Managed service

Managed Detection & Response.

Attacks are detected and stopped around the clock — 24/7 detection and response with one contract, one named senior contact, and reporting you can act on.

Attackers work at night, on weekends, and on public holidays. An EDR tool without a team behind it produces alerts nobody reads. Our 24/7 SOC handles monitoring, triage, and response — you only see the alerts that need a decision from you.

What this includes

  • EDR platform of Microsoft Defender or SentinelOne class, licence management included
  • 24/7 alert monitoring by our cyber defence team: triage and false-positive filtering
  • Active containment under an agreed rulebook — e.g. immediate endpoint isolation
  • Escalation to your named senior contact at Cortavion
  • Onboarding with rollout, tuning, and an alerting playbook
  • Monthly reporting plus a quarterly review with threat picture and recommendations

Expansion path: from endpoint to XDR

Detection & response grows with your environment. You start at the endpoint and extend visibility step by step — each tier builds on the previous one.

EDR

Base: Endpoint

Detection and response on servers and clients — the foundation of any detection strategy.

ITDR

+ Identity

Monitoring of Entra ID and Active Directory: account takeover, privilege abuse.

CDR

+ Cloud

Azure and M365 workloads: misconfigurations, suspicious API activity.

NDR

+ Network

Network visibility: east-west traffic, anomalies, OT boundaries.

XDR

Full MDR

Cross-technology correlation via SIEM — every signal in one threat picture.

How we start

01

Scoping

Map environment, endpoints, protection needs, and the escalation chain.

02

Rollout & tuning

Platform rollout, baseline tuning, alerting playbook agreed with you.

03

Steady state

24/7 monitoring, triage, containment under the agreed rulebook.

04

Review

Monthly report, quarterly review with threat picture and expansion advice.

What you get

  • Response to critical alerts around the clock — not on the next business day
  • Filtered, triaged alerts instead of alert noise
  • An agreed containment rulebook with documented interventions
  • Monthly report and quarterly review at executive level
  • Seamless handover to incident response when it matters

Why this matters

In modern ransomware attacks, the time between initial access and encryption is often under a day. If alerts are read the next morning, the race is already lost. Detection without response is just logging — containment within minutes is what turns an incident into a footnote.

Questions we get

What happens on a critical alert at 3 a.m.?

Our 24/7 SOC triages the alert immediately, isolates the affected endpoint under the agreed rulebook when confirmed, and escalates along your agreed chain. You get woken up when a decision is needed from you — not for every false positive.

Which platform do you use?

An EDR platform of Microsoft Defender or SentinelOne class — depending on your environment and existing licences. If you already hold Microsoft licences, we use them; licence management is on us.

What does the service cost?

Pricing depends on the number of endpoints and the modules booked — fixed price after free scoping. If you want market clarity first, our vendor-neutral Detection & Response Consulting can precede the service.

Does MDR replace an incident response plan?

No — it complements one. MDR detects and stops attacks early; for anything beyond that you need playbooks, reporting chains, and rehearsed procedures. Together they form a resilient defence.

Next step.

A 30-minute scoping call clarifies your environment, endpoints, and the right tier.

Request a briefing