Cybersecurity · Monitoring

Managed Detection and Response (MDR)

Detection tools are only half of the equation. Attacks are timed for evenings, weekends and holidays precisely because nobody is watching the console then. Managed detection and response supplies the watching.

We combine the telemetry from endpoints, Microsoft 365 identities and network devices with round-the-clock analyst review, so a detection becomes a contained incident rather than a message waiting in an inbox on Monday.

The problem

Alerts without analysts are shelfware

A single compromised account can generate a handful of subtle signals: an unusual sign-in location, a new inbox rule, a mailbox permission change, an unexpected login to a file server. Individually each is plausible. Together they are an intrusion in progress.

Recognising that pattern requires someone comparing signals from different systems at the moment they occur. Most small and mid-sized organizations have no capacity to do that at 3am, and no realistic prospect of hiring for it.

Managed detection exists to fill precisely that gap: continuous review of the signals, with the authority to act quickly when the picture is clear.

What we do

How the service works

  1. 01

    Consolidate the signals

    Endpoint telemetry, Microsoft 365 sign-in and audit activity, firewall logs and server events collected into one platform so correlation is possible.

  2. 02

    Human triage, continuously

    Analysts review detections around the clock, separating genuine activity from noise and escalating with context rather than forwarding raw alerts.

  3. 03

    Pre-authorised containment

    Agreed actions we may take immediately — isolate a device, disable an account, revoke sessions, block a sender — documented in advance so nobody is waiting for permission during an incident.

  4. 04

    Proactive hunting

    Regular searches for indicators that do not raise alerts on their own: unusual persistence, dormant administrative accounts, unexpected remote-access tooling.

  5. 05

    Clear escalation to your people

    A named contact list with out-of-hours numbers, a defined severity scale, and plain-language notifications describing what happened and what we did.

  6. 06

    Close the loop

    Every incident ends with a written timeline and a remediation recommendation — the configuration or process change that stops the same route being used again.

Business outcome

What you get from continuous coverage

  • Overnight incidents contained early
  • Fewer false alarms reaching staff
  • Documented incident history
  • Stronger insurance position
  • Reduced reliance on one internal person
  • Measurable response times

Where this fits

This service is one layer of the broader programme set out on cybersecurity services in St. Catharines.

Questions

Frequently asked questions

How is MDR different from EDR?
EDR is the technology on the device. MDR is the service that watches what the technology reports, investigates it and acts. You can have EDR without MDR, but then the alerts depend on someone internal noticing them.
Can you act without asking us first?
Only within the boundaries you approve in advance. Most clients authorise device isolation and account disablement immediately, because the alternative is waiting hours while an attacker works.
Does this replace our need for backups?
No. Detection reduces how often you need a recovery and how bad it is when you do, but tested, immutable backups remain the control that guarantees you can come back.

Next step

Talk to Griffin IT Group about your St. Catharines IT environment

Tell us how your technology is set up today and what is getting in the way. We will walk through your environment, outline the gaps we see and recommend a practical path forward.