Does MDR Include Incident Response? What to Check Before You Buy.
Managed Detection and Response (MDR) combines threat monitoring, investigation and response delivered by a security provider. But the name alone does not tell you which actions the provider will carry out, how much work remains with your team, or what happens once a threat is contained.
For businesses evaluating MDR, and MSPs choosing a service for their customers, those details matter. A useful service needs to explain what happened, establish how far the incident extends and take agreed action. It should also make clear who owns the work needed to address the weaknesses the investigation uncovers.
This guide explains how incident response fits into MDR, why SIEM matters to investigation, and what to check when comparing providers.
Does MDR include Incident Response?
MDR includes a response capability, but the extent of incident response varies by provider and contract. A service may recommend actions, carry out agreed containment measures, or include a broader incident response engagement. Detailed forensic investigation, recovery support and managed remediation should be checked separately rather than assumed to be included.
The buying question is therefore more specific than “Do you offer response?” Ask what the provider does when a threat is confirmed, which actions it can perform directly, and where responsibility passes to the customer or MSP.
Guided response, managed response and remediation: what is the difference?
These activities can work together during an incident, but they describe different responsibilities.
| Capability | What it means | What to check |
|---|---|---|
| Response Guidance | Analysts explain their findings and recommend actions for the customer or MSP to carry out. | Who implements the recommendations, and what support is available? |
| Managed Response | The provider performs agreed response actions through supported tools and authorised processes. | Which actions are included, and which need approval? |
| Broader Incident Response | A specialist engagement may cover deeper investigation, evidence handling, eradication and recovery support. | What triggers the engagement, and what are its limits and charges? |
| Managed Remediation | An agreed service addresses vulnerabilities, misconfigurations and other weaknesses, with progress and closure tracked. | Who applies the fixes, how are they verified, and is this included or additional? |
Guidance remains useful within a managed service. Some actions require local access, business decisions or changes that the provider cannot make independently. The important distinction is whether guidance supports an active response or leaves the customer responsible for carrying out the entire response themselves.
Why investigation matters before and during response
An alert is a starting point. It might identify a suspicious process, an unusual sign-in or a connection to a malicious destination. On its own, it may not show how the activity began, whether other systems are affected or whether the attacker still has access.
Investigation turns those signals into an assessment that can inform action. Analysts need to establish whether the activity is malicious, which assets or identities are involved, how events relate to one another and what evidence supports the findings.
That assessment affects the response. Isolating one device may be appropriate, but it may be insufficient if the attacker is also using a compromised account elsewhere. Equally, a disruptive action needs to be proportionate to the evidence and the business impact.
What role does SIEM play in MDR investigation?
Security Information and Event Management (SIEM) brings security data from connected sources together so it can be searched and analysed. Within an MDR workflow, that evidence helps analysts investigate suspicious activity and establish a timeline across the systems covered by the service.
SIEM is technology; MDR is a managed service. Collecting logs does not, by itself, provide the people, decisions or authority needed to respond to an incident. Buyers should check both the investigation capability and the service operating around it.
Investigate is CybaVerse’s SIEM within CybaOps. It brings security events, alerts and telemetry into a shared operational view, with advanced search and dashboards to support investigation. Alongside case management and automation in CybaOps, it connects the evidence analysts examine with the wider incident workflow.
Visibility depends on the data sources connected and the capabilities included in the agreed package. Ask which sources are covered, what data is retained and how analysts access it during an incident.
What should happen after an MDR service detects a threat?
A clear MDR workflow connects detection to investigation, response and follow-up. The exact actions depend on the incident, available tools and agreed service scope.
- Detect and assess. Review suspicious activity, add relevant context and determine whether it requires investigation or response.
- Investigate and establish scope. Examine available evidence, connect related activity and identify affected assets and identities.
- Respond and contain. Take authorised action to limit the threat, with customer or partner involvement where needed.
- Address the cause. Identify the weaknesses or access routes that need attention and assign responsibility for resolving them.
- Track and verify. Record actions, outstanding work and evidence of completion, then use the findings to improve protection.
Containment and remediation can overlap, but they answer different questions. Containment asks how to stop the immediate threat. Remediation asks what needs to change to reduce the chance of the same route being used again. Isolating an endpoint does not automatically fix an exploited vulnerability or remove an inappropriate permission.
Six questions to ask an MDR provider
1. What response actions do you carry out directly?
Ask for examples of supported actions and the conditions under which they are performed. Establish what is pre-authorised, what needs approval and what remains with your team. A recommendation to isolate a device and a managed action that isolates it are different service commitments.
2. Is broader incident response included?
Check whether the contract includes specialist incident response or only defined actions within the monitoring service. Ask about activation, supported environments, exclusions and any additional charges. If a service advertises unlimited incident response, establish exactly what that covers.
3. How do you investigate beyond the original alert?
Ask which endpoint, identity, cloud and other data sources are available to analysts. Check whether related events can be examined together and whether SIEM is included in the proposed package. This helps reveal whether the provider can investigate the incident across the environment you need covered.
4. What service levels apply to investigation and response?
Detection time, analyst engagement, customer notification and containment are separate milestones. Ask what each commitment measures, when its clock starts and whether it depends on customer approval. Compare written commitments rather than broad promises of rapid response.
5. Who owns remediation after containment?
Establish whether the provider identifies required fixes, supports your team in implementing them, or delivers managed remediation. Ask how outstanding actions are assigned, prioritised and verified. This is where the gap between a contained incident and a resolved weakness becomes visible.
6. What can we see and report on?
Ask to see an example of the incident record and reporting. Look for findings, evidence, actions taken, approvals, responsibilities and outstanding work. Confirm which reports are included and whether they meet your internal and customer reporting needs.
How CybaVerse Connects Detection, Investigation and Response
CybaVerse brings managed security operations and platform capabilities together through CybaOps. Its approach combines automated correlation with human expertise, supported by 24/7 detection and response from UK-based Cyber Operators.
Investigate provides the SIEM capability within the platform. Case management records the investigation and response activity, while remediation workflows help organise the actions that follow. This gives businesses and partners a connected way to work through an incident rather than treating the alert, investigation and follow-up as unrelated tasks.
CybaVerse describes this approach as MDR+R: Managed Detection, Response and Remediation. Its FAFO cycle — Find, Analyse, Fix, Operate — connects identifying risk, understanding it, taking action and maintaining protection.
The operating approach does not mean every capability is included in every package:
- CybaEdge includes unlimited incident response, alongside its managed detection and response offering.
- CybaOne includes the Edge capabilities and adds SIEM, alongside further managed security services.
- CybaRemediate provides managed remediation, extending the service with agreed fixes, verification and an audit trail.
The proposal and contract should confirm the response scope, SIEM coverage and remediation responsibilities for the chosen service.
What should MSPs and resellers look for?
Partners need to understand both the customer’s protection and how the service will operate under their own delivery model. An MSP without an internal SOC needs a different division of responsibilities from a partner with analysts who want to use the platform themselves.
Check customer separation, access permissions, escalation contacts and how approvals are handled. Establish who communicates with the customer during an incident and who owns changes outside the provider’s access. Reporting should make it easy to explain findings, actions and outstanding work to each customer.
CybaOps supports multi-customer visibility and white-label reporting. Partners should agree how those capabilities will be used alongside CybaVerse’s managed services, with clear ownership throughout investigation, response and remediation.
Frequently Asked Questions
Is MDR the same as incident response?
No. MDR is an ongoing managed service for monitoring, investigating and responding to threats. Incident response is the structured work performed when an incident occurs. An MDR contract may include a broader incident response service, but buyers should check its scope.
Does every MDR service include SIEM?
No. MDR services use different technologies and data sources. Ask whether SIEM is included, which systems it covers and how it supports investigation. CybaVerse’s SIEM is called Investigate and sits within CybaOps; SIEM is included in CybaOne.
Does CybaVerse offer incident response?
CybaVerse’s offering is positioned around managed detection and response, with unlimited incident response included in CybaEdge and CybaOne.
Is remediation automatically included in MDR?
Do not assume it is. Threat response, recovery support and ongoing remediation may have different contractual scopes. CybaVerse offers managed remediation through CybaRemediate, while CybaOps supports tracking the work that needs to be completed.
Choose MDR by what happens after the alert
An MDR buying decision should establish who investigates, who takes action and who owns the work that remains. Ask providers to walk through a representative incident from the first signal to the final outstanding task, including what their team does and what they need from yours.
To explore how CybaVerse combines managed detection and response, Investigate SIEM and remediation, speak to the team about the coverage your organisation or customers need.