Practical guide · verified against the real thing
Managed detection and response, honestly: what you are actually buying, and when DIY is the right call
In one line: MDR is not antivirus with a pricier logo. It is staffing and coverage you do not have. This is the honest trade-off: what the service buys, what it cannot buy, and the choose-A-if / choose-B-if line.
The core question about managed detection and response (MDR) is not "is it good" but "what scarcity does it relieve." What MDR buys is the thing most organisations genuinely lack: people watching, around the clock, who have seen enough real incidents to tell an attack from a backup job. If you understand exactly what is being bought, the decision makes itself.
What you are actually buying
- Coverage you cannot staff. Alerts do not keep office hours. A solo admin or a small team covers perhaps the working day; MDR's value is the 2am alert that a human actually triages. That is the headline purchase.
- Analyst judgement at volume. The hard part of detection is not collecting logs - tools do that - it is the judgement call on thousands of ambiguous events. MDR vendors amortise that judgement across many customers.
- A defined response path. Good MDR includes the playbooks and authority to contain - isolate a machine, disable an account - fast, instead of after a meeting.
What it cannot buy
MDR does not remove the need for the basics: if your estate is unpatched, unbacked-up and full of admin-everything accounts, a managed team is watching a burning building. It also does not remove your accountability - you still own the risk and the decisions; the service changes how fast and how well they are made. And quality varies: "we monitor your antivirus dashboard" is not MDR, so the contract's specifics (what telemetry, what response authority, what hours) are the whole ballgame.
The choose-A-if / choose-B-if line
Choose managed detection if you have no person whose job is security triage today, you hold data you would pay to keep, and you cannot staff 24/7 coverage yourself - that combination is exactly the scarcity MDR is priced to relieve. Choose the do-it-yourself path if you have the people and the hours, your footprint is small and simple, and you can honestly say someone sober is reading the alerts; in that case the money is better spent on the basics - patching, backups, MFA - which is the framing in the security checklist.
Pricing varies too widely to print: it tracks device count and telemetry volume, and the honest move is to price the same scope with two or three vendors and read what response authority each contract actually grants. The number matters less than whether the 2am alert reaches a human who can act.
Sources
Next