Managed detection & response
Your estate is watched at 04:00 on a public holiday
Guardian MDR puts 340 analysts across nine SOCs behind your Sentinel tenant. Every alert is triaged by a human within three minutes, investigated to a verdict, and contained under authority you define in advance — then written up in plain language.
3-minute acknowledgement · 15-minute investigation · 30-minute containment
Signal, not noise
Four million events become eleven things worth your attention
The value of MDR is not that somebody is watching. It is that almost nothing reaches you. Sentinel's correlation engine resolves the overwhelming majority of activity autonomously; Guardian analysts adjudicate what is left; and only a verified, actionable escalation lands in your queue.
The figures shown are a representative week for a 12,000-endpoint customer in financial services. Your own funnel is published in the monthly service review, with every stage broken down by detection source.
One week of telemetry, 12,000 endpoints
24 / 7 / 365 coverage
Three shifts, nine centres, no handover gaps
Guardian runs a genuine follow-the-sun model. Every shift begins with a 45-minute overlap and a structured handover of open investigations, so nothing is dropped at a boundary — the failure mode that quietly defeats most "24/7" claims.
Structured handover, not a shared inbox
Each open investigation carries a state, a hypothesis, the evidence gathered so far and the next intended action. The incoming shift lead accepts it explicitly. Handover records are visible in your tenant, so you can audit continuity yourself.
Your estate is anchored to a home SOC
One centre owns your account for tuning, service reviews and relationship continuity, chosen for language and residency fit. The other eight provide coverage but work to your home SOC's documented context.
Surge capacity is real
A confirmed major incident pulls responders from adjacent shifts within minutes and, if required, escalates onto the incident response bridge without a separate commercial conversation.
Who looks at your alerts
Four tiers, and a rule about which one you get
Escalation between tiers is triggered by evidence, not by queue depth. An alert that shows adversary interaction goes to Tier 3 immediately, regardless of how busy the floor is — and the promotion is timestamped in your tenant.
-
Tier 1 · Triage
Acknowledges every alert within three minutes, applies the documented triage runbook, validates enrichment and closes the confirmed benign. Roughly 78% of alerts terminate here with a recorded rationale you can review.
Median tenure: 2.1 years · Security+ and Sentinel Analyst certified
-
Tier 2 · Investigation
Pivots across the correlation graph, reconstructs the process and identity chain, pulls additional telemetry and reaches a verdict. Owns pre-authorised containment: host isolation, token revocation, account disablement.
Median tenure: 4.3 years · GCIA or GCIH certified
-
Tier 3 · Hunting
Handles anything showing hands-on-keyboard activity, novel tradecraft or suspected identity compromise. Also runs scheduled proactive hunts against your estate using fresh Guardian Labs intelligence, whether or not an alert fired.
Median tenure: 7.8 years · GCFA, GREM or equivalent
-
Tier 4 · Incident command
A declared major incident converts the engagement into a full IR bridge with an incident manager, forensic examiner and your named contacts. Retainer hours are drawn automatically where a retainer exists.
Guardian incident response practice · 210 responders
Service levels
Contracted, measured and reported monthly
Every figure below is a contractual commitment with a service credit attached. Actual performance against each one is published in your monthly service review and available live in the tenant.
| Service level | Essential | Complete | Complete + Co-managed |
|---|---|---|---|
| Human acknowledgement, critical | 10 minutes | 3 minutes | 3 minutes |
| Investigation to verdict, critical | 60 minutes | 15 minutes | 15 minutes |
| Containment action taken, critical | Advisory only | 30 minutes | 30 minutes |
| Human acknowledgement, high | 60 minutes | 15 minutes | 15 minutes |
| Coverage window | 24 / 7 / 365 | 24 / 7 / 365 | Configurable by shift |
| Proactive threat hunting | — | Monthly | Weekly |
| Detection tuning requests | 5 business days | 2 business days | Same day, joint queue |
| Named shift leads | — | Yes | Yes, plus embedded liaison |
| Service review cadence | Quarterly | Monthly | Weekly operational, monthly service |
| Purple-team validation | — | Annual | Quarterly |
| Service credits on miss | Yes | Yes | Yes |
Scroll the table sideways to compare every tier.
Severity definitions, measurement methodology and the credit schedule are published in the service description attached to every order form. See how MDR is priced.
Scope, stated plainly
What we do, and what stays with you
Most MDR disappointment comes from an unstated boundary. Here is ours, in the same words that appear in the service description.
Guardian MDR delivers
- 24 / 7 / 365 monitoring of every alert your Sentinel tenant produces, across endpoint, network, cloud, identity, email and data.
- Human triage, investigation and a written verdict on every alert — including the ones we close as benign.
- Containment actions inside the authority matrix you sign at onboarding, executed immediately and logged in full.
- Continuous detection tuning, false-positive suppression and new content deployment as Guardian Labs publishes it.
- Proactive threat hunts on a published schedule, plus ad-hoc hunts when a relevant campaign emerges in your sector.
- Monthly service review with trend, coverage gaps and prioritised recommendations.
- Escalation onto an incident response bridge when an alert becomes an incident.
Guardian MDR does not include
- General IT service desk. We do not reset passwords, fix printers or triage non-security tickets.
- Patch and vulnerability remediation. We identify and prioritise; applying the fix remains with your platform teams.
- Full-scale incident response. Beyond the first containment, major incidents draw on an IR retainer or an emergency engagement.
- Managing third-party security tooling. We ingest from it; we do not administer your firewalls, proxies or email gateway.
- Regulatory notification decisions. We supply the evidence and the timeline; the notification decision is yours and your counsel's.
- Business decisions during a crisis. We will not take a revenue- generating system offline without your named authority.
Onboarding
Protected in six weeks, tuned in twelve
Onboarding is a funded, project-managed engagement with a named lead and a written acceptance test. Nothing is billed as "in service" until you have signed off that it actually is.
-
Week 1
Discovery and authority matrix
We map your estate, your crown-jewel systems and your existing tooling, then agree the single most important document in the engagement: the authority matrix. It states, per asset group and per action, whether Guardian may act unilaterally, must notify first, or must wait for your approval.
-
Weeks 2–3
Telemetry and integration
Sentinel agents deploy through your existing management tooling, and integrations are built to your identity provider, ticketing system, chat platform and any third-party sources you want correlated. Best-effort monitoring begins as soon as data flows.
-
Week 4
Baseline and suppression
A learning period establishes what normal looks like in your environment, so that administrative scripting, vulnerability scanners and your own red team do not generate noise for the next year. Known-good behaviour is suppressed with a documented rationale.
-
Week 5
Playbook authoring and rehearsal
Response playbooks are written against your authority matrix and then rehearsed against simulated detections in your own tenant. Your team watches every action Guardian would take, before it matters.
-
Week 6
Acceptance test and go-live
A live validation exercise fires real detections across each surface. You sign the acceptance test, the SLA clock starts, and the account transitions to its home SOC with a named shift lead introduced by name.
-
Weeks 7–12
Tuning to steady state
Weekly tuning reviews reduce residual noise and raise coverage against the MITRE ATT&CK techniques most relevant to your sector. At week 12 we run the first purple-team validation and publish a coverage baseline.
Global SOC network
Nine centres, each accredited in its own right
Every Guardian SOC is a physically secured facility with independent power and connectivity, staffed by Guardian employees only. Residency-constrained accounts are served exclusively from centres inside the permitted jurisdiction.
| Centre | Region served | Primary window (UTC) | Languages | Accreditation |
|---|---|---|---|---|
| Austin, USA | North America | 16:00–24:00 | English, Spanish | SOC 2 Type II, FedRAMP High enclave |
| Ottawa, Canada | North America | 13:00–21:00 | English, French | SOC 2 Type II, PBMM aligned |
| São Paulo, Brazil | Latin America | 12:00–20:00 | Portuguese, Spanish, English | SOC 2 Type II, LGPD aligned |
| London, UK | UK & Ireland | 08:00–16:00 | English | ISO 27001, CREST SOC, NCSC CIR |
| Frankfurt, Germany | Continental Europe | 07:00–15:00 | German, French, Dutch, Polish, English | ISO 27001, C5 attestation, EU-staffed |
| Dubai, UAE | Middle East & Africa | 05:00–13:00 | Arabic, English, French | ISO 27001, UAE IA, in-country keys |
| Bengaluru, India | South Asia | 02:00–10:00 | English, Hindi, Tamil | ISO 27001, DPDP aligned |
| Singapore | South-East Asia | 00:00–08:00 | English, Mandarin, Malay, Japanese | ISO 27001, MTCS Level 3 |
| Sydney, Australia | Australia & New Zealand | 21:00–05:00 | English | ISO 27001, IRAP assessed |
Scroll the table sideways to see accreditations.
Primary windows are the hours each centre leads. All nine operate continuously, so surge capacity is available in any time zone. See the full accreditation register.
We went from three analysts covering nine-to-five badly to genuine round-the-clock cover in six weeks. The number that convinced my board was not the SLA — it was that our own team stopped getting paged at night and started building detections instead.
Common questions
Things buyers ask us in week one
If your question is not here, the SOC leadership team will answer it directly on a scoping call — not through a sales intermediary.
Browse the full FAQDo we lose control of our own environment?
No. The authority matrix you sign at onboarding is enforced by the platform, per asset group and per action type. Guardian analysts physically cannot take an action you have not authorised, and every action taken is visible in your tenant in real time with the analyst's name against it.
Most customers start conservatively — notify-first on production, unilateral isolation on corporate endpoints — and widen the authority as trust builds.
What happens to our existing SOC team?
In the co-managed model, which is what most established teams choose, your analysts keep the mandate and the daytime shift. Guardian takes nights, weekends and holidays, plus surge. The measurable effect is usually that your senior people stop doing Tier 1 triage and move to detection engineering, threat modelling and purple teaming.
Can you monitor sources that are not Guardian?
Yes, for correlation. Sentinel ingests from over 400 third-party sources — firewalls, proxies, email gateways, cloud providers, identity platforms, OT historians and custom applications through the open API. Those feeds enrich investigations and contribute to detections.
The SLA, however, attaches to alerts raised in the Sentinel platform, because response time depends on the actions the platform can take. Third-party-only alerting is handled on a best-effort basis and is stated as such in the service description.
How do you avoid alert fatigue on our side?
By escalating almost nothing. Roughly four alerts in a thousand reach the customer, and each arrives as a written narrative with the evidence, the verdict, the action already taken and the specific decision we need from you. If your escalation volume rises above the agreed threshold, that is treated as a service defect on our side and tuned down.
What if we are already contracted to another MDR provider?
Parallel running is normal and supported. Guardian can operate in advisory mode alongside an incumbent for a defined evaluation period, escalating in parallel so you can compare detection quality, escalation usefulness and response time on the same real events. Most evaluations run 60 to 90 days.
Ask the SOC, not the sales team
Scoping calls are run by a SOC shift lead who can answer what actually happens at 04:00. Bring your alert volumes and your worst false-positive source.