Defend · Service 03

Detection & response

Monitoring earns its keep when somebody acts on it. We watch endpoint, identity and cloud around the clock, with written authority to contain a threat at 2am and let you know straight away.

Analysts monitoring security dashboards in an operations centre
The gap

Every alert needs a person awake to triage it

Most organisations we assess already generate detections. Defender is licensed, the EDR console is populated, the sign-in logs are there. What is missing is the person who looks at an impossible-travel alert at 11pm on a Saturday and decides whether it is a VPN or an intrusion.

The industry average for dwell time — how long an intruder is inside before anyone notices — is still measured in days. Almost all of that is triage latency: the time between a detection firing and a person acting on it.

We close that gap with people, on a roster, with delegated authority and a documented playbook, so every alert reaches someone who can act on it at any hour.

Telemetry

What we watch, and what we are watching for

Four signal sources, correlated. An event that looks unremarkable on its own often stands out once you can see the other three.

Identity
Entra ID sign-in and audit logs. Impossible travel, unfamiliar sign-in properties, MFA fatigue patterns, token replay indicators, new OAuth application consent, privileged role assignment, and mailbox rule creation — still the clearest early signal of business email compromise.
Endpoint
EDR telemetry across workstations and servers: credential access attempts, suspicious parent-child process chains, script interpreter abuse, defence evasion, persistence mechanisms and ransomware pre-cursors such as shadow copy deletion.
Cloud & SaaS
Microsoft 365 and Azure activity: mass file download or deletion, sharing-link anomalies, conditional access policy changes, tenant configuration drift, and administrative actions performed outside change windows.
Network & perimeter
Firewall and VPN logs, command-and-control indicators, exposed service changes, and alerting on the external attack surface when something new appears.
When it happens

Six stages, in this order, every time

The sequence is fixed. Containment comes before eradication, and you need to know what left the building before you can notify anyone.

  1. Detect

    An alert fires, or a user reports something. Both routes reach the same queue, and a user report is treated with the same urgency as a machine detection.

  2. Triage

    A human establishes whether it is real within the response target. False positives are tuned out permanently, so the same noise stays gone.

  3. Contain

    Under pre-agreed authority: isolate the device, revoke the sessions, disable the account, block the sender. We act first and inform you immediately, because waiting for approval costs hours.

  4. Investigate

    Initial access, scope, dwell time, lateral movement and data accessed. This is the stage that determines whether you have a notification obligation.

  5. Eradicate & recover

    Remove persistence, rotate credentials, rebuild rather than clean where there is any doubt, restore from verified backup, and confirm the environment is clean before returning it to service.

  6. Report

    A written incident record: timeline, root cause, what we did, what you must decide, OAIC notifiability assessment, and the control changes that stop it recurring.

Containment authority is agreed in writing during onboarding, including which systems we may isolate without consultation and who we escalate to when we may not.

Who acts first at containment Where the authority allows it, we contain first and inform you immediately, because waiting for approval costs hours. Where it names a system as consult-first, you hear from us before anything is isolated.

Systems we may isolate straight away

  1. Next CyberTriageA person confirms the threat is real
  2. Next CyberContainIsolate the device, revoke the sessions, disable the account, block the sender
  3. YouInformed immediatelyWith containment already in place

Systems named as consult-firstSuch as a production line or a clinical system

  1. Next CyberTriageA person confirms the threat is real
  2. Your named contactConsultedWe escalate to the person your authority names
  3. Next CyberContainAfter consultation
Honest limits

Where MDR's job ends

Detection and response is a safety net. It works alongside the controls that stop the incident happening in the first place.

  • It builds on the Essential Eight. If your patching is twelve months behind, that gets fixed first; MDR on its own would be treating the symptom.
  • It sees what it is fed. Unmanaged devices and unmonitored SaaS are blind spots, and we will tell you exactly where yours are.
  • It shortens downtime. Containing ransomware quickly means fewer machines encrypted, though you should still plan for some.
  • Legal and insurance advice sits with your advisers. We provide the technical facts your lawyers and insurer need, and we work alongside them.
Questions

What people ask

Is this a real 24/7 service or an on-call phone?

Rostered coverage with defined escalation, backed by the response targets in your agreement and reported against monthly. Ask any provider to put a P1 response target in writing; the answer tells you what their after-hours arrangement actually is.

Do you use our existing tools or your own?

Yours where they are adequate — most organisations with Microsoft 365 Business Premium or E5 already have the telemetry. We add what is genuinely missing and keep the working parts of your stack in place.

What if you isolate a machine we needed?

It happens, and it is the right trade. Isolation reverses in minutes, while a domain controller encrypted during a wait for approval is a far longer recovery. The systems where we must consult first — a production line, a clinical system — are named in your containment authority during onboarding.

Where is our data stored?

Onshore in Australia. Telemetry retention periods are stated in the agreement, and we will tell you which components of the platform process data offshore so you can assess it against your own obligations.

Already in an incident

Call us. We take incident response engagements for any organisation, client or otherwise, and the first conversation is free.