- Service
- MDR — managed detection & response
- Coverage
- 24/7 detection
- Sources
- M365, endpoint, cloud, network
- Escalation
- Named contact, direct line
What MDR actually means here
Managed detection and response — MDR — is the shorthand most buyers now use, and it is a fair description of what we deliver: someone else runs the detection, triages what it produces, and tells you when something is real.
We deploy and tune detection across the places attacks actually surface — Microsoft 365 and Entra ID, endpoints, cloud platforms and network perimeter — and we triage what comes out of it, so you hear about the things that matter and not about the other four thousand events.
Tuning is the work
Any monitoring platform will generate alerts on day one. The difference between a useful capability and expensive noise is the months of tuning that follow: understanding what normal looks like in your environment, suppressing the benign, and writing detections for the things generic rules miss.
This is where most SME monitoring deployments fail. The tooling gets installed, the alert volume is unmanageable, and within a quarter nobody is looking at it.
Triage by someone who has done incident response
An alert is a hypothesis, not a conclusion. Working out whether an impossible-travel sign-in is a compromise or a VPN, whether a PowerShell execution is an attacker or an IT script, requires context and experience. You get that judgement applied before anything reaches you.
What escalation looks like
When something is real, you get a phone call and a plain-English explanation: what happened, what it means, what we have already done, and what we need from you. Not a ticket in a portal with a severity score and a link to a knowledge base article.
What we monitor
- Microsoft 365 and Entra ID — sign-in anomalies, mailbox rule creation, consent grants, privilege changes, and the patterns that precede business email compromise.
- Endpoints — process execution, persistence, credential access and lateral movement.
- Cloud platforms — AWS and Azure control plane activity, identity changes, resource creation in unusual regions.
- Perimeter and network — firewall, VPN and remote access telemetry.
- External exposure — new services appearing on your perimeter, certificate changes, and credentials surfacing in breach corpora.
How delivery works
Monitoring is built on established platform technology with our own detection engineering and human triage on top. You get a named contact who knows your environment rather than a rotating tier-one analyst reading from a runbook, and escalations come with judgement already applied.
Because the same people run our incident response practice, detection and response are not handed between teams. Whoever calls you about an alert is capable of dealing with what it turns out to be.
We will always tell you plainly what our coverage model is and where its limits sit. If your risk profile genuinely requires something different, we would rather say so at the first conversation than discover it during an incident.
Common questions
Do you replace our IT provider?
No. We work alongside them. They keep running your IT; we provide the security detection layer and the expertise to interpret it. Most of our monitoring clients have an existing IT provider, and the arrangement works best when everyone is clear on who does what.
What does 24/7 actually mean here?
Detection runs continuously and high-severity events generate out-of-hours escalation. We are direct about the distinction between continuous automated detection with human response, and a permanently staffed follow-the-sun operations centre. If your risk profile genuinely requires the latter, we will tell you and help you find it.
How long until it is useful?
Initial deployment is usually days. Meaningful tuning takes six to eight weeks — that is not a delay, it is the work. Anyone promising a fully tuned deployment in a week is describing default rules.
Can you monitor if we are not a testing client?
Yes, the services are independent. That said, testing first is usually the better sequence: it is more effective to fix the obvious ways in before investing in detecting people who have already used them.
Related
Solusec
Typically replies within one business day
Hi 👋 Need a hand with pen testing, Cyber Essentials, or something urgent? Pick whichever suits you:
💬 WhatsApp usQuick questions, quick answers 📞 Call us
+44 (0)1902 288763 ✉️ Email us
info@solusec.co.uk 📝 Leave a message
We'll reply within one business day