" /> Managed Detection and Response (MDR): 24/7 SOC from $8 per Device
Veiledning

Managed Detection and Response (MDR) for SMBs and MSPs

24/7 MDR on Sophos, Microsoft Defender, SentinelOne or CrowdStrike with 15-minute triage, active response and compliance evidence, from $8 per device per month at partner pricing.

Oppdatert · sep 2026 By ITSECOPS Gratis · Ingen påmelding

Managed Detection and Response (MDR) gives your business a 24/7 security team that watches every endpoint, identity and cloud sign-in, investigates alerts within minutes and stops attacks before they become ransomware. ITSecOps delivers MDR on Sophos, Microsoft Defender, SentinelOne or CrowdStrike, from SOC teams in Norway (CET) and India (IST), at a fixed monthly price per endpoint and with no minimum seat count.

Updated September 4, 2026. In August 2026 the Medusa ransomware operation passed 500 confirmed victims and was observed exploiting newly published vulnerabilities within 24 hours of disclosure. Boston Scientific’s global operations were disrupted by a cyberattack in the same month. In both patterns the initial access happened outside business hours, and the companies that contained it had someone responding at 02:00. That is what MDR is for.

What is included in ITSecOps MDR

Capability What you get Why it matters
24/7 monitoring Analysts in two time zones, 365 days, 15-minute triage SLA on high-severity alerts Ransomware is deployed at night and on weekends by design
Endpoint agent (EDR/XDR) Sophos Intercept X with XDR, Microsoft Defender for Business or Endpoint, SentinelOne Singularity or CrowdStrike Falcon Behavioural detection, ransomware rollback, device isolation
Identity and cloud telemetry Microsoft 365 / Entra ID, Google Workspace, firewall and VPN logs correlated with endpoint events Credential theft precedes most intrusions; endpoint-only tools miss it
Threat hunting Weekly hypothesis-driven hunts across your estate, plus hunts triggered by new CVEs and campaigns Finds dwelling attackers that never trip an alert
Active response We isolate hosts, disable accounts, block hashes and domains, and revoke sessions, with your pre-agreed rules of engagement Containment in minutes instead of a ticket in your inbox
Reporting and evidence Monthly report, incident timelines, and evidence packs mapped to ISO 27001, SOC 2, NIS2, CMMC and cyber-insurance questionnaires Turns security spend into audit and insurance value
Onboarding Agent rollout via Intune, RMM or scripts, policy baseline, tuning period of 2 weeks Live in 5 to 10 business days for most SMBs

Who MDR is for

  • SMBs with 25 to 500 endpoints that have EDR or antivirus but nobody watching the console after 17:00.
  • Regulated companies under NIS2, CMMC, HIPAA, ISO 27001 or SOC 2, where 24/7 monitoring and incident reporting evidence are expected.
  • Businesses renewing cyber insurance, where the questionnaire now asks for EDR plus 24/7 monitoring and MFA.
  • MSPs that want to sell MDR under their own brand. See our white-label NOC and SOC service.

MDR pricing

MDR is priced per protected device (workstation or server) per month. Indicative list ranges for the platforms we deliver on:

Platform Best for Indicative price per device / month
Microsoft Defender for Business + ITSecOps MDR Microsoft 365 Business Premium tenants (Defender licence already included) $8 to $12
Sophos MDR Complete (Intercept X Advanced with XDR) Most SMBs, mixed Windows/macOS estates, firewall integration $10 to $16
SentinelOne Singularity Complete + ITSecOps SOC Autonomous response, rollback, Linux-heavy environments $11 to $17
CrowdStrike Falcon Complete Enterprise and best-of-breed requirements $14 to $22

A 50-endpoint company therefore budgets roughly $500 to $800 per month for MDR, less than the cost of one day of a ransomware outage. Use the Security Stack Recommender to see which platform fits your environment and get a quotation, or compare in-house against managed on our 24/7 SOC monitoring cost guide.

How the service runs

  1. Scoping call (30 minutes). Endpoints, servers, identity platform, existing tools, compliance drivers, insurance requirements.
  2. Rules of engagement. We agree what we may do automatically (isolate a host, disable an account) and what needs your approval.
  3. Deployment. Agents pushed through Intune, your RMM or our scripts. Legacy antivirus removed. Microsoft 365 and firewall log sources connected.
  4. Tuning (2 weeks). Noise suppression, allow-listing of line-of-business software, baseline of normal behaviour.
  5. Steady state. 24/7 monitoring, weekly hunts, monthly report and a quarterly review with your management.

MDR versus EDR, XDR and a SIEM

EDR is the software; MDR is the software plus the people. XDR extends detection beyond the endpoint to identity, email and network, and is included in our MDR because we ingest those sources. A SIEM adds long-term log retention and compliance reporting across every system, which most SMBs only need once they pass roughly 100 endpoints or fall under NIS2 or CMMC. Read the full comparison in EDR vs MDR vs XDR, or see SIEM as a Service if you need retention and reporting.

Frequently asked questions

Can you use the EDR licence we already own?

Yes. We run MDR on top of Microsoft Defender for Business, Sophos, SentinelOne and CrowdStrike licences you already hold. If your current product is a legacy antivirus, we replace it as part of onboarding.

Do you actually respond, or just send alerts?

We respond. Under the rules of engagement agreed at onboarding we isolate hosts, kill processes, disable compromised accounts and block indicators, then tell you what we did and why.

How fast is onboarding?

Most companies under 200 endpoints are fully monitored within 5 to 10 business days, including a 2-week tuning window that runs in parallel.

Where is my data processed?

Telemetry stays in the vendor’s cloud region you choose (EU or US). ITSecOps analysts access it through the vendor console with MFA and audited sessions. We sign a DPA and NDA before onboarding.

Is there a minimum contract?

Month-to-month after a 3-month initial term. Multi-year terms reduce the per-device price.

Do you offer MDR to MSPs under their brand?

Yes. MSPs resell our MDR as their own SOC, with us working inside their PSA and ticketing. See how we compare with other white-label SOC providers.

Trenger du hjelp til å ta dette i bruk i din bedriftsmiljø?

Vi gjør compliance-guider om til implementerte kontroller. Snakk med en ingeniør.

Bestill en konsultasjon