Bristol, Gloucestershire, Wiltshire, Somerset, Dorset, Devon, Cornwall and the South West
MULTI AWARD WINNING IT SUPPORT, SOLUTIONS AND SERVICES
Managed Detection
Response. MDR.
"I would have no hesitation in recommending Soltech.”
Janie Tucker, Managing Director, Waste-Disposer Warehouse
SME
Managed Detection and Response (MDR)
Corporate
Managed Detection and Response (MDR)
Charity
Managed Detection and Response (MDR)
Public Sector
Managed Detection and Response (MDR)
What If Someone Is Attacking Your Business Right Now?
Cyber attacks don't only happen during office hours.
An attacker could be attempting to compromise your business at 2am on a Sunday morning, when your IT team isn't working.
Traditional antivirus can generate an alert.
Your firewall can generate an alert.
Microsoft 365 can generate an alert.
But who is watching those alerts, determining what is a genuine threat and taking action?
That's where Managed Detection & Response (MDR) comes in.
Soltech IT's MDR service provides continuous security monitoring, threat detection, investigation and response, helping identify and contain cyber threats before they become a major business incident.
What Is Managed Detection & Response?
MDR combines advanced cyber security technology with human security expertise.
Rather than simply installing security software and waiting for an alert, MDR continuously analyses activity across your environment to identify suspicious behaviour.
When a potential threat is detected, security specialists can:
Detect → Investigate → Contain → Respond → Recover
This provides an additional layer of protection between your business and cyber criminals.
Why Businesses Need MDR
Modern cyber attacks are increasingly difficult to detect.
- Attackers may:
- Steal legitimate credentials
- Exploit vulnerabilities
- Use legitimate Windows tools
- Compromise Microsoft 365 accounts
- Move laterally through networks
- Disable security controls
- Remain undetected for extended periods

Simply having antivirus installed isn't enough.
You need to know when something unusual is happening—and have someone capable of investigating it.
24/7 Security Monitoring
Cyber criminals don't work 9–5.
MDR provides continuous monitoring of security events, helping identify threats outside your normal working hours.
This is particularly important for businesses that don't have their own:
- Security Operations Centre
- Security analysts
- Incident response team
- 24/7 IT department
MDR effectively gives smaller organisations access to capabilities that would otherwise be difficult and expensive to build internally.
What Does MDR Monitor?
Depending on the service and technology deployed, MDR can monitor activity across areas such as:
- Endpoints
- Servers
- Microsoft 365
- User identities
- Cloud services
- Network activity
- Security applications
- Authentication events
This provides a broader view than monitoring a single security product.
Detecting Ransomware
Ransomware can spread rapidly once attackers gain access to an organisation.
MDR can identify suspicious activity associated with ransomware, including:
- Unusual file activity
- Suspicious processes
- Malicious scripts
- Credential abuse
- Attempts to disable security controls
- Abnormal network behaviour
Where appropriate, affected systems can be isolated while the incident is investigated.
The objective is simple: Stop the attack before it spreads.
Detecting Account Compromise
An attacker doesn't necessarily need malware to compromise your business.
They may simply steal an employee's Microsoft 365 credentials.
MDR can help identify suspicious activity such as:
- Unusual sign-ins
- Abnormal authentication
- Suspicious account activity
- Unusual access patterns
- Privilege escalation
This can help identify compromised accounts before attackers have time to cause significant damage.
Human-Led Threat Investigation
One of the key differences between MDR and basic security monitoring is human investigation.
A security alert doesn't automatically mean your organisation has been hacked.
Security analysts can investigate:
- What happened?
- Which device was involved?
- Which account was involved?
- How did the activity begin?
- What happened immediately before it?
- What systems were accessed?
- Is the threat still active?
- Has it spread?
This reduces the risk of important threats being buried among thousands of routine alerts.
Automated Response
Where supported by the technology and service configuration, MDR can respond rapidly to threats.
This can include actions such as:
- Isolating a compromised endpoint
- Blocking malicious activity
- Disabling compromised accounts
- Quarantining malicious files
- Preventing further communication
Rapid containment can be critical during ransomware and account compromise incidents.

MDR vs EDR
These services are closely related but aren't the same thing.
EDR — Endpoint Detection & Response
EDR is the technology installed on endpoints that provides visibility and detection capabilities.
MDR — Managed Detection & Response
MDR adds security specialists who monitor, investigate and respond to threats using EDR and potentially other security data sources.
A simple way to think about it:
EDR provides the eyes and sensors.
MDR provides the security team watching them.
MDR & Microsoft 365
Microsoft 365 is a major target for cyber criminals.
MDR can work alongside Microsoft security technologies to help identify suspicious activity involving:
- Entra ID
- Microsoft 365
- Defender
- Exchange Online
- SharePoint
- OneDrive
- User accounts
This provides additional security visibility around one of the most important systems in your business.
MDR & Email Security
Email remains one of the primary ways attackers gain initial access.
MDR can complement your email security by helping identify what happens after an email gets through.
For example:
Phishing email → Employee clicks → Credentials compromised → Suspicious sign-in → MDR detects unusual activity → Account investigated → Threat contained
This layered approach helps protect against the reality that no email security system can stop every malicious message.
MDR & Cyber Essentials
MDR does not replace Cyber Essentials.
Cyber Essentials establishes a baseline of technical security controls.
MDR provides continuous threat detection and response.
They address different parts of your cyber security strategy and can work effectively together.
MDR & Cyber Essentials Plus
Cyber Essentials Plus provides additional independent technical assurance.
MDR provides ongoing monitoring and response.
For organisations with higher security requirements, combining certification with continuous security monitoring can provide a stronger overall security posture.
MDR & Cyber Insurance
Cyber insurers increasingly ask organisations about their ability to detect and respond to cyber incidents.
MDR can help demonstrate that your organisation has an active security monitoring and incident response capability.
Your insurer's specific requirements will vary, so we recommend checking your policy and renewal requirements.
MDR for Small & Medium-Sized Businesses
You don't need to be a large enterprise to require enterprise-level security.
Small and medium-sized businesses can be particularly vulnerable because they may have:
- Valuable customer information
- Financial data
- Microsoft 365
- Remote workers
- Limited internal IT resources
- No dedicated security team
MDR gives smaller organisations access to continuous security monitoring without having to build their own Security Operations Centre.
MDR for Professional Services
Accountants, solicitors, financial organisations and other professional services businesses hold information that criminals may find highly valuable.
MDR can provide additional protection for organisations handling:
- Financial information
- Customer records
- Personal information
- Contracts
- Intellectual property
- Confidential communications
MDR for Schools
Schools and Multi Academy Trusts have a complex security environment.
They may have:
- Large numbers of users
- Staff and pupil devices
- Microsoft 365
- Sensitive safeguarding information
- Financial information
- Remote access
MDR can provide additional monitoring and response capabilities without requiring the school or Trust to employ its own 24/7 security team.
Discover the right certification for your business.
Explore Cyber Essentials and Cyber Essentials Plus.
What Happens When MDR Detects a Threat?
1. Detect
Suspicious activity is identified.
2. Analyse
Security specialists investigate the activity.
3. Determine
The team establishes whether the activity represents a genuine threat.
4. Contain
Where appropriate, affected devices or accounts are isolated.
5. Respond
The threat is removed and systems secured.
6. Report
Relevant information is provided to the customer.
7. Learn
The incident is reviewed and additional security improvements recommended.
MDR Is Part of a Complete Cyber Security Strategy
MDR shouldn't operate in isolation.
A strong security strategy combines multiple layers.
- Prevent
- Cyber Essentials
- Microsoft 365 Security
- Email Security
- MFA
- Secure Configuration
- Protect
- EDR
- Firewalls
- Endpoint Security
- Vulnerability Management
- Detect
- MDR
- Dark Web Monitoring
- Security Monitoring
- Test
- Penetration Testing
- Cyber Security Auditing
- Phishing Simulation
- Educate
- Security Awareness Training
- Recover
- Backup & Disaster Recovery
- Incident Response
Speak to Soltech IT about your businesses Cyber Security needs
Contact Us
Why Choose Soltech IT for MDR?
MDR is most effective when it is integrated with the rest of your IT and security environment.
Soltech IT can provide a complete cyber security service including:
- Managed Detection & Response
- Managed Security Risk
- Endpoint Detection & Response
- Microsoft 365 Security
- Email Security
- Cyber Essentials
- Cyber Essentials Plus
- Penetration Testing
- Cyber Security Auditing
- Vulnerability Management
- Phishing Simulation
- Security Awareness Training
- Dark Web Monitoring
- Incident Response
- Backup & Disaster Recovery
This means your security isn't a collection of disconnected products.
It's a managed security strategy.
Frequently Asked Questions
What is MDR?
Managed Detection & Response is a cyber security service that combines security technology with security specialists who continuously monitor, investigate and respond to potential threats.
Is MDR the same as antivirus?
No. Antivirus is an important preventative security control. MDR provides ongoing detection, investigation and response across your security environment.
Do I need EDR before getting MDR?
MDR commonly uses EDR as an important source of security telemetry, although the exact technology requirements depend on the MDR service.
Does MDR really monitor 24/7?
MDR services can provide continuous monitoring, but the precise hours, response arrangements and service levels depend on the service package.
Soltech IT can explain exactly what is included in your MDR service.
Is MDR the same as antivirus?
No. Antivirus is primarily designed to prevent and detect malicious software. MDR provides broader threat detection, monitoring, investigation and response.
Do I need MDR if I already have Microsoft Defender?
Microsoft Defender provides powerful security capabilities, but configuration, monitoring and response are equally important. MDR can add managed monitoring and expert investigation to your existing security technologies.
Is MDR suitable for small businesses?
Yes. MDR can be particularly valuable for smaller organisations that cannot justify the cost of employing a dedicated 24/7 cyber security team.
Does MDR prevent every cyber attack?
No security solution can guarantee that an organisation will never be attacked. MDR is designed to improve the likelihood of detecting and containing threats quickly, reducing their potential impact.
Can Soltech IT manage our existing security systems?
In many cases, yes. We can assess your current security environment and determine where your existing technology can be used, improved or supplemented
Can MDR stop ransomware?
MDR can help detect and contain ransomware attacks, potentially limiting their spread and impact. No security service can guarantee that every attack will be prevented.
Don't Wait Until Someone Discovers an Attack
By the time an employee notices something is wrong, an attacker may already have been inside your environment for hours—or longer.
MDR gives your business an additional security team watching for the warning signs.
Detect threats earlier. Respond faster. Reduce the impact of cyber attacks.
Contact Soltech IT Ltd today to discuss Managed Detection & Response for your business.

Meet the team
Richard founded Soltech IT in 2009. Today the company works with an extensive range of clients throughout the UK, including globally recognised organisations, such as, The University of Oxford, Taylor Wimpey and Costa Coffee.
Richard has over 30 years experience working within the IT industry and having previously worked for UK and international accountancy software and IT firms,































