Managed detection and response
Also known as MDR
A service where an outside team watches your security alerts around the clock and responds to real threats on your behalf.
Detection tooling produces alerts continuously, and most attacks progress outside business hours precisely because nobody is watching. MDR closes that gap by putting analysts behind the tooling at all hours, with authority to contain a threat rather than just email you about it.
The distinction worth checking when buying is whether the provider actually responds or only notifies. A service that sends an alert at 3am and waits achieves very little that the tool did not already do.
Where this comes up
Managed detection and response sits inside our cybersecurity and threats work. If you are trying to work out what this means for your own environment rather than in the abstract, that is the page worth reading next, and a short call will get you a straight answer faster than either.