Cybersecurity

Managed Detection and Response (MDR): What It Is and Why It Matters

MDR (Managed Detection and Response) is a 24/7 security service combining technology and human analyst expertise to detect threats across your environment and respond to incidents in real time. For UK businesses without in-house security operations capability, MDR provides enterprise-grade threat detection at a manageable cost.

NH

Nathan Hill-Haimes

Technical Director

9 min read·Mar 2026

This guide explains what MDR does, how it differs from older managed security models, what it detects, and what it realistically costs a UK business. If you run security for a company between 10 and 500 staff, this is the model most likely to give you genuine coverage you can afford. AMVIA delivers MDR as part of its managed cybersecurity service.

What gap does MDR fill for UK SMEs?

Most UK SMEs cannot fund a full managed SOC staffed with dedicated analysts. Hiring, training and retaining qualified security people — plus the tooling to run an operation 24/7 — sits well beyond the budget of a business with fewer than 500 employees. MDR closes that gap.

At the same time, the threat picture has shifted. Passive defences alone no longer hold. Attackers who establish a foothold often sit undetected for weeks before detonating ransomware or exfiltrating data, a dwell-time pattern documented repeatedly in the NCSC's threat reporting. By the time the damage is visible, it is usually done.

The UK Government's annual Cyber Security Breaches Survey shows breaches and attacks remain common across UK businesses year on year. MDR answers this by supplying the human expertise and technology of a security operations centre as a managed service — the SOC capability without the salary bill.

How does managed detection and response work?

MDR is not a single product. It is a stack of integrated capabilities — endpoint telemetry, log correlation, human analysis and proactive hunting — operated together by a security team. Each layer does a job the others cannot, and the combination is what turns raw signal into a contained incident.

Endpoint detection and response (EDR) agents

Software agents sit on every endpoint — workstations, servers, cloud workloads — collecting detailed telemetry: process execution, file activity, network connections, registry changes and user behaviour. Under analyst direction or pre-defined playbooks, they also act: isolating a device from the network, killing a process, or collecting forensic artefacts. AMVIA's MDR uses Microsoft Defender for Endpoint as the EDR layer.

SIEM correlation

Logs from endpoints, firewalls, email platforms, cloud identity and network devices flow into a centralised SIEM. Correlation rules surface attack techniques — lateral movement, privilege escalation, exfiltration — and enrich raw logs with threat intelligence so analysts can judge severity fast. For smaller teams, this is the value of a SIEM built for SMEs: enterprise visibility without enterprise complexity.

Human analyst oversight

Technology surfaces alerts; people make decisions. AMVIA's in-house 24/7 SOC reviews alerts, investigates suspicious activity, separates genuine threats from false positives, and executes response. This human layer is what divides MDR from unmanaged SIEM or basic managed antivirus — real expertise applied to your environment, not automated ticket generation.

Threat hunting

Beyond reactive alerting, effective MDR includes proactive threat hunting: analysts searching for indicators of compromise that automated rules may have missed, using current knowledge of attacker tactics, techniques and procedures. This matters most against patient attackers who move slowly to stay under automated detection thresholds.

What does MDR actually detect?

MDR provides coverage across the full attack lifecycle, not just the moment malware lands. It watches for the behavioural fingerprints attackers leave at each stage, which is how genuine intrusions get caught before they reach their objective.

  • Initial access: phishing payloads executing, exploitation of public-facing vulnerabilities, compromised credentials authenticating
  • Persistence: new scheduled tasks, registry run keys, malicious services being created
  • Privilege escalation: attempts to gain admin rights, exploitation of local privilege-escalation flaws
  • Lateral movement: unusual remote connections between workstations, pass-the-hash and pass-the-ticket attacks, abuse of admin shares
  • Data exfiltration: unusual outbound data volumes, connections to unknown destinations, large file-staging events
  • Ransomware indicators: mass file encryption, shadow-copy deletion, wallpaper modification — flagged early enough to enable containment before encryption completes

When something critical surfaces, it routes straight into incident response rather than a queue.

MDR vs MSSP — what is the difference?

The distinction is worth being precise about, because the words get used loosely. A traditional MSSP detects and hands you the alert; MDR detects, investigates and responds on your behalf. For a business without dedicated security staff, that response element is the whole point.

CapabilityTraditional MSSPManaged Detection & Response (MDR)
Monitoring & alertingYesYes
Alert investigationClient's teamProvider's analysts
Active response (isolation, containment)Client's responsibilityPerformed by provider
Threat huntingRarelyStandard
Best fitIn-house security team presentNo dedicated security staff

A traditional MSSP sends correlation alerts to your team to triage and act on. MDR includes the response — the provider's analysts investigate and contain (isolation, blocking, remediation guidance) rather than passing a stream of tickets back to you. That is the line that matters when you have no one to work the queue.

How fast does MDR respond to an attack?

Speed between detection and response is where MDR earns its keep. Ransomware can encrypt a network in under 30 minutes in well-documented incidents, so a slow response SLA is inadequate. AMVIA's MDR service targets under 1 hour for critical (P1) incident response, with a 2-hour target for others, giving the rapid containment needed to limit an active attack's blast radius.

That response is delivered by AMVIA's own 24/7 security monitoring team — not outsourced offshore. When an endpoint shows active ransomware behaviour, an analyst can isolate it from the network in minutes, block the malicious account or IP, and call your designated contact, rather than wait for you to notice a ticket.

What does MDR cost in the UK?

MDR pricing in the UK market typically ranges from £8–£25 per user per month depending on coverage scope, technology platform and response SLAs. For a 25-user business, that is roughly £2,400–£7,500 per year — a fraction of the cost of one experienced analyst's salary, typically £45,000–£75,000 per year in the UK for a competent SOC analyst.

AMVIA's MDR service is built specifically for UK SMEs, with pricing and service levels appropriate for businesses from 10 to 500 users. Deployment typically takes 3–5 business days for a standard SME environment as of 2026, covering agent rollout, log-source configuration, behavioural baselining and stakeholder briefing. The economics are simple: you get a security operations capability for far less than building one in-house, with a single accountable provider standing behind it.

Does Your Business Have 24/7 Threat Detection?

Most attacks happen outside business hours. AMVIA's MDR service monitors your environment continuously and responds to threats in real time — contact us to understand what coverage would look like for your business.

Frequently Asked Questions