Christchurch · Dunedin · Nationwide
Managed Detection and Response for NZ Businesses
Security analysts monitor your connected devices, servers, Microsoft 365 accounts and supported cloud and network sources 24/7, investigate suspicious activity and take the actions you have approved in advance. Exodesk sets up the service, keeps you informed and works alongside your IT team.
Supporting New Zealand businesses since 1989
The short answer
What is managed detection and response?
Managed detection and response (MDR) is a security service in which analysts monitor your systems around the clock, investigate suspicious activity and take agreed action to contain a threat.
It connects to supported endpoint, cloud and network tools, and compatibility and licensing are checked before onboarding. Endpoint and cloud security tools raise alerts and can block or remediate some threats on their own. Managed detection and response adds the people who decide what an alert means, what else is affected and what to do next, at any hour.
Security tools
Software on devices, in Microsoft 365 and on the firewall that records activity, raises alerts and blocks known threats. Each tool sees only its own part of the business, and the alerts it raises wait until someone reads them.
Automated action
Responses the tools carry out themselves, such as quarantining a file. Microsoft documents that its automated investigation and response can remediate automatically or wait for approval, depending on configuration.
Analyst investigation and response
People reviewing alerts across the connected sources, deciding which are real and taking the containment steps you have approved. This is the managed part of the service.
When to look closer
When you need someone watching the alerts
Security tools can be installed and working while nobody is in a position to act on what they report.
These are signs managed detection and response is worth a closer look, not a diagnosis.
Alerts land in an unwatched inbox
Security warnings go to a shared mailbox or one person, and nobody checks them at night or over a weekend.
Support ends with the working day
Your IT support covers business hours, and there is no arrangement for a security problem that starts after them.
Nobody has authority to act
It has not been decided who can isolate a laptop or disable an account in the middle of the night.
Sign-in warnings go unread
Microsoft 365 reports risky sign-ins or new mailbox forwarding rules, but nobody reviews them.
Each tool is watched on its own
Devices, email and the firewall each have their own console, so activity that moves from one to another is not connected.
Problems are found by accident
Suspicious activity comes to light when a staff member notices something odd, rather than through monitoring.
What we monitor
What does our managed detection and response service monitor?
Analysts can only see what is connected to the service, so the scope lists each source.
Devices
Laptops, desktops and servers
Analysts see: processes, file activity, network connections and alerts from the endpoint detection and response agent.
Pre-agreed actions: isolating a device from the network, stopping a process or quarantining a file.
Covered while a supported agent is installed and reporting. Deploying and maintaining that protection is part of endpoint security.
Identity
Microsoft 365 accounts
Analysts see: sign-ins, multi-factor authentication changes, mailbox rules, permission changes and connected apps.
Pre-agreed actions: blocking account sign-in, revoking supported sessions and removing malicious forwarding rules, where the platform and permissions allow.
The signals available depend on your Microsoft 365 licences. Revoked sessions can take time to end, so access is checked afterwards.
Cloud
Other cloud platforms
Analysts see: sign-ins, administrator changes and file sharing.
Pre-agreed actions: the account actions the platform supports.
Coverage depends on a supported integration being available for the platform.
Network
Firewalls and network equipment
Analysts see: connection logs, blocked traffic and remote access sign-ins.
Pre-agreed actions: the actions agreed in your scope for the equipment in use.
Configuring the firewall stays with our managed firewall and network security services.
Your agreement lists the connected sources, the devices and accounts covered and the actions approved for each. The signals and actions available depend on the supported integration, licences, permissions and configuration, which we confirm during onboarding. A device or system that is not connected creates a monitoring gap. Other connected sources may still show related activity, but they do not replace the missing coverage.
Monitoring Microsoft 365 and other cloud accounts is sometimes called cloud detection and response. Here it is part of the managed detection and response service, so an attacker who signs in with a stolen password and then reaches a laptop is followed by the same analysts across both.
When something is found
What happens when a threat is detected?
Managed detection and response works through the steps below, whatever time an alert arrives. Investigation, containment and notification can overlap, depending on the threat.
Alert raised
A connected source reports something unusual. The tool may already have blocked it automatically, and that action is recorded.
Triage
An analyst checks whether the alert is a real threat, a false alarm or expected activity, such as a staff member signing in while on holiday overseas.
Investigation
For a real threat, the analyst establishes what happened, which devices and accounts are involved and whether anything has spread.
Containment
Analysts can take the containment actions you have approved, such as isolating a device or blocking an account, at any hour without waiting to reach you first. What an action achieves depends on the threat, the connected system and the permissions available. Anything outside that list follows the agreed escalation process.
Notification
Your named contacts are told what was found, what was done and what needs a decision from you.
Recovery and review
Clean-up and restoration are handed to whoever supports your systems, whether that is your own IT team, your IT provider or Exodesk. The incident is included in your monthly report.
Receiving an alert, investigating it and containing a threat are separate steps. Your agreement describes each one, including who is contacted and in what order. If you have an incident response plan, the notification and hand-off steps are aligned with it.
Worked example
Example: suspicious activity on a laptop after hours
An illustration of how managed detection and response works in practice, not a record of a real incident. It assumes the laptop and the Microsoft 365 account are both connected and the response permissions are in place.
- What was seen. Late on a Saturday, the agent on a finance laptop reports a script making changes staff do not normally make. Shortly before, the same user’s Microsoft 365 account signed in from an unfamiliar country.
- What was checked. The analyst confirms the script is not approved software, that the overseas sign-in was not expected, and which other devices the account has used.
- What was done. Device isolation and blocking the account from signing in are on the pre-agreed list, so the analyst starts both without waiting to reach anyone, then checks the results. Any remaining access or unsuccessful action is escalated through the agreed process.
- Who was told. The named contact receives a summary and the decisions that remain: resetting the password, checking mailbox rules and returning the laptop to use.
Endpoint security and MDR
How does MDR work with endpoint security?
Endpoint security protects the devices. Managed detection and response adds people who investigate and respond across devices, accounts and the network.
Modern endpoint protection does more than match known malware. It watches behaviour, detects suspicious activity and can respond automatically. MDR relies on those tools rather than replacing them, and adds a team that reviews what they report, connects it with activity elsewhere and acts on it.
The tools
Endpoint security
Protection deployed and maintained on your devices.
- Runs continuously on each device with the agent installed
- Blocks and remediates using the automatic actions configured
- Needs devices enrolled and kept up to date
The service
Managed detection and response
People who monitor, investigate and respond.
- Analysts monitor and respond 24/7
- Acts using the containment steps you have approved
- Watches devices, Microsoft 365, other cloud accounts and firewalls
- Needs named contacts and a pre-agreed list of actions
Together
How they work together
The tools stop what they can on their own, and analysts handle what needs a decision.
- Device alerts are investigated alongside account and network activity
- Deployment and maintenance sit with endpoint security
- Investigation and response sit with MDR
For deploying and maintaining protection on your devices, see endpoint security.
The service
What our managed detection and response service includes
Six parts, scoped around the devices, accounts and systems your business relies on.
24/7 monitoring
Analysts monitor the connected sources around the clock, every day of the year.
Investigation
Alerts are triaged and real threats investigated across devices, accounts and the network, rather than one tool at a time.
Agreed response
Pre-agreed containment actions are taken at any hour without waiting to reach you. Anything else goes to your named contacts for a decision.
Notification
You are told what was found, what was done and what needs your decision, with a record of each action.
Monthly report
A monthly summary of what was detected, what was dealt with and anything that needs attention.
Onboarding
Connecting the sources, agreeing response authority and contacts, and checking each source is reporting before monitoring starts.
Your agreement sets out the sources, devices and accounts covered and the actions approved. Managed detection and response can be bought on its own or alongside our managed IT services, and it works with your current IT provider or internal team on a co-managed basis.
Getting started
How do we put monitoring in place?
Managed detection and response covers a source only once it is connected and reporting, so setup is completed and checked before the service goes live.
Agree the scope
List the devices, servers, Microsoft 365 and cloud accounts and network equipment to connect, and anything that cannot be connected.
Agree authority and contacts
Decide which actions analysts can take without waiting to reach you, who is contacted and in what order, and who approves anything else.
Connect the sources
Install or confirm agents on devices and connect the cloud and network sources in scope.
Check every source is reporting
Confirm each device and integration is sending data and that a test alert reaches the right people.
Go live and keep it current
Monitoring starts once the checks pass. New devices, departing staff and system changes need adding or removing, so let us know when they happen. Your agreement states how a device or source that stops reporting is identified and followed up.
NZ guidance
What New Zealand guidance says about monitoring
The National Cyber Security Centre treats effective logging as the foundation of threat detection.
The NCSC co-published best practices for event logging and threat detection with international partners in 2024. It notes that attackers increasingly use tools already present on a system to avoid detection, known as living off the land, which makes effective logging more important.
Logging on its own does not find an attack. Detection depends on which sources are collected, how long records are kept, how detections are configured and whether someone acts on the result. That last part is what managed detection and response provides.
Cost
What affects the cost of managed detection and response?
MDR is priced on what is monitored.
We scope the service before quoting. These are the things that move the figure:
- Devices and servers. The number of laptops, desktops and servers with an agent.
- User accounts. The number of Microsoft 365 and other cloud accounts monitored.
- Sources connected. Which cloud platforms and network equipment are included.
- Endpoint protection. Whether suitable licences are already in place or supplied with the service.
Your quote sets out what the recurring fee covers and how adding devices, accounts or sources changes it. If you already buy endpoint protection, the quote shows how it fits with the service.
Why Exodesk
Why work with Exodesk?
Supporting businesses since 1989
We support New Zealand organisations from our teams in Christchurch and Dunedin, with security considered alongside your systems and support.
Detection and support coordinated
Exodesk sets up the service and agrees with your IT team how alerts, approvals and recovery work, so an incident has a clear route from detection to repair.
Part of your wider security
Managed detection and response sits alongside our cyber security services, with cyber resilience covering how quickly the business can recover.
Questions
Managed detection and response questions
What is the difference between EDR and MDR?
EDR, or endpoint detection and response, is software on each device that records activity, raises alerts and can respond automatically. Managed detection and response is a service in which security analysts monitor those alerts and other connected sources, investigate them and take agreed action at any hour. MDR relies on tools such as EDR rather than replacing them.
Who investigates alerts outside business hours?
Security analysts monitor the connected sources and respond 24/7, including nights, weekends and public holidays. Alerts are triaged according to risk, and analysts can take approved containment actions without waiting for you to answer a call. Your agreement sets out the escalation and notification arrangements.
Can analysts act without calling us first?
Yes, for actions you approve in advance. At onboarding you agree a list of containment steps, such as isolating a device or blocking an account, that analysts can take at any hour without calling first. Anything outside that list follows the agreed escalation process, and you are notified after every action.
Does MDR include Microsoft 365 monitoring?
Microsoft 365 accounts can be connected to the service, covering sign-ins, multi-factor authentication changes, mailbox rules and connected apps, which is sometimes called cloud detection and response. Your quote shows whether Microsoft 365 monitoring is included. The signals available depend on your licences, permissions and configuration.
What happens after a threat is contained?
Your named contacts receive a summary of what happened, what was done and what needs a decision. Clean-up and restoration are handed to whoever supports your systems, whether that is your own team, your IT provider or Exodesk. Your agreement sets out what the service includes.
How does MDR work with our current IT provider?
Managed detection and response can be bought on its own, without moving the rest of your IT to Exodesk. We agree with you and your provider who receives notifications, who handles recovery work and how changes are approved. The same applies if you have an internal IT team.
How much does managed detection and response cost?
The cost depends on the number of devices, servers and user accounts monitored and which cloud and network sources are connected. Existing endpoint protection licences also affect the figure. Your quote sets out what the recurring fee covers and how adding devices or sources changes it.
Can MDR stop ransomware?
No service can guarantee that. MDR aims to detect the early signs of ransomware, such as unusual file changes or suspicious scripts, and contain the affected device before the attack spreads. Tested backups and a disaster recovery plan are still needed in case an attack succeeds.
Which systems can the service monitor?
Laptops, desktops and servers with a supported agent, Microsoft 365 accounts, other cloud platforms with a supported integration, and firewalls and network equipment. The sources connected to your service are listed in your agreement. Anything not connected is a monitoring gap, although other connected sources may still show related activity.
What happens if a device stops reporting?
A device that stops reporting creates a monitoring gap. Other connected sources may still show related activity, but they do not replace the missing coverage. Your agreement states how silent devices and sources are identified and followed up. Telling us about new, replaced and retired devices keeps the coverage accurate.
What reports will we receive?
You receive a monthly report summarising what was detected, what was dealt with and anything that needs attention. Between reports, your named contacts are notified whenever something needs a decision or an action has been taken.
Do you provide MDR outside Christchurch and Dunedin?
Yes. Monitoring and response work remotely, so the service is available to businesses across New Zealand. We support organisations throughout the country from our teams in Christchurch and Dunedin.
Next step
Need someone watching your systems out of hours?
Talk to Exodesk about managed detection and response for the devices, accounts and systems your business relies on. We will discuss what you have in place, what could be connected and what a sensible first step looks like.
It helps to know roughly how many devices and staff accounts you have and which security tools are installed. If you would rather establish where you stand first, request an IT assessment.
Get in touch
Discuss MDR coverage
Tell us a little about your systems and we will be in touch to arrange a time that suits.
Prefer to talk?
Christchurch
Level 1, 85 Riccarton Road
Christchurch 8011
03 343 3124
Dunedin
Level 3, Bartons Building
2 Stafford Street, Dunedin 9016
03 479 2941