Book an Appointment

Managed Detection & Response (MDR)

How to position Managed Detection & Response, choose the right operating and provider model, and integrate the service cleanly into your security organization – from log source onboarding to the SLA.

Last updated: July 2026 · Valeri Milke, ISO 27001 & ISO 42001 Lead Auditor

24/7Monitoring of telemetry from endpoints, identities, network, and cloud
24 hEarly warning under Art. 23 NIS2 after becoming aware of a significant incident
72 hIncident notification under Directive (EU) 2022/2555
4Metrics (MTTD, MTTR, MTTA, MTTC) — only meaningful per severity class

Cyberattacks do not follow office hours – yet in many organizations, detection does. This is exactly the gap Managed Detection & Response (MDR) addresses: an external provider takes over the monitoring, analysis, and active containment of threats as a continuous managed service, complemented by proactive threat hunting. The topic is also gaining regulatory weight: Article 21(2)(b) of the NIS2 Directive (EU) 2022/2555 requires incident handling measures, and the reporting deadlines under Article 23 presuppose fast, reliable detection. This article puts the market terminology in context, describes the service components and metrics, and shows what matters in onboarding, SLAs, and the make-or-buy decision.

The Essentials at a Glance

Six topic blocks — tap to expand.

Make or buy: three operating models

In-house SOC, MDR, or co-managed — regardless of the model, governance, crisis communication, and recovery remain internal responsibilities (NIST SP 800-61 Rev. 3, 2025).

Make
  • Requires continuous shift operations, ongoing detection engineering, and constant upskilling.
  • Given the skills shortage, only some organizations can sustain these efforts over the long term.
shift operationsdetection engineeringupskillingskills shortage

Standards & Sources

The content on this page is based on the following publicly available guides and studies.

Gartner · 2025

Market Guide for Managed Detection and Response Services

Describes MDR generically as remotely delivered, human-led 24/7 SOC functions including containment; referenced here solely to delineate the terminology.

NIST · 2025

NIST SP 800-61 Rev. 3: Incident Response Recommendations and Considerations for Cybersecurity Risk Management

Incident response recommendations finalized in April 2025 as a CSF 2.0 community profile; supersedes Rev. 2 from 2012 and anchors incident handling in risk management.

BSI · 2024

Mindeststandard des BSI zur Protokollierung und Detektion von Cyberangriffen, Version 2.1

Binding logging and detection requirements for Germany's federal administration; also usable by other organizations as guidance on log sources and detection scope.

Amtsblatt der EU / EUR-Lex · 2022

Richtlinie (EU) 2022/2555 (NIS2)

Art. 21(2)(b) requires incident handling measures; Art. 23(4) defines the reporting deadlines (24 h early warning, 72 h notification, final report within one month).

Microsoft · 2026

What Is MDR? Managed Detection and Response (Security 101)

Continuously maintained foundational article without a fixed publication date (year given = as retrieved, July 2026); distinguishes MDR from MSSP, EDR, XDR, and SIEM and describes the process steps of prioritization, hunting, investigation, and containment.

Evaluating MDR for your organization?

In a no-obligation initial consultation, we work with you to determine which operating model fits your organization – from requirements gathering through selection and SLA criteria to onboarding.