Managed EDR · MDR · XDR · SIEM

Antivirus is not enough. Your business needs MDR.

Modern attackers do not trip alarms. They log in with stolen credentials, use the tools already on your network, and reach ransom in under 24 hours. Traditional antivirus does not see any of it.

Managed detection and response is the core of our business cybersecurity model, and our cyber-first engineering approach. 24/7 SOC, human threat hunters, and rapid response across endpoints, Microsoft 365, identity and cloud. We do not just sell you a licence, we operate the security.

24/7 Human SOC
ACSC Network Partner
Huntress · CrowdStrike · Defender
Essential Eight aligned
Last updated:
Reviewed by Blake Bath, General Manager

The 2026 picture

< 24 hrs

average time from initial access to ransomware deployment in 2025. Huntress 2026 Threat Report

83%

of email threats now carry credential-harvesting phishing. Acronis, H1 2025

$2M

average global ransom payment in 2025. Recovery costs are typically much higher. Acronis

Plain English

EDR, MDR, XDR, SIEM. What do they actually mean?

Every cybersecurity vendor uses these acronyms differently. Here is what they actually are, in the order they build on each other, and where each one fits in a real Australian SMB environment.

AV

Traditional Antivirus

What it is

Signature-based software that compares files on a device against a list of known malware.

Catches

Known viruses and well-documented malware.

Misses

Anything new, fileless, identity-based, or that uses legitimate tools. About 70% of modern attacks.

Verdict: Necessary baseline, not sufficient on its own.

EDR

Endpoint Detection & Response

What it is

Software on every laptop, desktop and server that watches behaviour: what processes run, what files change, what network connections open.

Catches

Suspicious behaviour, ransomware patterns, fileless attacks, living-off-the-land techniques and zero-day exploits.

Misses

Without people watching the alerts, EDR is just a noisy dashboard. It still needs a human to interpret and respond.

Verdict: The technology layer. Required, but not a complete service.

MDR

Managed Detection & Response

What it is

EDR plus a 24/7 security operations centre (SOC) of human analysts who watch, triage, hunt and respond on your behalf.

Catches

Everything EDR catches, plus the slow-burn intrusions and quiet attacker behaviour that automated rules miss.

Misses

Visibility outside the endpoint, like email and identity, unless extended with XDR or ITDR.

Verdict: The full service. What an SMB actually needs.

XDR

Extended Detection & Response

What it is

MDR extended beyond endpoints to also cover email, Microsoft 365 identity, cloud workloads and network. Signals are correlated into one incident view.

Catches

Multi-stage attacks that cross from phishing email to identity to endpoint to cloud, which is how most modern breaches actually unfold.

Misses

Nothing significant when implemented properly. Adds cost and complexity if you do not have multiple surfaces to protect.

Verdict: The modern standard for any business on Microsoft 365 or with cloud infrastructure.

SIEM

Security Information & Event Management

What it is

A central log collection and correlation platform. Every security event from endpoints, firewalls, Microsoft 365 and cloud feeds into one place for analysis and retention.

Catches

Patterns across systems, compliance evidence, forensic timelines after an incident, and the audit trail your insurer and auditor want.

Misses

Traditional SIEM is heavy and needs tuning. Modern SMB-focused SIEM (like Huntress) hides that complexity.

Verdict: The evidence and correlation layer. Critical for Essential Eight and cyber insurance.

Anatomy of an MDR service

What you actually get with managed detection and response.

A licence is not a service. MDR is the combination of the right technology, a 24/7 human team, and a documented response process. Here is exactly what is included when Real Bytes runs your MDR.

24 / 7 / 365

Continuous monitoring

Every endpoint, every server, every Microsoft 365 mailbox and identity is watched in real time. No business hours gap, no weekend blind spot.

Tier 1 to Tier 3 analysts

Human SOC analysts

Real people, not just dashboards. A dedicated security operations centre triages every alert and decides what is real before it lands on your desk.

Minutes, not hours

Active response

When a confirmed threat appears, we contain it. Isolate the device, kill the session, revoke the token, lock the account. Stop the bleeding first, investigate after.

Weekly hunts

Proactive threat hunting

Analysts go looking for adversary behaviour that automated rules miss. Persistence mechanisms, credential harvesting, dormant beacons and supply chain abuse.

On-call IR team

Incident response

If something gets through, we lead the response. Forensics, root cause analysis, eradication, recovery and communication with your insurer and regulators.

Audit-ready logs

Reporting and evidence

Monthly security reports, quarterly business reviews, and audit-ready evidence for Essential Eight, SMB1001, ISO 27001 and your cyber insurance renewal.

And every month, we also

Translate the latest threat intelligence into your environment.

MDR is not a set-and-forget service. The attacker playbook shifts every quarter, so the detections, baselines, training and procedures shift with it.

Tune detections to the current playbook

ITDR rules and Microsoft 365 alert policies reviewed against the latest threat reports. AiTM, malicious OAuth and inbox rule abuse get priority.

Harden the identity baseline

Conditional Access, named admin accounts, token protection and phishing-resistant MFA. Configuration drift caught and corrected.

Train staff on lures that actually work

Security awareness training and simulated phishing focused on e-signature, voicemail and invoice lures, not generic content.

Document a payment verification process

Out-of-band verification for new bank details and dual approval thresholds. The procedural control that consistently breaks the BEC chain.

Build or buy

Why MDR beats running it yourself.

Running an in-house SOC is realistic for a bank or a federal agency. For a 20 to 200 person Australian business, the maths does not work. MDR delivers the same outcome at a fraction of the cost.

Dimension

DIY or EDR-only

Managed MDR

Coverage hours

Business hours, gaps overnight and on weekends

24 / 7 / 365 including public holidays

Detection capability

Whatever the EDR console surfaces, often missed in the noise

Triaged by analysts, correlated with threat intelligence

Response time

Hours to days, depending on staff availability

Minutes for containment, hours for full investigation

Cost of a real SOC

3 to 5 FTE analysts, around $500k to $900k per year fully loaded

From around $25 per endpoint per month

Skills and retention

Hard to hire, hard to retain, single-person dependency risk

Backed by a vendor SOC with hundreds of analysts

Threat intelligence

Generic feeds, manual research

Curated intelligence from millions of monitored endpoints globally

Ransomware reporting readiness

You find out about the 72-hour rule during the incident

Reporting obligations built into the incident response playbook

Cyber insurance answers

Difficult to evidence at renewal

Documented controls and 24/7 monitoring directly addresses insurer questions

Cost estimates based on Australian average salaries for security analysts (PayScale, Hays) and Real Bytes managed service pricing. Specific costs vary by environment.

The Abuse Of Trust

Modern attacks follow a predictable pattern.

The 2026 ConnectWise Cyber Research Unit threat report, drawn from real incident response cases, says it plainly: cybercriminals are no longer breaking in. They are logging in, then exploiting normal business activity to avoid detection. Most successful intrusions follow these four steps.

1

Log in, not break in

Attackers buy or phish valid credentials. They arrive as a trusted user, not a hacker punching through a firewall.

2

Move with trusted tools

PowerShell, RMM, RDP and VPN. Living off the land means no signature for traditional antivirus to catch.

3

Disable your recovery

Backups, EDR agents and monitoring tools are targeted first so you cannot restore or detect the rest of the attack.

4

Steal data and encrypt

Data exfiltration first, then ransomware. Often within hours of the first login, well inside any business-hours response window.

Source: ConnectWise Cyber Research Unit, 2026 MSP Threat Report. Compiled from real-world incident response investigations and customer telemetry.

Ransomware timing

You have hours, not days

Ransomware is no longer a slow-burn intrusion. The Huntress 2026 Cyber Threat Report found average time to ransom dropped to under a day in 2025, with the fastest crews under 10 hours. That makes 24/7 monitoring and rapid containment the difference between a contained incident and a business-stopping event.

20 hrs

Average time to ransom in 2025 (up from 17 hrs in 2024)

< 10 hrs

Fastest crews (RansomHub, INC/Lynx, Akira) reach ransom

6 hrs

Average time from data exfiltration to encryption

51%

Of 2025 incidents linked to just 4 groups: Akira, RansomHub, Qilin, Medusa

Pre-ransom signals

Identity threats often show up first

Day -14

Suspicious identity activity often visible

Day -7

Shady logins typically spotted before ransomware deploys

Day -0

Day ransom note appears, encryption complete

Identity

Shady logins, OAuth abuse and AiTM token theft are the early warning we instrument with Huntress ITDR.

Endpoint

Living-off-the-land binaries, ProcessHacker, AnyDesk and abnormal admin tool use trigger SOC review.

Containment

Confirmed compromise gets the host isolated, the account session revoked and your incident playbook activated.

Sources: Huntress 2026 Cyber Threat Report, ACSC Annual Cyber Threat Report. Aligned to the ACSC Essential Eight and the OAIC Notifiable Data Breaches scheme for response obligations.

The Real Business Impact

Cyber incidents are not IT problems. They are business crises.

Operational downtime, lost revenue, customer trust damage, regulatory exposure under the Privacy Act, and recovery costs that routinely exceed the original ransom. The financial maths is stark: prevention costs a fraction of recovery.

$56,600

average cost of a cybercrime incident for a small Australian business, up 14% year on year.

ASD Annual Cyber Threat Report 2024 to 2025

78%

of SMBs fear a serious cyberattack could put them out of business.

ConnectWise State of SMB Cybersecurity, 2025

58%

of SMBs spent more on cybersecurity in 2024 than planned, most of it reactive, not preventive.

ConnectWise SMB Cybersecurity Trends, 2025

$2M

surge in average ransom payment, with ransomware victims globally up 500%.

Acronis Cyberthreats Report H1 2025

Australian regulatory context

What Australian law now expects when you are attacked

Global threat stats explain the attacker. These are the Australian obligations that apply to you, the defender, and they are built into how we run incident response.

The local cost of getting it wrong keeps rising

The ASD puts the average cybercrime cost at $56,600 per incident for small businesses (up 14%) and $97,200 for medium businesses (up 55%), against more than 84,700 cybercrime reports in a single year. Roughly one every six minutes.

Source: ASD Annual Cyber Threat Report 2024 to 2025

Ransomware payments must be reported within 72 hours

Under the Cyber Security Act 2024, businesses with annual turnover above $3 million must report any ransomware or extortion payment to the government within 72 hours. The education-only grace period ended on 1 January 2026 and enforcement is active. Our incident response playbooks include this clock from minute one.

Data breaches likely mean the OAIC

A breach exposing personal information that risks serious harm triggers the Notifiable Data Breaches scheme. In the OAIC's latest reporting period there were 532 notifications, with human error's share rising from 29% to 37%. Containment speed directly shapes whether an incident crosses the notification threshold.

The Essential Eight is the benchmark everyone measures against

Insurers, auditors, tenders and now the AI standards all reference ACSC controls. Every MDR deployment we run maps to Essential Eight evidence, so monitoring pays off at renewal and audit time, not just during incidents.

Even your office hardware is regulated now

Since 4 March 2026, smart devices supplied in Australia must meet mandatory security standards for default passwords and update policies. Connected cameras, sensors and door controllers are part of your attack surface and we include them in scope.

General practitioner summary, not legal advice. Sector obligations (SOCI Act, APRA CPS 234 and CPS 230) may add further requirements. Confirm scope with your legal counsel before rollout.

What the 2026 breach data shows

The numbers behind why MDR exists

The Verizon 2026 DBIR makes the case for managed detection in three figures: vulnerability exploitation is now the top way in, edge-device CVEs reach mass exploitation in zero days, and the human element is still involved in most breaches. None of these are caught by antivirus alone. They are exactly what a 24/7 SOC is built to see and stop.

Read the Verizon 2026 DBIR

Top vector

Vulnerability exploitation now the leading initial access vector for breaches

Overtook stolen credentials in 2026. The patch backlog has become the front door.

0 days

0 days median time from edge-device CVE disclosure to mass exploitation

Firewalls, VPN gateways and remote-access appliances are now hit at internet speed.

62%

62% of breaches still involved a human element across all sectors

Identity, awareness and process discipline remain the controllable variables.

16%

16% of breaches started with social engineering, with voice and mobile pretexting on the rise

Voice phishing inside the workday is now common enough to warrant its own playbook.

Source: Verizon 2026 Data Breach Investigations Report. Dataset window Oct 2024 to Nov 2025. 31,000+ incidents and 22,000+ confirmed breaches across 145 countries.

Tools + Operations

Software alone is not security.

EDR, email security, identity protection and vulnerability scanners are capable, but they do not make decisions. Strong cybersecurity needs both: capable tools and an active security operation that triages alerts, hunts for threats, and runs the response when it matters.

Security tools

EDR, email security, vulnerability scanning, identity protection

Strengths

  • Catches known threats on devices in real time
  • Automates blocking before damage can spread
  • Builds an activity trail for later investigation

Limits on their own

  • Cannot connect endpoint activity to identity, email or cloud
  • Automated responses can disrupt legitimate work if untuned
  • Tools alone do not triage, hunt, or remediate

Security operations

24/7 SOC, threat hunting, MDR, incident response

Strengths

  • Triages and prioritises alerts so nothing critical gets missed
  • Continuously tunes detection rules to reduce noise
  • Investigates and responds to threats tools flag but cannot resolve

Limits on their own

  • Only as effective as the tools and integrations feeding it
  • Building and staffing an internal SOC is expensive and slow
  • Without clear playbooks, response can stall under pressure

Real Bytes runs the operation around the tools. Huntress, CrowdStrike, SentinelOne, Microsoft Defender and ThreatLocker do the detection. Our team and the Huntress SOC handle triage, hunting, response and reporting, so a tool alert turns into a contained incident, not a missed one.

Identity Threat Detection & Response

Identity is the new endpoint

Most attacks now start with stolen credentials and session tokens, not malware on a laptop. Real Bytes deploys Huntress Managed ITDR across Microsoft 365 and Google Workspace to spot identity attacks the moment they happen, then shut them down before money or data leaves.

Location & VPN anomalies

Flag unusual login locations, impossible travel and known malicious VPN providers so only the right people get in.

Malicious inbox & forwarding rules

Detect rules that hide attacker emails, auto-forward invoices or quietly delete payment notifications, the classic BEC moves.

Session hijacking

Catch stolen session tokens being replayed from a different device or country, the way attackers bypass MFA in 2025.

Credential theft

Monitor for credential-stealing malware, AiTM phishing kits and password spray patterns against Microsoft 365 and Google Workspace.

Rogue OAuth apps

Find and remove unauthorised OAuth applications and shadow workflows installed by attackers to keep persistent access.

Mass outbound phishing

Stop compromised mailboxes being used to phish your customers and contacts, and clean up the resulting mess fast.

Huntress reports the following from their Managed ITDR platform across more than 10 million identities they protect globally. Numbers are vendor-published, not Real Bytes claims. Source: Huntress Managed ITDR datasheet and the 2026 Cyber Threat Report.

10M+

Identities monitored by Huntress globally

37%

Of 2025 ITDR incidents were suspicious logins

19%

Of 2025 incidents involved mailbox manipulation

67%

Increase in identity threats vs 3 years ago (Huntress)

Client handout

The first 60 minutes of a cyber incident

What to do the moment you suspect a compromise. Print this, put it where people can find it when screens are locked.

Print-friendly timeline

1

Minute 0 to 10

Do not destroy evidence, do cut access

Disconnect affected machines from the network (pull the cable, kill the wi-fi). Do not wipe, reboot or "clean" anything. Forensics needs it intact. Do not pay anything, promise anything or reply to any demand.

2

Minute 10 to 20

Call for help, off the compromised systems

Call your MDR provider or IT partner by phone. If email or Teams might be compromised, assume the attacker is reading them. Real Bytes clients: 07 3114 2808, any hour.

3

Minute 20 to 40

Contain the identity layer

Reset passwords and revoke active sessions for affected accounts, starting with admin accounts. Check for new inbox rules, forwarding rules and unfamiliar OAuth apps. Freeze any payments queued for release, and verify no bank details were changed recently.

4

Minute 40 to 60

Start the record

Write down what was seen, when, by whom, on which systems. Note the exact time of first detection. The regulatory clocks (72 hours for any ransom payment, 30 days for OAIC breach assessment) run from what you knew and when. Notify your insurer's cyber hotline, as late notification can affect coverage.

Then: Hand over to the professionals. A proper response covers forensics, eradication, recovery, and your regulator and insurer communications. That is what an incident retainer or MDR agreement exists for.

Real Bytes clients: 07 3114 2808, any hour.
Vendor partners

Business cybersecurity built on proven platforms, matched to your environment.

We are vendor-neutral. Good business cybersecurity starts with the right platform for your environment, not the one with the biggest margin. The right MDR or EDR platform depends on your environment, headcount, compliance obligations, and budget. Every platform below is one we actively deploy and manage in Australian businesses.

MDR · ITDR · SIEM

Huntress MDR

Primary Platform

Our primary MDR platform. Combines automated threat hunting with a 24/7 human SOC that reviews every alert. Used by 100,000+ SMBs globally. Includes ITDR, SIEM and security awareness training in one platform.

EDR · XDR

CrowdStrike Falcon

Enterprise Tier

Enterprise-grade EDR and XDR for larger organisations and regulated industries. AI-powered detection, adversary intelligence and a cloud-native architecture at scale.

EDR · XDR

SentinelOne Singularity

Autonomous AI

Autonomous AI-driven EDR with patented rollback that can reverse damage from ransomware without relying on backups. Strong fit for high-availability environments.

XDR · Email · Identity

Microsoft Defender XDR

M365 Integrated

For Microsoft 365 environments, Defender XDR unifies email, endpoint, identity and cloud app protection into a single correlated detection platform. Included with M365 Business Premium and managed by Real Bytes.

EDR · MDR

Sophos Intercept X

Deep Learning

Deep learning endpoint protection with anti-ransomware and exploit prevention. Sophos MDR adds a fully managed option backed by their own threat response team. Strong fit for mid-market and healthcare.

Zero Trust · Allowlisting

ThreatLocker

Zero Trust Layer

Default-deny application control that stops unauthorised software from executing at all. Neutralises ransomware and malware at the point of execution, before detection even needs to occur.

FAQs

The questions we get asked the most.

Board briefing

Cyber security: a one-page brief for Australian directors

Forward this to your board. Print it, attach it to a board paper, or use it to frame the conversation at your next risk committee meeting.

Printable one-pager

The situation

The ASD received over 84,700 cybercrime reports last year. Average incident cost: $56,600 for a small business, $97,200 for a medium one, both rising. Attackers now reach ransomware deployment in around 20 hours from first access, and they increasingly log in with stolen credentials rather than breaking in. In 2026 the victims have included an accounting firm, a home builder and a food processor, not just airlines and universities.

Why this is a board matter

Directors carry the risk on three fronts. Legal: ransom payments must be reported within 72 hours (enforced since January 2026), and breaches of personal information engage the OAIC. Financial: recovery costs routinely exceed any ransom, and insurers now decline claims where basic controls were missing. Operational: manufacturers and processors have been stopped mid-production this year. This is a continuity risk, not an IT line item.

The questions to ask management

  • 1.If an attacker logged in with a stolen password at 2am Saturday, who would notice, and when?
  • 2.Are our backups immutable, off-tenant, and when did we last actually restore from them?
  • 3.Is MFA enforced on every mailbox and remote access point, with no exceptions for executives?
  • 4.Do we have an incident plan that covers the 72-hour ransomware reporting clock and OAIC notification?
  • 5.What would our cyber insurer say about our controls at next renewal?

What good looks like

Essential Eight Maturity Level 1 or better, evidenced. 24/7 monitored detection and response across endpoints and identity. Immutable, tested backups. A one-page incident plan people have rehearsed. Evidence for all of it, ready for insurer and auditor.

The ask

A 30-minute security assessment maps current exposure and produces a prioritised remediation order. It is free, and the findings are yours either way.

Real Bytes · Brisbane · realbytes.au · 07 3114 2808. General practitioner summary, not legal advice.

Next step

Stop ransomware before it starts.

Attackers are already inside networks like yours, moving quietly and escalating privileges. A free 30-minute security assessment maps your real exposure, recommends a best-fit MDR platform, and gives you a clear remediation order. No obligation.

Brisbane based. Australian engineers. No obligation. Also delivering managed IT services Hobart and across Tasmania.

Cookie Preferences

We use cookies to improve your experience, analyse site traffic, and personalise content. By clicking "Accept All", you consent to our use of cookies. Privacy Policy

Privacy Act 1988 compliant. Your data is never sold.