What Is MDR? A Plain-English Guide for New York Firms

MDR — managed detection and response — has moved from security-conference vocabulary to a line item on cyber-insurance applications, which is why New York business owners who never asked about it are now being asked about it. This guide explains what the service is, what it is not, and how to evaluate it. The service page for our own offering is managed detection and response; this article is the background reading.

MDR in one paragraph

MDR is a service, not a product. A provider collects telemetry from your environment — what programs run on each laptop, who signs in from where, what email arrives — watches it continuously with detection tooling, has people triage what the tooling flags, and takes action when something is real: isolating a machine from the network, disabling a compromised account, blocking a malicious sender. It exists to answer one question: if an attacker is in your environment right now, who notices, and what happens next?

What MDR does, step by step

  • Collect. An EDR agent on every endpoint records process activity; identity logs — in Microsoft environments, Entra ID sign-ins — and email events feed the same pipeline. Coverage matters more than any single tool: an attacker who avoids your instrumented laptops but owns your identity provider has won.
  • Detect. Analytics flag behavior rather than just known malware: impossible-travel sign-ins, credential abuse, lateral movement between machines, mass file encryption beginning. Behavioral detection is what catches the attacks antivirus misses, because modern intrusions mostly use legitimate credentials and built-in tools.
  • Triage. A person distinguishes real compromise from the false alarms that behavioral detection inevitably produces. This is the step that separates MDR from software you bought that nobody watches.
  • Respond. Containment — isolate the host, disable the account, expire the sessions — happens under authority you granted in writing, followed by remediation guidance and a written incident report.

One honesty note that applies to every provider, including us: tooling watches around the clock; humans work in staffing models that vary widely across the industry. Ask any MDR vendor to describe precisely who is on duty and when, and prefer the vendor who answers precisely.

MDR versus the things it gets confused with

Tool or serviceWhat it isWhat it is not
Antivirus / EPPSoftware that blocks known malware on a machineNobody is watching; credential-based attacks walk past it
EDRSoftware that records endpoint behavior and enables remote responseA tool, not a service — unmonitored EDR is a flight recorder for a crash nobody prevents
SIEMA system that aggregates logs for search and correlationCollection without operators is storage, not security
MDRPeople operating detection tooling: triage, containment, reportingIt does not patch, back up, or administer your systems
MSSPThe broader security-operations relationship: vulnerability management, reporting, compliance evidenceMDR is usually one service inside it

The category lines confuse almost everyone, including some of the people selling the services. If the vocabulary still feels slippery, our comparison of MSP, MSSP, and MDR covers where the boundaries sit, and our managed cybersecurity page shows how the pieces assemble into a full scope.

Why New York firms keep hearing about it

Insurers ask first. Cyber-insurance carriers now routinely condition coverage on enforced MFA and on endpoint detection; underwriting surveys published in 2025 report that the large majority of carriers require EDR or MDR, and that ransomware drove most carrier losses in the first half of that year. For many firms, the renewal application is the first place the acronym appears.

Regulators assume monitoring. For firms covered by NYDFS 23 NYCRR 500 — anyone licensed under New York’s Banking, Insurance, or Financial Services Law — the amended rule’s requirements, fully phased in as of November 1, 2025, include monitoring, incident response, and an annual certification due April 15. HIPAA and the FTC Safeguards Rule carry their own monitoring and testing expectations for healthcare practices and for CPA and tax firms of any size. MDR is not named in any of these texts, but it is how smaller firms typically operate the monitoring these programs assume exists.

Clients ask in writing. Law firms and B2B vendors increasingly receive security questionnaires from their own clients — outside-counsel guidelines in particular ask directly who monitors endpoints and how incidents are contained. “We have antivirus” does not survive contact with those documents.

What MDR does not do

  • It does not patch. Detection tells you an unpatched server was exploited; vulnerability management is the separate discipline that prevents the sequel.
  • It does not back up or restore anything. Ransomware containment limits the blast radius; recovery still depends on tested backups.
  • It does not make you compliant by itself. MDR is one control inside a program — the risk assessments, policies, and evidence a regime requires are separate work.
  • It does not fix a weak environment. Containment on a flat network with shared admin passwords is a treadmill; the incidents keep coming until the hygiene improves.
  • It does not answer help-desk tickets. Detection and IT operations are different jobs, even when — as we would argue — they belong under one accountable roof.

Questions to ask any MDR provider

  • What telemetry do you cover beyond endpoints — identity, email, cloud? Identity is where modern attacks live.
  • Who triages alerts, and on what staffing model? Accept only a precise answer.
  • What response actions are pre-authorized, and where is that written down?
  • What do I receive after an incident, and will it stand up in front of my insurer or regulator?
  • What happens at termination — do I keep the telemetry, the reports, and the tooling configuration?

Stedholm operates MDR as part of a single discipline with managed IT, because detection without remediation authority adds hours to every incident — the person who isolates a machine should work from the same playbook as the person who rebuilds it. If you want to know what your current tooling would actually catch, a scoped IT and security assessment maps your telemetry coverage and hands you the findings either way.

Ready for firmer ground?

Talk through your environment with an engineer — no scripts, no pressure.