Glossary · simply explained

MDR (Managed Detection and Response)

Managed detection and response (MDR) is an operating model: a provider monitors the environment around the clock, assesses alerts, actively hunts for threats and responds to incidents — with defined authority up to containment, such as isolating affected systems.

MDR answers a staffing problem: detection technology like EDR or XDR only delivers value when someone evaluates the alerts promptly — at night, on weekends, during holidays. That is exactly the gap the service fills.

What an MDR service delivers

  • 24/7 monitoring and triage of alerts from EDR/XDR and further sources.
  • Threat hunting: active search for attack traces beyond automatic alerts.
  • Response following an agreed playbook — from recommendation to direct containment.
  • Regular reports, lessons learned and hardening recommendations.

MDR, MSSP or your own SOC?

The lines blur, but the distinction helps: a classic MSSP operates security platforms and rulesets; MDR focuses on the detection and response chain with analysts in shifts; your own SOC bundles all of that internally — at the price of several full-time roles and permanent training. For most mid-sized companies MDR is the fastest path to real 24/7 response capability, often combined with an MSSP for platform operations.

Frequently asked questions about MDR (Managed Detection and Response)

What is the difference between MDR and MSSP?

An MSSP operates security platforms — firewall, WAF, Zero Trust — as ongoing operations. MDR focuses on detection and response: analysts monitor, assess and act 24/7. In practice both roles complement each other and sometimes come from one provider.

Does an MDR provider actively intervene in my systems?

Depending on the agreement: anything from pure alerting with recommendations to active containment — isolating hosts, locking accounts — can be defined. Serious contracts specify authority, approvals and liability precisely before an emergency occurs.

Do I need EDR before MDR?

Usually the MDR service brings a detection platform or builds on existing EDR/XDR. What matters is the telemetry base: without visibility into endpoints, identities and network, even the best analyst can detect little.

What does threat hunting mean in MDR?

Threat hunting is the active, hypothesis-driven search for attack traces that no automatic rule has flagged — such as unusual login patterns or rare process chains. Good MDR services hunt regularly instead of only waiting for alerts.

How fast does an MDR service react?

Guaranteed triage times in the minute range for critical alerts, around the clock, are common. More important than raw response time is quality: how quickly does an alert become a confirmed assessment with containment under way?

From term to implementation: KAEMI supports you from the first assessment to the ongoing managed service.