Managed Detection and Response (MDR) combines threat monitoring, investigation and response delivered by a security provider. But the name alone does not tell you which actions the provider will carry out, how much work remains with your team, or what happens once a threat is contained.
For businesses evaluating MDR, and MSPs choosing a service for their customers, those details matter. A useful service needs to explain what happened, establish how far the incident extends and take agreed action. It should also make clear who owns the work needed to address the weaknesses the investigation uncovers.
This guide explains how incident response fits into MDR, why SIEM matters to investigation, and what to check when comparing providers.
MDR includes a response capability, but the extent of incident response varies by provider and contract. A service may recommend actions, carry out agreed containment measures, or include a broader incident response engagement. Detailed forensic investigation, recovery support and managed remediation should be checked separately rather than assumed to be included.
The buying question is therefore more specific than “Do you offer response?” Ask what the provider does when a threat is confirmed, which actions it can perform directly, and where responsibility passes to the customer or MSP.
These activities can work together during an incident, but they describe different responsibilities.
| Capability | What it means | What to check |
|---|---|---|
| Response Guidance | Analysts explain their findings and recommend actions for the customer or MSP to carry out. | Who implements the recommendations, and what support is available? |
| Managed Response | The provider performs agreed response actions through supported tools and authorised processes. | Which actions are included, and which need approval? |
| Broader Incident Response | A specialist engagement may cover deeper investigation, evidence handling, eradication and recovery support. | What triggers the engagement, and what are its limits and charges? |
| Managed Remediation | An agreed service addresses vulnerabilities, misconfigurations and other weaknesses, with progress and closure tracked. | Who applies the fixes, how are they verified, and is this included or additional? |
Guidance remains useful within a managed service. Some actions require local access, business decisions or changes that the provider cannot make independently. The important distinction is whether guidance supports an active response or leaves the customer responsible for carrying out the entire response themselves.
An alert is a starting point. It might identify a suspicious process, an unusual sign-in or a connection to a malicious destination. On its own, it may not show how the activity began, whether other systems are affected or whether the attacker still has access.
Investigation turns those signals into an assessment that can inform action. Analysts need to establish whether the activity is malicious, which assets or identities are involved, how events relate to one another and what evidence supports the findings.
That assessment affects the response. Isolating one device may be appropriate, but it may be insufficient if the attacker is also using a compromised account elsewhere. Equally, a disruptive action needs to be proportionate to the evidence and the business impact.
Security Information and Event Management (SIEM) brings security data from connected sources together so it can be searched and analysed. Within an MDR workflow, that evidence helps analysts investigate suspicious activity and establish a timeline across the systems covered by the service.
SIEM is technology; MDR is a managed service. Collecting logs does not, by itself, provide the people, decisions or authority needed to respond to an incident. Buyers should check both the investigation capability and the service operating around it.
Investigate is CybaVerse’s SIEM within CybaOps. It brings security events, alerts and telemetry into a shared operational view, with advanced search and dashboards to support investigation. Alongside case management and automation in CybaOps, it connects the evidence analysts examine with the wider incident workflow.
Visibility depends on the data sources connected and the capabilities included in the agreed package. Ask which sources are covered, what data is retained and how analysts access it during an incident.
A clear MDR workflow connects detection to investigation, response and follow-up. The exact actions depend on the incident, available tools and agreed service scope.
Containment and remediation can overlap, but they answer different questions. Containment asks how to stop the immediate threat. Remediation asks what needs to change to reduce the chance of the same route being used again. Isolating an endpoint does not automatically fix an exploited vulnerability or remove an inappropriate permission.
Ask for examples of supported actions and the conditions under which they are performed. Establish what is pre-authorised, what needs approval and what remains with your team. A recommendation to isolate a device and a managed action that isolates it are different service commitments.
Check whether the contract includes specialist incident response or only defined actions within the monitoring service. Ask about activation, supported environments, exclusions and any additional charges. If a service advertises unlimited incident response, establish exactly what that covers.
Ask which endpoint, identity, cloud and other data sources are available to analysts. Check whether related events can be examined together and whether SIEM is included in the proposed package. This helps reveal whether the provider can investigate the incident across the environment you need covered.
Detection time, analyst engagement, customer notification and containment are separate milestones. Ask what each commitment measures, when its clock starts and whether it depends on customer approval. Compare written commitments rather than broad promises of rapid response.
Establish whether the provider identifies required fixes, supports your team in implementing them, or delivers managed remediation. Ask how outstanding actions are assigned, prioritised and verified. This is where the gap between a contained incident and a resolved weakness becomes visible.
Ask to see an example of the incident record and reporting. Look for findings, evidence, actions taken, approvals, responsibilities and outstanding work. Confirm which reports are included and whether they meet your internal and customer reporting needs.
CybaVerse brings managed security operations and platform capabilities together through CybaOps. Its approach combines automated correlation with human expertise, supported by 24/7 detection and response from UK-based Cyber Operators.
Investigate provides the SIEM capability within the platform. Case management records the investigation and response activity, while remediation workflows help organise the actions that follow. This gives businesses and partners a connected way to work through an incident rather than treating the alert, investigation and follow-up as unrelated tasks.
CybaVerse describes this approach as MDR+R: Managed Detection, Response and Remediation. Its FAFO cycle — Find, Analyse, Fix, Operate — connects identifying risk, understanding it, taking action and maintaining protection.
The operating approach does not mean every capability is included in every package:
The proposal and contract should confirm the response scope, SIEM coverage and remediation responsibilities for the chosen service.
Partners need to understand both the customer’s protection and how the service will operate under their own delivery model. An MSP without an internal SOC needs a different division of responsibilities from a partner with analysts who want to use the platform themselves.
Check customer separation, access permissions, escalation contacts and how approvals are handled. Establish who communicates with the customer during an incident and who owns changes outside the provider’s access. Reporting should make it easy to explain findings, actions and outstanding work to each customer.
CybaOps supports multi-customer visibility and white-label reporting. Partners should agree how those capabilities will be used alongside CybaVerse’s managed services, with clear ownership throughout investigation, response and remediation.
No. MDR is an ongoing managed service for monitoring, investigating and responding to threats. Incident response is the structured work performed when an incident occurs. An MDR contract may include a broader incident response service, but buyers should check its scope.
No. MDR services use different technologies and data sources. Ask whether SIEM is included, which systems it covers and how it supports investigation. CybaVerse’s SIEM is called Investigate and sits within CybaOps; SIEM is included in CybaOne.
CybaVerse’s offering is positioned around managed detection and response, with unlimited incident response included in CybaEdge and CybaOne.
Do not assume it is. Threat response, recovery support and ongoing remediation may have different contractual scopes. CybaVerse offers managed remediation through CybaRemediate, while CybaOps supports tracking the work that needs to be completed.
An MDR buying decision should establish who investigates, who takes action and who owns the work that remains. Ask providers to walk through a representative incident from the first signal to the final outstanding task, including what their team does and what they need from yours.
To explore how CybaVerse combines managed detection and response, Investigate SIEM and remediation, speak to the team about the coverage your organisation or customers need.