What managed detection and response is, and where it sits inside a managed cyber security service.
Managed detection and response is the continuous monitoring and response capability that turns security tools into a working security operation. Endpoint and identity telemetry is reviewed by analysts around the clock, alerts are triaged and investigated, and confirmed incidents are contained and remediated — not left sitting in a dashboard until someone has time to look.
See the operating flow from telemetry to remediationWhat MDR is, how it works, what it monitors, how it differs from EDR, SIEM and an internal SOC, and where it sits inside a broader managed cyber security service. It is an explainer page. The service that delivers MDR-grade detection and response capability for Australian organisations is Managed Cyber Security, where MDR is the detection-and-response component of a wider operating layer.
Managed detection and response gives an organisation 24/7 threat monitoring, investigation and response capability without building an internal security operations function.
Managed detection and response (MDR) is a cybersecurity service that combines endpoint telemetry, identity monitoring and threat intelligence with human analysts who triage alerts, investigate incidents and coordinate containment and response actions.
The defining characteristic of MDR is that it includes the operational layer behind detection. Security tools generate alerts. MDR is the function that confirms whether an alert represents a real threat, scopes the incident, and takes — or coordinates — the response.
For most Australian organisations, MDR delivers the operational outcomes of a security operations capability without requiring an internal function to be built and staffed. The economics of building an in-house 24/7 detection and response capability do not work for most organisations outside the enterprise segment — covered in detail later on this page.
How MDR works, from telemetry to remediation.
MDR is not a single product. It is a managed service layer that sits on top of endpoint, identity and email tooling. The outcome is continuous monitoring with human expertise behind it, not just automated alerts sent to an IT inbox.
Endpoint agents, identity platform integration (Entra ID, Active Directory) and email telemetry continuously send signals to the MDR platform. Process execution, authentication events, network connections, mailbox activity and file behaviour are all recorded.
Automated detection rules and threat intelligence correlate signals and surface alerts. Human analysts review flagged activity, eliminate false positives, and determine whether an alert represents a genuine threat or a benign event. The client team sees confirmed threats, not raw alert volume.
When a genuine threat is confirmed, analysts investigate the full scope: which systems are affected, what the attacker has done or is attempting to do, and what containment actions are appropriate. The investigation produces a clear operational picture, not just an alert summary.
Response actions range from guided recommendations to direct containment — isolating a compromised endpoint, blocking a malicious process or revoking a compromised credential. The scope of what the MDR provider can do directly versus what requires client action varies between providers and tiers.
Monthly reporting on detection activity, incidents handled and response times — structured for board reporting, insurer submissions and Essential Eight evidence. Reporting feeds posture improvement, not just compliance.
Detection across endpoint, identity, email and edge — matched to where threats actually enter.
Coverage scope varies by environment. Most incidents in Australian environments do not start at the endpoint. They start with a compromised credential, a misconfigured identity permission or an email that bypassed standard controls. Endpoint-only detection misses where many attacks actually begin.
Process execution, network connections, file activity and persistence mechanisms. Works with existing Microsoft Defender for Endpoint, SentinelOne, Sophos and Fortinet deployments where supported, or deploys a new agent where required.
Entra ID and Microsoft 365 monitoring for anomalous authentication, impossible travel, privilege escalation, consent grant abuse and legacy authentication exceptions. Credential compromise is the most common initial access vector for cyber attacks and BEC in Australian environments.
Forwarding rules, impersonation patterns, rogue app consent and unusual send behaviour. Email remains the consistent initial vector for BEC attacks that result in fraudulent payment and data exfiltration.
Edge device and lateral movement visibility for environments with Fortinet or similar platforms. ASD data shows that a majority of high-severity incidents involve compromised infrastructure and network-edge devices rather than direct endpoint compromise.
MDR is a service. EDR is a tool. SIEM is a platform. A SOC is a capability.
EDR, MDR, SIEM and SOC address overlapping but distinct needs. The most important distinction is between tools that generate alerts and services that act on them. Brief positioning below; the dedicated comparison pages go deeper on each.
- EDR (Endpoint Detection and Response) — a tool. Deployed on endpoints to collect process telemetry, network connections and file activity. Detects threats based on behavioural rules and threat intelligence. Enables response actions on the endpoint. Produces alerts that require a human to triage and investigate. Does not provide 24/7 analyst coverage. Acting on the alerts is still on the client. See: MDR vs EDR.
- SIEM (Security Information and Event Management) — a platform. Centralised log aggregation, long-term retention, correlation rules and compliance reporting. Used for audit trails, regulatory reporting and detection across a broad log set. Requires significant ongoing tuning and operational effort. Excellent for compliance and log management. Does not replace active detection and response. See: MDR vs SIEM.
- SOC (Security Operations Centre) — a capability — the people, processes and tooling used to monitor, detect and respond. Can be internal, managed or hybrid. Internal SOC build typically takes 12–24 months, requires 5–8 FTE analysts minimum for genuine 24/7 coverage and carries significant ongoing tooling cost. MDR delivers similar operational outcomes as a managed service. See: MDR vs SOC.
- MDR (Managed Detection and Response) — a service. Typically uses an EDR tool as its detection layer, adds human analyst oversight, and provides 24/7 monitoring, alert triage, incident investigation and guided response. MDR delivers the operational outcome. EDR is one component of the technology stack it operates.
MDR is the detection-and-response component of a broader managed cyber security service.
MDR delivers continuous detection and response capability — the operating layer that ensures security signals are reviewed, triaged and acted on around the clock. For many organisations, that is exactly the capability that is missing, and MDR-grade coverage is what closes the gap.
A broader managed cyber security service includes MDR as one component alongside identity governance, Microsoft 365 security posture management, backup recoverability oversight, security evidence and reporting for insurance and customer due diligence, and escalation and remediation coordination across the wider posture.
For Australian organisations, Inlight IT delivers MDR-grade detection and response capability as part of Managed Cyber Security, the service designed to provide the deeper security operating layer above the managed IT baseline. The Managed Cyber Security service is delivered in two operating tiers — standard, and SOC-backed for environments that require fuller security operations depth, broader telemetry and after-hours response authority.
Most organisations do not look for MDR because they read a vendor whitepaper. They look for it because something in their environment made the gap impossible to ignore.
The need for MDR-level capability usually shows up before a major incident does. The signs are operational. The situations below are the most common triggers.
Essential Eight controls address prevention and recovery. They reduce common attack paths but do not provide visibility into whether those controls are failing or being actively bypassed. An organisation at ML2 without a detection capability has a defensible prevention posture and limited visibility into what is happening in the environment after hours.
Insurers are asking specific questions about continuous threat monitoring, how alerts are triaged and what the incident response process looks like. EDR tools generating alerts into an unmonitored inbox does not satisfy this requirement.
A cyber attack deployment, a compromised account used for weeks without detection, a BEC attack that progressed unnoticed. The discovery that dwell time was measured in days or weeks rather than hours is the common trigger.
Endpoint and identity tools are deployed and producing alerts. The team cannot review them all, prioritise them or investigate the suspicious ones in time. The volume is greater than the available capacity.
General IT, patching and infrastructure are managed. 24/7 security monitoring and incident response are not. MDR fills that gap without replacing the existing IT arrangement.
The person who knows the environment, recognises anomalies and handles incident response informally is leaving. Formalising the capability before that departure rather than after an incident reveals the gap.
If more than one of these situations describes your environment, the detection gap is already operational — the only question is whether it is found before or after an incident.
Test where you stand →The economics of building 24/7 security operations internally do not work for most Australian organisations outside the enterprise segment.
The personnel costs of an internal 24/7 security operations capability alone typically exceed the total cost of managed IT for the same organisation. The full comparison is below.
- Personnel — genuine 24/7 coverage requires 5–8 FTE analysts minimum (one monitored “seat” requires approximately 4 FTE before leave, training and turnover). Personnel costs alone are typically seven figures annually before tooling.
- Tooling — an internal SOC requires EDR platform, SIEM, SOAR, threat intelligence feeds and ticketing integration — significant ongoing annual spend on top of personnel, scaled to environment size.
- Turnover and knowledge risk — security analysts are in high demand. Turnover is significant. Each departure takes environment knowledge with it and requires a replacement hiring and onboarding cycle.
- Time to operational maturity — building an internal function from scratch takes 12–24 months to hire, onboard, tool and reach operational maturity.
- Total cost — for organisations without an existing security operations function to build from, the in-house build is materially more expensive than a managed MDR service.
- Personnel — human analysts are available 24/7 as part of the service, without the organisation hiring, training or managing them.
- Tooling — tooling is provided by the partner. The organisation pays per endpoint rather than licensing and managing the platform independently.
- Turnover and knowledge risk — the service continues regardless of individual analyst changes. Environment knowledge is maintained in the service platform, not in a single analyst's head.
- Time to operational maturity — MDR coverage typically begins within two to four weeks of scope agreement.
- Total cost — MDR scales with environment size rather than carrying fixed headcount overhead.
One internal security engineer supported by a managed MDR service can cover a far larger environment than an internal business-hours-only security function, because monitoring, triage and detection workload is handled continuously as part of the service.
Insurers are asking specific operational questions. MDR provides specific operational answers.
Cyber insurers are asking increasingly specific questions about detection and response capability. Not “do you have antivirus” but “do you have 24/7 monitoring, what is your process for triaging alerts, how quickly can you contain an active threat, and who is responsible for incident response?”
MDR provides a clearer and more credible answer to these questions than endpoint tooling alone. Continuous monitoring is documented. Alert triage is performed by a human analyst. Incident response has a defined workflow with named escalation paths. The organisation can demonstrate that it has detection and response capability in place, not just prevention tools.
This matters beyond premium negotiation. When an incident occurs, the claims process involves demonstrating that the organisation had reasonable security controls in place. MDR produces the evidence trail that supports that case: detection timestamps, alert triage records, response actions taken and incident timeline documentation.
What insurers ask for, that MDR produces:
- 24/7 monitoring evidence — documented analyst coverage across endpoints, identity and email.
- Alert triage and response process — a defined workflow with named analyst responsibility and documented response timelines.
- Incident response capability — the combination of detection capability and response workflow — both required, not one or the other.
- Identity monitoring — credential compromise is the most common entry point for cyber attacks and BEC. MDR providers that include identity monitoring can detect compromised account indicators before they result in an incident.
- Mean time to detect and respond — some insurers now ask for documented MTTD and MTTR figures. MDR providers track these metrics as part of their reporting, which makes them available for submissions.
MDR is the operational layer that sits behind the prevention controls Essential Eight establishes.
MDR is not the Essential Eight framework. It is the supporting operational capability that helps organisations sustain stronger maturity in the areas where continuous monitoring and response readiness matter most.
Essential Eight controls address prevention and recovery. They reduce common attack paths but do not provide visibility into whether prevention is failing or being actively bypassed. MDR provides that visibility — and the response capability behind it.
Where MDR supports Essential Eight:
- Logging and event visibility across endpoints, servers and network devices
- Timely analysis of security events aligned to monitoring and response maturity requirements
- Detection of privilege misuse and unusual account behaviour
- Incident response capability when a prevention control is bypassed or fails
For organisations moving from an Essential Eight assessment into ongoing managed security, the detection and response capability provided by MDR — delivered as part of Managed Cyber Security — is the operational layer that sits behind the prevention controls. Prevention matters. Detection and response are what tell you when prevention has failed.
The Inlight IT view on MDR.
The question for most Australian organisations is not whether they need detection and response capability. It is whether the model they are considering actually delivers response, or just delivers alerts.
Many organisations have endpoint tools that generate alerts. What they lack is someone who investigates those alerts, determines whether they represent a genuine threat, and takes action when they do — specifically at 11pm on a Sunday when the IT team is not at their desk. That is the gap MDR fills. The technology is not the scarce resource. The trained human capacity to act on it at the right moment is.
MDR is most valuable when the team responding to an alert already knows the environment. A service that generates accurate detections but delivers them into the hands of people unfamiliar with the infrastructure, the business or the risk context produces a different outcome than one where the response is handled in close coordination with engineers who know and manage the environment. That continuity between detection and remediation is what makes MDR an operational service rather than a monitoring product.
It is also why Inlight IT delivers MDR as the detection-and-response component of Managed Cyber Security rather than as a standalone service. The detection layer matters. The continuity from detection through to remediation in the live environment is what makes the detection layer worth having.
Continuous monitoring coverage is the benefit. The last-mile response discipline — who acts, how fast, with what authority — is the trade-off.
Questions Australian IT managers and security buyers ask when researching MDR.
What is managed detection and response?
What is the difference between MDR and EDR?
Do we need a SIEM if we have MDR?
Is MDR the same as a security operations centre?
Is MDR worth it compared to building in-house?
How does MDR help with cyber insurance?
Do we need to replace our existing endpoint tools to add MDR?
How is MDR delivered by Inlight IT?
MDR-grade detection and response, delivered as part of Managed Cyber Security.
Confirm what is monitored, escalated and acted on today.
Discuss Managed Cyber Security