Managed Detection and Response (MDR)

Continuously monitor your IT environment and detect threats before they become incidents.

Powered by Field Effect and backed by 24/7 monitoring, our service turns security signals into clear, prioritized alerts with actionable remediation guidance.

LEARN MORE

Faster Threat Detection and Response

A Few Milliseconds

to block certain malicious activities directly on an endpoint*

18 Seconds

median time to detect an endpoint threat and publish an alert*

2.6 Minutes

median investigation time when expert analysis is required*
*Operational results published by Field Effect in 2026. These figures are not service-level commitments and may vary depending on the nature of the event and the monitored environment.

A simple explanation, without the jargon

Managed detection and response, commonly known by the acronym MDR, is a fully managed cybersecurity service.

It combines continuous monitoring and protection technology with a specialized security operations team. Signals from multiple layers of your environment are analyzed, correlated and prioritized to identify the risks that genuinely require your attention.

An MDR service therefore does more than provide a console or a list of alerts. It helps you understand what is happening, determine what must be addressed first and respond according to predefined rules. It is also referred to as a managed SOC.

What Is Managed
Detection and Response?

MDR vs. EDR: What Is the Difference?

An EDR (endpoint detection and response) is primarily a detection and response technology designed to protect endpoints and servers.

An MDR service may incorporate EDR capabilities, but it goes further:

  • it monitors multiple layers of the environment, not just endpoints;
  • it correlates events from the network, cloud, identities and other sources;
  • it provides continuous monitoring;
  • it reduces noise and prioritizes alerts;
  • it adds the intervention of a security operations centre;
  • it provides remediation guidance and controlled response capabilities.

The difference therefore lies not only in the technology itself, but in the ability to operate it continuously and turn detections into operational decisions.

THE SERVICE ENABLES YOU TO:

See

A unified view of activity across endpoints, networks, cloud services, identities, external exposures and artificial intelligence, depending on the selected plan.

Understand

Analyzed and correlated events that distinguish genuinely concerning activity from normal background noise in your environment.

Act

Prioritized alerts, relevant context, remediation instructions and response capabilities suited to the nature of the threat.

Stay in Control

Response policies defined with you to balance risk reduction, operational continuity and tolerance for disruption.
Field Effect groups relevant events into alerts known as AROs — Actions, Recommendations and Observations. Each ARO provides a priority level, context and next steps, rather than leaving your team to interpret isolated technical alerts on its own.

WHY DOES YOUR ORGANIZATION NEED
AN MDR SERVICE?

Three converging factors make continuous monitoring essential for small and medium-sized businesses, municipalities and non-profits: an attack surface expanding faster than internal teams can keep up with, increasingly stringent regulatory and contractual requirements, and an in-house SOC that remains beyond the budget of most organizations.

1. The attack surface is expanding faster than internal teams can keep up

Remote work, cloud services, SaaS applications, mobile devices, external vendors and digital identities are multiplying potential entry points.

A real-world attack rarely remains confined to a single layer. A compromised account can lead to an unusual login, a privilege change, a data transfer and then lateral movement across endpoints or the network.

Without unified visibility, these signals remain scattered across multiple tools and may go unnoticed until an incident disrupts operations.

2. Regulatory and contractual expectations are increasing

Organizations must be able to protect the information they hold and respond appropriately when an incident occurs.

In Québec, a confidentiality incident may require an organization to take reasonable measures to reduce the risk of harm and, when it presents a risk of serious injury, to notify the Commission d’accès à l’information and the individuals concerned.

MDR can help your organization detect events earlier, document them and support decision-making. However, it does not make an organization compliant on its own and does not replace a comprehensive governance, privacy protection or incident management program.

3. Attacks do not follow business hours

A weak signal left unaddressed overnight or over the weekend can become a significant disruption before your team returns.

Continuous monitoring reduces the time between the first signs of an attack, understanding what is happening and implementing an appropriate response.

4. Internal resources are already under significant pressure

Alert triage, threat hunting and the analysis of suspicious activity require specialized expertise and continuous availability.

Building and maintaining an in-house SOC means recruiting, training and retaining multiple specialists capable of providing 24/7 coverage. MDR provides access to this shared capability without shifting the entire burden onto your internal IT team.

Field Effect makes its platform available through reseller partners. Commissionnaires du Québec acts as your point of contact to make the solution accessible to your organization, define the appropriate scope and support its integration into your operations.

Our role goes beyond providing access to a licence. We connect continuous monitoring to your critical assets, response policies, responsibilities and the other capabilities required to reduce your risk over the long term.

OUR OFFERING: FIELD EFFECT MDR, INTEGRATED INTO YOUR OPERATIONAL REALITY

What Field Effect MDR
does for you

The platform brings prevention, detection, analysis and response capabilities together in a single environment:

  • continuous monitoring by a 24/7 SOC;
  • protection for compatible endpoints and servers;
  • network and cloud service monitoring, depending on the selected plan;
    detection of abnormal behaviour and indicators of compromise;
  • blocking or containment of certain malicious activities;
    proactive threat hunting;
  • identification of vulnerabilities, misconfigurations and exposures;
  • prioritized alerts with clear guidance;
  • reporting to track risks and corrective actions.

WHAT COMMISSIONNAIRES DU QUÉBEC
BRINGS TO THE PLATFORM

Beyond access to the platform, our value lies in combining MDR with the other cybersecurity services we deliver directly. This is how a coherent cybersecurity program is built—not by stacking disconnected tools.

1. Local access and support

Field Effect is available through reseller partners. Commissionnaires du Québec provides access to the solution and remains your point of contact throughout the deployment.

We help you select the plan, scope and response policies best suited to your organization.

2. Risk-based scoping

Before deployment, we identify your critical assets, operational constraints and security priorities.

Our security posture assessment helps focus MDR coverage on the gaps and blind spots that genuinely increase your exposure.

3. Escalation support for major incidents

MDR detects and contains certain threats and guides remediation. However, a serious incident may require a more in-depth investigation.

Our incident response service and our expertise in digital forensics can then take over as part of a separate service.

4. Long-term risk reduction

Technology alone is not enough. Human error, risky behaviour and changes in your environment must also be addressed.

Our training and awareness activities, combined with periodic reviews of your coverage, complement MDR over the long term.

WHAT THE SERVICE COVERS

The exact scope is defined with you during the scoping process. Available components and levels of coverage vary depending on the selected plan.

1. Compatible Endpoints and Servers

An agent installed on compatible Windows, macOS and Linux systems can:
  • monitor processes, files, registry activity and endpoint network activity;
  • detect abnormal or malicious behaviour;
  • block certain malware and ransomware execution attempts;
  • identify vulnerable software or systems;
  • remotely contain or isolate a device when permitted by the response policy.

2. Network

Depending on the selected plan, a network sensor can monitor inbound and outbound communications to detect:
  • command-and-control communications;
  • connections to malicious destinations;
  • abnormal data transfers; unmanaged devices, services or applications;
  • Shadow IT;
  • certain network vulnerabilities and misconfigurations.

3. Cloud Services and Identities

Field Effect MDR can monitor Microsoft 365, Google Workspace and various supported cloud and SaaS integrations. Monitoring can identify:
  • signs of account compromise;
  • impossible travel or suspicious login activity;
  • suspicious inbox rules;
  • abnormal privilege changes;
  • unusual downloads or data transfers;
  • activity that may indicate data exfiltration.
The list of available integrations must be confirmed during the scoping process.

4. External Risk and the Dark Web

Field Effect monitors sources where credentials, personal information, financial data or other information associated with your organization may be circulated.

This monitoring can identify certain external exposures before they are used to compromise accounts or prepare an attack.

Monitoring frequency and available capabilities depend on the selected plan.

5. Vulnerabilities and Exposures

The service is not limited to attacks already in progress. It can also identify conditions that increase the likelihood of an incident:
  • unpatched or end-of-life software; unnecessarily exposed services;
  • high-risk protocols or configurations; vulnerable browsers;
  • unmanaged applications and devices; compromised credentials;
  • misconfigurations observed within the environment.
Findings are prioritized so that your team can focus its efforts on the weaknesses that genuinely increase risk.

6. Additional Components

Depending on the selected plan and options, the service may also include:
  • a DNS firewall capable of blocking malicious destinations;
  • DNS protection for devices used outside the organization’s network;
  • a suspicious email analysis service;
  • advanced reporting on risks, trends and coverage;
  • extended log retention options;
  • integrations with selected management and cybersecurity tools.

Artificial Intelligence,
Now Under Surveillance (AIDR)

The adoption of artificial intelligence tools often moves faster than internal policies.

The AIDR (AI detection and response) capability extends Field Effect MDR visibility to the AI tools used within your environment. It is integrated into the platform and available depending on the selected plan.

1. Visibility Into AI Usage

Identify approved, unauthorized or unknown AI tools, the people using them and the connections associated with that use.

2. Understand the Risks Introduced

Gain better visibility into the data and systems AI tools connect to, as well as the behaviours that could increase your exposure.

3. Monitor Compliance With Your Policies

Compare observed usage with the rules established by your organization and identify the adoption of unsanctioned tools.

4. Govern Adoption Without Blocking Innovation

Enable use cases that support productivity and apply controls to tools or behaviours that do not comply with your policies.

1. Understand: We define your environment, critical assets, constraints and security priorities.

2. Configure: We deploy the selected components, connect the relevant sources and establish your response policies.

3. Monitor and Respond: Field Effect analyzes signals 24/7, prioritizes threats and takes action according to the agreed rules.

4. Improve: We adjust coverage and policies based on observed trends and changes within your organization.

Our Process, From Scoping
to Full Operation

Submit a Request

Trust Commissionnaires du Québec and Field Effect for 24/7 monitoring. Contact us to discuss your MDR project.

    Scroll to Top