Managed Detection and Response, Defined
Managed detection and response or MDR, is a service where an outside team watches your systems around the clock, spots the signs of an attack, investigates them and acts to shut the attack down. It delivers the work of a security operations centre as a managed, human-led service rather than a tool you run yourself.
The research firm Gartner defines MDR as a service that provides security operations centre functions remotely, covering endpoints, networks, logs and cloud with human analysts who detect, investigate and contain threats. Gartner recommends it for organisations that cannot staff a round-the-clock security team of their own which describes most Swedish businesses and public bodies.
The need is sharper than it used to be. Ransomware now appears in 44% of breaches, up from 32% the year before, according to Verizon’s 2025 Data Breach Investigations Report and “the EU cybersecurity agency ENISA lists ransomware among its prime threats in the region. Attacks like these unfold in stages over hours or days and someone has to be watching when they do.
How MDR Works
MDR starts with telemetry, the raw activity signals your systems produce. Software agents on laptops and servers, network sensors, identity systems and cloud platforms all send data to the provider. This is the same endpoint detection and response tooling many companies already own, now feeding a team that reads it full time.

Analytics and threat intelligence sift that flood of data and surface the events worth a human look. An analyst then investigates each one, decides whether it is a real attack and how far it has spread and either contains it or tells you exactly what to do. Automation handles the machine-speed steps and people make the judgement calls.
This maps onto two functions of the NIST Cybersecurity Framework, Detect and Respond. NIST’s updated incident-response guidance, Special Publication 800-61 Revision 3 from April 2025, treats detection and response as continuous risk management rather than a one-off drill. MDR is how an organisation buys those functions instead of building them.
Strong MDR also hunts. Instead of only waiting for an alert, analysts go looking for attacker behaviour that slipped past the automated checks. And the service runs at night and at weekends, when many intrusions are deliberately timed to land.
MDR vs EDR, XDR and MSSP
The market is crowded and the labels blur together. More than 600 providers now use the term MDR by Gartner’s count so it helps to separate the technology from the service.
- EDR (endpoint detection and response): Software that records what happens on laptops, servers and other endpoints and can isolate a compromised device. It is a tool and on its own it still needs someone to watch it, read its alerts and act.
- XDR (extended detection and response): The same idea widened beyond the endpoint to pull network, email, identity and cloud signals into one place. Also a technology, not a team.
- SIEM (security information and event management): A platform that collects and correlates logs from across the estate. Powerful and demanding, it needs skilled people to tune it and chase what it flags.
- MSSP (managed security service provider): A broader managed-security relationship that can include firewalls, patching and device management. Detection and response may be one part of it and may be lighter than a dedicated MDR service.
- SOC (security operations centre): The function that ties these together, the people and process who monitor, investigate and respond. MDR is a way to buy an SOC’s detection and response work as a service.
The short version is that EDR, XDR and SIEM are things you buy and MDR is a service that operates them for you. You can own excellent tooling and still be undefended at 2am if no one is watching it. MDR supplies the watching, the judgement and the response.
Why MDR Matters for the Business
The case for MDR rests on time. The average breach in 2025 took 241 days to identify and contain, the lowest figure in nine years but still roughly eight months, according to the Cost of a Data Breach Report from IBM and the Ponemon Institute. For most of that window the attacker is inside and the longer they stay the more it costs.
That cost is real. The same report puts the global average breach at 4.44 million US dollars and finds that organisations using AI and automation extensively saved about 1.9 million and cut the breach lifecycle by around 80 days. Faster detection and response is the main lever on what an incident costs.
The threats are not slowing. Ransomware featured in 44% of breaches in Verizon’s 2025 report and in 88% of breaches at small and medium businesses. ENISA lists ransomware among its prime threats in the EU and reports that public administration, its most targeted sector, is increasingly hit, Swedish municipalities included.
Building this in-house is hard and getting harder. In ISC2’s 2025 workforce study, 88% of organisations had suffered at least one significant security problem tied to a skills gap in the past year and about a third said they simply cannot staff their security teams adequately. Round-the-clock monitoring needs people most organisations cannot hire or keep.
Real-World Cases
Tietoevry and the Akira Ransomware Attack (2024)
In the early hours of 20 January 2024 the Akira ransomware group hit one of Tietoevry’s data centres in Sweden and encrypted the servers running its hosting platform. Tietoevry isolated the affected systems quickly but the damage had already reached its customers.
The outage took down Primula, a payroll and HR platform used by most Swedish universities and more than 30 government authorities. Cinema chain Filmstaden could not sell tickets, retailer Rusta and farming supplier Granngården were disrupted and Granngården closed stores.
A health-care region in Uppsala lost access to records, Sweden’s central bank filed a police report and the civil defence minister said 178 possible personal-data-breach reports were filed. Recovery ran from days into weeks.
Finland’s national cyber centre later reported that most of the Akira intrusions it examined came in through unpatched VPN appliances. The joint CISA advisory on Akira urges enforcing multi-factor authentication on every remote-access route and keeping tested offline backups since the group hunts for backups too.
The lesson is entry hygiene backed by monitoring. Close the remote-access gap, then watch for the lateral movement that follows so an intrusion is caught in the hours before the encryptor runs.

Miljödata and the Municipal Supply-Chain Attack (2025)
In August 2025 attackers hit Miljödata, a Swedish supplier whose software handles sick leave, medical certificates, rehabilitation plans and workplace-accident reports for roughly 80% of the country’s municipalities. Early estimates put the disruption at around 200 of Sweden’s 290 municipalities along with several regions. Authorities later confirmed 164 municipalities and four regions directly affected, and around 250 client organisations in total once universities and private firms are included.
This was double extortion. “The attackers stole sensitive HR and health data and threatened to publish it, then demanded about 1.5 bitcoin, close to 144,000 euros, a sum small enough to point at opportunists rather than a major crew. “Miljödata pulled the affected systems offline. No group claimed the attack at first, but the DataCarry extortion group later listed Miljodata on its leak site and published the stolen data in mid-September 2025, exposing the personal data of around 1.5 million people in one of Sweden’s largest breaches.
No amount of monitoring inside a single municipality would have stopped a breach at its supplier and that is the point. When hundreds of bodies depend on one provider, supplier concentration becomes a board-level risk and NIS2 now treats supply-chain security as a duty rather than a courtesy.
The realistic defence is to know which suppliers hold your data, to keep watching your own environment and to hold a reporting and recovery plan you have actually rehearsed. When the supplier is the target, the damage is measured in how fast you detect, report and restore.
MDR and Compliance
For Swedish organisations, detection and response is now partly a legal duty. Cybersäkerhetslagen, statute SFS 2025:1506, brought the EU NIS2 Directive into Swedish law on 15 January 2026. “Its risk management measures include incident handling under Article 21.2b, the core duty MDR is built to deliver and continuous detection and response support the wider monitoring the directive expects. Article 21.2a covers policies on risk analysis and information system security, so continuous monitoring should not be attributed to it. You can read the detail on our NIS2 compliance guide for Sweden.
NIS2 also raises the stakes at the top. Under Article 20 the management body must approve and oversee security measures and board members can be held personally accountable for failures. Detection and response is no longer only an IT concern.
When an incident hits, the clock starts. Reporting runs to the National Cyber Security Centre (NCSC) at FRA which took over as Sweden’s single point of contact and CSIRT on 1 July 2026 and to the relevant sector authority in a set cascade. You must send an early warning within 24 hours, a full notification within 72 hours and a final report within one month. An MDR provider should produce the incident documentation these deadlines demand.
Other regimes add their own detection and reporting duties. Financial entities fall under DORA, whose Article 17 requires managed ICT incident handling and is supervised by Finansinspektionen. Any personal-data breach also triggers GDPR Article 33, a 72-hour notification to the Swedish authority IMY. Well-documented detection is what makes these deadlines survivable.
Where your data lives matters too. After the Schrems II ruling, storing data inside the EU is not enough on its own if the provider can be compelled to hand it to a foreign government under laws like the US CLOUD Act.
For regulated Swedish bodies this makes the location of MDR telemetry and the provider’s sub-processors a real question to ask. A provider’s own certifications, such as ISO 27001, are worth checking here as well.
How to Choose an MDR Provider
Because so many services wear the MDR label, the differences that matter are easy to miss. A few questions separate a real detection-and-response partner from a dashboard with a logo.
- Is it human-led? Gartner warns that some offerings lean on technology and thin out the human analysis. Ask who reads your alerts and makes the call.
- Does it respond, or only alert? A real service contains threats or drives the response, rather than emailing you an alert and leaving the rest to you.
- Is the cover genuinely round-the-clock? Attacks are timed for nights and weekends so a gap in cover is a gap an attacker will use.
- What does it actually watch? Endpoints are the baseline. Network, identity and cloud signals matter as much, because that is where modern intrusions move.
- Where does your data go? Ask where telemetry and logs are stored and who the sub-processors are so you can weigh Schrems II and CLOUD Act exposure.
- Is the provider itself certified? Independent certification such as ISO 27001 shows its own security is held to a recognised standard.
- How fast can it start, and how cleanly can you leave? Onboarding time and a clear exit with your data returned tell you a great deal about a provider.
One caveat matters more than any single feature. MDR is detection and response, not prevention. It shortens the time an attacker has and limits the damage, but it does not replace patching, backups, strong identity controls and staff training. The strongest setups treat it as a safety net under those basics.
Getting Started with MDR
If MDR looks like the right move, a little groundwork makes it far more effective.

- Map what you are protecting. List your critical systems, your data and the suppliers who touch them so monitoring and supplier risk are scoped from the start.
- Get telemetry in place. Make sure endpoint detection and response covers your laptops and servers because that data is what an MDR team reads.
- Close the common entry routes. Enforce multi-factor authentication on all remote access and patch internet-facing systems, the gaps the Tietoevry attackers used.
- Agree who can act. Decide in advance whether the provider may contain a threat directly or must wait for your go-ahead, because minutes matter during an incident.
- Rehearse the reporting clocks. Walk through the 24-hour, 72-hour and one-month NIS2 deadlines with the provider before a real incident forces the pace.
- Test the plan. Run a tabletop exercise so detection, response and reporting are muscle memory rather than theory.
None of this is exotic. It is the difference between an attack that becomes a headline and one that ends as a line in a monthly report. Detection and response only works when someone is watching and ready to act so decide who that is before an attacker does.


