شركة أمن البيانات للأمن السيبراني

DataSec — Zero Trust SecurityRequest a consultation

Detect & respond

Managed Detection & Response (MDR)Early detection and documented response across endpoints and identity

We run your EDR/XDR tooling with analysts who investigate alerts and contain what needs containing, within agreed authority.

At a glance

Frameworks

  • NCA ECC
  • SAMA CSF
  • MITRE ATT&CK
  • ISO 27001

Deliverables

  • Signed response authority matrix
  • Response runbooks per incident type
  • Detection coverage map against MITRE ATT&CK
  • Monthly incident and trend report
  • Alert and endpoint health dashboard

The challenge

Many organisations buy EDR and then find alerts piling up with no one to investigate them. The NCA Essential Cybersecurity Controls (ECC) and the SAMA Cyber Security Framework (CSF) expect security events to be monitored and handled, not just a product installed.

Today's attacker usually starts with a leaked credential or a hijacked session, not an obvious piece of malware. Monitoring therefore has to cover identity and account behaviour, not only devices.

MDR closes that gap: human investigation of every prioritised alert, written response procedures, and reporting that both the CISO and the compliance auditor can use.

How we work

  1. 1

    Onboarding and integration

    We inventory priority assets and accounts, connect EDR/XDR and identity sources (Active Directory, Entra ID) to the monitoring platform, and agree response authority in writing.

  2. 2

    Tuning and monitoring

    We tune detection rules to your environment to cut false positives, map them to MITRE ATT&CK tactics, and analysts investigate alerts under documented procedures.

  3. 3

    Response and reporting

    On a confirmed incident we isolate the host or disable the account within agreed authority, document every step, and deliver periodic reports plus a review session for improvement.

What is included

  • EDR/XDR operation

    Policy management, updates and alert investigation on platforms such as SentinelOne, Microsoft Defender and whatever you already run.

  • Identity threat detection

    Detection of anomalous sign-ins, privilege escalation, misuse of privileged accounts and MFA-fatigue attacks.

  • SIEM integration

    Forwarding endpoint and identity events into Splunk or your existing SIEM to correlate with network and application logs.

  • Threat hunting

    Recurring hypothesis-led hunts using fresh indicators of compromise, looking for what automated rules missed.

  • Agreed containment

    Host isolation, process termination, account disablement and session revocation under an authority matrix you sign before go-live.

  • Custom detection content

    Use cases written for your environment and reviewed as threats and systems change.

  • Reporting and compliance

    Monthly reports on incidents, trends and coverage, structured to support ECC and SAMA CSF evidence needs.

  • SOC integration

    Delivered from our managed SOC, and expandable to full log and network monitoring when you are ready.

Frameworks and regulations

We align the service with the frameworks your organisation is subject to.

  • NCA ECC
  • SAMA CSF
  • MITRE ATT&CK
  • ISO 27001

Frequently asked questions

How is MDR different from the managed SOC?

MDR focuses on endpoints and identity through EDR/XDR, with active response. The managed SOC covers all log sources through SIEM. Many clients start with MDR and widen the scope later.

Do we have to replace our current EDR?

No. We work with your existing tool if it supports remote response, and suggest an alternative only where there is a documented gap.

Who decides to isolate a host?

The authority matrix we agree together. Some actions run immediately; others require sign-off from a named contact on your side.

Is the service available to government entities?

The service is delivered under the Managed Security Operations Center (MSOC) Services Licence — Tier 2, which excludes government entities and organisations that own, operate or host critical national infrastructure. For those we offer GRC, assessment and solutions services.

What affects the cost of an MDR service?

Cost follows scope: the number of endpoints, servers and user identities monitored, the EDR/XDR platform and whether you already hold its licences, and the response actions you authorise us to take. The depth of threat hunting, the coverage hours agreed and the reporting you need also play a part. We set this out in a written proposal after a scoping session.

What do we need to prepare before MDR starts?

An EDR or XDR tool that supports remote response, deployed or planned across the devices in scope, with administrator access for our analysts. We also need to connect your identity sources, such as Active Directory or Entra ID, plus a list of priority assets and privileged accounts and named contacts for escalation and approvals. The response authority matrix is agreed and signed before go-live.

How does MDR relate to incident response?

MDR detects threats on endpoints and identities and contains them within the authority you agree, such as isolating a host or disabling an account. When an incident needs digital forensics, malware analysis, recovery or support with regulatory notification, our Incident Response service takes over, working from the evidence and timeline MDR has already recorded.

  • Detect & respond

    Managed SOC

    24/7 monitoring, analysis and response under an NCA licence.

  • Detect & respond

    Incident response

    Contain, investigate and recover from incidents with documented procedures.

  • Detect & respond

    Threat intelligence & brand protection

    See what is said and sold about you beyond your perimeter, from fake domains to leaked credentials.

  • Assess & test

    Vulnerability management

    Recurring scanning, prioritisation and remediation tracking through to closure.

Contact

Let's talk about what you need

We answer enquiries through the form, WhatsApp, a call or email.