How Does Managed Detection and Response (MDR) Work?
MDR works by pairing endpoint detection software with a 24/7 human SOC team that monitors the alerts the software generates, investigates which ones are real, and contains threats on your behalf — usually within minutes.
Quick answer
MDR works by pairing endpoint detection software with a 24/7 human SOC team that monitors the alerts the software generates, investigates which ones are real, and contains threats on your behalf — usually within minutes. At AMVIA, that means Microsoft Defender for Endpoint telemetry watched around the clock by our in-house UK security analysts.
Key Points
How managed detection and response combines EDR tooling with a 24/7 human SOC to contain threats on your behalf.
Breaches cause real losses
21% of businesses that experienced a breach reported a negative outcome such as loss of money or data.
Downtime is rising
7% of businesses that experienced a breach reported temporary loss of access to files or networks — up from 4% in 2024.
Incidents at record highs
The NCSC handled 429 total incidents in 2025, with 204 classified as nationally significant — the highest-ever number.
How MDR responds
When a threat is detected, the SOC analyst contains the affected endpoint within minutes, investigates the root cause, and guides remediation — replacing the need for an in-house security team.
Quick Comparison
| Feature | Option A | Option B |
|---|
MDR works by pairing endpoint detection software with a 24/7 human SOC team that monitors the alerts that software generates, investigates which ones are real, and contains threats on your behalf — usually within minutes. At AMVIA, that means Microsoft Defender for Endpoint telemetry watched around the clock by our in-house UK security analysts.
Managed Detection and Response exists because the tooling on its own is not enough. An endpoint agent can flag a thousand suspicious events a week; someone still has to read them, decide which matter, and act before an attacker moves laterally. That "someone" is the part most SMEs cannot staff, and it is the part MDR replaces. If you are weighing up your wider security strategy, this question sits underneath our broader managed cybersecurity pillar — MDR is one layer of it, not the whole thing.
The rest of this guide breaks down the MDR workflow step by step, shows where the technology ends and the human work begins, and explains what AMVIA actually does when an alert fires at 3am.
What are the stages of the MDR process?
MDR runs as a continuous loop: collect telemetry, detect anomalies, triage alerts, investigate confirmed threats, contain and respond, then review and harden. The technology handles collection and first-pass detection; analysts handle the judgement calls — deciding what is a genuine attack versus a noisy false positive.
Here is the workflow in order:
1. Collect — lightweight agents and connectors stream logs and behavioural telemetry from endpoints, identity, and email into a central platform. 2. Detect — detection rules and behavioural analytics flag anomalies: unusual sign-ins, suspicious process execution, credential misuse, lateral movement. 3. Triage — a SOC analyst validates each meaningful alert, dismisses false positives, and grades severity. 4. Investigate — for confirmed threats, the analyst traces the root cause and the blast radius: which device, which account, what was touched. 5. Contain — the analyst isolates the affected endpoint or disables the compromised account, stopping spread. 6. Respond and harden — remediation guidance, removal of attacker persistence, and a review of what let the attack in.
The reason this matters is speed. The UK's National Cyber Security Centre handled 429 total incidents in 2025, with 204 classified as nationally significant — the highest-ever number (NCSC). When incident volume rises, the gap between detection and response is where damage happens. A loop that runs 24/7 closes that gap.
How is MDR different from just buying EDR software?
EDR is the technology layer; MDR is EDR plus the people who run it. EDR collects endpoint telemetry and raises alerts, but it does not decide which alerts are real or take action — your staff do. MDR wraps a 24/7 SOC around the tooling so trained analysts triage, investigate, and contain on your behalf.
Without the human layer, every alert lands on your IT team's desk to be sorted manually — a job most SMEs have neither the headcount nor the round-the-clock cover to do. The result is alert fatigue, missed signals, and slow response. This is exactly the distinction we draw out in our MDR vs EDR comparison.
| Capability | EDR (software only) | MDR (software + SOC) |
|---|---|---|
| Endpoint telemetry collection | Yes | Yes |
| Alert generation | Yes | Yes |
| Alert triage / false-positive filtering | Your staff | 24/7 SOC analysts |
| Threat investigation | Your staff | SOC analysts |
| Containment action | Your staff | SOC analysts (minutes) |
| Out-of-hours cover | No | Yes |
| Remediation guidance | No | Yes |
The data backs the case for the human layer. 43% of UK businesses experienced a breach or attack in the past year (DSIT Cyber Security Breaches Survey 2025), and many lacked the monitoring to detect it promptly. Buying the software without anyone watching it is how that happens. Our endpoint detection and response service is built on the MDR model for this reason.
What does the SOC team actually do when a threat is detected?
When a genuine threat is confirmed, the SOC analyst validates the alert, grades severity, and initiates containment — typically isolating the affected endpoint within minutes. They then investigate the root cause, assess how far the compromise spread, and provide remediation guidance to close the gap permanently.
This is where MDR earns its keep. Containment speed is the single biggest factor between a contained incident and a full outbreak. 19,000 UK businesses were hit by ransomware in 2025 (Sophos), and ransomware spreads fastest in the first hour after foothold. A SOC that isolates a machine in minutes denies the attacker the time they need.
AMVIA's response work is run by our in-house managed SOC service — UK analysts, not an offshore queue. For confirmed incidents that need hands-on eradication and recovery, the SOC hands off to our incident response process so containment and clean-up are one continuous chain, not two separate phone calls.
Does MDR work with our existing IT and Microsoft 365 setup?
Yes. MDR deploys lightweight agents onto endpoints and connects to platforms you already run — Microsoft 365, identity providers, firewalls, and cloud services. It ingests logs and telemetry from those sources to build a single, correlated view of activity across your whole environment, rather than watching endpoints in isolation.
That correlation is the point. 22% of breaches involved compromised credentials (Verizon DBIR 2025), and credential-based attacks only become obvious when you can join the dots across identity, email, and endpoint signals. A SOC watching all three at once catches the multi-stage attack that any single tool would miss.
AMVIA builds MDR on the Microsoft security stack our clients already pay for — Microsoft Defender for Endpoint and Defender for Office 365, hardened and monitored by our team, with Barracuda covering email and network filtering. Microsoft's own guidance on Defender for Business is a useful primer (Microsoft Security). Because the detection runs on tooling you already license, MDR rarely means ripping anything out. It is continuous 24/7 security monitoring layered onto your current environment.
What does AMVIA recommend?
For most UK SMEs with 10–500 staff, MDR is the highest-leverage security spend available — more so than another point product. The honest reason: detection tooling is now commoditised and cheap, but the analysts who turn alerts into action are scarce and expensive. MDR lets you rent that capability 24/7 for a fraction of building an in-house SOC.
What we would not do is buy EDR and assume it is sorted. Software that nobody is watching is a compliance checkbox, not a defence. If your endpoint tool has been raising alerts into an inbox no one reads, you already have the worst of both worlds — cost without coverage.
One provider, security-first, Microsoft-certified engineers: that is the model AMVIA runs MDR on, so detection, response, and your Microsoft 365 estate sit with one accountable team.
Frequently Asked Questions
A mature MDR service contains confirmed threats within minutes, not hours. The endpoint agent flags suspicious behaviour in near real time, a SOC analyst validates it, and containment — isolating the device or disabling the account — follows immediately. The 24/7 model means that response is the same at 3am on a Sunday as it is at midday on a Tuesday.
No. A SIEM is a log-aggregation and correlation platform; MDR is an outcome-based service that may use a SIEM under the hood but adds the human SOC, the investigation, and the containment action. SIEM tells you something happened; MDR decides what it means and stops it. The two are complementary, not interchangeable.
Most do. 43% of UK businesses experienced a breach or attack in the past year (DSIT 2025), and smaller firms are targeted precisely because they lack monitoring. MDR gives an SME the same round-the-clock detection a large enterprise SOC provides, without the headcount cost of building one in-house.
MDR is the always-on detection and rapid-containment service that catches threats early. Incident response is the deeper eradication, forensics, and recovery work that follows a confirmed, significant compromise. Good MDR reduces how often you need full incident response — and when you do, the handover is seamless because the same team already holds the context.
No — it removes a job they cannot realistically do. Your IT team keeps running day-to-day systems; MDR adds 24/7 security analysts who watch for threats out of hours and take containment action your team is not staffed to deliver round the clock. It augments internal IT rather than replacing it.
MDR attacks the most expensive part of a breach: dwell time. 21% of businesses that experienced a breach reported a negative outcome such as loss of money or data (DSIT 2025), and 7% reported temporary loss of access to files or networks — up from 4% in 2024. Faster detection and containment is what shrinks those numbers.
Related Questions
MDR vs EDR
How managed detection and response differs from standalone endpoint detection and response tools.
Cybersecurity Guide for UK SMEs
A complete guide to cybersecurity controls including MDR and SOC monitoring.
How Much Does Managed Cybersecurity Cost?
Per-user pricing for MDR and managed security services for UK businesses.
Endpoint Security Service
EDR-based endpoint protection that forms the technology layer beneath MDR monitoring.
How Much Does Penetration Testing Cost in the UK?
Direct answer: How Much Does Penetration Testing Cost in the UK?. Expert guidance with UK-specific data, key requirements, and practical…
How to Protect Your Business from AI-Generated Cyber Attacks
Direct answer: How to Protect Your Business from AI-Generated Cyber Attacks. Expert guidance with UK-specific data, key requirements, and…
Protect your business → Get Cybersecurity Assessment