Managed detection & response

Your estate is watched at 04:00 on a public holiday

Guardian MDR puts 340 analysts across nine SOCs behind your Sentinel tenant. Every alert is triaged by a human within three minutes, investigated to a verdict, and contained under authority you define in advance — then written up in plain language.

3-minute acknowledgement · 15-minute investigation · 30-minute containment

340 SOC analysts on a follow-the-sun rotation
9 Security operations centres across five continents
2:41 Median human acknowledgement time, trailing 90 days
0.4% Of alerts reach a customer as an escalation
31 Languages supported for service delivery

Signal, not noise

Four million events become eleven things worth your attention

The value of MDR is not that somebody is watching. It is that almost nothing reaches you. Sentinel's correlation engine resolves the overwhelming majority of activity autonomously; Guardian analysts adjudicate what is left; and only a verified, actionable escalation lands in your queue.

The figures shown are a representative week for a 12,000-endpoint customer in financial services. Your own funnel is published in the monthly service review, with every stage broken down by detection source.

One week of telemetry, 12,000 endpoints

4.1 B 62,400 1,840 214 11 raw telemetry events correlated signals platform detections analyst-reviewed alerts escalations sent to you −99.998% −97.1% −88.4% −94.9%

24 / 7 / 365 coverage

Three shifts, nine centres, no handover gaps

Guardian runs a genuine follow-the-sun model. Every shift begins with a 45-minute overlap and a structured handover of open investigations, so nothing is dropped at a boundary — the failure mode that quietly defeats most "24/7" claims.

00:00 UTC 12:00 18:00 06:00 24 / 7 continuous cover 365 days, incl. holidays Asia-Pacific shift EMEA shift Americas shift 00:00–08:00 UTC Sydney · Singapore · Bengaluru 08:00–16:00 UTC London · Frankfurt · Dubai 16:00–24:00 UTC Austin · Ottawa · São Paulo 45-minute overlap and written handover at every shift boundary.

Structured handover, not a shared inbox

Each open investigation carries a state, a hypothesis, the evidence gathered so far and the next intended action. The incoming shift lead accepts it explicitly. Handover records are visible in your tenant, so you can audit continuity yourself.

Your estate is anchored to a home SOC

One centre owns your account for tuning, service reviews and relationship continuity, chosen for language and residency fit. The other eight provide coverage but work to your home SOC's documented context.

Surge capacity is real

A confirmed major incident pulls responders from adjacent shifts within minutes and, if required, escalates onto the incident response bridge without a separate commercial conversation.

How MDR hands off to incident response

Who looks at your alerts

Four tiers, and a rule about which one you get

Escalation between tiers is triggered by evidence, not by queue depth. An alert that shows adversary interaction goes to Tier 3 immediately, regardless of how busy the floor is — and the promotion is timestamped in your tenant.

  1. Tier 1 · Triage

    Acknowledges every alert within three minutes, applies the documented triage runbook, validates enrichment and closes the confirmed benign. Roughly 78% of alerts terminate here with a recorded rationale you can review.

    Median tenure: 2.1 years · Security+ and Sentinel Analyst certified

  2. Tier 2 · Investigation

    Pivots across the correlation graph, reconstructs the process and identity chain, pulls additional telemetry and reaches a verdict. Owns pre-authorised containment: host isolation, token revocation, account disablement.

    Median tenure: 4.3 years · GCIA or GCIH certified

  3. Tier 3 · Hunting

    Handles anything showing hands-on-keyboard activity, novel tradecraft or suspected identity compromise. Also runs scheduled proactive hunts against your estate using fresh Guardian Labs intelligence, whether or not an alert fired.

    Median tenure: 7.8 years · GCFA, GREM or equivalent

  4. Tier 4 · Incident command

    A declared major incident converts the engagement into a full IR bridge with an incident manager, forensic examiner and your named contacts. Retainer hours are drawn automatically where a retainer exists.

    Guardian incident response practice · 210 responders

You can see the analyst, and the analyst can see you Every escalation names the individual who wrote it. Your team can reply in-thread, request the underlying evidence, or open a live bridge from the escalation itself. Anonymous ticket shuffling is not part of the service.

Service levels

Contracted, measured and reported monthly

Every figure below is a contractual commitment with a service credit attached. Actual performance against each one is published in your monthly service review and available live in the tenant.

Guardian MDR service levels by tier. Times are measured from alert creation in the Sentinel platform. Severity is assigned by the platform and may be raised by an analyst or by you.
Service level Essential Complete Complete + Co-managed
Human acknowledgement, critical 10 minutes 3 minutes 3 minutes
Investigation to verdict, critical 60 minutes 15 minutes 15 minutes
Containment action taken, critical Advisory only 30 minutes 30 minutes
Human acknowledgement, high 60 minutes 15 minutes 15 minutes
Coverage window 24 / 7 / 365 24 / 7 / 365 Configurable by shift
Proactive threat hunting — Monthly Weekly
Detection tuning requests 5 business days 2 business days Same day, joint queue
Named shift leads — Yes Yes, plus embedded liaison
Service review cadence Quarterly Monthly Weekly operational, monthly service
Purple-team validation — Annual Quarterly
Service credits on miss Yes Yes Yes

Scroll the table sideways to compare every tier.

Severity definitions, measurement methodology and the credit schedule are published in the service description attached to every order form. See how MDR is priced.

Scope, stated plainly

What we do, and what stays with you

Most MDR disappointment comes from an unstated boundary. Here is ours, in the same words that appear in the service description.

Included Guardian owns this

Guardian MDR delivers

  • 24 / 7 / 365 monitoring of every alert your Sentinel tenant produces, across endpoint, network, cloud, identity, email and data.
  • Human triage, investigation and a written verdict on every alert — including the ones we close as benign.
  • Containment actions inside the authority matrix you sign at onboarding, executed immediately and logged in full.
  • Continuous detection tuning, false-positive suppression and new content deployment as Guardian Labs publishes it.
  • Proactive threat hunts on a published schedule, plus ad-hoc hunts when a relevant campaign emerges in your sector.
  • Monthly service review with trend, coverage gaps and prioritised recommendations.
  • Escalation onto an incident response bridge when an alert becomes an incident.
Out of scope You own this — or buy it separately

Guardian MDR does not include

  • General IT service desk. We do not reset passwords, fix printers or triage non-security tickets.
  • Patch and vulnerability remediation. We identify and prioritise; applying the fix remains with your platform teams.
  • Full-scale incident response. Beyond the first containment, major incidents draw on an IR retainer or an emergency engagement.
  • Managing third-party security tooling. We ingest from it; we do not administer your firewalls, proxies or email gateway.
  • Regulatory notification decisions. We supply the evidence and the timeline; the notification decision is yours and your counsel's.
  • Business decisions during a crisis. We will not take a revenue- generating system offline without your named authority.
See the services that cover these

Onboarding

Protected in six weeks, tuned in twelve

Onboarding is a funded, project-managed engagement with a named lead and a written acceptance test. Nothing is billed as "in service" until you have signed off that it actually is.

6 wkto full SLA coverage
12 wkto steady-state tuning
1named onboarding lead
Monitoring starts in week two, not week six Coverage is switched on progressively. From the moment telemetry is flowing we watch it on a best-effort basis, even though the contractual SLA does not begin until acceptance.
  1. Week 1

    Discovery and authority matrix

    We map your estate, your crown-jewel systems and your existing tooling, then agree the single most important document in the engagement: the authority matrix. It states, per asset group and per action, whether Guardian may act unilaterally, must notify first, or must wait for your approval.

  2. Weeks 2–3

    Telemetry and integration

    Sentinel agents deploy through your existing management tooling, and integrations are built to your identity provider, ticketing system, chat platform and any third-party sources you want correlated. Best-effort monitoring begins as soon as data flows.

  3. Week 4

    Baseline and suppression

    A learning period establishes what normal looks like in your environment, so that administrative scripting, vulnerability scanners and your own red team do not generate noise for the next year. Known-good behaviour is suppressed with a documented rationale.

  4. Week 5

    Playbook authoring and rehearsal

    Response playbooks are written against your authority matrix and then rehearsed against simulated detections in your own tenant. Your team watches every action Guardian would take, before it matters.

  5. Week 6

    Acceptance test and go-live

    A live validation exercise fires real detections across each surface. You sign the acceptance test, the SLA clock starts, and the account transitions to its home SOC with a named shift lead introduced by name.

  6. Weeks 7–12

    Tuning to steady state

    Weekly tuning reviews reduce residual noise and raise coverage against the MITRE ATT&CK techniques most relevant to your sector. At week 12 we run the first purple-team validation and publish a coverage baseline.

Global SOC network

Nine centres, each accredited in its own right

Every Guardian SOC is a physically secured facility with independent power and connectivity, staffed by Guardian employees only. Residency-constrained accounts are served exclusively from centres inside the permitted jurisdiction.

Guardian security operations centres, primary coverage windows and accreditations.
Centre Region served Primary window (UTC) Languages Accreditation
Austin, USA North America 16:00–24:00 English, Spanish SOC 2 Type II, FedRAMP High enclave
Ottawa, Canada North America 13:00–21:00 English, French SOC 2 Type II, PBMM aligned
São Paulo, Brazil Latin America 12:00–20:00 Portuguese, Spanish, English SOC 2 Type II, LGPD aligned
London, UK UK & Ireland 08:00–16:00 English ISO 27001, CREST SOC, NCSC CIR
Frankfurt, Germany Continental Europe 07:00–15:00 German, French, Dutch, Polish, English ISO 27001, C5 attestation, EU-staffed
Dubai, UAE Middle East & Africa 05:00–13:00 Arabic, English, French ISO 27001, UAE IA, in-country keys
Bengaluru, India South Asia 02:00–10:00 English, Hindi, Tamil ISO 27001, DPDP aligned
Singapore South-East Asia 00:00–08:00 English, Mandarin, Malay, Japanese ISO 27001, MTCS Level 3
Sydney, Australia Australia & New Zealand 21:00–05:00 English ISO 27001, IRAP assessed

Scroll the table sideways to see accreditations.

Primary windows are the hours each centre leads. All nine operate continuously, so surge capacity is available in any time zone. See the full accreditation register.

We went from three analysts covering nine-to-five badly to genuine round-the-clock cover in six weeks. The number that convinced my board was not the SLA — it was that our own team stopped getting paged at night and started building detections instead.

Lena Novak
Head of Security Operations, European payments provider

Common questions

Things buyers ask us in week one

If your question is not here, the SOC leadership team will answer it directly on a scoping call — not through a sales intermediary.

Browse the full FAQ
Do we lose control of our own environment?

No. The authority matrix you sign at onboarding is enforced by the platform, per asset group and per action type. Guardian analysts physically cannot take an action you have not authorised, and every action taken is visible in your tenant in real time with the analyst's name against it.

Most customers start conservatively — notify-first on production, unilateral isolation on corporate endpoints — and widen the authority as trust builds.

What happens to our existing SOC team?

In the co-managed model, which is what most established teams choose, your analysts keep the mandate and the daytime shift. Guardian takes nights, weekends and holidays, plus surge. The measurable effect is usually that your senior people stop doing Tier 1 triage and move to detection engineering, threat modelling and purple teaming.

Can you monitor sources that are not Guardian?

Yes, for correlation. Sentinel ingests from over 400 third-party sources — firewalls, proxies, email gateways, cloud providers, identity platforms, OT historians and custom applications through the open API. Those feeds enrich investigations and contribute to detections.

The SLA, however, attaches to alerts raised in the Sentinel platform, because response time depends on the actions the platform can take. Third-party-only alerting is handled on a best-effort basis and is stated as such in the service description.

How do you avoid alert fatigue on our side?

By escalating almost nothing. Roughly four alerts in a thousand reach the customer, and each arrives as a written narrative with the evidence, the verdict, the action already taken and the specific decision we need from you. If your escalation volume rises above the agreed threshold, that is treated as a service defect on our side and tuned down.

What if we are already contracted to another MDR provider?

Parallel running is normal and supported. Guardian can operate in advisory mode alongside an incumbent for a defined evaluation period, escalating in parallel so you can compare detection quality, escalation usefulness and response time on the same real events. Most evaluations run 60 to 90 days.

Ask the SOC, not the sales team

Scoping calls are run by a SOC shift lead who can answer what actually happens at 04:00. Bring your alert volumes and your worst false-positive source.