actually is, how it works, what separates the real thing from the alert cannon, and whether your business needs it at all.
So what does MDR actually do?
MDR combines three things your business probably can't run alone. Detection software, a team of human analysts, and a defined response process, delivered as a 24/7 service. The analysts watch your telemetry, decide what's real, and take action to contain threats, usually before you know anything happened.
Gartner defines it more formally. MDR delivers remotely delivered security operations center functions that let an organization detect, analyze, investigate, and respond to threats through disruption and containment. Read that again. Not just detect. Respond.
That last word is where the value lives. Plenty of security tools can spot something suspicious. Far fewer will do anything about it at 3am without waiting for you to reply to an email. MDR is the difference between a smoke alarm and a fire department. One tells you the building is burning. The other shows up and puts it out.
Here is the part vendors gloss over. MDR does not replace your IT team. It sits on top of it. Microsoft frames MDR as a way to gain a full-time SOC without hiring one, and that framing is right. Your internal people keep running the business. The MDR team handles the 24/7 threat-hunting grind that no five-person IT department can staff on its own.
MDR vs EDR vs XDR vs MSSP, what's the real difference?
The short version. EDR and XDR are tools. MSSP and MDR are services. But an MSSP forwards you alerts, and a real MDR provider acts on them. That single distinction decides whether you actually get protected or just get notified.
These four acronyms get thrown around like they're interchangeable. They aren't. CrowdStrike puts it cleanly. EDR is a tool you operate. MDR is a service that operates on your behalf. Here is how they stack up.
- EDR (Endpoint Detection and Response) is software on your laptops and servers that spots suspicious behavior. You run it, and it flags. It does not act on its own.
- XDR (Extended Detection and Response) stretches that same idea across endpoints, cloud, email, and identity. Broader visibility, but still a tool you have to operate.
- MSSP (Managed Security Service Provider) is a service that monitors your tools and forwards alerts. Useful, but the ticket usually lands in your inbox for you to sort out.
- MDR (Managed Detection and Response) is a service whose 24/7 SOC detects, investigates, and contains threats for you. That last part, acting on your behalf, is the whole point.
Most confusion happens at the MSSP-versus-MDR line, and it's worth understanding how MDR compares to MSSP and SIEM before you sign anything. An MSSP will tell you a laptop is talking to a sketchy IP address in another country. Helpful. But it's 1am, your IT lead is asleep, and the ticket sits until Monday. A real MDR provider sees the same thing, confirms it's malicious, isolates the laptop, and calls you after the fire is out. Same alert. Wildly different outcome.
How does MDR work, step by step?
MDR runs a loop. Collect data, detect anomalies, triage them, hunt for what the tools missed, contain what's real, then report back with context. The good providers close that loop in minutes, not days. Here is what each step looks like in practice.
- Telemetry collection. Logs and signals stream in from your endpoints, cloud workloads, Microsoft 365, network, and identity systems. Everything feeds one place.
- Detection engines and analysts sort the flood. Automation kills the obvious false positives so humans only see what might actually matter.
- Triage. An analyst confirms whether an alert is a real threat or noise. This is the step MSSPs skip and hand to you.
- Threat hunting. Analysts go looking for attackers who never tripped an alert. Quiet lateral movement, a dormant foothold, credentials being tested.
- Containment and response. When it is real, the SOC isolates the machine, kills the process, or disables the account. Fast.
- Then you get a report. What happened, what they did, and what you should fix so it does not happen again.

Speed is the whole game here, and there are two numbers that measure it. Mean time to detect and mean time to respond, or MTTD and MTTR. The industry benchmark for finding a breach on your own is brutal. IBM's 2025 research puts the average breach lifecycle at 241 days from break-in to containment. A capable MDR provider compresses that to hours. Some report median detection in minutes.
One caution. Ask what response means in the contract. If the provider can't isolate an endpoint or disable an account without waiting for your sign-off, that's guided response, not active response. Secureworks calls this out directly. Real response means the SOC pulls the plug on a compromised machine at 3am on its own authority. Guided response means you're still the one clicking the button, half asleep.
What most buyers get wrong about MDR
The biggest mistake is assuming every service labeled MDR does the same job. It doesn't. The gap between the best and the worst providers is enormous, and the marketing looks identical from the outside.
Gartner has been blunt about this. AI-enabled MDR services all claim higher quality, but buyers face real discrepancies in delivered value across providers. Translation. Two vendors quote you the same price per endpoint and deliver completely different things. One has analysts investigating your environment. The other has a dashboard and a hope.
Here's the test I give clients. When your provider pings you, has the triage already been done, or are they handing you a labeled alert and expecting you to decide if it's real? If you're the one still deciding what's a true positive, you don't have MDR. You have an alert forwarder. You're paying a managed-service price for a tool-service outcome.
The other quiet trap is scope. Gartner's 2025 guidance is that MDR has to stretch past endpoints into cloud, SaaS, and identity, because that's where attackers actually operate now. A provider that only watches laptops is blind to a compromised Microsoft 365 account or an attacker moving through your Azure tenant. Ask what they monitor. If the answer is only endpoints, you have a partial view of your own risk.
Does your business actually need MDR?
Most California SMBs and mid-market companies with 10 or more endpoints benefit from MDR, because they hold data worth stealing but can't staff a 24/7 SOC. Below roughly 10 devices, EDR plus security awareness training often covers the risk at a better price.
I'll disclose the bias up front. We sell managed security, so of course a security company thinks you need security. But the honest version has a threshold. If you're a five-person shop with a handful of laptops and no regulated data, a good EDR tool and trained employees might be enough for now. Spending $30,000 a year on MDR to protect a business that couldn't lose that much in a breach is math that doesn't work.
The math flips fast, though. IBM pegs the average data breach at $4.44 million in 2025. You don't need to be a Fortune 500 to get hit. Attackers target small businesses precisely because they have fewer controls and no one watching overnight. If a ransomware event would shut your production line down for a week or freeze payroll, the exposure dwarfs the contract cost.
Compliance changes the calculation too. If you handle CDI for a defense contract, process cardholder data, or need SOC 2 to close deals, continuous monitoring and documented incident response aren't optional. They're written into the frameworks. This is where MDR stops being insurance and starts being a requirement, and where compliance readiness and detection work start to overlap. A manufacturer chasing CMMC Level 2 needs the 24/7 monitoring anyway. MDR just delivers it as a service instead of a hiring plan.
Who should think hard before buying? Very small teams with no sensitive data. Companies that already run a mature internal SOC. Everyone in between, from a 40-person distributor to a 250-user food processor, is squarely in the target zone.
What does MDR cost?
MDR usually runs $7 to $30 per endpoint per month in 2026. For a business with 25 to 100 devices, that lands around $15,000 to $60,000 a year, depending on how much you monitor and whether active containment is included.
Price swings on four things, and vendors won't always volunteer them. Expel breaks the drivers down as endpoint count, your response SLA, how many data sources you monitor, and whether MDR is bundled or bought as an add-on. Adding cloud, email, and identity coverage on top of endpoints tends to roughly double the base rate. That's not a hidden fee so much as a broader job.
The per-vendor spread is wide. Rough 2026 monthly ranges look like this.
- Huntress, on the lower end, around `$3 to `$9 per endpoint.
- Sophos and SentinelOne land in the middle, roughly `$7 to `$23.
- Arctic Wolf sits around `$8 to `$25.
- CrowdStrike Falcon Complete runs higher, `$25 to `$45, at the premium tier.

Now put that against the risk. Call it $40,000 a year for solid mid-market MDR. Weigh it against a $4.44 million average breach and the 241 days it takes an unwatched environment to notice it got hit. You're not really buying software. You're buying the 240 days back. That's the frame that makes the number make sense.
How to tell a good MDR provider from a bad one
The best providers already did the investigation before they contacted you. The weak ones send you homework. Judge on response depth, coverage, and what happens at 3am, not on the slickness of the dashboard.
Adoption is climbing fast, which means more vendors are slapping the MDR label on thinner services. Gartner expects around half of organizations to be using MDR for 24/7 monitoring and containment, with spend outpacing other managed security services. A crowded market rewards buyers who ask sharp questions. Here's what to press on.
- Is the triage done before they call you? If they forward labeled alerts and wait for your call, that is not managed response.
- Can they take action without your approval? Isolating a machine, killing a process, disabling an account. Guided response is slower and it shows.
- What do they actually watch? Endpoints only is a red flag. You want cloud, identity, email, and network in scope.
- How long do they keep your data? Look for at least 90 days of retention, ideally a year, so hunts and forensics have something to work with.
- Is it human-led? The Gartner line is that MDR stays human-led with AI assisting, not the reverse. Ask who is actually on the keyboard at 3am.

One more move. Run a short proof of concept with your top two choices before you commit. Watch how they handle a real alert in your environment. If you don't have the security leadership in-house to judge what you're seeing, a vCISO can run the evaluation for you. The gap between a provider that investigates and one that forwards becomes obvious in about a week.
The bottom line
MDR is a 24/7 security team plus detection technology, sold as a service, that finds and stops threats you'd never catch on your own. That's the definition. The catch is that half of what carries the label is really alert-forwarding wearing a managed-service price tag.
Three things to hold onto. Real MDR responds, it doesn't just notify. It has to cover cloud and identity, not only laptops. And it earns its cost the moment you weigh a $40,000 contract against a multi-million-dollar breach you found 8 months too late. If you're weighing MDR for a California business, the cleanest first step is a security assessment that maps what you already have against what an attacker would actually exploit. Start there, then decide what you're really buying.