You've signed the contract. You're being told your systems are watched around the clock, threats are detected, and someone responds when something looks wrong. That should feel like a weight off your shoulders (and for a lot of what it covers, it is). But you might still have a nagging question: is everything covered, or is there a gap somewhere that has been missed because nobody's thought to ask?
As a cyber security solution specialist at Babble, this is a conversation I have often. Instead of talking about whether Managed Detection and Response (MDR) works, I walk SMBs through what it was actually built to do, and what it was never designed to cover.
This is exactly what this article will unpack. By the end of reading this, you'll know where MDR's job ends, and which responsibilities still need a named owner inside your business, regardless of who you've hired.
–
It's worth saying plainly: this isn't about MDR failing to do its job, or about your provider cutting corners. A service can be delivering exactly what's in the contract, and there can still be ground it was never asked to cover. That's not a performance problem. It's a scope problem, but it’s easy to get the two confused. You'll see the same pattern with your IT provider, probably before MDR even comes into the conversation.
Regardless of how well anyone's doing their job, the risk here lies in the untested assumption that someone's covering monitoring and response when it hasn’t been confirmed. And once MDR is in place, the same thing can happen one level up: it closes a specific gap, so it's worth being clear on exactly which one.
Managed Detection and Response (MDR) does what its name says: it detects threats across a defined set of data sources and responds to them within a defined set of hours and actions, as set out in your contract. When something suspicious happens, it's investigated, contained, and reported back to you. That's incredibly valuable and for most SMBs it's the difference between alerts going unwatched and someone actively keeping an eye on them.
What it isn't though, is a blanket guarantee that covers everything cyber-related in your business. It's a specific, contracted piece of the picture.
A few things sit outside that piece, regardless of provider you're with:
Of everything I see in the work I do with clients, one thing consistently needs a named owner inside the business: ownership of your cyber security strategy and risk decisions. That person doesn't need to perform every technical task themselves (which would be nothing short of impossible). What they do need to do is coordinate with providers, prioritise risk acceptance, and make the calls that are genuinely the business's to make.
Outsourcing delivery does not outsource accountability. Sure, you can hand the monitoring, the investigation and the containment to a specialist provider. But you can't hand them the responsibility for deciding what your business is willing to risk.
Whether you're reviewing an existing MDR contract or considering a new one, three questions cut through most of the ambiguity and confusion:
If any of those three has an unclear answer, that's worth resolving before you make any further investments.
MDR certainly earns its place: it detects and responds within its contracted scope. What it was never designed to own is your risk strategy, your asset visibility, or the accountability for the calls that are genuinely yours to make.
The risk is assuming MDR covers ground that was never in scope, and only finding that out after something's gone wrong. As a cyber security solution specialist at Babble, I help UK SMBs draw that line clearly before it becomes a problem.
Now it’s time to put your own setup to the test. Join our webinar, "Managed Cyber Security: What to Buy, and How to Buy It", to understand whether your current cyber model includes active monitoring, investigation and response: register here.