Managed Detection & Response
Detect and respond to the threats that matter in minutes.
Named analysts watching your environment around the clock. Every incident triaged within 15 minutes, critical incidents contained within an hour.
What is Managed Detection and Response?
A team of analysts watching your alerts, day and night.
Your tools probably already spot most things. Endpoint protection flags an odd process, the firewall logs a connection nobody recognises, someone signs in from a country you don’t operate in. That part works.
What a tool can’t tell you is which of those is worth getting out of bed for. That takes someone who knows your environment, knows what a normal Tuesday looks like on your network, and is allowed to act without waiting for a meeting.
So you’re buying two things. The hours nobody on your team wants to work, and the judgement to use them well.
Nobody installs MDR. You agree in advance what we can do without waking you, and then we do it.
The in-house problem
Four reasons teams stop trying to run it themselves.
Almost everyone we talk to already has tools in place. What they don’t have is a way to monitor them overnight, at weekends and over bank holidays, when the one person who understands the environment is asleep.
One person on call is not a rota
A proper rota means hiring a team to monitor your environment 24/7/365, and holding on to those people. One person with a phone by the bed is not the same thing.
Incident response is a specialism
Spotting something wrong is the easy half. Shutting it down at speed, without taking the business offline, is a skill most IT teams have never had to use and would rather not learn on the fly.
The signals are scattered
Endpoint, network, cloud and identity tools each send signals. But an attack that looks insignificant in any one of them is often obvious across all four, but only if somebody is reading all four at once.
Cyber is not what you were hired for
You were hired to make the business work better. Every hour you spend sorting alerts is an hour you are not spending on value-added work, and nobody is measuring you on the alerts.
How it works
Agreed in advance, so nobody is improvising at 3am.
The service is designed around a central objective - when something happens, the decisions should already have been made. What counts as critical, who gets called, and what we are permitted to do without asking are all agreed before we start.
-
01
Onboarding and service design
We agree the categorisation and prioritisation matrix, the SLAs attached to each level, and the escalation paths. This is also where we establish what your environment looks like and what normal is for you.
-
02
Battle cards
Our rules of engagement, agreed with you in writing. They set out exactly what we can contain on your behalf without waiting for approval, and what always needs a conversation first. They are rehearsed and revisited, not filed.
-
03
Telemetry connected
We work with the tooling you have: endpoint, SIEM, cloud, identity. Sources are integrated and tuned so that what reaches an analyst is worth an analyst's time.
-
04
24/7 triage
Alerts are triaged within 15 minutes of receipt, every hour of every day, by named analysts who know your environment rather than whoever is next in a queue.
-
05
Investigation and containment
Where something is real, it is investigated and contained inside the agreed rules. Critical incidents are contained within an hour of the threat being confirmed.
-
06
Reporting and service review
Monthly reporting within five working days of month end, and a service review where the incidents, the near misses and the recommendations are discussed in language your board will follow.
Clear commitments
Timings you can hold us accountable for.
What we commit to
- Alert triage
- Critical incident containment
- Customer escalation
- Monthly reporting
- Service review sessions
When
- Within 15 minutes of receipt
- Within 1 hour of a confirmed threat
- Via paths agreed during onboarding
- Within 5 working days of month end
- Quarterly, or as requested
These are contractual, agreed during onboarding, and reported against every month. Most providers will tell you they respond quickly, but is what is guaranteed in the SLA that counts.
Who is watching
Named analysts, not a ticket queue.
Your service is delivered by a named team of at least seven analysts, supported by security engineers, incident responders, threat intelligence specialists and a service manager. You know who they are, and they know your environment.
7+
Named analysts on your account
8
Cybersecurity and IT qualifications each, on average
7
Years with Talanos, on average
24/7
Cover across multiple time zones
- SOC Analysts
- Threat Intelligence Experts
- Security Engineers
- Incident Responders
- Service Managers
- Dedicated Account Manager
Long tenure is the part that matters most and the part nobody advertises. An analyst who has watched your environment for three years recognises the thing that is slightly wrong. A new one on a rota reads it as normal.
Two services, one question
The difference isn’t how fast we respond, it’s what happens before and after.
These two services overlap in many ways, but only one focuses on continuous improvement. The response times are identical.
Managed Detection & Response
Find threats and stop them.
- 24/7 monitoring and alert triage
- Investigation and containment within agreed rules
- SIEM, endpoint, cloud and identity telemetry
- Monthly reporting and service review
- 15-minute triage, 1-hour containment
Managed SOC
Reduce how often a breach occurs.
- Everything in MDR
- Deeper investigation: artifact analysis and forensics
- Threat intelligence, contextualised to your sector
- Continuous threat exposure management and control validation
- 15-minute triage, 1-hour containment
Start with MDR if you need coverage and containment now. Move to a Managed SOC when the question changes from whether you are being attacked to whether you are getting better.
Delivery models
EDR, XDR and MDR: what is the difference?
EDR and XDR are not alternatives to MDR. They describe where the detection data comes from, not what happens to it afterwards.
Managed EDR monitors your endpoint platform: Defender, SentinelOne, CrowdStrike or similar. It suits organisations whose risk is concentrated on laptops and servers.
Managed XDR brings endpoint together with network, cloud and application telemetry, so an attack can be recognised by its behaviour across the whole environment rather than in one tool.
Both are delivered by the same analysts, under the same SLAs, as part of MDR. Which one fits depends on what you run and where your risk is concentrated, and that is a conversation rather than a decision you need to make before contacting us.
Questions we are asked
What buyers ask before they get started.
What does MDR stand for?
Managed Detection and Response. It means a third-party team monitoring your security tooling around the clock, deciding which alerts represent real threats, and containing the ones that do.
How is MDR different from just buying a security tool?
A tool generates alerts. It cannot tell you which of them matters in your environment, and it cannot act at three in the morning. MDR is the analysts, the process and the agreed authority to respond.
Does it work with the security tools we already have?
Yes. We are tool-agnostic and work with what you have deployed across endpoint, SIEM, cloud and identity. If your tooling has gaps we will tell you, but replacing it is not a precondition of starting.
What happens during an incident?
It depends on what you have agreed with us. During onboarding we write battle cards: the rules of engagement setting out what we can contain without asking, and what always requires a conversation first.
In an incident we follow those rules, contain within the agreed SLA, and escalate through the paths you specified.
What are your SLAs?
All security events are triaged within 15 minutes of receipt. The highest priority incidents are contained within an hour of the threat being confirmed.
The categorisation and prioritisation matrix, and the SLAs attached to each level, are agreed with you during onboarding rather than imposed.
Do you take your own security seriously?
Talanos is ISO 27001 and ISO 9001 certified and has held Cyber Essentials Plus for several years, which includes testing of our own controls. Controls outside those frameworks are maturity assessed against NIST CSF v2.0 with reference to NIST 800-53 rev 5.
Customers can request our security maturity assessments under NDA.
Ready to talk
Talk to our team about finding the right mananged detection and response model for your organisation.
A conversation, not a pitch. We will tell you where the gaps are, what MDR would and would not cover, and whether you need a Managed SOC instead.