MDR can sound abstract until you've seen one work. Here's a real (anonymised) end-to-end incident from a 60-person UK professional services firm earlier this year.
00:00 — The alert
EDR fires a medium-severity alert: a finance laptop has spawned an unusual PowerShell command shortly after a Teams message was opened. Out of business hours.
00:03 — Triage
An analyst picks up the alert. They pivot through telemetry: the PowerShell command is attempting to download a second-stage payload from an unfamiliar domain. The user account has just authenticated from the UK and from a VPS in another country, two minutes apart.
00:08 — Containment
The analyst isolates the endpoint via EDR. The user account is force-signed-out of all sessions and an interim password reset is triggered. Conditional Access is tightened to block the suspicious IP range.
00:20 — Scoping
Identity logs are reviewed: the attacker also accessed the user's mailbox and created a hidden inbox rule to auto-forward and delete messages containing 'invoice'. The rule is removed; mailbox rules across the tenant are audited; no other accounts affected.
00:45 — Communication
The client's named contact is called. A plain-English summary is sent: what happened, what we did, what they need to do (revoke a small number of sessions, brief the affected user).
Morning — Hardening
Root cause: a convincing phishing message that bypassed click-time protection on a brand-new domain. Recommendations issued: move admins to phishing-resistant MFA, tighten mailbox rule policies, add the lookalike domain to gateway blocks. All actions implemented within 48 hours.
What MDR did that EDR alone wouldn't
- Triaged an out-of-hours alert in minutes, not the next morning.
- Connected endpoint, identity and email signals into one story.
- Took response actions without waiting for the client to wake up.
- Delivered a plain-English brief and a hardening plan, not a wall of logs.
Next step
If you'd like to see what 24/7 monitoring would look like for your business — and what it would have caught in the last 12 months — book a free 30-minute review.

