Threat detection and response

Managed detection and response combines continuous monitoring of configured systems with investigation and agreed containment actions. Our published full managed plan includes endpoint and identity threat detection and response. Covered systems, human response hours and escalation routes are set out in the service schedule.

Verified
ISO 27001 & 9001Certified by a UKAS-accredited certification body Cyber Essentials & PlusCertification body NCSC AssuredCyber Advisor scheme MicrosoftCertified Expert CISSPHeld by Daniel McClure Fisher

What managed detection and response is

Managed detection and response, or MDR, combines detection tools with a response service. Configured systems generate alerts for investigation, with containment actions such as device isolation or account restriction agreed in advance. Continuous monitoring does not by itself define the hours of staffed response.

What we monitor

The proposal identifies the devices, identities, email services and any network integrations in scope.

01Endpoints

Endpoint detection and response

Continuous monitoring of laptops, desktops and servers for malicious behaviour, and a compromised machine can be isolated before it spreads.

EDRBehaviour analysisDevice isolation
02Identities

Identity threat detection and response

Watching for compromised accounts, suspicious sign ins and the identity attacks that bypass the perimeter. Compromised credentials can expose cloud services as well as individual devices.

ITDRSign in monitoringAccount takeover
03Intelligence

Informed by published intelligence

Detection is tuned to the techniques in use, informed by advisories from the NCSC and the US Cybersecurity and Infrastructure Security Agency (CISA), and the security notices from the platforms we run for you, and updated as those change.

NCSC advisoriesCISA advisoriesDetection tuning
04Network

Network and firewall integration

We work with the firewalls you already run, including pfSense, Fortinet, Sophos and Palo Alto, with blocking at the network edge available where the integration and response permissions are in scope.

Firewall integrationBlocking at the edgeVulnerability scanning

From signal to response

Detection only matters if something happens next, and without drowning you in alerts you cannot act on.

01

Monitor

Endpoints, identities and email are watched for the behaviour that gives an attacker away.

02

Detect and triage

Suspicious activity is surfaced and triaged by engineers, who prioritise investigation according to the agreed severity and response process.

03

Contain

Where authorised and supported, response actions can include isolating a device or restricting an account to limit the spread.

04

Report

You get a clear account of what happened and what we did, with anything you should change to reduce the risk again.

When detection becomes an incident, the escalation follows the agreed incident route. See incident response for what happens on the worst day.

Who watches your systems

Context is what makes monitoring useful. Knowing what normal looks like for your business is how an engineer separates a signal worth acting on from noise.

We run and secure the technology we monitor, so the investigation can draw on the existing configuration, service records and agreed access.

ContextWe know your normalInvestigation draws on the systems and service records already in place.
ActionWe act on what we findEngineers investigate and take the containment actions agreed for the service.
IncludedFull managed planEndpoint and identity detection and response included in the published plan.

Common questions

What is managed detection and response?

Managed detection and response, or MDR, combines continuous monitoring of configured systems with investigation and agreed response actions. Endpoint and identity tools produce alerts that engineers can investigate. Monitoring coverage and staffed response hours are set out in the service schedule.

How is MDR different from antivirus or a firewall?

Antivirus and firewalls are preventative tools that try to keep threats out. MDR assumes some attacks will get past them, so it watches for the signs and responds. It adds two things antivirus cannot: continuous monitoring across endpoints, identities and email, and a human team that triages and contains what it finds.

Is monitoring included or an extra cost?

Endpoint and identity threat detection and response are included in our published full managed plan. Co-managed, standalone monitoring and additional integrations are scoped separately. See our pricing for the current plan; the service schedule defines coverage and human response hours.

What do you monitor?

The agreed scope can cover endpoints (laptops, desktops and servers), identities (accounts and sign ins), and email. Detection is tuned using the published advisories from the NCSC and CISA and the security notices from the platforms we run, and we work with the firewalls you already have, including pfSense, Fortinet, Sophos and Palo Alto, so a confirmed bad address can be blocked at the edge.

What happens when you detect a threat?

An engineer investigates and prioritises the alert through the agreed response process. Authorised actions may include isolating a device or restricting an account. If it becomes a wider incident, the agreed escalation route applies. Afterwards, the record explains what was found, what was done and any recommended changes.

Talk to us about monitoring

Book a consultation to talk through how we would monitor your business, and what good detection looks like for an organisation your size.

Reading, Berkshire  /  monitoring and response scoped in writing  /  reply within one working day