MDR

Managed Detection and Response

Verwaltete Erkennung und Reaktion

MDR is not a product but a service: a specialised provider operates detection and response for an organisation, combining technology with human analysts and taking over triage, investigation and initiated countermeasures. MDR closes the gap between „we bought tools“ and „someone evaluates the alerts around the clock“. It is the operated answer to the cybersecurity skills shortage.

History. The term Managed Detection and Response was coined around 2016 by Gartner to capture a new provider category: service providers that do not merely supply tools but actively detect and respond. The background was the realisation that many organisations procure technology but possess neither the team nor the processes to operate it effectively. Facts. MDR typically comprises continuous monitoring, analyst-run triage, threat intelligence, threat hunting and a defined response up to containment. The distinction: MDR is outcome-oriented (detection and response as a service), whereas a classic SOC describes the organisational unit and pure SIEM only the technology. Quality differences lie in response times, depth of investigation and how far the provider is actually permitted to intervene. Outlook & recommendation. For most mid-sized organisations, MDR is the pragmatic route to NIS2-compliant detection and response capability without building an in-house SOC. In comparing providers, the contractually assured scope of response matters more than the technology promise. In the XIEM model, MDR corresponds to the middle tier, Orchestrate, which builds on the Sentry foundation.
MDR — Managed Detection and Response