Managed detection and response (MDR) for small businesses.
Managed detection and response (MDR) is a security service where analysts watch your devices, accounts and cloud services around the clock, investigate every alert and contain real threats. You can buy it as a separate service, and it is also included in Lanmark Total.
What does MDR do, step by step?
It is 2.40 on a Tuesday morning and someone has been reading your mailboxes for weeks. This is what MDR does about it.
- It watches everything
- Every sign-in, file access and network connection across your devices, servers and Microsoft 365 is checked for patterns, such as a sign-in from London and another from a different continent twenty minutes later.
- A person reads every alert
- Most alerts are harmless. An analyst reads each one in context and decides whether it is real. That is the difference between MDR and software that emails you hundreds of warnings.
- It acts straight away
- When a threat is real, the analyst can isolate a laptop, revoke a stolen password and every session attached to it, or block a malicious address before the attacker spreads.
- It finds out how
- Afterwards we work out how the attacker got in, what they touched and whether any data left, so it does not happen again.
- You get a plain report
- A written account in plain language, which is also what a regulator or an insurer will want to see.
- It keeps looking
- Regular reports on what was detected and done, and periodic searches for an attacker who has been quiet for weeks.
Why do small businesses need MDR?
The tools have become cheap. Ransomware is sold as a service, complete with a support desk, and phishing kits are bought off the shelf. Attacking a great many smaller businesses now pays, and a firm with client files, a finance function and no security team is an attractive target.
Building your own security operation does not work at this size. One analyst cannot cover nights, weekends and annual leave, and a working security operations centre needs several people. That is why the capability is bought, not built.
There is a regulatory side as well. UK data protection law expects appropriate technical and organisational measures, and insurers and clients increasingly ask for evidence of continuous monitoring and a documented response, not just a line saying you have antivirus.
What a cyber insurer asks of your IT providerAntivirus, basic managed security and MDR
A lot of businesses believe they are covered because they pay for antivirus. Here is what each level actually does.
| What you get | Antivirus | Basic managed security | MDR with a security operations centre |
|---|---|---|---|
| What it watches | One device at a time | Firewall and antivirus updates | Every device, account and cloud service together |
| Who reads the alerts | Nobody: it blocks known malware automatically | Someone receives them, often during working hours | A security analyst, in context, around the clock |
| Stolen password logins | Not detected | Rarely detected | Detected by watching sign-in activity |
| Acts straight away | Only on known malware | Usually after a ticket is raised | Yes: isolates a device or disables an account |
If antivirus is a good lock on the door, MDR is the lock plus someone watching the cameras all night with the keys to every room.
What does Lanmark bring to MDR?
Our analysts work with the kind of tooling enterprise security teams use: endpoint detection and response on every device, a central platform that collects and correlates logs, controls over how cloud applications are accessed, and live threat intelligence. If you already own tools such as Microsoft Defender or CrowdStrike, we monitor those instead of asking you to replace them.
The analysts work in shifts, so the person reading an alert at 3am is as awake as the one reading it at 3pm.
And because MDR sits alongside your IT support, there is no hand-off between the people who spot a threat and the people who can fix it. The analyst who isolates a device is a message away from the engineer who rebuilds it and checks the rest of your estate.
How do you buy MDR?
You can buy MDR as a separate service, on its own. Tell us how many users you have and we will quote.
It is also included in Lanmark Total. On Lanmark Core and Lanmark Flex it is an optional add-on.
See what is in Lanmark TotalWho is MDR for?
Businesses whose data would be expensive to lose and embarrassing to leak, and that cannot justify a security team of their own. Law firms hold privileged material and are a persistent target for payment redirection fraud. Financial services and accountancy practices hold banking and tax details. Consultancies hold clients’ commercially sensitive information. Care providers hold medical records. Multi-site retailers process card payments.
What they share is not the sector. It is that a serious incident would cost clients and invite regulatory attention, not just a few days of inconvenience.
Managed cyber security for small businessesWhat do people ask about MDR?
What is managed detection and response (MDR)?
MDR is a security service in which an outside team monitors your IT environment around the clock using detection software and human analysts. They investigate suspicious activity, contain real threats, and then tell you what happened and how to prevent it happening again. Lanmark’s MDR runs 24x7x365. You can buy it on its own, and it is included in Lanmark Total.
How is MDR different from antivirus or endpoint protection?
Antivirus detects and blocks known malware on a single device, usually once it has arrived. Endpoint protection adds behaviour-based detection. Both are essential, but they are limited to the device they sit on. MDR watches every device, account and cloud service at once, and analysts decide what is real and act on it.
How much does MDR cost for a small business?
MDR is a separate service, quoted for your business: tell us how many users you have and we will price it. It is also included in Lanmark Total, and on Lanmark Core and Lanmark Flex it is an optional add-on.
What happens when a threat is detected?
Detection software flags the activity, and an analyst investigates it using the logs, the file and threat intelligence. If it is real, the analyst contains it: isolating an infected device, revoking stolen credentials, removing malware or blocking malicious traffic. We then work out how the attacker got in, and you receive a written report with recommendations.
Do I need MDR if I already have antivirus?
Antivirus is essential but not sufficient. Attacks that use a stolen password, or that move quietly from a mailbox to shared files, do not trip antivirus. If you hold sensitive data, work for clients who expect strong security, or need to satisfy a regulator or insurer, you should have both.
Is MDR the same as a SOC?
Not quite. A security operations centre (SOC) is a team and the tools it uses to monitor security. A SOC can be your own or run by a provider. MDR is a managed service in which a provider runs a SOC for you and acts on what it finds.
Where to go next
Book a free IT review.
We look at what you have, what it costs and where the risks are, and tell you plainly if you do not need to change anything.
Book a free IT review