What is MDR? Managed Detection and Response explained

Managed Detection and Response (MDR) is the common name for a service that detects attacks, investigates them and responds, including isolating compromised systems. MDR is neither a tool nor a platform, but a contract with defined response duties. At ANOMAL, this service is part of SOC as a Service.

All

How this compares to neighbouring topics

This page defines MDR as a service. How SOC, SIEM, EDR, XDR and MDR differ overall is covered in the terms overview. For the underlying detection platform, see What is XDR. For the fundamentals of the operating unit, read What is a SOC. As a full offering, SOC as a Service Switzerland covers platform, team and response together.

Short definition

MDR combines detection telemetry (endpoint, identity, cloud), an analyst team and contractually defined response commitments. The provider takes over triage, investigation, containment and recovery coordination. You receive a clear outcome: the provider contains and documents the incident.

The short version

MDR is detection and response as an outcome, not as a tool.

What MDR covers

  • 24/7 monitoring across endpoint, identity and cloud telemetry
  • Triage and investigation with context beyond alert forwarding
  • Active response including endpoint isolation and account lockout per playbook
  • Response times per severity, shown separately as contractual commitments and typical performance
  • Monthly reporting with clear KPIs and documented measures
  • Handoff to your IT for recovery, coordinated by the MDR team

What MDR is not

MDR is not a plain EDR subscription and not a replacement for your IT. Pure monitoring without response duties is platform operation; whether that suffices depends on who steps in during an incident. The terms overview shows how the concepts relate.

MDR in Switzerland

If you fall under FINMA, DORA or NIS2, you need documented response that plain alerts do not provide. The mandate is what counts: response in a shared mandate means the SOC team contains incidents without round trips wherever the playbook scope allows. If you want platform, analysts and response from one source, choose SOC as a Service Switzerland, which includes MDR services.

Frequently asked questions

Is MDR the same as a SOC?

A SOC is an operating unit; MDR is a service contract. An MDR provider runs a SOC internally and sells you the outcome it delivers.

Does MDR only cover endpoints?

Modern MDR covers endpoint, identity and cloud. Endpoint-only response was the origin of the category but is the exception today.

How fast does an MDR team respond in an incident?

Responsible providers report response times per severity, split between contractual commitment and typical performance. At ANOMAL, critical cases are contractually under 60 minutes, typically under 15 minutes.

Can we keep our own tools or does MDR require a specific stack?

Both models exist. Many providers work with your existing EDR and identity stack, others bring their own tools. At ANOMAL you keep your tools; we remove nothing and bolt nothing on.

What do I measure to check MDR quality?

Response time per severity, automatically isolated endpoint counts, documented response actions per month and the false-positive rate after triage.