Skip to content
This is an image of a gloved hand pointing at a laptop screen
Nikoo FullertonSep 14 20264 min read

What Managed Detection and Response doesn't solve

What Managed Detection and Response doesn't solve
5:46

You've signed the contract. You're being told your systems are watched around the clock, threats are detected, and someone responds when something looks wrong. That should feel like a weight off your shoulders (and for a lot of what it covers, it is). But you might still have a nagging question: is everything covered, or is there a gap somewhere that has been missed because nobody's thought to ask?

As a cyber security solution specialist at Babble, this is a conversation I have often. Instead of talking about whether Managed Detection and Response (MDR) works, I walk SMBs through what it was actually built to do, and what it was never designed to cover.

This is exactly what this article will unpack. By the end of reading this, you'll know where MDR's job ends, and which responsibilities still need a named owner inside your business, regardless of who you've hired.

What this article covers:

Why good coverage still has edges

It's worth saying plainly: this isn't about MDR failing to do its job, or about your provider cutting corners. A service can be delivering exactly what's in the contract, and there can still be ground it was never asked to cover. That's not a performance problem. It's a scope problem, but it’s easy to get the two confused. You'll see the same pattern with your IT provider, probably before MDR even comes into the conversation.

Your MSP can be doing a good job, and still not be your security team

Regardless of how well anyone's doing their job, the risk here lies in the untested assumption that someone's covering monitoring and response when it hasn’t been confirmed. And once MDR is in place, the same thing can happen one level up: it closes a specific gap, so it's worth being clear on exactly which one.

What Managed Detection and Response (MDR) is built to do

Managed Detection and Response (MDR) does what its name says: it detects threats across a defined set of data sources and responds to them within a defined set of hours and actions, as set out in your contract. When something suspicious happens, it's investigated, contained, and reported back to you. That's incredibly valuable and for most SMBs it's the difference between alerts going unwatched and someone actively keeping an eye on them.

What it isn't though, is a blanket guarantee that covers everything cyber-related in your business. It's a specific, contracted piece of the picture.

What MDR doesn't do

A few things sit outside that piece, regardless of provider you're with:

  • It doesn't set your organisation's risk strategy, or decide what level of risk you're prepared to accept. That's a judgement call for your business, not your provider's.
  • It doesn't maintain your asset inventory. If you don't know how many laptops, servers and mobile devices are connecting to your network (or what your policy is for personal devices), no provider can protect what they don't know exists.
  • It doesn't manage the handover between your everyday IT support and your specialist monitoring. That line must be documented, in a playbook both sides use, or it only exists on paper.
  • It doesn't automatically extend to a business you acquire. As I mentioned in the previous article, when you take on another company's technology and customers, you take on their cyber risk with it. That needs a thorough review, from people and processes to technology and environment, and isn’t something you can assume is already covered.

This graphic visually represents a "pro tip" that advises you to build a cyber and IT risk review into due diligence. It features an image of a man and woman working on a laptop together.

The responsibilities that always stay with you

Of everything I see in the work I do with clients, one thing consistently needs a named owner inside the business: ownership of your cyber security strategy and risk decisions. That person doesn't need to perform every technical task themselves (which would be nothing short of impossible). What they do need to do is coordinate with providers, prioritise risk acceptance, and make the calls that are genuinely the business's to make.

Outsourcing delivery does not outsource accountability. Sure, you can hand the monitoring, the investigation and the containment to a specialist provider. But you can't hand them the responsibility for deciding what your business is willing to risk.

The questions worth asking before you assume you're covered

Whether you're reviewing an existing MDR contract or considering a new one, three questions cut through most of the ambiguity and confusion:

  • What do you see? Which systems, devices and signals are actively being monitored.
  • What do you do? What action the provider takes on your behalf, and when.
  • What do you need from us? What must happen on your side before they can act, both during an incident and afterwards.

If any of those three has an unclear answer, that's worth resolving before you make any further investments.

The bottom line

MDR certainly earns its place: it detects and responds within its contracted scope. What it was never designed to own is your risk strategy, your asset visibility, or the accountability for the calls that are genuinely yours to make.

The risk is assuming MDR covers ground that was never in scope, and only finding that out after something's gone wrong. As a cyber security solution specialist at Babble, I help UK SMBs draw that line clearly before it becomes a problem.

Now it’s time to put your own setup to the test. Join our webinar, "Managed Cyber Security: What to Buy, and How to Buy It", to understand whether your current cyber model includes active monitoring, investigation and response: register here.

avatar
Nikoo Fullerton
Nikoo Fullerton is a people-focused Cyber Security Solution Specialist from Cambridge, UK. He helps organisations strengthen their cyber resilience and navigate their cyber transformation journey. Nikoo enjoys turning complex security challenges into practical solutions that make a real difference for the people and businesses he works with.

RELATED ARTICLES