Cyber Security & Compliance
Managed detection and response
Detection without response is a notification. MDR is the part where someone acts on it, at whatever hour it happens.
What MDR actually does
Endpoint and identity telemetry is collected continuously and analysed for the behaviours that indicate compromise — unusual sign-in patterns, privilege escalation, credential dumping, encryption activity, lateral movement. When something genuine is found, the response is to contain it: isolate the device, disable the account, stop the process.
The distinction from antivirus is that MDR looks for behaviour rather than known files, which is what catches an attack using legitimate tools and stolen credentials — currently the most common pattern by a wide margin.
Why the 24/7 part is not optional
Intrusions are disproportionately actioned outside business hours, for the obvious reason. An alert raised at 2am and read at 8:30am has given an attacker six and a half hours of uninterrupted time in your environment — which, with modern tooling, is more than enough to reach backups.
This is also where a security product bought and left running fails most clearly. The licence is current, the dashboard is green, and nobody is on the other end of the alert.
What you get in writing
- Containment actions taken, with timestamps, for anything genuine
- An incident write-up for anything with real consequence — what happened, what we did, what stops it recurring
- Monthly detection summary as part of service reporting
- Remediation tracked into the roadmap rather than closed and forgotten
Common questions
Is this the same as antivirus?
No. Antivirus blocks known-bad files. MDR watches behaviour across endpoints and identities and has humans who respond. You want both; only one of them catches a credential-based attack.
Can you isolate a machine without asking us?
For genuine active compromise, yes — that authority is agreed in writing during onboarding, because asking permission first is how a containable incident becomes a recovery project. Every action is logged and reported.
Related
Book a Technology Review.
One to two hours onsite, across support, cyber posture, backup and recovery, infrastructure, Microsoft 365 and where the organisation is heading. You receive a written findings report within five days — prioritised risks, quick wins and gaps, in writing.
$1,500 including GST. Credited in full against your engagement if you proceed.
The report is yours to keep regardless of what you decide to do next.
The 90-day guarantee. Give us 90 days. If you're not satisfied with our service in that time, cancel and we'll refund our fees. You keep the audit, the report and every improvement we've made. Third-party hardware, licences and subscriptions purchased on your behalf are excluded. Full terms
