The 24/7 Managed Detection and Response Blueprint for Indian Enterprises

TL;DR
Managed detection and response is remotely delivered, AI-augmented, human-led SOC capability — monitoring, investigation and response, running 24×7.
The deciding question is not detection. It is response. Ask whether the provider acts on your network or sends you a ticket. Most escalate.
Attackers move in 29 minutes on average. CERT-In gives you six hours to report. Neither clock respects your business hours.
Gartner added "AI-augmented" to its MDR definition in 2026 and made SaaS coverage a key evaluation criterion. Older vendor shortlists are out of date.
Budget the full picture: platform licence, log retention to Indian regulatory periods, and the managed service. Retention is the line most quotes hide.
An in-house 24×7 SOC in India runs to roughly ₹1.5 crore a year and upward. That is the number MDR is measured against, not the licence cost.
What is managed detection and response?
Managed detection and response is a service that monitors your environment around the clock, investigates what it finds, and takes containment action — delivered remotely by an external team using a security stack they operate for you.
Gartner's 2026 Market Guide for MDR defines it as remotely delivered, AI-augmented, human-led, turnkey modern SOC functions. Each word in that phrase is doing work. AI handles triage volume. Humans lead investigation and decision. It is turnkey, meaning the provider brings the stack rather than managing yours.
The distinction that matters commercially: MDR includes response. A service that only tells you something happened is monitoring, whatever it is called on the invoice.
Why do Indian enterprises need 24×7 detection in 2026?
Because the gap between your last analyst logging off and your first one logging on is where intrusions succeed.
CrowdStrike's 2026 Global Threat Report, published in February 2026, put average eCrime breakout time — the interval between initial access and lateral movement — at 29 minutes. That is 65% faster than 2024. The fastest observed was 27 seconds. AI-enabled adversary operations rose 89% year on year.
Set that against a security team that works 9 to 7, five days a week. That team is absent for roughly 70% of the week. An intrusion starting at 9 p.m. on a Friday has the weekend.
Then add the regulatory clock. CERT-In requires specified cyber incidents to be reported within six hours of noticing them. An incident nobody notices until Monday has already missed that window by two days. Nobody meets a six-hour obligation with business-hours monitoring. That single sentence is the whole argument for 24×7 coverage in India, and it is a compliance argument before it is a security one.
What changed in MDR in 2026?
Three things, and any vendor shortlist built before this year needs revisiting.
AI moved into the definition- Gartner added "AI-augmented" to how it describes MDR and predicts that by 2029, 90% of initial findings from MDR providers will be processed without human action, up from around 30% today. The guide's caution to buyers is the useful part: ask which parts of the service are AI-augmented and which are genuinely human-led. Several providers have quietly moved work from analysts to models without changing the price.
Investigation scope became a requirement- Gartner's expectation is no limitation on the volume of investigations or the time spent on discovery. If a contract caps investigation hours or incident counts, that is a cost-control mechanism working against you at the worst possible moment.
SaaS coverage became a differentiator- Endpoint and network monitoring is table stakes. Your data now lives in Microsoft 365, Google Workspace, Salesforce and a dozen others. An MDR service that cannot see business email compromise in your tenant is monitoring the wrong half of your estate.
MDR vs in-house SOC vs MSSP vs XDR: what is the actual difference?
These four get compared as if they are alternatives. They are not the same category. XDR is a technology. MDR, an in-house SOC and an MSSP are three ways of operating one.
MDR | In-house SOC | Traditional MSSP | XDR | |
|---|---|---|---|---|
What it is | Outsourced detection and response service | Your own 24×7 team | Outsourced monitoring and device management | A detection and response platform |
24×7 coverage | Included | Requires three shifts | Usually included | Not applicable — it is a tool |
Investigation | Provider investigates | Your analysts | Often limited to alert forwarding | Provides the data for one |
Response action | Provider contains, or guides you | Your team acts | Typically raises a ticket | Enables action, does not take it |
Threat hunting | Expected | Depends on maturity | Rarely included | Supplies the telemetry |
Who owns the stack | Provider | You | Mixed | You license it |
Typical fit | Organisations without 24×7 staffing | Very large, mature security programmes | Device and perimeter management at scale | Any of the above, as the underlying layer |
The practical reading: XDR is what MDR runs on. An MSSP watches. MDR acts. An in-house SOC is the right answer when you can genuinely staff three shifts with skilled analysts and keep them.
What does "response" actually mean in an MDR contract?
This is the question that separates providers, and most buyers never ask it precisely enough.
"Response" is used to describe three very different things:
Notification. The provider tells you something happened. You do everything else. This is monitoring sold as MDR.
Guided response. The provider tells you what to do, in detail, and may stay on a call while you do it. Useful, but the containment clock runs at your team's speed and availability.
Direct response. The provider isolates the host, disables the account, blocks the hash, kills the process — on your environment, under agreed authority, without waiting for you to wake up.
At 2 a.m., only the third one contains an intrusion. If the contract does not say which one you are buying, assume the first.
Ask these four things in writing:
Which specific actions can you take on our environment without calling us first?
What is the response SLA for a critical severity incident, measured from detection to containment action?
Who has the authority to isolate a production server at 3 a.m., and what is the escalation path if they hesitate?
What happens when the SLA is missed?
A provider who cannot answer the first question with a concrete list of actions is selling you notification.
How does MDR support CERT-In and DPDP compliance?
For Indian enterprises this is often the budget justification, not the security case.
CERT-In six-hour reporting. Reporting within six hours of noticing an incident requires that someone notices at hour zero. Your MDR provider should be contractually accountable for detection and for supporting the filing, not merely "available to assist."
CERT-In 180-day log retention. ICT system logs must be retained for 180 days within Indian jurisdiction. Most security platforms retain far less by default — commonly 14, 30 or 90 days in the standard tier. Check where the retention sits in the quote.
DPDP Rule 6. When the substantive DPDP obligations commence in 2027, Rule 6 requires logs and personal data to be retained for one year, and requires logs, monitoring and review sufficient to detect unauthorised access. That is a monitoring obligation, not a logging one. Logs nobody reads detect nothing, and the ceiling for failing to take reasonable security safeguards is ₹250 crore.
Sector overlays. RBI, SEBI CSCRF and IRDAI requirements sit on top, and where regimes overlap the stricter one governs.
Design for the longest applicable retention period rather than tracking three separately. NetNXT runs CERT-In six-hour reporting and 180-day Indian retention as service defaults rather than add-ons, with DPDP, RBI and SEBI CSCRF mapping in standard reporting — which is usually where a like-for-like cost comparison actually lands. Our compliance automation practice keeps that evidence continuous rather than an annual scramble.
What does a modern MDR stack look like?
A credible 24×7 service is four layers, and a gap in any one shows up as a missed detection.
Telemetry: Endpoint, identity, cloud, network, SaaS and email, centrally ingested. Identity is the layer most commonly missing, and it is where credential-based intrusions begin. If your MDR provider is not consuming sign-in logs from Entra ID or your IdP, they cannot see the most common modern attack path. That is why identity and access management belongs inside the monitoring scope, not beside it.
Detection and correlation: Endpoint detection plus AI-assisted correlation across those sources. A single alert is noise. The same account failing MFA, then succeeding from a new country, then a new inbox rule, then mass file access — that is an attack chain, and only correlation shows it.
Automation: SOAR playbooks that enrich, triage and execute containment. Automation earns its place on the boring work: pulling context, checking reputation, isolating a confirmed match. SentinelOne reports that its AI capabilities cut detection time by 63% and remediation time by 55%; treat vendor figures as indicative and ask for evidence against your own environment.
Humans: Analysts who hunt, investigate and decide. This is what Gartner means by human-led. The automation handles volume; people handle judgment.
NetNXT delivers this on partner platforms rather than building its own: SentinelOne for managed XDR and endpoint, JumpCloud for identity and device management, Cato Networks for SASE, Fortinet and Twingate for network and ZTNA, Scrut for compliance automation. We are SentinelOne's SAARC Partner of the Year for 2026. The stack is documented on our partners page, and the managed service that runs it is managed XDR, operated from India-located SOCs by the same certified team that deploys it — with no reseller in between.
How long does MDR take to deploy?
Ninety days to full value is realistic. Anyone promising full capability in a fortnight is describing agent installation, not an operating service.
Days 1–30: telemetry and baseline: Deploy agents, connect log sources, integrate identity and cloud. Establish what normal looks like in your environment. Expect elevated alert volume in this window; that is the baseline forming, not a failure.
What you should see by day 30: all agreed sources ingesting, an asset inventory, and 24×7 monitoring live.
Days 31–60: tuning and hunting: Suppress the false positives your environment generates, finalise escalation paths and contact trees, and begin proactive threat hunting.
What you should see by day 60: a measurable fall in alert volume with no fall in true positives, an agreed severity matrix, and the first hunt report.
Days 61–90: automation and response: Build and enable SOAR playbooks. Move agreed containment actions from manual to automatic. Run a live response exercise.
What you should see by day 90: documented playbooks, response times against SLA, and a tested incident runbook covering both CERT-In and DPDP reporting.
Put those deliverables in the contract with dates. A provider confident in their onboarding will accept them.
How much does MDR cost in India?
Most articles refuse to give a number here. That is not helpful when you are building a budget.
Published market anchors, in USD, because most vendors price that way:
Huntress publishes Managed EDR at around $7.99 per endpoint per month at 100 endpoints.
Red Canary's AWS Marketplace listing works out to roughly $10 per endpoint per month, excluding user accounts, cloud resources and network units.
CrowdStrike publishes self-service bundles from $7.99 to $19.99 per device per month; Falcon Complete is quote-only.
Arctic Wolf, Sophos MDR, SentinelOne's managed service and Expel do not publish per-endpoint rates.
Third-party working estimates put total annual MDR spend at roughly $42,000 to $150,000 for 500 endpoints, and $96,000 to $300,000 for 1,000 — ranges, not list prices, driven mostly by response SLA and how many data sources are monitored.
Indian pricing typically lands below global list because delivery is local, but the spread is wide and depends on log volume more than endpoint count. Treat any figure as a range to confirm.
Budget four components, not one:
Platform licensing — per endpoint, per user, or both.
Log retention — to 180 days for CERT-In, and a year for DPDP Rule 6. Frequently 20–40% on top of the licence and frequently absent from the first quote.
The managed service — monitoring, investigation, response and reporting.
Onboarding and tuning — the first 90 days, where the value is realised or lost.
The comparison that matters is not MDR against a licence. It is MDR against the in-house alternative. A 24×7 SOC staffed in India runs to approximately ₹1.5 crore a year and upward once you account for three shifts, tooling, and the attrition rate on trained analysts. That figure is an approximation and varies widely with scope, but it is the right denominator.
Model your own numbers with our cost calculator before you take a sales call. NetNXT publishes indicative ranges; treat the output as a range to confirm, never a fixed quote.
Twelve questions to ask an MDR provider before you sign
Use these in the shortlist meeting. Weak providers fail the same ones.
On response
List the specific containment actions you can take on our environment without our approval.
What is your response SLA for a critical incident, from detection to containment, and what is the remedy if you miss it?
Who makes the isolation decision at 3 a.m., and what are their credentials?
On coverage
Which of our SaaS platforms can you monitor, and what does that coverage actually see?
Do you consume our identity provider's sign-in logs?
Are investigations capped by volume, hours, or incident count in the contract?
On compliance
Are you contractually accountable for supporting CERT-In filing within six hours, or only available to assist?
Where are our logs stored, and for how long, at the price quoted?
What changes when DPDP Rule 6 commences?
On the relationship
Who operates the platform day to day — your team, or a subcontractor?
Show us a redacted incident report and a redacted monthly report.
What does your onboarding commit to at days 30, 60 and 90?
Ask us the same twelve. If our answers are weaker than someone else's for your situation, that is worth knowing before you sign, not after.
What are the most common MDR mistakes?
Buying detection and assuming response- The single most expensive misunderstanding in this market. Covered above, and worth re-reading the contract for.
Leaving identity out of scope- Most modern intrusions use valid credentials rather than malware. Endpoint-only monitoring misses them by design.
Forgetting cloud and SaaS logs- Entra ID, Microsoft 365, AWS and Google Workspace hold the evidence. If they are not connected, the investigation has a hole in it.
Requiring manual approval for every action- A response capability that needs a human to approve each step is a response capability with your business hours attached.
Pricing the licence and ignoring retention- The regulator asks for 180 days of logs. Find out what that costs before signing, not at the audit.
Treating onboarding as installation- Value arrives at tuning, not deployment. Budget the 90 days.
When should you not buy MDR?
Honest answer, because it will save some readers money.
If you already run a mature 24×7 internal SOC with skilled analysts across three shifts, and your problem is tooling rather than coverage, buy the platform and run it yourself. A managed wrapper adds cost without adding capability you lack.
If you are a single-site organisation under 50 users with three internal applications, fix the fundamentals first — MFA everywhere, patch discipline, backups you have tested. Those cost less and close more risk than a monitoring contract.
And if your leadership will not grant containment authority to an external team, MDR will underdeliver whoever you buy it from. Resolve that question internally before you go to market, because it decides what you are actually able to buy.
MDR earns its cost when you have real telemetry, a regulatory clock, and no realistic path to staffing 24×7 yourself. That describes most fast-scaling and multi-site Indian enterprises.
What proof should you ask for?
Ask for outcomes at organisations shaped like yours, not logos on a slide.
NetNXT has run programmes of this kind end to end: a Cato SASE and Zero Trust rollout across 22 Shahi Exports locations, and an identity infrastructure rebuild for Arya.ag ahead of its IPO-readiness work. Both are documented in our case studies.
Then ask any provider, including us, for a redacted incident report from the last six months. How an incident is written up tells you more about a SOC than any capability matrix.
Want to know where your detection gaps actually are? Request a 24×7 SOC and MDR readiness assessment — we will map your after-hours exposure, telemetry coverage and CERT-In readiness against your real environment, and tell you plainly if you do not need us.
FAQs
1) What is the difference between MDR and a SOC?
A SOC is the capability — people, process and technology performing detection and response. MDR is one way to obtain it, delivered remotely by an external provider who brings the stack and the analysts. You can have a SOC without MDR by building it in-house, and MDR gives you SOC outcomes without three shifts of hiring.
2) Does MDR include actual response, or just alerts?
It depends entirely on the contract, which is why it is the first thing to check. Some providers notify only, some guide your team, and some take containment action directly on your environment under pre-agreed authority. Ask for the specific list of actions the provider can take without calling you first.
3) How much does MDR cost in India?
Published global rates run from roughly $8 to $20 per endpoint per month, with most enterprise services quote-only. Total annual spend commonly lands between $42,000 and $150,000 for 500 endpoints as a third-party estimate. Indian delivery is typically below global list. Budget licensing, log retention, the managed service and onboarding separately, and compare against roughly ₹1.5 crore a year and upward for an in-house 24×7 SOC.
4) Does MDR help with CERT-In compliance?
It is close to a prerequisite. CERT-In requires reporting within six hours of noticing an incident, which is not achievable with business-hours monitoring. Confirm your provider is contractually accountable for detection and for supporting the filing, and that log retention covers 180 days within Indian jurisdiction at the quoted price.
5) How long does MDR onboarding take?
Roughly 90 days to full value: telemetry and baseline in the first 30, tuning and threat hunting by 60, automation and tested response by 90. Agent deployment is faster, but agents are not the service. Ask for deliverables committed at each of those three milestones in the contract.
