Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Darktrace Managed Detection & Response (MDR) adds human analyst monitoring and investigation to Darktrace’s existing detection and response capabilities. Announced on June 6, 2024, the service is intended to help organizations using Darktrace DETECT and RESPOND investigate high-priority alerts and manage response actions across network, cloud, operational technology (OT), endpoint and SaaS environments.

What Darktrace MDR does

Darktrace said it introduced MDR in March 2024 and announced it publicly on June 6, 2024. The service pairs Darktrace’s detection and response technology with managed support from its security operations center (SOC). The company described MDR as a way to help internal security teams handle high-priority alerts and response work; these are the service’s stated aims, not independently measured outcomes.

Darktrace’s announcement said its SOC monitors customer environments for high-priority alerts that may indicate an attack. Analysts investigate potentially severe incidents, notify customers and perform initial triage while engaging with actions taken by Darktrace’s AI.

How analysts and automated response work together

  1. Detection: Darktrace’s systems identify alerts, including high-priority alerts that may indicate an attack.
  2. Human investigation and triage: SOC analysts investigate potentially severe incidents and notify the customer.
  3. Review of response: Analysts review response measures already taken by the autonomous system.
  4. Additional containment: Darktrace said analysts may take further steps to contain threats, including extending or escalating response actions.
  5. Customer remediation: The company framed analyst investigation and triage as giving internal teams more time and context for remediation.

The announcement does not specify customer approval requirements for individual response actions, contractual response times or service-level guarantees. Organizations evaluating the service should clarify those operational details with Darktrace or an authorized reseller.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Which systems Darktrace MDR covers

Darktrace described MDR coverage across five areas. It said the service was available to customers using Darktrace DETECT and RESPOND across these environments.

  • Network
  • Cloud
  • Operational technology (OT)
  • Endpoints
  • Software-as-a-service (SaaS) applications

The launch announcement does not enumerate supported products, integrations or technical prerequisites within each area. Buyers should confirm that their particular systems and deployment are supported.

Analyst availability and reporting

Darktrace listed unlimited access to its analyst team for 24/7 assistance, along with these service features:

  • Semi-annual operational efficiency reports
  • Quarterly analyst reviews
  • Regular service reports summarizing alerts raised and resolved by the SOC

The company described its support model as follow-the-sun, with operations headquartered in the United Kingdom, United States and Singapore. The announcement does not provide specific escalation response times or define the contents and format of each report.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What Darktrace said about the service

Denise Walter, Darktrace’s chief revenue officer, said: “Our AI-powered MDR service gives our customers added peace of mind that a Darktrace human expert is monitoring their environment 24/7 to keep them protected.” This is the company’s description of the intended reassurance offered by human monitoring, not evidence of measured protection outcomes.

Darktrace’s announcement also cited its State of AI Cybersecurity 2024, saying that more than 40% of security leaders identified improving SOC technology and processes as a top priority for defending against AI-powered threats. The announcement did not provide the study’s sample size or methodology, so the figure should be treated as Darktrace’s reported survey result.

At launch, Darktrace said its global SOC team included more than 100 cybersecurity analysts. That was a 2024 company statement and does not establish the team’s current size.

How to assess MDR fit

Darktrace MDR is designed for organizations already using DETECT and RESPOND that want managed analyst support alongside automated detection and response. When assessing whether it fits your team, ask Darktrace or a reseller about:

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • Environment coverage: Whether your specific network, cloud, OT, endpoint and SaaS systems are supported.
  • Human and automated response: How analysts review, extend or escalate actions initiated by the autonomous system, and which actions require customer authorization.
  • Availability and escalation: What 24/7 access means in practice, including channels, escalation paths and any response-time commitments.
  • Reporting: What the regular alert reports, quarterly reviews and semi-annual efficiency reports contain, and who receives them.
  • Team responsibilities: How MDR coordinates with your internal security staff during investigation, containment and remediation.
  • Commercial terms: Current eligibility, pricing, contract terms and any service-level commitments, none of which were detailed in the launch announcement.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Availability and reseller context

At launch, Darktrace said MDR was available to customers using DETECT and RESPOND and that partners could resell the service. The company named Grove Group as a global partner, reseller and distributor; Grove Group CEO James Vintin said: “At Grove, we are excited to partner with Darktrace to offer their Managed Detection & Response (MDR) service to our clients.” Darktrace also described Grove’s dSOC service as complementary.

Those launch statements do not establish current partner terms, geographic eligibility, pricing, contract conditions or a public affiliate or commission-based referral program. Confirm present-day availability and terms directly with Darktrace or an authorized reseller.

Source and date

This description is based on Darktrace’s official June 6, 2024 MDR announcement. It records what the company said at launch; it is not independent verification of service performance or confirmation of current commercial terms.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.