Threat detection and response

Managed detection and response watches your systems around the clock. Engineers investigate what the monitoring finds and contain it, so a threat is caught while it is still small. For our managed clients it is included as standard, and the team that monitors your business is the same team that secures and runs it.

Verified
ISO 27001 & 9001Certified by a UKAS-accredited certification body Cyber EssentialsCertification body NCSC AssuredCyber Advisor MicrosoftCertified Expert CISSPHeld by Daniel McClure Fisher
Threat detection / 01 · What it is

What managed detection and response is

Managed detection and response, or MDR, means your systems are monitored continuously for signs of attack, and engineers investigate and contain what is found. It is the watching and the responding, so a threat is caught while it is small rather than discovered weeks later in the damage it caused.

Threat detection / 02 · What we watch

What we monitor

The devices your people work on, the accounts they sign in with, and the email that carries most of the attempts.

01Endpoints

Endpoint detection and response

Continuous monitoring of laptops, desktops and servers for malicious behaviour, and a compromised machine can be isolated before it spreads.

EDRBehaviour analysisDevice isolation
02Identities

Identity threat detection and response

Watching for compromised accounts, suspicious sign ins and the identity attacks that bypass the perimeter. Stolen credentials are the most common way in.

ITDRSign in monitoringAccount takeover
03Intelligence

Informed by published intelligence

Detection is tuned to the techniques in use, informed by advisories from the NCSC and the US Cybersecurity and Infrastructure Security Agency (CISA), and the security notices from the platforms we run for you, and updated as those change.

NCSC advisoriesCISA advisoriesDetection tuning
04Network

Network and firewall integration

We work with the firewalls you already run, including pfSense, Fortinet, Sophos and Palo Alto, so a confirmed threat is blocked at the network edge as well as on the device.

Firewall integrationBlocking at the edgeVulnerability scanning
Threat detection / 03 · How it works

From signal to contained

Detection only matters if something happens next, and without drowning you in alerts you cannot act on.

01

Monitor

Endpoints, identities and email are watched for the behaviour that gives an attacker away.

02

Detect and triage

Suspicious activity is surfaced and triaged by engineers, who separate signal from noise so nothing important is missed.

03

Contain

A confirmed threat is isolated and shut down quickly, a device quarantined or an account locked, before it can spread.

04

Report

You get a clear account of what happened and what we did, with anything you should change to reduce the risk again.

When detection becomes an incident, there is no handover delay. See incident response for what happens on the worst day.
Threat detection / 04 · The difference

Who watches your systems

Context is what makes monitoring useful. Knowing what normal looks like for your business is how an engineer separates a signal worth acting on from noise.

We run and secure the technology we monitor, so we recognise a problem faster and can act on it directly.

ContextWe know your normalThe team that runs your systems recognises a problem faster.
ActionWe act on what we findA threat is contained directly, by the engineers who already monitor it.
IncludedMDR as standardOn every managed plan, included by default.
FAQ

Common questions

What is managed detection and response?

Managed detection and response, or MDR, is a service that continuously monitors your systems for signs of attack and has engineers investigate and contain what is found. It combines the tools, endpoint and identity monitoring, with the people who act on the alerts. The point is to catch a threat while it is small rather than discover it weeks later.

How is MDR different from antivirus or a firewall?

Antivirus and firewalls are preventative tools that try to keep threats out. MDR assumes some attacks will get past them, so it watches for the signs and responds. It adds two things antivirus cannot: continuous monitoring across endpoints, identities and email, and a human team that triages and contains what it finds.

Is monitoring included or an extra cost?

For our managed clients, managed detection and response is included as standard rather than sold as an add on. If you are not a managed client, we can provide monitoring as a standalone service.

What do you monitor?

Your endpoints (laptops, desktops and servers), your identities (accounts and sign ins), and your email. Detection is tuned using the published advisories from the NCSC and CISA and the security notices from the platforms we run, and we work with the firewalls you already have, including pfSense, Fortinet, Sophos and Palo Alto, so a confirmed bad address can be blocked at the edge.

What happens when you detect a threat?

An engineer triages the signal to rule out a false alarm, then contains it, isolating a device or locking an account before it can spread. If it escalates into a full incident, our incident response team takes over, and because the engineers who monitor your systems are the ones who run them, the handover is immediate. Afterwards you get a clear account of what happened and what to change.

Talk to us about monitoring

Book a consultation to talk through how we would monitor your business, and what good detection looks like for an organisation your size.

Reading, Berkshire  /  MDR as standard for managed clients  /  reply within one working day