Someone is awake at 3am. It doesn’t have to be you.
MDR puts Sophos analysts — a staffed, follow-the-sun SOC — behind the EDR telemetry on your machines. They investigate, contain and neutralise around the clock, and wake us with a report instead of waking you with a ransom note.
No small business can staff a 24/7 SOC, and no honest provider should pretend to be one.
A real security operations centre needs a dozen analysts just to cover shifts, holidays and attrition — a seven-figure payroll before the tooling. Attackers know this, which is why small-business intrusions start on Friday night. Renting Sophos’s SOC per endpoint is the only honest way a twenty-person company gets that coverage, and we would rather resell it transparently than imitate it badly.
A night shift you never meet.
What actually happens when the telemetry turns hostile at an inconvenient hour. Response authority is agreed at onboarding — isolate-first for most clients, call-first where an outage costs more than the risk.
| The event | What the SOC does | What you experience |
|---|---|---|
| 01Ransomware behaviour, 2am Saturday | What the SOC doesIsolates the machine, kills the process tree, hunts for siblings across the estate | What you experienceA report over coffee, not an outage |
| 02Stolen credentials used from abroad | What the SOC doesSession revoked, account locked, entry point traced to the phish that started it | What you experienceA password reset and an explanation |
| 03Attacker “living off the land” | What the SOC doesAnalysts recognise hostile use of legitimate tools that automation alone would score too low | What you experienceNothing — which is the product |
| 04Ambiguous alert | What the SOC doesInvestigated by a human before anyone is woken; most alerts die here as benign | What you experienceSilence instead of alert fatigue |
| 05Confirmed incident | What the SOC doesContained, documented, then escalated to us with a full timeline and actions taken | What you experienceOne call from an engineer you know, with answers |
| 06Novel campaign elsewhere | What the SOC doesIntelligence from thousands of watched estates arrives as protection before it arrives as news | What you experienceImmunity you never knew you acquired |
Sophos publishes that figure on its Managed Detection and Response page; it measures automated containment, not a human analyst, and it is Sophos’s number for their platform rather than a commitment from us. Ours are the response targets on the Managed IT page. Sophos also reports that 52% of MDR cases now close end-to-end without an analyst touching them — which is the argument for it, not against it. The automation clears the routine half, so the people on shift spend the night on the half that actually needs a judgement call. Nobody is removed from the loop; they are moved to the part of it that matters. The last row is the quiet argument for renting a SOC: a detection written for someone else’s incident at noon is protecting your estate by dinner. If you are weighing the two, MDR versus managed EDR sets them side by side, and antivirus versus EDR covers the layer underneath. Sectors that buy this first: healthcare, law firms and retirement residences.
The ones people actually ask.
If yours isn’t here, ask it directly — you’ll get an answer from an engineer, not a form letter.
Because a staffed SOC carries a real per-endpoint cost that we pay Sophos, and hiding it in a bundle would just mean padding every bundle. You see the number, you decide with it in front of you. EDR, mail, DNS and firewall are the included baseline; MDR is the human tier above it.
Honest answer: it depends on what an outage costs you. A dental clinic that loses a day of appointments, or a firm that moves client money, usually finds the per-endpoint cost trivial against one avoided incident. A five-person office with good backups may reasonably wait — and we will say which one you are.
What you pre-authorise. Most clients grant isolate-first authority — a machine behaving hostilely is cut off immediately, questions after. The alternative is call-first for environments where isolation itself is costly. Either way it is written down at onboarding.
An alert service tells you something happened and wishes you luck. MDR investigates, decides and acts — containment is part of the service, not a recommendation in an email you read on Monday.
Us. The SOC handles the moment; we handle you — the explanation, the follow-up hardening, and whatever the incident revealed about the estate. You never manage the vendor relationship, because that is our job.
Next
Watched while you sleep.
Twenty minutes. Tell us what an unplanned day of downtime costs you — that number decides whether MDR is worth it, and we will do the arithmetic with you.