Detection: MDR and EDR

Your operation runs no detection for attacks yet. We select, set up and roll out. After that your operation sees an attack while it is happening.

We select managed detection and response (MDR) and EDR, and get them running across your estate. Ongoing operation then belongs to the provider that fits your estate. We do not run it.

You then learn about an attack from your own operation, not from a customer and not from the press. Seeing, not intervening: containment is the operator's job. Cleaning up is the job of the incident response provider in your cyber insurance policy. We neither broker them nor provide them.

What you get

  • The selection: which provider fits your estate, and why.
  • The setup of managed detection, until it runs in production.
  • EDR rollout across the estate, not only individual systems.
  • The provider's entry in your register of information, with the details DORA requires for that register.

No framework agreement, no automatic renewal. We earn nothing on the selection: no commission from the provider we recommend.

The boundary between us and operations

controlpunkt

Selection and rollout

We select the right detection, set it up, and roll it out across your estate.

The operator

Operations, detect and contain

Ongoing operation then belongs to the selected provider: detect, contain an attack.

Outside: no one, not even by referral

What we structurally do not do ourselves: no forensics, no evidence handling, no incident response retainer, not even by referral. We promise no response time of our own beyond what the partner operates, and we run no SOC of our own.

Second opinion

Do you already have detection running, and you do not know if it really covers you? That is what the second opinion checks, independent, because we earn nothing on the operation.

Case

A case

A fintech started with an assessment.

  • Out of it: managed detection, EDR across the estate, ISMS consulting, and a penetration test at the end.

Intro call

hello@controlpunkt.com

We reply within one business day.

What to put in the first email

  • Who you are and your company.
  • What it is about: the trigger, the real problem. A sentence or two is enough.
  • If a customer, an investor or a regulator has set a deadline: add the date.
  • After an incident: where the forensics stand.