Managed Detection & Response refers to remotely delivered, analyst-led SOC functions: continuous monitoring, investigation, and active containment of threats – this is also how analyst firms such as Gartner frame it in their Market Guides. Traditional Managed Security Service Providers (MSSPs), by contrast, primarily operate security infrastructure, monitor events, and forward alerts to the internal team; the actual response usually remains with the customer. "SOC-as-a-Service" is used inconsistently in the market and typically means a subscription-based external security operations center including platform and staff – in practice, this overlaps heavily with MDR. What matters is therefore not the label but the contractually guaranteed capability: who detects, who investigates – and who is allowed to intervene?
Managed Detection & Response (MDR)
How to position Managed Detection & Response, choose the right operating and provider model, and integrate the service cleanly into your security organization – from log source onboarding to the SLA.
Cyberattacks do not follow office hours – yet in many organizations, detection does. This is exactly the gap Managed Detection & Response (MDR) addresses: an external provider takes over the monitoring, analysis, and active containment of threats as a continuous managed service, complemented by proactive threat hunting. The topic is also gaining regulatory weight: Article 21(2)(b) of the NIS2 Directive (EU) 2022/2555 requires incident handling measures, and the reporting deadlines under Article 23 presuppose fast, reliable detection. This article puts the market terminology in context, describes the service components and metrics, and shows what matters in onboarding, SLAs, and the make-or-buy decision.
The Essentials at a Glance
Six topic blocks — tap to expand.
Make or buy: three operating models
In-house SOC, MDR, or co-managed — regardless of the model, governance, crisis communication, and recovery remain internal responsibilities (NIST SP 800-61 Rev. 3, 2025).
- Requires continuous shift operations, ongoing detection engineering, and constant upskilling.
- Given the skills shortage, only some organizations can sustain these efforts over the long term.
- Delivers a rapid maturity leap at predictable cost.
- But reduces direct control over detection logic and prioritization.
- The organization retains ownership of the SIEM or data platform.
- The provider supplies 24/7 analysis and response.
Standards & Sources
The content on this page is based on the following publicly available guides and studies.
Market Guide for Managed Detection and Response Services
Describes MDR generically as remotely delivered, human-led 24/7 SOC functions including containment; referenced here solely to delineate the terminology.
NIST SP 800-61 Rev. 3: Incident Response Recommendations and Considerations for Cybersecurity Risk Management
Incident response recommendations finalized in April 2025 as a CSF 2.0 community profile; supersedes Rev. 2 from 2012 and anchors incident handling in risk management.
Mindeststandard des BSI zur Protokollierung und Detektion von Cyberangriffen, Version 2.1
Binding logging and detection requirements for Germany's federal administration; also usable by other organizations as guidance on log sources and detection scope.
Richtlinie (EU) 2022/2555 (NIS2)
Art. 21(2)(b) requires incident handling measures; Art. 23(4) defines the reporting deadlines (24 h early warning, 72 h notification, final report within one month).
What Is MDR? Managed Detection and Response (Security 101)
Continuously maintained foundational article without a fixed publication date (year given = as retrieved, July 2026); distinguishes MDR from MSSP, EDR, XDR, and SIEM and describes the process steps of prioritization, hunting, investigation, and containment.
Related Services
Evaluating MDR for your organization?
In a no-obligation initial consultation, we work with you to determine which operating model fits your organization – from requirements gathering through selection and SLA criteria to onboarding.