MDR (Managed Detection and Response) is a service from an external security team: it collects events from your servers, workstations and networks, investigates suspicious chains and responds to confirmed incidents following a procedure agreed in advance. It differs from antivirus in that it looks for unusual behaviour rather than malicious files, and a human analyst stands behind every alert.
Key takeaways
MDR is sold as a service, not as software: the client gets a working monitoring function with contractual obligations rather than a console full of alerts. There are always three parts inside.
Without the third part the service turns into a stream of alerts nobody reads. It is the human work that separates MDR from a pile of purchased tools.
These words are often used interchangeably although they mean different things: SIEM and EDR are tools, a SOC is a department, MDR and MSSP are ways to buy the work from outside.
| Name | What it is | What it does | Who does the work |
|---|---|---|---|
| EDR and XDR | Software | Collects and analyses events on endpoints; XDR also covers mail, network and cloud | Your specialists |
| SIEM | Software | Stores logs from every system and searches them for suspicious chains using rules | Your specialists |
| SOC | Department | Watches events and responds to incidents on a continuous basis | The company's in-house team |
| MSSP | Service | Operates the security tools: configuration, updates, availability | A contractor |
| MDR | Service | Detects incidents and responds to them, from investigation to isolating a machine | A contractor |
That defines the choice: tools without people produce a stream of alerts, people without tools see no events, and an in-house monitoring centre only pays off at scale. MDR closes the gap between "we have antivirus" and "we have our own monitoring team".
Antivirus protects a specific machine from known malware and works automatically. A monitoring service looks wider.
Example An employee entered a password on a fake page. Antivirus sees no violation: the login used a valid username and password. Monitoring notices something else — a login at three in the morning from an unknown device, followed by an export of the entire customer database. Chains like that are why the service is connected.
Antivirus does not go anywhere: it stays the baseline protection for workstations, while monitoring adds context and human review on top. The common causes of leaks and how they start are covered in our article on personal data breach risks.
Several steps sit between a line in a log and a call to the person on duty, and each of them is worth agreeing with the contractor before connection.
The response procedure is agreed in advance and written into the contract — at the critical moment there is no time left for negotiation.
After that comes the recovery of systems and data: backups, the order of services, the acceptable downtime. We covered it separately in the article on recovering IT systems after failures.
The working mode is the key parameter that drives both the value of the service and its price. Attackers pick the hours when nobody is watching the systems.
A round-the-clock analyst shift is the most expensive option. The middle ground is monitoring during business hours plus automated actions at night: blocking an account, isolating a machine and calling the person on duty following a written scenario.
Choose the mode by the consequences of downtime. If sales or production stopping overnight means lost money and broken commitments, paying for round-the-clock watch makes sense. If the systems are idle at night anyway, business hours with automated reaction to critical events is enough.
Monitoring is sold with the phrase "we watch over your security", and the only way to verify it is the contract. It should answer the following questions.
Check separately that the contractor reports not a count of "attacks repelled" but understandable figures: how many alerts were reviewed, how many were confirmed, how quickly and what was changed in the configuration afterwards.
For most companies monitoring is voluntary, but for part of the market the requirements are set by law. The Law on Cybersecurity No. ZRU-764 of 15 April 2022 has been in force since 17 July 2022, and the authorised body in this area is the State Security Service.
Owners of critical information infrastructure must notify the authorised body about incidents and assist in detecting cyberattacks. The procedure is set by resolution PP-167 of 31 May 2023 with its annexes on the procedure for securing such facilities and the general requirements for them. Government bodies without their own cybersecurity unit may engage only contractors from a dedicated register — we wrote about that rule in the article on penetration testing.
Personal data is another question. A monitoring contractor sees the logs, and the logs contain employee names, mail addresses and actions on customer records. Such a transfer falls under the Law on Personal Data No. ZRU-547: the scope of the data, the purpose and the contractor's duties are described in the contract, while liability towards customers stays with the company.
The price depends on the number of nodes and event sources, the working mode and which actions the contractor performs on its own. Count it together with the cost of downtime: a day of stopped sales is often more expensive than a month of monitoring.
At Syntra Systems this is the monitoring and response service — from $800 per month. We set up event collection from servers, networks and workstations, define what counts as suspicious in your particular infrastructure, run monitoring and response under an agreed procedure, send a clear report on what happened and what we did, and re-check the protection every quarter.
We do not use the term MDR on our service pages: the scope and the mode are described plainly and fixed in the contract. If it is unclear where to start, it is more sensible to order a security audit from $1,200 first — it shows what should be connected to monitoring in the first place. The full scope is on our cybersecurity for business page, and how to build roles and procedures around it is covered in the article on implementing an ISMS.
Let’s discuss your project
Tell us what you need, and we will estimate the timeline and cost and suggest a solution.
Antivirus stays: it protects individual workstations and blocks known malware on its own. Monitoring adds something different — watching the whole infrastructure, connecting events across different systems, and having a live analyst investigate every suspicious chain of events.
SIEM is software: it stores logs and searches them for suspicious chains using rules, but your own specialists have to operate it. MDR is a service that includes the tools, the analysts and contractual commitments on response times.
A single point of contact is enough: someone who approves actions, makes the business decisions and knows who to wake at night. The service team brings the detection and analysis expertise, but decisions to stop systems remain with the company.
Mass attacks do not pick victims by size: scanners work through available addresses one after another, and a login with a stolen password looks the same in a company of ten and of a thousand. Small companies are usually less protected and therefore an easier target.
The price depends on the number of nodes and event sources, the working mode and which actions the contractor performs on its own. At Syntra Systems monitoring and response under an agreed procedure costs from $800 per month, and a security audit from $1,200.
System logs, and those contain employee names and accounts, mail addresses, device addresses and actions on customer records. This is personal data, so its scope, the purpose of the transfer, the retention period and the contractor's duties must be set out in the contract.
For most companies it is not. Specific duties apply to owners of critical information infrastructure under the law on cybersecurity and resolution PP-167: they notify the authorised body about incidents and assist in detecting cyberattacks.