Home ServicesMicrosoft 365 Health CheckSecurity AssessmentManaged Cloud (Azure)Managed Modern WorkplaceManaged Detection & ResponseCISO as a ServiceCTO as a Service Pricing About News Contact Straight answers Book 20 minutes
Home/News/SOC, SIEM and MDR in plain language. What does your organisation really need?
Insights · 01-10-2026

SOC, SIEM and MDR in plain language. What does your organisation really need?

Security specialist with a headset behind three screens with dashboards

Anyone looking into the security of their organisation soon faces a row of abbreviations: EDR, XDR, SIEM, SOC, MDR. Providers use them interchangeably, which makes comparing hard. This article explains what they mean, what Microsoft already does for you and where you need a specialist.

Four terms, one building

Compare digital security with securing your building. Sensors and an alarm report that something is happening. Cameras record what happened. In a control room people judge whether it is real. And a guard takes action.

EDR / XDR

The sensors and the alarm

Microsoft Defender on every device, mailbox and account spots suspicious behaviour.

Part of your Microsoft licence, complete with the Defender Suite.
SIEM

All camera footage in one place

Collects and links logs from every source, so patterns become visible and you can look back.

Only needed with many sources outside Microsoft.
SOC

The control room with people

Specialists who assess the alerts: a real incident or a false alarm, and what is the impact?

A function, not a product.
MDR

The guard who steps in

Not just raising the alarm but acting at once: blocking the account, isolating the laptop, revoking sessions.

Control room and guard in one service.

Incident response is the fire brigade and the investigation afterwards, for a major attack.

The key insight: a SOC is a function, not a product. It is people and agreements that assess and follow up alerts. A SIEM is one of the tools such a control room can use, but not the only one. For most organisations running on Microsoft 365, a SIEM is not needed at the start.

Why one attack story says more than four alerts

An attack rarely consists of a single step. A phishing email leads to a stolen password, the attacker signs in with it, and then something happens on a laptop. With separate security products you get four alerts from four systems, and someone has to piece them together. Defender XDR does that automatically.

Without XDR: four alerts
  • Phishing emailDefender for Office 365
  • Risky sign-inEntra ID Protection
  • Suspicious PowerShellDefender for Endpoint
  • Unusual cloud activityDefender for Cloud Apps
With Defender XDR: one incident

A multi-stage attack

Phishing, a stolen sign-in and activity on the laptop, in one timeline.

  • User
  • Mailbox
  • Laptop
  • IP addresses
  • Files
  • Processes
Linked by Microsoft, without a SIEM.
And then
Microsoft

Contained automatically

Within minutes: user contained, device isolated.

Remarx

The human layer

  • Confirm the incident
  • Establish the impact
  • Inform you
  • Verify the containment
  • Carry out the fix

Microsoft does the detection, the correlation and the first containment. We provide the analysis, the follow-up and the remediation.

That saves more than time. Because Microsoft sees the whole story, it can also step in itself when it is confident enough: the account is contained and the laptop isolated, within minutes. After that a person is needed to judge how serious it is and what has to be fixed.

What does the technology do, and what do people do?

Good security analysts are scarce and expensive. A traditional control room grows with the number of alerts: more alerts, more people. We turn that around. The technology does the routine work, our specialists do the thinking.

  1. All signals

    Defender XDR sees and links what happens across accounts, devices, email and cloud apps.

    Microsoft
  2. Handled automatically

    Known attacks are disrupted and investigated automatically, at night too.

    Automatic
  3. The specialist

    What technology cannot do: judge how serious it is, weigh your situation, fix it and advise.

    Remarx

People remain accountable. In the runbook we agree together what may happen automatically and what gets a human check first.

For you that means three things. Known attacks are contained faster, at night too. You do not pay for analysts clicking away alerts. And our specialist has time for what matters: your situation, the fix and the advice. New Microsoft capabilities, such as AI assistants for security, we build in as soon as they are available for your licence. That is an ambition, not a promise.

How far back can you look?

To intervene now, Defender sees enough. For investigation afterwards something else counts: how long the data is kept.

Retention with Business Premium and the Defender Suite, without a SIEM

Advanced huntingRaw events from devices, mail and accounts
30 days
Sign-in logsEntra ID P1 and P2
30 days
Email investigationDefender for Office 365 P2
30 days
Incidents and alertsDefender XDR
180 days
Device timelineDefender for Endpoint P2
180 days
Audit logPurview Audit Standard
180 days
Cloud app activityDefender for Cloud Apps
180 days
With extra log retentionSentinel data lake or archive
12 months or longer, key data only
030 days90 days180 days365 days

Source Microsoft, October 2026. Default retention periods may change per product.

If an incident is only discovered after two months, you will still see the alert, but the details are gone: which processes ran and where the sign-ins came from. That requires extra log retention. It can be targeted, for the most important data only, without a full SIEM.

When do you actually need a SIEM?

Both options below are a full control-room function on the same Microsoft foundation. The SIEM layer with Microsoft Sentinel adds sources outside Microsoft, automated playbooks and a longer history.

MDR on Defender XDROur advice for most organisationsMDR with a SIEMEverything on the left, plus Microsoft Sentinel
SourcesAccounts, devices, email and Teams, cloud apps, on-premises Active DirectoryAlso firewall, VPN, network, production systems and other SaaS
DetectionMicrosoft detections, linked into one attack story, plus custom rulesAlso correlation with sources outside Microsoft and threat intelligence
InterventionIsolate device, block account, revoke sessions, remove emailAlso automated playbooks, including on external systems
Looking back30 days in detail, 180 days for incidents90 days as standard, up to years in a low-cost archive
CostsDefender Suite per user plus the MDR serviceAlso Sentinel per gigabyte of data and managing the SIEM
SuitsAn organisation that works almost entirely in Microsoft 365Many sources outside Microsoft or strict logging requirements

What do you need to get started?

The foundation is Microsoft 365 Business Premium with the Defender Suite, an add-on of € 8.70 per user per month (Microsoft list price for an annual subscription, excluding VAT). Business Premium on its own is not enough: protection for identities and cloud apps and the extended detection on devices and email are in the Defender Suite. If you work with Microsoft 365 E5, you already have it.

On top of that you need someone who watches and steps in. That is our Managed Detection & Response: contained automatically day and night, reviewed and fixed on working days by a dedicated specialist, alongside your current IT provider. Curious what that would look like for you? Book twenty minutes with Martijn or Remy.

← All articles

Twenty minutes with Martijn or Remy.

You speak directly with one of the founders. You tell us what's going on; we tell you honestly whether and how we can help. Even if the answer is 'you don't need us'.

Martijn MolRemy Cavo

Pick a time

On working days, via Teams or phone. Choose a slot in our calendar and get an instant confirmation.

Open the calendar Prefer to call? 085 060 9448 · Or send a message