Managed Detection and Response (MDR): What It Is and Why It Matters
MDR (Managed Detection and Response) is a 24/7 security service combining technology and human analyst expertise to detect threats across your environment and respond to incidents in real time. For UK businesses without in-house security operations capability, MDR provides enterprise-grade threat detection at a manageable cost.
Nathan Hill-Haimes
Technical Director
This guide explains what MDR does, how it differs from older managed security models, what it detects, and what it realistically costs a UK business. If you run security for a company between 10 and 500 staff, this is the model most likely to give you genuine coverage you can afford. AMVIA delivers MDR as part of its managed cybersecurity service.
What gap does MDR fill for UK SMEs?
Most UK SMEs cannot fund a full managed SOC staffed with dedicated analysts. Hiring, training and retaining qualified security people — plus the tooling to run an operation 24/7 — sits well beyond the budget of a business with fewer than 500 employees. MDR closes that gap.
At the same time, the threat picture has shifted. Passive defences alone no longer hold. Attackers who establish a foothold often sit undetected for weeks before detonating ransomware or exfiltrating data, a dwell-time pattern documented repeatedly in the NCSC's threat reporting. By the time the damage is visible, it is usually done.
The UK Government's annual Cyber Security Breaches Survey shows breaches and attacks remain common across UK businesses year on year. MDR answers this by supplying the human expertise and technology of a security operations centre as a managed service — the SOC capability without the salary bill.
How does managed detection and response work?
MDR is not a single product. It is a stack of integrated capabilities — endpoint telemetry, log correlation, human analysis and proactive hunting — operated together by a security team. Each layer does a job the others cannot, and the combination is what turns raw signal into a contained incident.
Endpoint detection and response (EDR) agents
Software agents sit on every endpoint — workstations, servers, cloud workloads — collecting detailed telemetry: process execution, file activity, network connections, registry changes and user behaviour. Under analyst direction or pre-defined playbooks, they also act: isolating a device from the network, killing a process, or collecting forensic artefacts. AMVIA's MDR uses Microsoft Defender for Endpoint as the EDR layer.
SIEM correlation
Logs from endpoints, firewalls, email platforms, cloud identity and network devices flow into a centralised SIEM. Correlation rules surface attack techniques — lateral movement, privilege escalation, exfiltration — and enrich raw logs with threat intelligence so analysts can judge severity fast. For smaller teams, this is the value of a SIEM built for SMEs: enterprise visibility without enterprise complexity.
Human analyst oversight
Technology surfaces alerts; people make decisions. AMVIA's in-house 24/7 SOC reviews alerts, investigates suspicious activity, separates genuine threats from false positives, and executes response. This human layer is what divides MDR from unmanaged SIEM or basic managed antivirus — real expertise applied to your environment, not automated ticket generation.
Threat hunting
Beyond reactive alerting, effective MDR includes proactive threat hunting: analysts searching for indicators of compromise that automated rules may have missed, using current knowledge of attacker tactics, techniques and procedures. This matters most against patient attackers who move slowly to stay under automated detection thresholds.
What does MDR actually detect?
MDR provides coverage across the full attack lifecycle, not just the moment malware lands. It watches for the behavioural fingerprints attackers leave at each stage, which is how genuine intrusions get caught before they reach their objective.
- Initial access: phishing payloads executing, exploitation of public-facing vulnerabilities, compromised credentials authenticating
- Persistence: new scheduled tasks, registry run keys, malicious services being created
- Privilege escalation: attempts to gain admin rights, exploitation of local privilege-escalation flaws
- Lateral movement: unusual remote connections between workstations, pass-the-hash and pass-the-ticket attacks, abuse of admin shares
- Data exfiltration: unusual outbound data volumes, connections to unknown destinations, large file-staging events
- Ransomware indicators: mass file encryption, shadow-copy deletion, wallpaper modification — flagged early enough to enable containment before encryption completes
When something critical surfaces, it routes straight into incident response rather than a queue.
MDR vs MSSP — what is the difference?
The distinction is worth being precise about, because the words get used loosely. A traditional MSSP detects and hands you the alert; MDR detects, investigates and responds on your behalf. For a business without dedicated security staff, that response element is the whole point.
| Capability | Traditional MSSP | Managed Detection & Response (MDR) |
|---|---|---|
| Monitoring & alerting | Yes | Yes |
| Alert investigation | Client's team | Provider's analysts |
| Active response (isolation, containment) | Client's responsibility | Performed by provider |
| Threat hunting | Rarely | Standard |
| Best fit | In-house security team present | No dedicated security staff |
A traditional MSSP sends correlation alerts to your team to triage and act on. MDR includes the response — the provider's analysts investigate and contain (isolation, blocking, remediation guidance) rather than passing a stream of tickets back to you. That is the line that matters when you have no one to work the queue.
How fast does MDR respond to an attack?
Speed between detection and response is where MDR earns its keep. Ransomware can encrypt a network in under 30 minutes in well-documented incidents, so a slow response SLA is inadequate. AMVIA's MDR service targets under 1 hour for critical (P1) incident response, with a 2-hour target for others, giving the rapid containment needed to limit an active attack's blast radius.
That response is delivered by AMVIA's own 24/7 security monitoring team — not outsourced offshore. When an endpoint shows active ransomware behaviour, an analyst can isolate it from the network in minutes, block the malicious account or IP, and call your designated contact, rather than wait for you to notice a ticket.
What does MDR cost in the UK?
MDR pricing in the UK market typically ranges from £8–£25 per user per month depending on coverage scope, technology platform and response SLAs. For a 25-user business, that is roughly £2,400–£7,500 per year — a fraction of the cost of one experienced analyst's salary, typically £45,000–£75,000 per year in the UK for a competent SOC analyst.
AMVIA's MDR service is built specifically for UK SMEs, with pricing and service levels appropriate for businesses from 10 to 500 users. Deployment typically takes 3–5 business days for a standard SME environment as of 2026, covering agent rollout, log-source configuration, behavioural baselining and stakeholder briefing. The economics are simple: you get a security operations capability for far less than building one in-house, with a single accountable provider standing behind it.
Does Your Business Have 24/7 Threat Detection?
Most attacks happen outside business hours. AMVIA's MDR service monitors your environment continuously and responds to threats in real time — contact us to understand what coverage would look like for your business.
Frequently Asked Questions
EDR (endpoint detection and response) is a technology — software agents that collect endpoint telemetry and enable response actions on individual devices. MDR (managed detection and response) is a service that uses EDR among other tools and adds human analyst oversight, SIEM correlation, threat hunting and managed incident response. EDR is a component of MDR; MDR is the complete managed service.
Yes. EDR, a core component of MDR, supersedes traditional antivirus. Modern EDR agents use behavioural analysis and cloud-delivered threat intelligence rather than signature matching, catching threats that antivirus would miss. Most MDR deployments replace existing antivirus with the EDR agent, simplifying the endpoint security stack rather than adding to it.
For a standard SME environment, deployment is usually completed within a few business days. It covers rolling out EDR agents to endpoints, configuring log ingestion (Microsoft 365, firewall, Active Directory), establishing baseline normal behaviour and briefing internal stakeholders. Environments with more complex architecture or legacy systems may take longer.
It depends on severity. For critical threats — active ransomware, credential compromise with live malicious activity — AMVIA's analysts can immediately isolate affected endpoints, block malicious IPs or accounts, and contact your designated incident contact. For lower-severity detections, analysts investigate further and provide a detailed report with recommended remediation actions.
Microsoft Defender provides strong endpoint detection but still needs someone to monitor alerts and respond. Microsoft Defender for Business, included in Microsoft 365 Business Premium per Microsoft's documentation, adds some automated response. AMVIA's MDR manages and monitors Defender as the EDR layer, adding 24/7 analyst oversight, SIEM correlation with other sources and structured incident response — the parts Defender alone does not cover.
Yes. MDR was created precisely for organisations that cannot justify a full in-house SOC. It scales to businesses from 10 to 500 staff, delivering enterprise-grade detection and response at a predictable per-user cost. For most UK SMEs, MDR is the most cost-effective route to credible 24/7 security coverage.
Related Reading
AMVIA Cybersecurity Benchmark | How We Compare
How AMVIA's MDR and managed security service compares against other UK providers across key dimensions.
AMVIA Cybersecurity | Your Business's First Line of Defence
An overview of AMVIA's full cybersecurity stack, including MDR, SOC and email security.
Ransomware Protection for UK Businesses | AMVIA Guide
How MDR contributes to ransomware detection and containment before encryption is complete.
Protect your business → Get Cybersecurity Assessment