Skip to main content
Resilien

by Precursor

Managed Detection & Response (MDR).
Expert investigation when threats emerge.

Resilien’s UK analysts investigate suspicious activity across your connected security tools and take authorised action on confirmed threats. Your team receives clear escalation and practical next steps, day or night.

From £900/month. Coverage, licensing and response permissions confirmed in your quote.

CREST-Accredited SOC
UK-Based Analysts
Your Existing Tools

Human expertise.
Machine velocity.

Security tools collect and correlate signals. UK analysts investigate and direct the response, 24/7/365.

  1. Detect suspicious activity

    Bring endpoint, identity, network and cloud signals together.

  2. Confirm the threat

    Human analysts investigate and establish the impact.

  3. Contain and coordinate

    Use authorised response actions and involve your team.

CREST accredited Security Operations Centre

Resilien by Precursor Security
Delivered through our CREST-accredited UK SOC.

Scroll
3,000+ Assessments DeliveredTriple-CREST Accredited24/7 UK SOC in NewcastleReports Accepted by Insurers & RegulatorsEst. 2018

From detection to action.
Delivered by Resilien.

Get specialist investigation and authorised threat response when suspicious activity needs attention.

MDR is delivered through our Managed SOC. You keep your existing security tools while our UK analysts turn their signals into investigation and action.

From £900/month

Your quote confirms the users, endpoints, log sources, licensing and response actions in scope before the service begins.

Get your Resilien quote

What’s included in Resilien?

The core service
24/7 detection and human-led investigation across your agreed telemetry, with containment and escalation through documented response procedures.
Coverage agreed with you
Your quote sets out the SIEM and EDR integrations, log sources, retention, threat hunting and response authority. Licensing and any additional costs are confirmed before onboarding.
Optional extensions
Extend your coverage with vulnerability management, EdgeProtect attack surface monitoring, penetration testing or a specialist incident response retainer.
Your team’s role
You provide access, name escalation contacts and approve response permissions. Your IT team retains infrastructure ownership and works with us on remediation and recovery.

What is Managed Detection and Response (MDR)?

24/7 threat detection and response from a CREST-accredited UK SOC, vendor-agnostic across endpoint, network, identity, and cloud.

Managed Detection and Response (MDR) is an outsourced 24/7 service combining endpoint, network, identity, and cloud telemetry with human analyst triage to detect and contain threats in real time.

Resilien delivers MDR through Precursor’s CREST-accredited UK SOC in Newcastle, with human-led investigation and containment under agreed response procedures.

MDR is the investigation and response capability within a broader outsourced SOC engagement. For a full side-by-side breakdown, see our MDR vs SOC vs SIEM vs EDR vs XDR buyer's guide.

Resilien MDR capabilities

24/7 UK analysts

CREST-accredited SOC analysts, based in the UK and available around the clock.

Your existing tools

Vendor-agnostic integration with CrowdStrike, SentinelOne, Microsoft Defender, and Carbon Black.

Scoped threat hunting

Threat hunting scoped to your needs and MITRE ATT&CK-mapped detection.

Agreed response

Human-led response with named escalation contacts and agreed permissions.

Offensive security insight

Vulnerability context fed in from our offensive security team.

Direct analyst access

Access analysts and investigation updates through the customer portal.

From £900/month

Onboarding schedule agreed after reviewing your integrations.

What We Do

From security alerts to investigated threats.

Resilien gives your team specialist support when suspicious activity needs investigation. Analysts in our UK security operations centre assess the evidence, take authorised containment actions and explain what your team needs to do next. Coverage continues through nights, weekends and public holidays.

Discuss your coverage
Provider-dependent service
Check who investigates alerts
Confirm out-of-hours investigation
Check hunting and response scope
Resilien MDR
Human analyst triage on critical alerts
Containment under agreed permissions
Agreed incident response
Capabilities

What Resilien MDR
Delivers.

Resilien brings monitoring, investigation and response together through Precursor’s UK SOC. We agree the integrations, hunting programme and response permissions for your environment.

Continuous Monitoring

24/7 Threat Monitoring

Our UK-based SOC analysts monitor your environment 24/7/365 against the broader UK threat landscape tracked by the NCSC. We ingest telemetry from EDR, SIEM, and XDR platforms to detect malicious activity in real time. No follow-the-sun model. Every analyst operates from our physical Security Operations Centre in Newcastle.

Active Pursuit

Proactive Threat Hunting (Scoped)

Where included in your Resilien scope, our analysts run hypothesis-driven hunts using MITRE ATT&CK TTPs, intelligence from Mandiant M-Trends dwell-time research, and vulnerability data from our offensive security team to find threats before they trigger rules. See how our SOC hunts and catches MSIX malware campaigns via SEO poisoning.

Rapid Response

Rapid Incident Response

When a confirmed threat is identified, our analysts investigate the threat and isolate affected endpoints where authorised by your response plan. Incident response follows your agreed permissions and scope. Specialist forensics, recovery and retainer services can be added where required.

Platform Agnostic

Keep the security tools you already use

Bring your existing stack or choose from our recommended vendors. We integrate via API with Microsoft Defender, SentinelOne, CrowdStrike Falcon, and Elastic SIEM. Supported connectors, access and licensing are confirmed before onboarding.

Closed-Loop

Offensive + Defensive Fusion

Unlike pure-play MDR providers, Precursor Security combines CREST-accredited penetration testing with SOC operations. Vulnerabilities found by our Red Team feed directly into detection rules, closing the loop between attack and defence, mapped to the NIST Cyber Security Framework identify, protect, detect, respond functions.

Visibility

See what happened and what happens next

Real-time visibility into your security posture. Track alerts, investigations, and monthly trend reports through our dedicated client portal. Board-ready reports delivered monthly. Agreed log retention with audit-ready event export.

Executive Summary

The MDR Investment Case

Give your team continuous monitoring, specialist investigation and a documented response plan.

Human-led
Threat investigation

Analysts assess suspicious activity in context and give your team clear findings and next steps.

Agreed
Response permissions

Know which containment actions analysts can take and when your named contacts will be involved.

24/7
UK-Based Human Coverage

UK analysts investigate suspicious activity around the clock, with containment and escalation governed by your agreed response procedures.

Mapped
Controls
CRESTSOC Accredited
ISO 27001Certified
ISO 9001Certified
Cyber EssentialsPlus Certified
Crown CommercialSupplier
Coverage

360° Threat Coverage

Resilien MDR monitors the technology sources agreed in your service scope. Our SOC correlates signals across endpoints, networks, cloud, identity, and email to deliver threat detection and response against sophisticated multi-stage attacks that siloed tools miss.

Endpoint (EDR/XDR)

Continuous endpoint telemetry analysis across workstations and servers. Our analysts provide managed endpoint detection and response across your in-scope endpoints.

managed endpoint detection and response →

Network Traffic

East-west and north-south traffic analysis for lateral movement detection. Threat detection and response across your network perimeter and internal segments.

network traffic analysis →

Vulnerability Context

Offensive intel from our CREST pen testing feeds directly into SOC detection rules. Testing and monitoring can inform each other where both are in scope.

CREST penetration testing →

Identity Threat Detection

Azure AD, Entra ID, and Active Directory monitoring for credential abuse, privilege escalation, and lateral movement via compromised accounts.

identity threat detection →

Cloud Security Monitoring

AWS, Azure, and GCP resource activity, API calls, and misconfiguration monitoring. Cloud-native telemetry correlated with endpoint and network signals.

cloud security monitoring →

Microsoft 365 & SaaS

Microsoft 365 security monitoring covering Exchange Online, SharePoint, Teams, and OneDrive. Business email compromise and account takeover detection.

managed Microsoft 365 security →

Ready to see what 24/7 monitoring would look like across your environment? Discuss your coverage No commitment. 30 minutes.

Response in Action

How Resilien Responds Out of Hours

An illustrative Resilien response, from alert to investigation and containment. Example times show the sequence, not a guaranteed resolution time.

Response actions are pre-authorised during onboarding. If an action needs approval, we contact your named decision-maker.

01
11:47pm

Threat Detected

Your EDR detects a malicious process executing on a domain controller. Alert fires in the Precursor SOC.

02
11:49pm

Analyst Triage

A Precursor analyst receives the alert and begins immediate triage. Critical severity alerts are prioritised above all other work.

03
11:52pm

ATT&CK Correlation

The process is correlated against MITRE ATT&CK TTPs and cross-referenced with your environment baseline established during onboarding.

04
11:58pm

Containment Initiated

Threat confirmed. Analysts isolate affected endpoints where authorised by your response plan, or request approval from your named contact. High-severity incidents trigger a phone call.

05
12:15am

Forensic Investigation

Analysts investigate the attack chain and preserve available evidence within the agreed scope. Specialist forensic support is engaged if required and agreed.

06
07:30am

Your Team Is Updated

An investigation update records actions taken, findings and remediation steps for your team. Follow-up continues according to the incident and agreed scope.

Comparison

MDR, MSSP and In-House SOC: A Comparison

Compare who monitors, investigates and responds, then confirm the scope and responsibilities in each provider’s proposal.

Comparison of Resilien MDR against a traditional MSSP and an in-house SOC across security capabilities.
CapabilityProvider-dependent serviceResilien MDROur approachIn-House SOC
Alert triageDepends on contractIncludedYour team
Threat huntingVariesScoped to your needsYour team
Incident responseVariesAgreed response planYour team
After-hours coverageDepends on contractIncludedDepends on staffing
CREST accreditationDepends on providerPrecursor SOC accreditedDepends on accreditation
Offensive intel integrationDepends on providerAgreed service scopeBuilt by your team
CostDepends on scopeFrom £900/mo; scoped quoteStaffing, tooling and operations
Time to deployAgreed with providerAgreed at scopingDepends on existing capability

Not sure which service model fits your organisation? Talk to a senior analyst. We will tell you honestly if MDR is right for you.

The Closed-Loop Advantage

Our pen testers harden the same environments our SOC defends.

Most managed detection and response providers operate only on the defensive side. Precursor Security holds CREST accreditation for both penetration testing and SOC operations. This means our red team finds real vulnerabilities in your environment, and those findings feed directly into custom SOC detection rules, closing the loop between attack and defence.

Red team finds a vulnerability. SOC detection rule is written. Next pen test validates the defence. Findings from agreed testing help calibrate detection to observed attacker behaviour alongside threat intelligence.

Explore CREST Penetration Testing
Offensive Security
CREST-accredited pen testing finds real vulnerabilities
Feeds into
MDR / SOC Operations
Custom detection rules built from real attack findings
Transparent Pricing

Resilien MDR Pricing: Your Scope, Your Quote

Resilien starts from £900/month. These examples describe scope considerations, not fixed packages. Your fixed quote confirms endpoints, log sources, licensing, hunting and response scope before onboarding.

Focused coverage

Prioritised security sources

24/7 monitoring, investigation and agreed response for smaller organisations. EDR/SIEM integration, alert triage, and monthly reporting.

Scoped quote

Broader coverage

More integrations and investigation needs

Agree additional data sources, threat hunting depth, analyst support and reporting requirements as your needs grow.

Scoped quote

Complex environments

Custom operational requirements

Review custom detection, specialist integrations, escalation arrangements and reporting for complex environments.

Scoped quote
Agreed incident response
24/7 UK-based SOC
Analysts from our CREST-accredited SOC
Vendor-agnostic integration
Monthly executive reports
Get your Resilien quote
A fixed monthly quote showing coverage, licensing and service options.
Engagement Pipeline

Getting Started with Resilien MDR

Your onboarding schedule separates first telemetry connected, 24/7 monitoring live and baseline tuning complete.

Step 01

Discovery & Onboarding

We assess your current environment, technology stack, and risk profile. Our engineers deploy or integrate monitoring agents and configure log ingestion to the agreed onboarding schedule.

OutputScoped proposal
Step 02

Baseline & Tuning

We learn what is normal in your environment. Baseline tuning has an agreed milestone and continues as your environment changes, helping keep alerts relevant.

OutputDetection Rules Tuned
Step 03

Active Monitoring & Investigation

24/7/365 detection and response kicks in. Our SOC triages alerts and investigates anomalies. Where included in your scope, analysts run proactive hunts using current threat intelligence and MITRE ATT&CK mapping.

OutputSOC Operational
Step 04

Continuous Improvement

Monthly reporting, quarterly reviews, and detection rule refinement. Insights from our offensive security engagements are continuously fed back to strengthen your defensive posture.

OutputOngoing Optimisation
Who It Fits

MDR for MSPs and
smaller teams.

Resilien can support two different operating models: managed detection and response for MSPs who want to add security to their stack without building a SOC, and MDR for SMBs that need enterprise-grade cover without enterprise headcount.

MDR for MSPs

Add 24/7 MDR to Your Stack

Precursor works with MSPs and IT service providers who want to offer clients managed detection and response without staffing a 24/7 SOC of their own. Our UK analysts from Precursor’s CREST-accredited SOC run detection, investigation, and response behind your service, so you keep the client relationship and add security cover without recruiting and managing a SOC rota. Licensing and integrations are agreed in the service quote. Engagements are co-managed and vendor-agnostic, integrating with the EDR and SIEM tooling your clients already run.

MDR for MSPsCo-ManagedVendor AgnosticUK CREST SOC
MDR for SMBs

Enterprise Cover, SMB Budget

MDR for SMBs gives small and mid-sized businesses 24/7 monitoring and human-led response within an agreed scope, starting from £900 per month. There is no in-house SOC to build and no analyst rota to run: our UK team is your night shift and weekend cover, so suspicious activity at 2am on Saturday can be investigated around the clock, with response actions taken under your agreed plan.

MDR for SMBsFrom £900/moNo In-House SOC
Deliverables

Your Resilien Service Specification

Your proposal documents the capabilities below for your agreed environment. Service options and response permissions are confirmed before onboarding.

24/7/365 human-led threat monitoring from our UK-based SOC facility
24/7 human analyst coverage with notifications under the agreed escalation plan
Monthly executive report with threat landscape summary and SLA metrics
Threat review schedule and analyst support agreed during scoping
Managed EDR deployment and ongoing agent management
Threat hunting depth and frequency agreed in your service scope
Log retention and audit-ready export agreed in your scope
Incident response through agreed containment and escalation procedures
Direct analyst access through agreed support channels
Customer portal with real-time alert visibility and trend dashboards

Your Resilien service is delivered through Precursor’s CREST-accredited SOC. Your quote confirms threat intelligence, hunting, reporting and response commitments for your environment.

Category cheatsheet

MDR vs MSSP vs XDR vs SOC

Four terms buyers are asked to choose between. They overlap, but each implies a different scope, commercial model, and operational expectation. Resilien MDR is vendor-agnostic: we operate it using your existing EDR/SIEM stack, add human analysts 24/7 from our UK SOC, and agree response permissions before onboarding. Your quote defines containment support and any specialist services.

Compare detection tools

Deciding between detection technologies? These side-by-side comparisons explain the differences and where each fits.

Related security terms

Plain-English definitions of the concepts behind this service, from our security glossary.

Managed Detection & Response

Put Resilien to Work for Your Team.

Tell us about your environment and the support your team needs. We will contact you to discuss coverage, licensing and response permissions, then prepare your Resilien quote.

CREST Accredited
UK-Based Analysts
From £900/month

Resilien MDR: Common Questions

Pricing, onboarding, coverage, and how MDR compares to MSSP and in-house SOC.