Syntra Systems
Cases Services Products About Blog IT Caravan
+998 70 010 68 44 +7 999 900 22 12
RusEngUzb
A building wall at night with a surveillance camera and duty lamps, an image of watching infrastructure outside business hours
Security

MDR: Security Monitoring and Incident Response

By Nikita Zhulin · · 7 min read · updated

MDR (Managed Detection and Response) is a service from an external security team: it collects events from your servers, workstations and networks, investigates suspicious chains and responds to confirmed incidents following a procedure agreed in advance. It differs from antivirus in that it looks for unusual behaviour rather than malicious files, and a human analyst stands behind every alert.

Key takeaways

  • MDR is a service from an external security team: it collects events from your systems, investigates suspicious chains and responds to confirmed incidents.
  • SIEM and EDR are software, a SOC is your own department, MDR and MSSP are ways to buy the work from outside; confusing them is expensive.
  • The key contract parameter is the working mode: around the clock or agreed hours, and what happens to alerts outside them.
  • The median time an attacker stays unnoticed inside a network is 14 days according to the M-Trends 2026 report.
  • At Syntra Systems monitoring and response under an agreed procedure costs from $800 per month, and a security audit from $1,200.

What MDR is and what the service consists of

MDR is sold as a service, not as software: the client gets a working monitoring function with contractual obligations rather than a console full of alerts. There are always three parts inside.

Without the third part the service turns into a stream of alerts nobody reads. It is the human work that separates MDR from a pile of purchased tools.

MDR, SIEM, EDR, XDR, SOC and MSSP: the difference

These words are often used interchangeably although they mean different things: SIEM and EDR are tools, a SOC is a department, MDR and MSSP are ways to buy the work from outside.

NameWhat it isWhat it doesWho does the work
EDR and XDRSoftwareCollects and analyses events on endpoints; XDR also covers mail, network and cloudYour specialists
SIEMSoftwareStores logs from every system and searches them for suspicious chains using rulesYour specialists
SOCDepartmentWatches events and responds to incidents on a continuous basisThe company's in-house team
MSSPServiceOperates the security tools: configuration, updates, availabilityA contractor
MDRServiceDetects incidents and responds to them, from investigation to isolating a machineA contractor

That defines the choice: tools without people produce a stream of alerts, people without tools see no events, and an in-house monitoring centre only pays off at scale. MDR closes the gap between "we have antivirus" and "we have our own monitoring team".

How MDR differs from antivirus

Antivirus protects a specific machine from known malware and works automatically. A monitoring service looks wider.

Example An employee entered a password on a fake page. Antivirus sees no violation: the login used a valid username and password. Monitoring notices something else — a login at three in the morning from an unknown device, followed by an export of the entire customer database. Chains like that are why the service is connected.

Antivirus does not go anywhere: it stays the baseline protection for workstations, while monitoring adds context and human review on top. The common causes of leaks and how they start are covered in our article on personal data breach risks.

How monitoring works: from an event to an alert

Several steps sit between a line in a log and a call to the person on duty, and each of them is worth agreeing with the contractor before connection.

  1. Inventory: what gets connected to monitoring and which systems count as critical.
  2. Event collection: agents on servers and workstations, logs from network equipment, mail and cloud services.
  3. Normalisation: records from different systems are brought to a common format and clocks are synchronised across servers, otherwise no chain can be assembled.
  4. Detection rules: they are written in terms of the open MITRE ATT&CK knowledge base, where adversary techniques are collected from real observations.
  5. Tuning to your infrastructure: the first weeks go into telling normal work from an anomaly and removing false positives.
  6. Analyst review: confirming or dismissing the alert, assessing the scale and starting the response.

What happens during an incident

The response procedure is agreed in advance and written into the contract — at the critical moment there is no time left for negotiation.

  1. Confirming the incident and assessing the scope: which machines and accounts are affected.
  2. Isolation: infected machines are cut off from the network, compromised accounts are blocked.
  3. Notifying the people responsible on the client side through pre-agreed channels, including a backup one.
  4. Collecting data for the investigation — before restoration starts and the traces are overwritten.
  5. Bringing systems back and removing the cause, not only the symptom.
  6. A post-incident review: what worked, what did not and which rules need to change.

After that comes the recovery of systems and data: backups, the order of services, the acceptable downtime. We covered it separately in the article on recovering IT systems after failures.

Around the clock or business hours: choosing the mode

The working mode is the key parameter that drives both the value of the service and its price. Attackers pick the hours when nobody is watching the systems.

A round-the-clock analyst shift is the most expensive option. The middle ground is monitoring during business hours plus automated actions at night: blocking an account, isolating a machine and calling the person on duty following a written scenario.

Choose the mode by the consequences of downtime. If sales or production stopping overnight means lost money and broken commitments, paying for round-the-clock watch makes sense. If the systems are idle at night anyway, business hours with automated reaction to critical events is enough.

What to fix in the contract

Monitoring is sold with the phrase "we watch over your security", and the only way to verify it is the contract. It should answer the following questions.

Check separately that the contractor reports not a count of "attacks repelled" but understandable figures: how many alerts were reviewed, how many were confirmed, how quickly and what was changed in the configuration afterwards.

What Uzbek law requires

For most companies monitoring is voluntary, but for part of the market the requirements are set by law. The Law on Cybersecurity No. ZRU-764 of 15 April 2022 has been in force since 17 July 2022, and the authorised body in this area is the State Security Service.

Owners of critical information infrastructure must notify the authorised body about incidents and assist in detecting cyberattacks. The procedure is set by resolution PP-167 of 31 May 2023 with its annexes on the procedure for securing such facilities and the general requirements for them. Government bodies without their own cybersecurity unit may engage only contractors from a dedicated register — we wrote about that rule in the article on penetration testing.

Personal data is another question. A monitoring contractor sees the logs, and the logs contain employee names, mail addresses and actions on customer records. Such a transfer falls under the Law on Personal Data No. ZRU-547: the scope of the data, the purpose and the contractor's duties are described in the contract, while liability towards customers stays with the company.

What it costs and how we work

The price depends on the number of nodes and event sources, the working mode and which actions the contractor performs on its own. Count it together with the cost of downtime: a day of stopped sales is often more expensive than a month of monitoring.

At Syntra Systems this is the monitoring and response service — from $800 per month. We set up event collection from servers, networks and workstations, define what counts as suspicious in your particular infrastructure, run monitoring and response under an agreed procedure, send a clear report on what happened and what we did, and re-check the protection every quarter.

We do not use the term MDR on our service pages: the scope and the mode are described plainly and fixed in the contract. If it is unclear where to start, it is more sensible to order a security audit from $1,200 first — it shows what should be connected to monitoring in the first place. The full scope is on our cybersecurity for business page, and how to build roles and procedures around it is covered in the article on implementing an ISMS.

Let’s discuss your project

Tell us what you need, and we will estimate the timeline and cost and suggest a solution.

Discuss security monitoring

Frequently asked questions

If we connect monitoring and response (MDR), do we still need antivirus?

Antivirus stays: it protects individual workstations and blocks known malware on its own. Monitoring adds something different — watching the whole infrastructure, connecting events across different systems, and having a live analyst investigate every suspicious chain of events.

How does MDR differ from SIEM?

SIEM is software: it stores logs and searches them for suspicious chains using rules, but your own specialists have to operate it. MDR is a service that includes the tools, the analysts and contractual commitments on response times.

Do we need in-house security specialists to use monitoring?

A single point of contact is enough: someone who approves actions, makes the business decisions and knows who to wake at night. The service team brings the detection and analysis expertise, but decisions to stop systems remain with the company.

Our company is small — is anyone even interested in us?

Mass attacks do not pick victims by size: scanners work through available addresses one after another, and a login with a stolen password looks the same in a company of ten and of a thousand. Small companies are usually less protected and therefore an easier target.

How much does security monitoring cost?

The price depends on the number of nodes and event sources, the working mode and which actions the contractor performs on its own. At Syntra Systems monitoring and response under an agreed procedure costs from $800 per month, and a security audit from $1,200.

What data does a monitoring contractor see?

System logs, and those contain employee names and accounts, mail addresses, device addresses and actions on customer records. This is personal data, so its scope, the purpose of the transfer, the retention period and the contractor's duties must be set out in the contract.

Is monitoring mandatory under Uzbek law?

For most companies it is not. Specific duties apply to owners of critical information infrastructure under the law on cybersecurity and resolution PP-167: they notify the authorised body about incidents and assist in detecting cyberattacks.

Read also