Cybersecurity

Managed detection and response in Australia

Most Australian mid-market organisations already own decent security tooling. What they do not have is anybody watching it at two in the morning. This page covers what MDR actually is, how it differs from a managed security services provider and from running your own tools, and what to establish before you sign.

What it is

Four things that decide whether MDR is the right purchase

MDR is a service, not a product. That single distinction is what separates it from the EDR and XDR licences many organisations already hold, and it is where the value sits.

01

You are buying people, not software

A provider operates the detection tooling and staffs analysts who investigate alerts around the clock. The software matters less than the team, the process and what they are authorised to do without ringing you first. Compare providers on response, not on the product logo behind it.

02

The gap it fills is out of hours

Attacks are timed for when nobody is watching. An organisation with excellent tooling and business hours coverage is undefended for two thirds of every week and all of every weekend. That is the actual problem MDR solves, and it is worth naming plainly before comparing quotes.

03

MDR and MSSP are not the same thing

A managed security services provider is a category of supplier that might run firewalls, email filtering, patching or monitoring. MDR is a specific service: detection and response with analysts attached. An MSSP contract may include MDR or may not, and the label will not tell you.

04

It rarely replaces what you own

Most MDR services run on tooling you already licence, or bring their own and let you retire a product. Establish which, because “we will use your existing Defender licences” and “you will also need our agent” are materially different totals.

Fit

MDR, or something else

MDR is bought for the wrong reason often enough to be worth stating clearly.

MDR suits you when

Nobody is watching out of hours, you have no security team and are not going to build one, and you need somebody able to isolate a compromised machine at three in the morning without waiting for approval. That is the case it answers better than any alternative.

Nobody is watching

Something else suits you when

The driver is a compliance obligation to retain and produce logs, which points to SIEM. Or nobody owns security decisions and the board is asking questions, which points to a vCISO and usually costs less. Or you already have a capable team and simply need better tooling, which points to XDR.

When the gap is different

How we help

Choosing an MDR provider properly

We are vendor funded, so the service costs your business nothing.

01

Name the gap before looking at providers

Out of hours coverage, alert fatigue, compliance evidence and no owner are four different problems. MDR answers one of them well and the others poorly.

02

Audit what you already licence

Microsoft 365 E5 includes a substantial detection stack that is frequently switched off. This regularly changes the shortlist and sometimes removes the need entirely.

03

Compare on response authority, not features

Every provider will say twenty four seven. The questions that separate them are what they are permitted to do without contacting you, how quickly, and what happens when your contact does not answer the phone.

04

Test the escalation path before signing

Ask to walk through a real incident from their own history, including the timestamps. Providers who cannot do this are selling monitoring rather than response.

05

Negotiate the term and the exit

What happens to your logs and detection history when you leave. It is cheap to fix before signature and awkward afterwards.

Due diligence

What to establish before signing an MDR contract

A demonstration shows a dashboard. These are the items that decide what happens when something is actually found.

What they can do without asking you

Isolating a device, disabling an account, blocking a domain. Containment authority agreed in advance is the difference between a contained incident and an email you read in the morning.

Where the analysts sit and when

Follow the sun coverage means somebody is awake, and it may not mean somebody in your time zone who knows your environment. Ask where Australian overnight coverage is staffed from.

Whose licences the service runs on

Yours, theirs, or both. This changes the total materially and is often unclear until the contract.

Mean time to contain, evidenced

Ask for the number and for the incident data behind it, not the marketing figure. Then ask what it excludes.

What is in scope

Endpoints only, or identity, email and cloud as well. Attacks move between these, and a service watching one of them will miss the path through the others.

What you get on exit

Detection history, log retention and the configuration itself. Establish it before you depend on the service.

Common questions

Questions about MDR

What Australian organisations ask us

What is managed detection and response?

A service where a provider operates security detection tooling and staffs analysts who investigate alerts around the clock and respond on your behalf, usually with agreed authority to contain a threat without waiting for you. It is the tooling plus the people, which is what separates it from an EDR or XDR licence you operate yourself.

What is the difference between MDR and an MSSP?

MDR is a specific service: detection and response with analysts attached. A managed security services provider is a category of supplier that might run firewalls, email security, patching, monitoring or all of it. An MSSP engagement may include MDR or may not, so compare the contracted scope rather than the label.

How much does MDR cost in Australia?

Usually priced per endpoint or per user per month, with the range driven by scope and by whose licences the service runs on. A service using detection tooling you already own prices differently from one bringing its own stack. The comparison worth making is total cost including licences, not the per seat rate.

Do we need MDR if we already have EDR?

That depends on who reads the alerts. EDR produces detections and expects somebody to investigate them. If nobody is doing that outside business hours, the licence is not providing much protection, and MDR is the addition that makes it useful. If you have a capable team already watching, you may need better tooling rather than a service.

Is SOC as a service the same as MDR?

They overlap and the terms are used loosely. In practice SOC as a service usually implies broader coverage including log management and compliance reporting, while MDR centres on detection and response. Compare what is actually in the contract rather than the name, particularly what the provider is authorised to do when something is found.

Can you help us choose a provider?

Yes. We audit what your existing licences already cover, name the gap you are actually filling, and compare providers on response authority and escalation rather than feature lists. We are vendor funded, so the service costs your business nothing.

We are vendor funded and completely free to your business. Always focused on the right outcome.

Find out whether the gap is tooling or people.

Most organisations we review already own detection they are not watching. Answer six questions and we will tell you what your licences already cover, whether the gap is out of hours coverage, and what a provider should be quoting for.

Book a Call

Independent guidance at no cost to your business.

Read further on this

The pages and articles that answer the next question a buyer usually asks.