# What is Managed Detection and Response (MDR)?

> Managed detection and response (MDR) is a security service in which an external team monitors agreed parts of a customer’s environment, investigates suspicious activity, and helps contain or remediate confirmed threats.

- Canonical URL: https://yellowcube.eu/glossary/managed-detection-and-response/
- Publisher: Yellow Cube
- Language: en
- Contact: hello@yellowcube.eu

## Content

The service usually combines technology with human analysts, defined operating procedures, and ongoing communication with the customer.

MDR is an operating model and outcome, not a single product category. Coverage may include endpoints, identities, cloud services, email, or networks, but the actual scope varies by provider and contract. No standards body defines MDR, so the term describes a market category rather than a fixed scope; the contract, not the label, determines what is actually delivered. Good MDR arrangements make response authority explicit before an incident — for example, whether the provider may isolate a device immediately or must first request approval.

### Key points

- **Core service:** Detection, triage, investigation, threat hunting, and guided or authorized response.
- **What to define:** Data sources, monitored assets, service hours, escalation paths, response actions, retention, and measurable service levels.
- **Shared responsibility:** The provider supplies operational capability; the customer still owns business risk, asset decisions, recovery, and governance.
- **Important limitation:** An MDR label does not guarantee broad visibility, expert-led response, or permission to contain an attack.

### Related terms

[Security operations center (SOC)](<https://yellowcube.eu/glossary/security-operations-center/>) · [Extended detection and response (XDR)](<https://yellowcube.eu/glossary/extended-detection-and-response/>) · [Endpoint detection and response (EDR)](<https://yellowcube.eu/glossary/endpoint-detection-and-response/>) · [Incident response (IR)](<https://yellowcube.eu/glossary/incident-response/>) · [Security operations center as a service (SOCaaS)](<https://yellowcube.eu/glossary/security-operations-center-as-a-service/>) · [Managed extended detection and response (MXDR)](<https://yellowcube.eu/glossary/managed-extended-detection-and-response/>)

### Sources

[NIST SP 800-61r3: Incident Response Recommendations](https://csrc.nist.gov/pubs/sp/800/61/r3/final) · [ENISA, Managed Security Services Market Analysis](https://www.enisa.europa.eu/publications/managed-security-services-market-analysis)

## Attribution and scope

This Markdown representation is generated from the same approved content records as the canonical HTML page. Cite the canonical URL above when referencing this material. Product and service descriptions are informational; confirm project-specific requirements with Yellow Cube.

