Managed detection and response (MDR) London: 24×7 threat detection for London businesses

It is 2.40 on a Tuesday morning. A partner at a London law firm has a laptop that has been running slowly, and somewhere in the last three weeks a link in a convincing email has quietly handed their login to someone who has been reading the firm’s mailboxes ever since. Right now that person is trying to move from the mailbox to the file server. Nobody at the firm is awake, and even if they were, nothing on the laptop is going to tell them what is happening.

Managed detection and response (MDR) exists for that moment. It is a security service in which your entire IT environment, the laptops, the servers, the Microsoft 365 tenant and the network between them, is watched continuously by a combination of detection software and human security analysts, 24 hours a day, every day of the year. When something looks wrong, an analyst investigates it. When it turns out to be real, the same team contains it: the account is disabled, the device is cut off from the network, and the attacker’s route into the file server closes before they reach it. The partner finds out in the morning, from a report, rather than in a fortnight, from a ransom note.

For London businesses of 20 to 500 users, especially those in finance, legal and professional services handling client data, this is the level of protection that used to be the preserve of much larger organisations. Lanmark’s MDR and Security Operations Centre (SOC) service brings it within reach of an SMB budget, and because it sits alongside our managed IT support, the people who spot the problem are the same people who can fix it.

What MDR actually does, hour by hour

The easiest way to understand MDR is to follow one alert through the system.

Every login, file access, process launch and network connection across your environment generates a record. Detection software watches those records for patterns: a user signing in from London at 9.00 and from a different continent at 9.20, a spreadsheet macro spawning a command prompt, a service account suddenly reading thousands of files it has never touched before. Most of what the software flags is harmless. Somebody is working from a hotel, or a legitimate tool behaved in an unusual way.

This is where the human part matters. Every alert goes to an analyst in Lanmark’s SOC who reads it in context. They look at the logs around it, check the file against threat intelligence sources, and decide whether it is noise or the start of something. That judgement is the difference between an MDR service and a piece of software that emails you 400 warnings a week and leaves you to work out which one matters.

When the analyst confirms a genuine threat, containment starts straight away. Depending on what they have found, that might mean isolating an infected laptop, revoking a compromised password and every session attached to it, blocking a malicious address at the firewall, or rolling back a change an attacker has made. The aim is to stop the incident spreading, not to write it up for the morning. If you are dealing with something right now and want the immediate steps rather than the service, our guide to what to do in the first hour after a suspected security breach sets them out.

After containment comes the part most businesses never see: working out how the attacker got in, what they touched, whether any data left the building, and what needs to change so it does not happen again. That investigation is written up and given to you in plain language. If you have a regulator to notify, or an insurer to satisfy, this is the document they will want.

Alongside the incident work you receive regular reporting on what was detected, what was done about it, and how your overall security posture is trending, which is usually the first time an SMB has seen its own security described in terms it can act on.

Why this matters more for a 50-person firm than it used to

Ten years ago a business of your size was rarely a target. That is no longer true, and the reason is not that criminals have become more interested in small firms specifically. It is that the tools have become cheap. Ransomware is sold as a service, complete with support desks. Phishing kits are bought off the shelf. The economics now favour attacking a great many mid-sized businesses rather than a few large ones, and a firm with confidential client files, a finance function and no security team is an attractive proposition. The National Cyber Security Centre’s guidance on mitigating malware and ransomware is written with precisely this kind of organisation in mind.

The traditional answer, building your own security operation, does not work at this size. A single experienced security analyst costs in the region of £200,000 a year before you have bought any tooling, and one person cannot cover nights, weekends and annual leave. A functioning SOC needs several. No 50-user firm can justify that, which is why the capability is bought rather than built.

There is a regulatory dimension too. If you hold personal data, the UK GDPR and the Data Protection Act 2018 require “appropriate technical and organisational measures”, and the Information Commissioner’s Office’s security guidance treats the ability to detect and respond to a breach as part of what appropriate means. Solicitors have SRA obligations around client confidentiality. FCA-regulated firms are expected to demonstrate operational resilience. Increasingly the sharpest question comes not from a regulator but from a client’s procurement team or your own cyber insurer, both of whom now ask for evidence of continuous monitoring and a documented response capability rather than a line confirming you have antivirus. See what a cyber insurer specifically asks of your IT provider in our plain-English guide to cyber insurance IT requirements.

What Lanmark brings to it

Plenty of providers will sell you an MDR badge. The differences are in who is watching, what they are watching with, and what happens after they see something.

Lanmark’s SOC runs on the same class of tooling that enterprise security teams use: endpoint detection and response on every device, a central platform that collects and correlates logs from across the environment, controls over how cloud applications are accessed, and live threat intelligence feeds. The analysts reviewing what that tooling produces hold recognised security qualifications (CISSP, CEH, OSCP or equivalent), and they work in shifts so that the person reading a 3.00 am alert is as awake and as qualified as the one reading it at 3.00 pm. Beyond responding to alerts, they periodically hunt through your environment for signs of an attacker who has been present for weeks and has so far avoided tripping anything.

Behind the tooling is an accreditation worth asking any provider about. Lanmark is a Microsoft Direct Cloud Solution Provider and holds Microsoft’s Support Service Designation, which only a handful of companies worldwide have been awarded. It is not a self-declared partner tier. Microsoft assessed our technical competence directly, and that matters for MDR because most London SMBs live in Microsoft 365, so the quality of your detection depends heavily on how well your provider understands the platform generating the signals. When you compare providers, ask each one what accreditation stands behind the claim and who assessed it.

The third difference is integration. If Lanmark also provides your managed IT support, and for most clients we do, there is no hand-off between the people who detect a threat and the people who can act on it. The SOC analyst who isolates a device at 2.40 am is a message away from the engineer who rebuilds it, resets the affected accounts and checks the patching across the rest of the estate. You are not waiting for two suppliers to agree whose problem it is.

What it costs, and why the model matters as much as the number

Most providers leave the commercial model until the proposal. We would rather set it out here.

Lanmark prices MDR and SOC per user, per month, the same way we price managed IT support. There is no per-device charge, no per-incident billing, and no separate call-out fee when something happens at three in the morning. That last point is worth dwelling on. A per-incident model prices your worst month highest, which is precisely the month you can least afford a surprise invoice, and it creates a quiet incentive for the provider to find incidents. Per-user pricing removes both.

For a firm of 50 to 200 users, a defensible security posture built around endpoint detection, MDR, a 24x7x365 SOC, conditional access, staff awareness training and a rehearsed incident response route typically sits between £40 and £75 per user per month. Where you land in that range depends largely on what your existing Microsoft licensing already covers, which is one reason we start with a licence review. Set that against the cost of one in-house analyst and the comparison is not close.

Antivirus, basic managed security and MDR: what you are actually buying

A lot of businesses believe they already have this covered because they pay for antivirus, or because their IT provider mentions “security monitoring” in the contract. It is worth being precise about the differences.

Antivirus and endpoint protection look at individual devices for known malware and for programs behaving suspiciously. They are essential, and everyone should have them. They are also limited to the device they sit on, and they act only once something malicious is already trying to run. An attacker using a stolen password does not trip antivirus, because logging in with a valid password is not malware. Neither does one who moves quietly from a compromised mailbox to a SharePoint site and downloads what they find.

Basic managed security, the kind bundled into many IT support contracts, typically means the firewall is maintained, antivirus is kept up to date, and someone receives alerts. Nobody is investigating those alerts at 2.00 am, and nobody has authority to act on them without a ticket being raised in the morning.

MDR is the layer above both. It looks across every device, every account and every cloud service at once, so it sees the pattern that no single machine can see. It has a human deciding what is real. And it has the authority and the means to act immediately. If antivirus is a good lock on the door, MDR is the lock plus someone watching the cameras all night with the keys to every room. Moving from antivirus to MDR is the same shift as moving from break-fix IT to managed support: from reacting after the damage to intervening before it.

Who this is for

Lanmark’s MDR clients are mostly London firms between 20 and 500 users whose data would be expensive to lose and embarrassing to leak. Law firms hold privileged material and, in conveyancing especially, are a persistent target for payment redirection fraud. Financial services and accountancy practices hold banking and tax details and answer to the FCA. Consultancies and other professional services firms hold their clients’ commercially sensitive information and lose the client if it leaks. Healthcare and care providers hold medical records under CQC scrutiny. Retailers with several sites process card payments and inherit PCI DSS obligations, which include continuous monitoring, as a result.

What these businesses have in common is not the sector. It is that a serious incident would be measured in lost clients and regulatory consequences rather than in a few days of inconvenience, and that none of them can justify a security team of their own. If that describes your firm, MDR is the control that closes the gap. For a wider view of how it fits with the rest of a security programme, see our cyber security services for London businesses.

Frequently asked questions

What is managed detection and response (MDR)?

Managed Detection and Response is a security service where an external provider monitors your IT environment 24 hours a day using automated tools and human analysts to detect cyber attacks, investigate suspicious activity, and respond to threats. When malware, unauthorised access, or other security incidents are detected, the MDR team takes action to contain and eliminate the threat, then provides you with forensic information about what happened and how to prevent similar incidents. MDR is continuous, proactive, and staffed by human analysts, not just automated alerts. Lanmark’s MDR service is available 24/7/365 and is integrated with our managed IT services, so incident response is fast and seamless.

How is MDR different from antivirus or endpoint protection?

Antivirus software detects and blocks known malware, usually after it has arrived on your system. Endpoint protection extends antivirus with behaviour-based detection and sandboxing of suspicious files. Both are essential tools, but they are reactive and limited to individual devices. MDR is continuous and proactive monitoring across your entire environment (all devices, all networks, all cloud services) looking for any sign of malicious activity. MDR includes human analysts who investigate alerts and make decisions about severity and response. If antivirus is a locked door, MDR is a locked door with a security guard monitoring cameras 24 hours a day and trained to respond to intruders.

How much does MDR cost for a small business?

Lanmark prices MDR per user, per month, not per device and not per incident. The total is therefore driven by your headcount and by the security tier you choose, rather than by how many laptops, servers and mobiles you happen to own. For a London SMB, a defensible posture built around endpoint detection, MDR, a 24x7x365 SOC, conditional access, awareness training and an incident response route typically sits between £40 and £75 per user, per month, and the figure depends on what your existing Microsoft licensing already covers. On a 50-user firm that is a knowable annual number you can put in a budget, against £200,000 or more a year for a single in-house security analyst before tooling. There are no per-incident charges, so a bad month does not produce a worse invoice. To get a specific figure, contact Lanmark for a free cyber security review.

What happens when a threat is detected?

When a threat is detected, the following sequence occurs: (1) Automated tools flag suspicious activity. (2) Our SOC analyst receives the alert and investigates, checking logs, looking at files, reviewing user behaviour, and consulting threat intelligence. (3) If a genuine threat is confirmed, the analyst opens an incident and notifies Lanmark’s incident response team and your organisation. (4) Response actions are taken immediately, disconnecting infected devices, revoking compromised credentials, removing malware, or blocking malicious network traffic. (5) Forensic investigation continues to understand how the attacker gained access and what damage was done. (6) You receive a detailed incident report documenting the threat, response actions, and recommendations to prevent recurrence.

Do I need MDR if I already have antivirus software?

Antivirus is essential but not sufficient. Modern threat actors use sophisticated techniques that antivirus alone cannot detect, fileless malware, credential theft, lateral movement through your network, and advanced persistent threats (APTs). If you have antivirus but no MDR, you have basic protection against known malware but are vulnerable to targeted attacks and advanced threats. If your business handles sensitive data, faces regulatory requirements, or works with partners that expect strong security, you need MDR. If your business is small with minimal data security requirements, antivirus alone may be acceptable, but most SMBs today should have both antivirus and MDR.

Is MDR the same as a SOC (Security Operations Centre)?

Not quite. A SOC is a team of analysts and tools that monitor security across an organisation. A Security Operations Centre can be internal (your own security team) or external (managed by an MSP like Lanmark). MDR is a managed service where an external provider operates a SOC on your behalf. Lanmark operates a dedicated SOC that provides MDR services to our clients. So MDR includes SOC capability, but not all SOCs are MDR services. An internal SOC is not MDR.

Get a free cyber security review

If you are not sure whether what you have today would catch the 2.40 am scenario at the top of this page, the quickest way to find out is to let us look. A free, no-obligation cyber security review covers your current environment, the gaps an attacker would use, how you measure up against Cyber Essentials and the obligations that apply to your sector, and a fixed per-user figure for MDR if it turns out you need it.

Book a free cyber security review