Security operations

What is MDR (Managed Detection and Response)?

A plain-language guide to managed detection and response. What MDR is, how it differs from the EDR you may already run and what NIS2 now asks of Swedish organisations.

Key takeaways
  • MDR (managed detection and response) is a managed, human-led service that watches your systems around the clock and detects, investigates and stops attacks.
  • It delivers the Detect and Respond functions of the NIST Cybersecurity Framework as a service, rather than a tool you run in-house.
  • EDR is a tool. MDR is the service that operates detection and response for you, so owning EDR is not the same as having someone watch it.
  • Speed is the point. The average breach took 241 days to identify and contain in 2025 (IBM and Ponemon), and the longer an attacker stays the more it costs.
  • Ransomware appeared in 44% of breaches and 88% of small-business breaches in 2025 (Verizon), and ENISA lists it among the EU’s prime threats.
  • Running a 24/7 security team in-house is hard. 88% of organisations hit a skills-gap problem in the past year and a third cannot staff their teams (ISC2, 2025).
  • In Sweden, MDR maps directly to the NIS2 incident-handling duty (Article 21.2b) and supports the detection and response the directive expects, now law under Cybersäkerhetslagen.
  • NIS2 makes boards personally accountable (Article 20) and sets reporting clocks of 24 hours, 72 hours and one month to the NCSC at FRA.
  • Choose a provider that is human-led, contains threats rather than only alerting and can tell you where your data is stored under Schrems II and the US CLOUD Act.

Managed Detection and Response, Defined

Managed detection and response or MDR, is a service where an outside team watches your systems around the clock, spots the signs of an attack, investigates them and acts to shut the attack down. It delivers the work of a security operations centre as a managed, human-led service rather than a tool you run yourself.

The research firm Gartner defines MDR as a service that provides security operations centre functions remotely, covering endpoints, networks, logs and cloud with human analysts who detect, investigate and contain threats. Gartner recommends it for organisations that cannot staff a round-the-clock security team of their own which describes most Swedish businesses and public bodies.

The need is sharper than it used to be. Ransomware now appears in 44% of breaches, up from 32% the year before, according to Verizon’s 2025 Data Breach Investigations Report and “the EU cybersecurity agency ENISA lists ransomware among its prime threats in the region. Attacks like these unfold in stages over hours or days and someone has to be watching when they do.

How MDR Works

MDR starts with telemetry, the raw activity signals your systems produce. Software agents on laptops and servers, network sensors, identity systems and cloud platforms all send data to the provider. This is the same endpoint detection and response tooling many companies already own, now feeding a team that reads it full time.

How MDR Works

Analytics and threat intelligence sift that flood of data and surface the events worth a human look. An analyst then investigates each one, decides whether it is a real attack and how far it has spread and either contains it or tells you exactly what to do. Automation handles the machine-speed steps and people make the judgement calls.

This maps onto two functions of the NIST Cybersecurity Framework, Detect and Respond. NIST’s updated incident-response guidance, Special Publication 800-61 Revision 3 from April 2025, treats detection and response as continuous risk management rather than a one-off drill. MDR is how an organisation buys those functions instead of building them.

Strong MDR also hunts. Instead of only waiting for an alert, analysts go looking for attacker behaviour that slipped past the automated checks. And the service runs at night and at weekends, when many intrusions are deliberately timed to land.

MDR vs EDR, XDR and MSSP

The market is crowded and the labels blur together. More than 600 providers now use the term MDR by Gartner’s count so it helps to separate the technology from the service.

  • EDR (endpoint detection and response): Software that records what happens on laptops, servers and other endpoints and can isolate a compromised device. It is a tool and on its own it still needs someone to watch it, read its alerts and act.
  • XDR (extended detection and response): The same idea widened beyond the endpoint to pull network, email, identity and cloud signals into one place. Also a technology, not a team.
  • SIEM (security information and event management): A platform that collects and correlates logs from across the estate. Powerful and demanding, it needs skilled people to tune it and chase what it flags.
  • MSSP (managed security service provider): A broader managed-security relationship that can include firewalls, patching and device management. Detection and response may be one part of it and may be lighter than a dedicated MDR service.
  • SOC (security operations centre): The function that ties these together, the people and process who monitor, investigate and respond. MDR is a way to buy an SOC’s detection and response work as a service.

The short version is that EDR, XDR and SIEM are things you buy and MDR is a service that operates them for you. You can own excellent tooling and still be undefended at 2am if no one is watching it. MDR supplies the watching, the judgement and the response.

Why MDR Matters for the Business

The case for MDR rests on time. The average breach in 2025 took 241 days to identify and contain, the lowest figure in nine years but still roughly eight months, according to the Cost of a Data Breach Report from IBM and the Ponemon Institute. For most of that window the attacker is inside and the longer they stay the more it costs.

That cost is real. The same report puts the global average breach at 4.44 million US dollars and finds that organisations using AI and automation extensively saved about 1.9 million and cut the breach lifecycle by around 80 days. Faster detection and response is the main lever on what an incident costs.

The threats are not slowing. Ransomware featured in 44% of breaches in Verizon’s 2025 report and in 88% of breaches at small and medium businesses. ENISA lists ransomware among its prime threats in the EU and reports that public administration, its most targeted sector, is increasingly hit, Swedish municipalities included.

Building this in-house is hard and getting harder. In ISC2’s 2025 workforce study, 88% of organisations had suffered at least one significant security problem tied to a skills gap in the past year and about a third said they simply cannot staff their security teams adequately. Round-the-clock monitoring needs people most organisations cannot hire or keep.

Real-World Cases

Tietoevry and the Akira Ransomware Attack (2024)

In the early hours of 20 January 2024 the Akira ransomware group hit one of Tietoevry’s data centres in Sweden and encrypted the servers running its hosting platform. Tietoevry isolated the affected systems quickly but the damage had already reached its customers.

The outage took down Primula, a payroll and HR platform used by most Swedish universities and more than 30 government authorities. Cinema chain Filmstaden could not sell tickets, retailer Rusta and farming supplier Granngården were disrupted and Granngården closed stores.

A health-care region in Uppsala lost access to records, Sweden’s central bank filed a police report and the civil defence minister said 178 possible personal-data-breach reports were filed. Recovery ran from days into weeks.

Finland’s national cyber centre later reported that most of the Akira intrusions it examined came in through unpatched VPN appliances. The joint CISA advisory on Akira urges enforcing multi-factor authentication on every remote-access route and keeping tested offline backups since the group hunts for backups too.

The lesson is entry hygiene backed by monitoring. Close the remote-access gap, then watch for the lateral movement that follows so an intrusion is caught in the hours before the encryptor runs.

Real-World Cases

Miljödata and the Municipal Supply-Chain Attack (2025)

In August 2025 attackers hit Miljödata, a Swedish supplier whose software handles sick leave, medical certificates, rehabilitation plans and workplace-accident reports for roughly 80% of the country’s municipalities. Early estimates put the disruption at around 200 of Sweden’s 290 municipalities along with several regions. Authorities later confirmed 164 municipalities and four regions directly affected, and around 250 client organisations in total once universities and private firms are included.

This was double extortion. “The attackers stole sensitive HR and health data and threatened to publish it, then demanded about 1.5 bitcoin, close to 144,000 euros, a sum small enough to point at opportunists rather than a major crew. “Miljödata pulled the affected systems offline. No group claimed the attack at first, but the DataCarry extortion group later listed Miljodata on its leak site and published the stolen data in mid-September 2025, exposing the personal data of around 1.5 million people in one of Sweden’s largest breaches.

No amount of monitoring inside a single municipality would have stopped a breach at its supplier and that is the point. When hundreds of bodies depend on one provider, supplier concentration becomes a board-level risk and NIS2 now treats supply-chain security as a duty rather than a courtesy.

The realistic defence is to know which suppliers hold your data, to keep watching your own environment and to hold a reporting and recovery plan you have actually rehearsed. When the supplier is the target, the damage is measured in how fast you detect, report and restore.

MDR and Compliance

For Swedish organisations, detection and response is now partly a legal duty. Cybersäkerhetslagen, statute SFS 2025:1506, brought the EU NIS2 Directive into Swedish law on 15 January 2026. “Its risk management measures include incident handling under Article 21.2b, the core duty MDR is built to deliver and continuous detection and response support the wider monitoring the directive expects. Article 21.2a covers policies on risk analysis and information system security, so continuous monitoring should not be attributed to it. You can read the detail on our NIS2 compliance guide for Sweden.

NIS2 also raises the stakes at the top. Under Article 20 the management body must approve and oversee security measures and board members can be held personally accountable for failures. Detection and response is no longer only an IT concern.

When an incident hits, the clock starts. Reporting runs to the National Cyber Security Centre (NCSC) at FRA which took over as Sweden’s single point of contact and CSIRT on 1 July 2026 and to the relevant sector authority in a set cascade. You must send an early warning within 24 hours, a full notification within 72 hours and a final report within one month. An MDR provider should produce the incident documentation these deadlines demand.

Other regimes add their own detection and reporting duties. Financial entities fall under DORA, whose Article 17 requires managed ICT incident handling and is supervised by Finansinspektionen. Any personal-data breach also triggers GDPR Article 33, a 72-hour notification to the Swedish authority IMY. Well-documented detection is what makes these deadlines survivable.

Where your data lives matters too. After the Schrems II ruling, storing data inside the EU is not enough on its own if the provider can be compelled to hand it to a foreign government under laws like the US CLOUD Act.

For regulated Swedish bodies this makes the location of MDR telemetry and the provider’s sub-processors a real question to ask. A provider’s own certifications, such as ISO 27001, are worth checking here as well.

How to Choose an MDR Provider

Because so many services wear the MDR label, the differences that matter are easy to miss. A few questions separate a real detection-and-response partner from a dashboard with a logo.

  • Is it human-led? Gartner warns that some offerings lean on technology and thin out the human analysis. Ask who reads your alerts and makes the call.
  • Does it respond, or only alert? A real service contains threats or drives the response, rather than emailing you an alert and leaving the rest to you.
  • Is the cover genuinely round-the-clock? Attacks are timed for nights and weekends so a gap in cover is a gap an attacker will use.
  • What does it actually watch? Endpoints are the baseline. Network, identity and cloud signals matter as much, because that is where modern intrusions move.
  • Where does your data go? Ask where telemetry and logs are stored and who the sub-processors are so you can weigh Schrems II and CLOUD Act exposure.
  • Is the provider itself certified? Independent certification such as ISO 27001 shows its own security is held to a recognised standard.
  • How fast can it start, and how cleanly can you leave? Onboarding time and a clear exit with your data returned tell you a great deal about a provider.

One caveat matters more than any single feature. MDR is detection and response, not prevention. It shortens the time an attacker has and limits the damage, but it does not replace patching, backups, strong identity controls and staff training. The strongest setups treat it as a safety net under those basics.

Getting Started with MDR

If MDR looks like the right move, a little groundwork makes it far more effective.

Getting Started with MDR
  • Map what you are protecting. List your critical systems, your data and the suppliers who touch them so monitoring and supplier risk are scoped from the start.
  • Get telemetry in place. Make sure endpoint detection and response covers your laptops and servers because that data is what an MDR team reads.
  • Close the common entry routes. Enforce multi-factor authentication on all remote access and patch internet-facing systems, the gaps the Tietoevry attackers used.
  • Agree who can act. Decide in advance whether the provider may contain a threat directly or must wait for your go-ahead, because minutes matter during an incident.
  • Rehearse the reporting clocks. Walk through the 24-hour, 72-hour and one-month NIS2 deadlines with the provider before a real incident forces the pace.
  • Test the plan. Run a tabletop exercise so detection, response and reporting are muscle memory rather than theory.

None of this is exotic. It is the difference between an attack that becomes a headline and one that ends as a line in a monthly report. Detection and response only works when someone is watching and ready to act so decide who that is before an attacker does.

Myths & Facts

Myth

MDR is just antivirus with a fancier name.

If we have EDR, we do not need MDR.

MDR is only for large enterprises.

We can just build our own 24/7 SOC.

MDR stops every attack.

All MDR services are basically the same.

Fact

MDR is a service, not a product. It puts human analysts on your telemetry around the clock to investigate and respond, which antivirus and EDR tools cannot do on their own.

EDR is the tool that generates the signals. MDR is the team that watches those signals full time and acts on them, and most breaches happen in the hours when no one is looking.

Smaller organisations are hit hardest. Ransomware featured in 88% of breaches at small and medium businesses in 2025 (Verizon), and MDR lets them reach skills they cannot hire.

In-house detection needs people few can find or keep. In 2025, 88% of organisations reported a security problem tied to a skills gap and a third could not staff their teams (ISC2).

MDR shortens the time an attacker has and limits damage, but it is not prevention. It works alongside patching, backups, identity controls and staff training, not instead of them.

More than 600 providers use the label (Gartner). What separates them is whether a human really leads the work, whether they contain threats or only raise alerts and where they keep your data.

Test Yourself

Four real-world scenarios, then six knowledge questions. See how prepared you would be under pressure.

Scenario Simulation

  1. It is 2am on a Saturday. Your EDR tool flags unusual access on a server, but your IT team does not work weekends.

    What is the safest arrangement to have in place beforehand?

    • Hope someone checks the alert on Monday
    • An MDR service watching and able to respond around the clock
    • A louder email notification
  2. A vendor tells you their EDR product will give you full detection and response.

    What should you check?

    • Nothing, EDR and MDR are the same thing
    • Whether a human team monitors and responds, or you are left to run the tool yourself
    • The colour of the dashboard
  3. A supplier that holds your HR and payroll data is hit by ransomware, and your services go down with theirs.

    What would have helped most?

    • Assuming the supplier's security is the supplier's problem
    • Knowing which suppliers hold your data and having a rehearsed reporting and recovery plan
    • Waiting for the supplier to explain what happened
  4. You confirm a significant security incident on a Monday morning.

    What does NIS2 require first?

    • A full technical report immediately
    • An early warning to the NCSC at FRA within 24 hours
    • Nothing until you have fixed it

Knowledge Test

  1. What does MDR stand for?

    • Managed Detection and Response
    • Monitored Data Recovery
    • Managed Data Retention
    • Multi-Domain Response

    MDR stands for managed detection and response, a service that detects and responds to threats on your behalf.

  2. Which two NIST Cybersecurity Framework functions does MDR mainly deliver?

    • Identify and Protect
    • Detect and Respond
    • Govern and Recover
    • Protect and Recover

    MDR delivers the Detect and Respond functions of the NIST Cybersecurity Framework as a managed service.

  3. Roughly how long did the average breach take to identify and contain in 2025?

    • About 24 hours
    • About 40 days
    • About 240 days
    • About 3 years

    The IBM and Ponemon 2025 report put the average at 241 days, the lowest in nine years but still around eight months.

  4. In Verizon's 2025 report, ransomware appeared in what share of breaches?

    • 4%
    • 24%
    • 44%
    • 94%

    Ransomware featured in 44% of breaches in 2025, up from 32% the year before.

  5. What is the main difference between EDR and MDR?

    • EDR is newer than MDR
    • EDR is a tool and MDR is the service that operates it
    • MDR only works on servers
    • There is no difference

    EDR is the detection tool and MDR is the human-led service that watches it and responds.

  6. Under NIS2, how quickly must an early warning of a significant incident be sent?

    • Within 24 hours
    • Within 72 hours
    • Within 1 month
    • Within 1 year

    NIS2 requires an early warning within 24 hours, a full notification within 72 hours and a final report within one month.

Take It with You

Share the Summary PDF with Your Team

A short distilled brief in PDF: key findings, red flags and action steps.

Download summary PDF

Why Training Matters

Even the best detection works better when fewer attacks get through in the first place. Most breaches still begin with a person, through a phishing email, a reused password or a malicious link, and Verizon’s 2025 report again found the human element behind a large share of incidents.

Security-awareness training lowers how often those first footholds succeed, which means fewer alerts for an MDR team to chase and fewer real intrusions to contain. Detection and response and trained staff work as two halves of the same defence, and the organisations that fare best invest in both.

Frequently Asked Questions

What is MDR (managed detection and response)?

MDR is a service where an external team watches your systems around the clock and detects, investigates and responds to cyberattacks for you. It delivers the work of a security operations centre, run by human analysts using detection tooling, so you get expert cover without building and staffing a 24/7 team yourself.

What is the difference between MDR and EDR?

EDR (endpoint detection and response) is a tool that records activity on your devices and can isolate a compromised one. MDR is the managed service that operates that tooling for you, with analysts who watch the alerts, investigate them and respond. In short, EDR is what you buy and MDR is who runs it.

Is MDR the same as an MSSP?

No. An MSSP (managed security service provider) offers a broad set of managed security tasks, which can include firewalls, patching and device management. MDR is focused specifically on detecting and responding to threats, usually with deeper analysis and faster containment. Some MSSPs include an MDR capability, but the depth varies, so ask what is covered.

Does MDR meet the NIS2 or Cybersäkerhetslagen monitoring requirement?

“MDR maps directly to the NIS2 incident-handling duty (Article 21.2b) and supports the detection and response the directive expects, now law in Sweden through Cybersäkerhetslagen. It does not cover every obligation, such as supply-chain security or awareness training, so treat MDR as one strong part of NIS2 compliance rather than the whole of it.

How much does MDR cost?

MDR is usually priced as a recurring fee, often per protected endpoint or by the size of your environment. What matters more than the headline figure is what the price includes, whether response and containment are covered, whether data volume is capped and whether an incident triggers extra charges. Ask for the full scope before comparing quotes.

Do we still need MDR if we already have antivirus or EDR?

Usually yes. Antivirus and EDR generate signals, but someone has to watch and act on them, and most intrusions unfold at night or over weekends when in-house teams are offline. MDR supplies the continuous human attention that turns those tools into real detection and response, closing the gap between an alert and a decision.

How do I choose an MDR provider?

Focus on the few things that separate real services from dashboards. Check that the service is human-led, that it contains threats rather than only alerting, that cover is genuinely 24/7 and that you know where your data is stored and who the sub-processors are. Onboarding time and clean exit terms tell you more still.

Where is our data stored with an MDR service, and why does it matter?

It depends on the provider, and it matters because of data-residency law. After the Schrems II ruling, keeping data in the EU is not enough if the provider can be compelled to disclose it to a foreign government under laws like the US CLOUD Act. Ask where your telemetry and logs sit and who can access them.

You Understand the Risk.
Now See Where You Stand.

Book a 30-minute briefing with one of our analysts, or run the free breach check first to find out what attackers already know about your organisation.

Book a 30-Min Briefing
No sales pitch, just a straight assessment

How eBuilder Security Can Help

Awareness is the first layer. These are the services that turn it into measurable protection.