What is MDR (managed detection and response)?
Managed detection and response, or MDR, is a subscription security service in which an outside provider monitors an organization's environment around the clock, triages the alerts it produces, investigates the ones that appear to matter, and escalates them with a severity and a recommended action.
It is security staffing and detection expertise sold as a service, layered on tooling the provider either supplies or operates on your behalf. The provider brings three things: a detection library refined across many customers, a platform to run it on, and a bench of analysts to work the output.
MDR is a service, not a product, which is where most of the confusion comes from. Two providers can use the same description and deliver different things, because coverage and escalation are not standardized terms.
Why does MDR exist?
Attacks do not observe business hours, so detection has to run continuously. Continuous coverage means roughly five to six full-time analysts before anyone takes a holiday, and those analysts are expensive, hard to hire, and prone to leaving after eighteen months of triage work.
For most organizations, that was never realistic to build. MDR turned it into a line item by spreading one analyst bench across many customers. The trade works. The question is what the subscription covers, which is where providers differ most and where the detail is hardest to get before you sign.
What is included in an MDR service?
Every provider lists the first column. Scope differences show up in the second and third columns, and those are usually not on the datasheet.
| Nearly always included | Included, but depth varies widely | Commonly out of scope |
|---|---|---|
| Around-the-clock monitoring | Threat hunting | A real investigation of every alert |
| Alert triage against provider playbooks | Containment actions such as host isolation | Custom detections for your own applications |
| Escalation with severity and a recommendation | Onboarding of standard log sources | Non-standard or bespoke telemetry |
| Periodic reporting and a named contact | An EDR or XDR license bundled in | Remediation beyond a pre-agreed action |
| Defined response time targets | Tuning of the provider's own detections | Tuning the tools you already run |
Read the statement of work, not the datasheet. The middle column is where scope gets negotiated and where change orders come from later.
How does an MDR work?
Four stages, and the volume narrows at every one of them.
Onboard: the supported source list is the coverage list
The provider connects the log sources named in the contract, typically endpoint, identity, email, cloud, and network, often through its own sensor.
Sources outside that list need a new integration or a change order, and until then they are not covered. This stage caps everything that follows, so read the source list first.
Monitor and detect: their detection content, your environment
The provider runs its own detection library against your telemetry continuously. That library is a real asset, refined across a large customer base and updated as threats change.
It is also generic by design. Detections tuned to what is normal across hundreds of environments will not know what is normal in yours, which produces a large share of the false positives that follow.
Triage: a shared bench works a queue
Analysts work incoming alerts against playbooks. Because the bench is shared and finite, a portion of alerts is filtered, suppressed, or auto-closed before a person sees it.
Providers rarely publish what that portion is. Ask directly: of the alerts generated last month, how many received a documented human investigation?
Escalate: where the definition of the word matters
You get a notification. What is in it varies more than any other part of the service, and the gap is easiest to see side by side.
EXAMPLE: A CREDENTIAL STUFFING ALERT
A weak escalation. "Suspicious authentication activity detected on user jdoe. Severity: Medium. Recommend investigating." Your team then pulls the login history, checks which other accounts saw the same source address, and works out whether anything actually happened.
A strong escalation. "Credential stuffing against 14 accounts from a single hosting provider address over 40 minutes. One success, jdoe, followed by creation of an inbox rule forwarding to an external address. Rule removed, session revoked, password reset forced. No lateral movement observed."
Both are called escalations in the contract. One is a finished investigation; the other hands the workup back to the team that bought the service to avoid doing the workup.
How does MDR relate to MSSP, XDR, EDR, and SOC-as-a-Service?
MDR, MSSP, and SOC-as-a-Service are services. XDR and EDR are products. SOC-as-a-Service is used loosely, and in most cases means the same thing as MDR.
| Term | Service or product | What it actually refers to |
|---|---|---|
| MDR | Service | A provider monitors, triages, and escalates on your behalf, using its own detection content and analyst bench. Measured on detection and response outcomes. |
| MSSP | Service | A provider manages security infrastructure such as firewalls, proxies, and log collection, and forwards alerts to you. Broader in scope, shallower on investigation, and the older model. |
| SOC-as-a-Service | Service | Largely used interchangeably with MDR. Where it means anything distinct, it implies a fuller function including compliance reporting and posture work. |
| XDR | Product | Tooling that correlates telemetry across endpoint, identity, email, and cloud so related signals surface as one detection. Frequently the platform an MDR service is delivered on. |
| EDR | Product | Endpoint detection and response tooling. Usually the sensor underneath both of the above. |
MDR vs. MSSP
Both are services, and the distinction is about depth rather than breadth. An MSSP manages security infrastructure and is measured largely on whether that infrastructure is up and configured correctly. Alerts get forwarded. An MDR provider brings its own detection content and analyst bench, and is measured on detection and response outcomes.
The simplest test is what arrives in your inbox. An MSSP typically sends you an alert. An MDR provider typically sends you an alert that a person has already looked at.
MDR vs. XDR
This pair gets conflated constantly, and the two are not comparable things. XDR is a product. MDR is a service.
XDR collects and correlates telemetry across endpoint, identity, email, and cloud so related signals surface as one detection rather than four. MDR is a subscription under which people operate detection and response on your behalf.
They are frequently sold together, because an MDR service is often delivered on top of the provider's own XDR or EDR platform, which is what makes the terms blur. Buying XDR gives you a tool to run. Buying MDR gives you someone to run it, and the tool underneath is usually the provider's choice rather than yours.
How much does MDR cost?
MDR is usually priced per endpoint or per user per month, sometimes per volume of data ingested, and often in tiers that gate response actions and threat hunting behind higher levels. A headline rate means little without knowing which tier and which source count it applies to.
The headline rate is only part of the cost. Four questions surface the rest:
-
What happens to the price when alert volume grows?
Volume growth is normal and continuous. If the price tracks it, the budget is not fixed. -
Does adding a non-standard log source trigger a change order?
This is the most common source of unbudgeted cost in year two. -
Are response actions included or metered?
A service that charges per containment action behaves differently in an incident. -
What happens at renewal?
Introductory pricing and renewal pricing are frequently not the same number.
Two quotes with the same headline rate can differ substantially once coverage and escalation scope are compared. The cheaper service is often cheaper because less reaches a person.
How do you tell MDR providers apart?
Feature lists look much the same across providers. These five do not, and none can be answered from a datasheet. Score them on live cases in your own environment, not on sample reports.
Coverage
What share of our alerts get a real investigation, and what happens to the rest?
Escalations
Is an escalation a complete investigation, or a handoff of work back to us?
Customization
Does the service learn our environment, or ask our environment to adapt to it?
Transparency
Can we read the work, and what do we keep if we leave?
Price at scale
Does the bill track endpoints, ingest, or incidents, and what does growth do to it?
A longer version of this exists as a scored worksheet in the MDR Evaluation Guide, which turns these five into twenty questions you can put to any provider.
What are the limits of MDR?
These are not failures of any one provider. They follow from how the model works, so they apply across the category.
It does not investigate every alert.
This is arithmetic, not effort. A shared analyst bench has finite hours, so some share of alerts is filtered, suppressed, or closed without a documented look. Any service priced on human capacity has this property. The only variable is how much of it the provider will tell you about.
It does not usually act on your behalf.
Most services stop at a recommendation, or at a narrow set of pre-agreed containment actions such as isolating a host. Anything past that waits on your team, which means the clock that matters, from detection to resolution, is only partly under the provider's control.
It does not learn your environment on its own.
Generic detection content is what makes the economics work. The cost is that a service can run for a year and still escalate the same benign internal tool every week, unless someone on your side spends the time to tune it out.
It does not always leave you with the work.
Ask what you keep if you leave. In many services the investigative reasoning lives in the provider's console and walks out the door with the contract, so a team that switches providers starts over rather than carrying its history forward.
Frequently Asked Questions (FAQs)
What is MDR?
MDR stands for managed detection and response. An outside provider monitors your environment around the clock, triages the alerts it produces, and escalates what matters with a severity and a recommended action. It exists because most organizations cannot staff three shifts of analysts.
What is included in an MDR service?
Around the clock monitoring, triage against the provider's playbooks, escalation with a severity and a recommendation, reporting, and a named contact. Threat hunting, containment, and non-standard log sources are usually included but vary in depth. Read the statement of work, not the datasheet.
What is the difference between MDR and MSSP?
An MSSP manages security infrastructure and forwards alerts to you. MDR brings its own detection content and analyst bench, and is measured on outcomes rather than uptime. The simplest test: an MSSP sends you an alert; an MDR provider sends you one a person has already looked at.
What is the difference between MDR and XDR?
XDR is a product, MDR is a service. XDR correlates telemetry across endpoint, identity, email, and cloud so related signals surface as one detection. MDR is people operating detection and response on your behalf. Buying XDR gives you a tool to run; buying MDR gives you someone to run it.
How much does MDR cost?
Usually per endpoint or per user per month, sometimes per volume ingested, and often in tiers that gate response actions and hunting. Ask what happens when alert volume grows, whether a new log source triggers a change order, and what renewal looks like.
Does MDR replace a SOC?
It replaces part of one. MDR covers monitoring, triage, and first-line investigation. It does not usually cover detection engineering for your own applications, incident command, or posture work. MDR absorbs the queue rather than replacing the function.
What does an MDR escalation actually include?
This varies more than any other part of the service. A strong escalation is a finished investigation with root cause, affected assets, and evidence. A weak one is a severity score and a suggestion to look into it. Ask to see real examples before signing.
Can 7AI replace my MDR?
Yes. Some teams bring 7AI in to take over from a provider they already pay for; others run it alongside a SOC of their own. PLAID ELITE is 7AI's managed service: AI agents investigate, respond, and hunt, with 7AI experts on the loop around the clock.
How is PLAID ELITE different from a traditional managed service?
A traditional service scales coverage by hiring, so how many alerts get a real investigation is bounded by bench size. In PLAID ELITE agents do the investigation work, so every alert gets investigated rather than a filtered share. Experts stay on the loop.
Where 7AI fits
7AI's managed service is PLAID ELITE. AI agents investigate, respond, and hunt, and 7AI experts stay on the loop around the clock for the decisions that need a person. Teams use it two ways: to take over from a provider they already pay for, or alongside a SOC they run themselves.
The difference from a people-led service is where the investigation work happens. A shared analyst bench scales by hiring, so the number of alerts that get a real investigation is bounded by headcount, which is what produces the narrowing in the diagram above. When agents do that work the ceiling moves: every alert gets investigated rather than a filtered share, and the first three limits on this page stop applying.
The change does not have to happen all at once. Some teams switch over entirely, some split coverage by use case, and some run both side by side and shift scope as results come in.