InsightMDRSecurity operationsReadiness

MDR is a force multiplier on good operations. It is not a substitute for them.

Managed Detection and Response gives Australian businesses access to security operations capability they usually cannot justify building in-house: after-hours triage, human investigation, proactive hunting, containment guidance and faster response decisions.

The value depends on the environment underneath. MDR performs when endpoints are managed, Microsoft 365 and identity telemetry are available, logs are retained, backups are tested, and someone has authority to act. Without those foundations, MDR still creates alerts, but response remains constrained.

Telemetry / operating model / response
RESPONSE TELEMETRYDETECTRESPOND Sound Operationsmakes MDR workTelemetry SourcesMDR DetectionMDR as Substitutealerts, no actionALERTALERTALERTALERT NO FOUNDATION
MultiplierForce multiplier, not substitute
TriggerOperational exposure, not headcount
SequenceReadiness over urgency
When MDR pays off and when it doesn't

Three questions a buyer should ask before signing

Three questions, three honest answers: what MDR really is, when it pays off for an Australian business, and when it does not yet.

01

What is MDR, really?

Outsourced security operations for organisations that do not have their own mature internal SOC. The important parts are not just monitoring and alerting — they are prioritisation, human review, proactive hunting, investigation, containment, remediation guidance and ongoing reporting. It is a service layer that sits on top of telemetry sources and operating controls. Without those underneath, the service is constrained no matter how good the demo looks.

ThemeOperating model
02

When does MDR pay off?

When several things are true at once: a real out-of-hours security gap, heavy reliance on Microsoft 365, Entra and SaaS, endpoint protection deployed and reporting consistently, logs centralised or routable and retained long enough to investigate, meaningful cost of disruption, and no justification for a full in-house SOC. When most of those are true, MDR solves a real operational problem rather than a hypothetical one.

ThemeReadiness signals
03

When does MDR not yet pay off?

Poor patching, missing or weak MFA, unmanaged endpoints, untested backups, short log retention, and no escalation authority. MDR detects what is happening but cannot fix the structural conditions that allowed it. Buying MDR before fixing the basics produces an expensive way to describe problems the business is still not operationally ready to fix.

ThemeBaseline first
The category mistake

MDR is an operating model, not a product. And not the same thing as the rest of the stack.

Tools
  • “We have an endpoint product”
  • “We have a SIEM”
  • Products, not an operating model
  • Managed well clean, patched, enrolled, recoverable
An operating model
  • “We have a SOC”
  • Prioritisation, human review, hunting
  • Investigation, containment, guidance
  • Sits on telemetry sources and operating controls
The honest readiness checklist

Is the environment ready for the kind of defence MDR provides?

The question is rarely whether cyber risk is real — in 2024, 22 percent of Australian SME owners said their business was impacted by cybercrime (Australian Institute of Criminology 2024 SME survey, cited in ACSC Annual Cyber Threat Report 2024–2025). If most of the first column is true, MDR is probably worth buying now. If two or more in the second are still true, baseline work should usually come first. Headcount is a weak trigger; the better trigger is operational exposure.

MDR is probably worth buying now if
01

Managed endpoints

Credible endpoint telemetry deployed across most devices and reporting consistently.

02

Microsoft 365 and Entra exposure

Used heavily enough that identity and email compromise are material risks.

03

MFA and baseline hardening in place

Including blocking legacy authentication.

04

Logs retained for investigation

Retained or routed for investigation, not just dashboarding.

05

Backups tested

A realistic recovery path documented and validated.

06

Escalation path and authority

A named after-hours escalation path and an authority matrix for containment actions.

07

24×7 need without an internal SOC

The business needs 24×7 triage and cannot justify staffing an internal SOC.

Baseline work should usually come first if
08

Chronic patch backlog

Unsupported systems remain in use, or asset discovery is inconsistent.

09

Weak identity controls

MFA is incomplete, legacy authentication is still tolerated, or Conditional Access is poorly designed.

10

Patchy endpoint management

Personal or unmanaged devices in production use.

11

Unvalidated backups

Not secure, synchronised and tested; restore confidence has not been validated.

12

Short log retention

No routing to centralised storage or analytics.

13

No incident ownership

No one owns incident escalation, communications or post-incident communications.

14

Muddy MSP–client boundary

No agreement on who isolates hosts, disables accounts, restores data or notifies the client.

Where the modern attack path actually runs

If MDR only watches endpoints, it is covering too little of the modern attack path.

Endpoint telemetry still matters, but recent threat reporting consistently shows that a substantial share of detections are now malware-free, with valid-account abuse, credential compromise and edge-device exploitation increasingly central. Microsoft 365 and Entra are where most Australian SMEs live operationally — and where the highest-value modern attacks land: identity compromise, mailbox takeover, OAuth consent abuse, mailbox rule manipulation.

Retention matters as much as coverage. The dwell time on a credential compromise can be weeks; log retention measured in days is incompatible with that timeline.

Where MDR needs visibility
01Endpoint telemetry
02Microsoft 365
03Entra identity signals
04Mailbox and OAuth activity
05Retention for investigation
The split that has to be agreed before buying

MDR is not outsourcing accountability. It is augmenting the operating model.

A common misconception is that buying MDR transfers responsibility for security outcomes to the SOC provider. It does not. ACSC guidance is explicit that organisations must define 24×7 reporting contacts, response roles, containment and remediation responsibilities, communications processes and service-provider arrangements. The SOC monitors and investigates. The customer and the MSP run the operating model around it.

A cyber-first MSP that signs an MDR service into its stack is augmenting the operating model, not abdicating it. The customer experience should be one accountable provider with deeper response capability behind it, not two providers blaming each other while an incident plays out.

Own
Telemetry pipeline and retention
Onboarding status, sensor health, device coverage, log forwarding and retention health.
Baseline hardening and remediation
The SOC describes the problem. The MSP owns the fix.
Authority to act
Who approves isolation, account disablement and mail-flow interruption — agreed and rehearsed.
Communications and stakeholders
When and how incidents reach leadership, regulators, clients and affected parties.
Recovery and post-incident operations
Restore readiness, continuity and cleanup — operations questions, not SOC questions.
Feedback into baseline improvement
Findings feed patching priorities, identity policy changes and Conditional Access tuning.
The Inlight IT view

MDR works best in an environment that can make the service actionable.

Inlight IT's view is that the SOC can investigate and escalate, but the environment still needs managed endpoints, Microsoft 365 and Entra visibility, retained logs, tested recovery, clear containment authority and an MSP or internal team that can remediate what the MDR service finds. If the basics are weak, MDR will surface real issues, but many will be issues the business is not yet operationally ready to fix. If the basics are in place, MDR becomes a genuine force multiplier: alerts are triaged faster, identity and endpoint signals are correlated, containment decisions are made earlier, and findings feed back into hardening, patching and recovery work. The practical question is not “do we need MDR because we are a certain size?” It is “do we have enough exposure, telemetry and operational ownership for MDR to improve our response capability?”

MDR works best when it is introduced into an environment with enough telemetry, baseline hygiene and response authority to make the service actionable.

01

Fix the baseline before buying MDR

02

Buy on exposure, not headcount

03

Agree containment authority up front

04

Feed findings back into hardening

From insight to engagement

Where this is delivered.

The argument on this page — MDR as an operating model that needs good operations underneath it, MDR-grade detection sitting inside an accountable client-facing layer rather than as a separate provider, findings feeding back into baseline improvement — describes how Inlight IT delivers Managed Cyber Security. Where the environment requires fuller security operations depth, the SOC-backed tier of MCS provides it, with Inlight IT remaining the accountable client-facing operating layer.

Managed Cyber Security

Confirm the environment can support response.

Review whether endpoint, identity, telemetry and recovery foundations are ready for MDR.

Discuss Managed Cyber Security