forumNew topic

We're being offered "MDR cybersecurity" for 400 €/mo — what is this, and does it replace a SOC?

DDoruk D***Member
Job title
IT manager
Sector
Freight
Organization type
a company within a holding
Joined
Jun 2022
Message
11

Doki · Incident response support · 2026

#1

We run a wholesale distribution business of 22 people based in Lyon, France. Our local IT provider told us our current antivirus is inadequate against ransomware and proposed moving us to an MDR (Managed Detection and Response) package. They are asking for a flat fee of 400 € per month covering our servers and around 20 laptops.

The proposal lists things like 24/7 monitoring, automated containment of suspicious activity, and expert intervention. People had mentioned dedicated SOC setups used by enterprise firms to us before, but their annual costs were way out of our league. Does this MDR thing genuinely take the place of a full SOC service, or are we just buying a rebranded, overpriced antivirus?

SSelin Ö***MemberCommunity member
Joined
Nov 2025
Message
336
Most Helpful#2

Short answer: MDR works like an outsourced mini-SOC for small businesses, but it monitors only the endpoints it is installed on rather than your entire network. If you are getting human-backed 24/7 monitoring and response across 20-22 devices for 400 € a month, that's a reasonable price and makes far more sense than trying to run an internal SOC.

In a traditional corporate SOC, all network switches, firewalls, email traffic, and server logs are fed into a centralized pool and monitored around the clock by shifts of dedicated security engineers. The tooling licenses and engineering salaries required for that level of operation are completely out of reach for small businesses. MDR narrows that focus down specifically to client workstations and servers.

When you buy MDR, an advanced telemetry agent gets installed on your endpoints. Whenever suspicious encryption behavior or an unauthorized intrusion attempt occurs, the provider's on-duty analyst flags it and can remotely quarantine the machine from the network if necessary. When evaluating this quote, get explicit answers to these three questions: 1) Do they immediately intervene and isolate the machine off the network when a threat is detected overnight, or do they simply email a summary report the next morning? 2) Is active incident response included in the 400 € monthly fee, or will malware remediation be billed at an hourly rate? 3) Are your backup servers included in this scope? If those terms check out, the offer is very solid for your scale.

YYağmur E***Member
Job title
General coordinator
Sector
Paper
Organization type
a company within a holding
Joined
Aug 2025
Message
197

Doki · SEO consulting · 2026

#3

The core difference between MDR and traditional endpoint protection is the human element. Standard software blocks known malware signatures; however, if a targeted attacker infiltrates your network using legitimate built-in administrative tools, conventional software might stay silent. An analyst in an MDR center spots that anomaly and cuts the device's network connection immediately.

KKaanMember
Job title
Product Manager
Joined
May 2024
Message
96
#4

What response time (SLA) does the contract specify? If suspicious activity kicks off at 2:00 AM, will it take them 15 minutes to spot it and act, or are they just promising to "investigate within 4 hours"? Also, is your corporate email environment covered under this MDR monitoring umbrella?

MMeryem Ö***Member
Job title
Export manager
Sector
Cleaning services
Organization type
40-person manufacturing company
Joined
Feb 2024
Message
13
#5

We rolled out a similar service for our 35-person office in Paris. We pay roughly 18 € per device each month, so 400 € for 20 machines is right around market average. Last month an employee opened a malicious payload inside a fake invoice attachment that slipped past the firewall, but the MDR analyst isolated the machine within 8 minutes and called us right away. Saved the day.

FFurkan Y***MemberCommunity member
Joined
Jan 2024
Message
11
#6

Is the IT company quoting 400 € actually doing the monitoring themselves, or are they just reselling a managed license from an enterprise security vendor and tacking on a markup? If they don't have dedicated engineers on duty 24/7 in-house, an alert triggered in the middle of the night won't get looked at until business hours start, which defeats the entire purpose of having MDR.

İİbrahim A***ExpertCommunity member
Joined
May 2024
Message
1
#7

I'd say get your basic cyber hygiene in order before moving to MDR. Is 2FA enforced, are your backups air-gapped from the network, do employees have restricted local admin privileges? Without these, even an MDR service you pay 400 € a month for won't stop ransomware caused by a misconfigured admin account.

ZZeynep Z***Member
Job title
Customer service representative
Sector
Law
Organization type
120-person company
Joined
Jan 2023
Message
1
#8

all we have is standard antivirus behind the modem. once this MDR is set up, do we need to uninstall the current antivirus or can both run side by side withoout bogging down the PCs?

BBurak O***Member
Job title
Operations manager
Sector
Jewelry
Organization type
early-stage startup
Joined
Feb 2023
Message
192
#9

Advanced MDR agents completely replace legacy antivirus; running both at the same time will cause system freezes. Your MDR provider runs its own protection engine in the background anyway and feeds suspicious logs directly to its SOC. You won't need to renew your old license.

İİbrahim G***MemberCommunity member
Joined
Mar 2024
Message
3
#10

There's a common mistake people make when doing this. Most time waste accumulates in tasks waiting for approval.

I'm also curious if anyone does it differently.

FFurkan B***ExpertCommunity member
Joined
Jul 2025
Message
32
#11

I'm curious too. Most incidents start with a leaked password, not a vulnerability.

AAleyna Ç***Member
Job title
Field sales representative
Sector
Packaging
Organization type
a company within a holding
Joined
Apr 2024
Message
225
#12

I have an objection here. The answer varies greatly by industry; there is no one-size-fits-all rule.

If I were you, I'd go this route.

AAleyna D***MemberCommunity member
Joined
Jul 2023
Message
3
#13

My questions are cleared up, thanks.

YYiğitMember
Job title
Video production
Joined
May 2024
Message
88
#14

following but payment information changes are never verified through the channel they came from.

if you have questions, write them; I'll answer as best I can.

BBarış K***Expert
Job title
Corporate IT manager
Joined
Jun 2023
Message
172
#15

I think differently. Mistakes made on the mdr cybersecurity side are usually reversible but expensive.

That's all, sorry if I went on too long.

RRecep S***ExpertCommunity member
Joined
Mar 2024
Message
243
#16

Saved.

ÜÜlkü B***New memberCommunity member
Joined
Sep 2026
Message
240
#17

My perspective changed after experiencing that. Security isn't absolute; it's about making attacks not worth the effort.

If I were you, I'd go this route.

OOrhan O***Member
Job title
Board member
Sector
Seafood
Organization type
medium-sized business
Joined
Jun 2023
Message
17
#18

Correct. Most incidents start with a leaked password, not a vulnerability.

I'm also curious if anyone does it differently.

AAycan K***Member
Job title
Data entry clerk
Sector
Logistics
Organization type
300-person organization
Joined
Jan 2023
Message
39
#19

i'll try it.

AAyşe Y***MemberCommunity member
Joined
Jun 2024
Message
10
#20

quick summary for newcomers: If you dont write this down from the start, it leads to arguments later.

forgotten test environments are more often the entry point than live systems and this is my opinion, Im not claiming its absollute truth.

Reply