by Precursor
Managed Detection & Response (MDR).
Expert investigation when threats emerge.
Resilien’s UK analysts investigate suspicious activity across your connected security tools and take authorised action on confirmed threats. Your team receives clear escalation and practical next steps, day or night.
From £900/month. Coverage, licensing and response permissions confirmed in your quote.
Human expertise.
Machine velocity.
Security tools collect and correlate signals. UK analysts investigate and direct the response, 24/7/365.
Detect suspicious activity
Bring endpoint, identity, network and cloud signals together.
Confirm the threat
Human analysts investigate and establish the impact.
Contain and coordinate
Use authorised response actions and involve your team.

Resilien by Precursor Security
Delivered through our CREST-accredited UK SOC.
From detection to action.
Delivered by Resilien.
Get specialist investigation and authorised threat response when suspicious activity needs attention.
MDR is delivered through our Managed SOC. You keep your existing security tools while our UK analysts turn their signals into investigation and action.
From £900/month
Your quote confirms the users, endpoints, log sources, licensing and response actions in scope before the service begins.
Get your Resilien quoteWhat’s included in Resilien?
- The core service
- 24/7 detection and human-led investigation across your agreed telemetry, with containment and escalation through documented response procedures.
- Coverage agreed with you
- Your quote sets out the SIEM and EDR integrations, log sources, retention, threat hunting and response authority. Licensing and any additional costs are confirmed before onboarding.
- Optional extensions
- Extend your coverage with vulnerability management, EdgeProtect attack surface monitoring, penetration testing or a specialist incident response retainer.
- Your team’s role
- You provide access, name escalation contacts and approve response permissions. Your IT team retains infrastructure ownership and works with us on remediation and recovery.
What is Managed Detection and Response (MDR)?
24/7 threat detection and response from a CREST-accredited UK SOC, vendor-agnostic across endpoint, network, identity, and cloud.
Managed Detection and Response (MDR) is an outsourced 24/7 service combining endpoint, network, identity, and cloud telemetry with human analyst triage to detect and contain threats in real time.
Resilien delivers MDR through Precursor’s CREST-accredited UK SOC in Newcastle, with human-led investigation and containment under agreed response procedures.
MDR is the investigation and response capability within a broader outsourced SOC engagement. For a full side-by-side breakdown, see our MDR vs SOC vs SIEM vs EDR vs XDR buyer's guide.
Resilien MDR capabilities
24/7 UK analysts
CREST-accredited SOC analysts, based in the UK and available around the clock.
Your existing tools
Vendor-agnostic integration with CrowdStrike, SentinelOne, Microsoft Defender, and Carbon Black.
Scoped threat hunting
Threat hunting scoped to your needs and MITRE ATT&CK-mapped detection.
Agreed response
Human-led response with named escalation contacts and agreed permissions.
Offensive security insight
Vulnerability context fed in from our offensive security team.
Direct analyst access
Access analysts and investigation updates through the customer portal.
From £900/month
Onboarding schedule agreed after reviewing your integrations.
From security alerts to investigated threats.
Resilien gives your team specialist support when suspicious activity needs investigation. Analysts in our UK security operations centre assess the evidence, take authorised containment actions and explain what your team needs to do next. Coverage continues through nights, weekends and public holidays.
Discuss your coverageWhat Resilien MDR
Delivers.
Resilien brings monitoring, investigation and response together through Precursor’s UK SOC. We agree the integrations, hunting programme and response permissions for your environment.
24/7 Threat Monitoring
Our UK-based SOC analysts monitor your environment 24/7/365 against the broader UK threat landscape tracked by the NCSC. We ingest telemetry from EDR, SIEM, and XDR platforms to detect malicious activity in real time. No follow-the-sun model. Every analyst operates from our physical Security Operations Centre in Newcastle.
Proactive Threat Hunting (Scoped)
Where included in your Resilien scope, our analysts run hypothesis-driven hunts using MITRE ATT&CK TTPs, intelligence from Mandiant M-Trends dwell-time research, and vulnerability data from our offensive security team to find threats before they trigger rules. See how our SOC hunts and catches MSIX malware campaigns via SEO poisoning.
Rapid Incident Response
When a confirmed threat is identified, our analysts investigate the threat and isolate affected endpoints where authorised by your response plan. Incident response follows your agreed permissions and scope. Specialist forensics, recovery and retainer services can be added where required.
Keep the security tools you already use
Bring your existing stack or choose from our recommended vendors. We integrate via API with Microsoft Defender, SentinelOne, CrowdStrike Falcon, and Elastic SIEM. Supported connectors, access and licensing are confirmed before onboarding.
Offensive + Defensive Fusion
Unlike pure-play MDR providers, Precursor Security combines CREST-accredited penetration testing with SOC operations. Vulnerabilities found by our Red Team feed directly into detection rules, closing the loop between attack and defence, mapped to the NIST Cyber Security Framework identify, protect, detect, respond functions.
See what happened and what happens next
Real-time visibility into your security posture. Track alerts, investigations, and monthly trend reports through our dedicated client portal. Board-ready reports delivered monthly. Agreed log retention with audit-ready event export.
The MDR Investment Case
Give your team continuous monitoring, specialist investigation and a documented response plan.
Analysts assess suspicious activity in context and give your team clear findings and next steps.
Know which containment actions analysts can take and when your named contacts will be involved.
UK analysts investigate suspicious activity around the clock, with containment and escalation governed by your agreed response procedures.
Controls
360° Threat Coverage
Resilien MDR monitors the technology sources agreed in your service scope. Our SOC correlates signals across endpoints, networks, cloud, identity, and email to deliver threat detection and response against sophisticated multi-stage attacks that siloed tools miss.
Endpoint (EDR/XDR)
Continuous endpoint telemetry analysis across workstations and servers. Our analysts provide managed endpoint detection and response across your in-scope endpoints.
Network Traffic
East-west and north-south traffic analysis for lateral movement detection. Threat detection and response across your network perimeter and internal segments.
Vulnerability Context
Offensive intel from our CREST pen testing feeds directly into SOC detection rules. Testing and monitoring can inform each other where both are in scope.
Identity Threat Detection
Azure AD, Entra ID, and Active Directory monitoring for credential abuse, privilege escalation, and lateral movement via compromised accounts.
Cloud Security Monitoring
AWS, Azure, and GCP resource activity, API calls, and misconfiguration monitoring. Cloud-native telemetry correlated with endpoint and network signals.
Microsoft 365 & SaaS
Microsoft 365 security monitoring covering Exchange Online, SharePoint, Teams, and OneDrive. Business email compromise and account takeover detection.
Ready to see what 24/7 monitoring would look like across your environment? Discuss your coverage No commitment. 30 minutes.
How Resilien Responds Out of Hours
An illustrative Resilien response, from alert to investigation and containment. Example times show the sequence, not a guaranteed resolution time.
Response actions are pre-authorised during onboarding. If an action needs approval, we contact your named decision-maker.
Threat Detected
Your EDR detects a malicious process executing on a domain controller. Alert fires in the Precursor SOC.
Analyst Triage
A Precursor analyst receives the alert and begins immediate triage. Critical severity alerts are prioritised above all other work.
ATT&CK Correlation
The process is correlated against MITRE ATT&CK TTPs and cross-referenced with your environment baseline established during onboarding.
Containment Initiated
Threat confirmed. Analysts isolate affected endpoints where authorised by your response plan, or request approval from your named contact. High-severity incidents trigger a phone call.
Forensic Investigation
Analysts investigate the attack chain and preserve available evidence within the agreed scope. Specialist forensic support is engaged if required and agreed.
Your Team Is Updated
An investigation update records actions taken, findings and remediation steps for your team. Follow-up continues according to the incident and agreed scope.
MDR, MSSP and In-House SOC: A Comparison
Compare who monitors, investigates and responds, then confirm the scope and responsibilities in each provider’s proposal.
| Capability | Provider-dependent service | Resilien MDROur approach | In-House SOC |
|---|---|---|---|
| Alert triage | Depends on contract | Included | Your team |
| Threat hunting | Varies | Scoped to your needs | Your team |
| Incident response | Varies | Agreed response plan | Your team |
| After-hours coverage | Depends on contract | Included | Depends on staffing |
| CREST accreditation | Depends on provider | Precursor SOC accredited | Depends on accreditation |
| Offensive intel integration | Depends on provider | Agreed service scope | Built by your team |
| Cost | Depends on scope | From £900/mo; scoped quote | Staffing, tooling and operations |
| Time to deploy | Agreed with provider | Agreed at scoping | Depends on existing capability |
Not sure which service model fits your organisation? Talk to a senior analyst. We will tell you honestly if MDR is right for you.
Our pen testers harden the same environments our SOC defends.
Most managed detection and response providers operate only on the defensive side. Precursor Security holds CREST accreditation for both penetration testing and SOC operations. This means our red team finds real vulnerabilities in your environment, and those findings feed directly into custom SOC detection rules, closing the loop between attack and defence.
Red team finds a vulnerability. SOC detection rule is written. Next pen test validates the defence. Findings from agreed testing help calibrate detection to observed attacker behaviour alongside threat intelligence.
Explore CREST Penetration TestingResilien MDR Pricing: Your Scope, Your Quote
Resilien starts from £900/month. These examples describe scope considerations, not fixed packages. Your fixed quote confirms endpoints, log sources, licensing, hunting and response scope before onboarding.
Focused coverage
Prioritised security sources24/7 monitoring, investigation and agreed response for smaller organisations. EDR/SIEM integration, alert triage, and monthly reporting.
Broader coverage
More integrations and investigation needsAgree additional data sources, threat hunting depth, analyst support and reporting requirements as your needs grow.
Complex environments
Custom operational requirementsReview custom detection, specialist integrations, escalation arrangements and reporting for complex environments.
Getting Started with Resilien MDR
Your onboarding schedule separates first telemetry connected, 24/7 monitoring live and baseline tuning complete.
Discovery & Onboarding
We assess your current environment, technology stack, and risk profile. Our engineers deploy or integrate monitoring agents and configure log ingestion to the agreed onboarding schedule.
Baseline & Tuning
We learn what is normal in your environment. Baseline tuning has an agreed milestone and continues as your environment changes, helping keep alerts relevant.
Active Monitoring & Investigation
24/7/365 detection and response kicks in. Our SOC triages alerts and investigates anomalies. Where included in your scope, analysts run proactive hunts using current threat intelligence and MITRE ATT&CK mapping.
Continuous Improvement
Monthly reporting, quarterly reviews, and detection rule refinement. Insights from our offensive security engagements are continuously fed back to strengthen your defensive posture.
MDR for MSPs and
smaller teams.
Resilien can support two different operating models: managed detection and response for MSPs who want to add security to their stack without building a SOC, and MDR for SMBs that need enterprise-grade cover without enterprise headcount.
Add 24/7 MDR to Your Stack
Precursor works with MSPs and IT service providers who want to offer clients managed detection and response without staffing a 24/7 SOC of their own. Our UK analysts from Precursor’s CREST-accredited SOC run detection, investigation, and response behind your service, so you keep the client relationship and add security cover without recruiting and managing a SOC rota. Licensing and integrations are agreed in the service quote. Engagements are co-managed and vendor-agnostic, integrating with the EDR and SIEM tooling your clients already run.
Enterprise Cover, SMB Budget
MDR for SMBs gives small and mid-sized businesses 24/7 monitoring and human-led response within an agreed scope, starting from £900 per month. There is no in-house SOC to build and no analyst rota to run: our UK team is your night shift and weekend cover, so suspicious activity at 2am on Saturday can be investigated around the clock, with response actions taken under your agreed plan.
Your Resilien Service Specification
Your proposal documents the capabilities below for your agreed environment. Service options and response permissions are confirmed before onboarding.
Your Resilien service is delivered through Precursor’s CREST-accredited SOC. Your quote confirms threat intelligence, hunting, reporting and response commitments for your environment.
Strengthen Defences.
Complete the Loop.
Your MDR detects threats. Our penetration testers validate whether those defences hold. We feed pentest findings directly back into SOC detection rules, building custom alerts for your specific attack surface. This is the closed-loop advantage.
Explore Penetration TestingSecurity Operations Centre
24/7 UK-based monitoring with SIEM, EDR and threat hunting scoped to your environment.
CREST Penetration Testing
Validate your SOC detections with manual exploitation by CREST-accredited testers.
EdgeProtect ASM
Continuous external attack surface monitoring for exposed services and credentials.
Incident Response
Emergency breach support, digital forensics, and ransomware recovery services.
MDR vs MSSP vs XDR vs SOC
Four terms buyers are asked to choose between. They overlap, but each implies a different scope, commercial model, and operational expectation. Resilien MDR is vendor-agnostic: we operate it using your existing EDR/SIEM stack, add human analysts 24/7 from our UK SOC, and agree response permissions before onboarding. Your quote defines containment support and any specialist services.
Deciding between detection technologies? These side-by-side comparisons explain the differences and where each fits.
Plain-English definitions of the concepts behind this service, from our security glossary.
Put Resilien to Work for Your Team.
Tell us about your environment and the support your team needs. We will contact you to discuss coverage, licensing and response permissions, then prepare your Resilien quote.
Resilien MDR: Common Questions
Pricing, onboarding, coverage, and how MDR compares to MSSP and in-house SOC.
Resilien is Precursor Security's managed security service, bringing together 24/7 UK-based monitoring, human-led investigation and agreed threat response. Precursor Security operates the service from its CREST-accredited Security Operations Centre in Newcastle. Resilien is the service brand, and Precursor is your security provider.
Managed SOC describes the broader security operations capability: monitoring, SIEM management, detection tuning and reporting. Managed detection and response (MDR) focuses on investigating and responding to threats. Resilien brings these capabilities together through one UK-based team, with coverage agreed around your environment and existing security tools.
From £900/month. Your quote confirms the users, endpoints, log sources, licensing and response actions in scope before the service begins. We also confirm the depth and frequency of threat hunting, log retention, reporting and any optional services. Analysts investigate confirmed threats and take containment actions under your agreed response procedures. Specialist forensics, recovery and incident response retainers are scoped separately where required.
Resilien starts from £900/month. We review your users, endpoints, security tools and monitoring requirements, then provide a fixed quote showing coverage, licensing and service options.
Managed Detection and Response (MDR) is a service in which a specialist provider monitors your IT environment 24/7, investigates threats using human analysts, and actively responds to confirmed incidents, with containment and remediation responsibilities defined in the service scope.
- Includes human-led investigation and agreed threat response. Proactive threat hunting is defined in your service scope.
- Human analysts investigate suspicious activity and escalate according to your response plan.
- Provides investigation and authorised response, with escalation responsibilities documented before onboarding.
MSSP describes a broad category of managed security providers; investigation and response capabilities vary. MDR specifically focuses on detecting, investigating and responding to threats. Compare the actual service commitments rather than the label.
- Ask who investigates alerts and which response actions the provider is authorised to take.
- Resilien: analysts investigate suspicious activity and take containment actions within agreed permissions.
- Confirm out-of-hours coverage, notification arrangements and what remains your team’s responsibility.
MDR is a service that investigates and responds to threats, typically wrapped around your existing EDR and SIEM tooling. A SOC (Security Operations Centre) is the broader function of continuous monitoring, detection, and response across your whole environment, delivered by people, process, and technology together.
- In practice, MDR is usually one delivery model for SOC capability: most UK organisations buying MDR are buying 24/7 SOC-delivered detection and response.
- A full outsourced SOC can extend further, adding SIEM log management, compliance reporting, and custom detection engineering on top of the MDR core.
- See our full MDR vs SOC vs SIEM vs EDR vs XDR buyer's guide for a term-by-term breakdown.
EDR (Endpoint Detection and Response) is a security technology that collects telemetry from endpoints. MDR (Managed Detection and Response) is a managed service that wraps human analysts around EDR and other tools. MDR analysts monitor, investigate, and respond to EDR alerts 24/7. EDR is the sensor, MDR is the team that acts on it. Resilien MDR analysts operate your EDR platform 24/7, investigating and responding to threats so your team does not have to.
An in-house SOC needs staffing, shift coverage, security tools, training and management. Resilien provides access to a UK analyst team through a scoped monthly service. Compare the full coverage, response permissions and licensing costs of each option rather than treating a starting price as an equivalent replacement for every internal capability.
Your security team may need additional capacity, specialist investigation or cover outside working hours. Resilien complements your team with continuous monitoring and agreed response support, leaving your staff time for their other security priorities. Think of MDR as your night shift and weekend coverage: threats detected at 2am on Saturday receive priority investigation, with authorised containment actions taken under your response plan.
Critical alerts are prioritised for human investigation around the clock. Your service agreement sets investigation targets, notification arrangements and response permissions. Authorised containment follows your response plan; actions outside those permissions require your approval.
Resilien can correlate activity across agreed endpoint, network, cloud, identity and email sources. Your quote identifies connected platforms and any coverage limitations.
- Endpoint: Windows, macOS and Linux workstations and servers via EDR.
- Network: north-south and east-west traffic analysis for lateral-movement detection.
- Cloud: AWS, Azure and GCP resource activity and misconfigurations.
- Identity: Entra ID and Active Directory for credential abuse.
- Email and SaaS: Microsoft 365 and Google Workspace for phishing and business email compromise.
Yes. Precursor Security operates a physical UK-based Security Operations Centre in Newcastle. We do not use a follow-the-sun model with offshore analysts. Every analyst is UK-based and DBS-checked, with no offshoring of work.
Absolutely. Resilien MDR is vendor agnostic. We integrate with your existing EDR, SIEM, XDR, and cloud security tooling via API. If you use Microsoft Defender for Endpoint, SentinelOne, CrowdStrike Falcon, or Elastic SIEM, we integrate without requiring you to switch vendors. If you lack existing tooling, we can deploy proven, enterprise-grade tooling as part of the bring your own EDR integration service.
Precursor Security is CREST accredited for both penetration testing and SOC operations. We also hold ISO 27001, ISO 9001, and Cyber Essentials Plus certifications. Our analysts hold GIAC, OSCP, and CREST-level certifications.
We agree an onboarding schedule after reviewing your integrations and access requirements. Your plan distinguishes first telemetry connected, 24/7 monitoring live and baseline tuning complete; detection tuning continues as your environment changes.
Yes. Resilien includes response through agreed procedures: analysts investigate confirmed threats, take authorised containment actions and guide your team on next steps. Your quote defines the scope and permissions. Specialist forensic investigation, recovery work or an incident response retainer can be scoped separately where required.
Yes. Precursor provides managed detection and response for MSPs and IT service providers who want to offer clients 24/7 security cover without building a SOC of their own. The model is co-managed and vendor-agnostic: our UK analyst team from Precursor’s CREST-accredited SOC runs detection, investigation, and response behind your service while you keep the client relationship. MSPs use MDR from Precursor to add enterprise-grade security to their stack without recruiting and managing a SOC rota. Licensing and integrations are agreed in the service quote.
Yes. Resilien starts from £900/month for scoped monitoring, human-led investigation and agreed threat response. We review your users, endpoints, security tools and required coverage before quoting, so you can assess the service against your team’s needs.
User count alone does not establish the price. For a 160-user organisation, we also review devices, servers, log sources, existing licences and response requirements. Resilien starts from £900/month; your fixed quote shows the actual agreed coverage and costs.
Yes. That is exactly what managed detection and response provides. Precursor delivers 24/7 threat detection and response across your agreed endpoints, network, cloud and identity sources, from our CREST SOC-accredited UK Security Operations Centre, with no need to build or staff an internal SOC. Our UK analysts monitor and investigate around the clock, taking containment actions under your agreed permissions, so you get continuous coverage across nights, weekends, and public holidays. Response permissions, integrations and licensing are agreed before onboarding.