MDR (Managed Detection and Response)
Last updated
Definition
Managed detection and response (MDR) is a service in which an outside provider's security analysts monitor EDR telemetry from your clients' endpoints 24/7, investigate alerts, and take containment actions – isolating a host, disabling an account, killing a process – on your behalf. EDR is the tool on the endpoint; a SOC is the team of analysts; MDR is the packaged service that combines both, sold per endpoint, so you get the team without hiring it.
Why it matters to an MSP
MDR is standard in the MSP stack because of staffing math. Round-the-clock coverage takes eight to twelve analysts before tooling, roughly $1M or more per year fully loaded, which does not pencil until you manage several thousand endpoints. Attackers know this and deliberately act on Friday nights and holiday weekends. Resold MDR buys that coverage at a marginal cost of roughly $3–15 per endpoint per month as of 2026, and it is typically marked up two to three times inside a security tier at $25–50 per user per month.
MDR also changes what you can promise. An incident response plan that starts "when the client calls us" is a plan to lose data; with MDR the first response happens before anyone on your team is awake, and your role shifts to the investigation and recovery that follows. Decide up front whether the provider has pre-authorized response – isolating a client's server without asking – or click-to-approve, and put that choice in the contract; a wrongly isolated production host at 2 a.m. is a conversation to have in advance. MDR is on most cyber insurance minimum-controls lists alongside MFA and immutable backup. How it fits with your other monitoring is in MSP security operations.
Related terms: EDR, SOC, Cyber Insurance, Ransomware