The challenge
Many organisations buy EDR and then find alerts piling up with no one to investigate them. The NCA Essential Cybersecurity Controls (ECC) and the SAMA Cyber Security Framework (CSF) expect security events to be monitored and handled, not just a product installed.
Today's attacker usually starts with a leaked credential or a hijacked session, not an obvious piece of malware. Monitoring therefore has to cover identity and account behaviour, not only devices.
MDR closes that gap: human investigation of every prioritised alert, written response procedures, and reporting that both the CISO and the compliance auditor can use.
How we work
- 1
Onboarding and integration
We inventory priority assets and accounts, connect EDR/XDR and identity sources (Active Directory, Entra ID) to the monitoring platform, and agree response authority in writing.
- 2
Tuning and monitoring
We tune detection rules to your environment to cut false positives, map them to MITRE ATT&CK tactics, and analysts investigate alerts under documented procedures.
- 3
Response and reporting
On a confirmed incident we isolate the host or disable the account within agreed authority, document every step, and deliver periodic reports plus a review session for improvement.
What is included
EDR/XDR operation
Policy management, updates and alert investigation on platforms such as SentinelOne, Microsoft Defender and whatever you already run.
Identity threat detection
Detection of anomalous sign-ins, privilege escalation, misuse of privileged accounts and MFA-fatigue attacks.
SIEM integration
Forwarding endpoint and identity events into Splunk or your existing SIEM to correlate with network and application logs.
Threat hunting
Recurring hypothesis-led hunts using fresh indicators of compromise, looking for what automated rules missed.
Agreed containment
Host isolation, process termination, account disablement and session revocation under an authority matrix you sign before go-live.
Custom detection content
Use cases written for your environment and reviewed as threats and systems change.
Reporting and compliance
Monthly reports on incidents, trends and coverage, structured to support ECC and SAMA CSF evidence needs.
SOC integration
Delivered from our managed SOC, and expandable to full log and network monitoring when you are ready.
Frameworks and regulations
We align the service with the frameworks your organisation is subject to.
- NCA ECC
- SAMA CSF
- MITRE ATT&CK
- ISO 27001
Frequently asked questions
How is MDR different from the managed SOC?
MDR focuses on endpoints and identity through EDR/XDR, with active response. The managed SOC covers all log sources through SIEM. Many clients start with MDR and widen the scope later.
Do we have to replace our current EDR?
No. We work with your existing tool if it supports remote response, and suggest an alternative only where there is a documented gap.
Who decides to isolate a host?
The authority matrix we agree together. Some actions run immediately; others require sign-off from a named contact on your side.
Is the service available to government entities?
The service is delivered under the Managed Security Operations Center (MSOC) Services Licence — Tier 2, which excludes government entities and organisations that own, operate or host critical national infrastructure. For those we offer GRC, assessment and solutions services.
What affects the cost of an MDR service?
Cost follows scope: the number of endpoints, servers and user identities monitored, the EDR/XDR platform and whether you already hold its licences, and the response actions you authorise us to take. The depth of threat hunting, the coverage hours agreed and the reporting you need also play a part. We set this out in a written proposal after a scoping session.
What do we need to prepare before MDR starts?
An EDR or XDR tool that supports remote response, deployed or planned across the devices in scope, with administrator access for our analysts. We also need to connect your identity sources, such as Active Directory or Entra ID, plus a list of priority assets and privileged accounts and named contacts for escalation and approvals. The response authority matrix is agreed and signed before go-live.
How does MDR relate to incident response?
MDR detects threats on endpoints and identities and contains them within the authority you agree, such as isolating a host or disabling an account. When an incident needs digital forensics, malware analysis, recovery or support with regulatory notification, our Incident Response service takes over, working from the evidence and timeline MDR has already recorded.
Related services
Detect & respond
Managed SOC
24/7 monitoring, analysis and response under an NCA licence.
Detect & respond
Incident response
Contain, investigate and recover from incidents with documented procedures.
Detect & respond
Threat intelligence & brand protection
See what is said and sold about you beyond your perimeter, from fake domains to leaked credentials.
Assess & test
Vulnerability management
Recurring scanning, prioritisation and remediation tracking through to closure.
Contact
Let's talk about what you need
We answer enquiries through the form, WhatsApp, a call or email.
Mobile (calls and WhatsApp)
+966 59 750 4669Email
info@datasec.sa

