If you had a genie at your service, what would you ask of it first? Instant flight? Limitless intelligence? For me, the tempting answer would be simple: instantaneous wish fulfilment. A snap of the fingers, a few magic words, and suddenly you have…well, anything. And in a way, modern technology has made that fantasy feel less far-fetched: we have access to instant deliveries, the internet at our fingertips, and, to keep online activity stress-free, there’s also always up-to-date security.

None of these are possible without some required set-up though, right? Deliveries require address details, internet access service agreements, and as for security…the right fit. People often expect things to be immediate, but it’s not so simple.

Case in point, managed detection and response (MDR)—awesome, human-delivered protection for those that might not have the right internal resources to operate in-house analyses of security findings. However, even the most advanced MDR service cannot protect assets it cannot see, including prioritizing alerts without business context, or responding effectively without established communication channels. In other words, some set-up is required.

Key points of this article:

  • MDR is not plug-and-play, as effective protection depends on the right combination of technology, people, processes.
  • Visibility is the foundation of security, meaning that MDR can only detect and respond to threats on systems it can see and monitor.
  • Unmanaged endpoints, legacy systems, or other overlooked assets can easily become attack entry points and security blind spots.
  • Thus, proper onboarding improves security outcomes. Providing support to configure protection correctly reduces misconfigurations, speeds up time to protection, and improves detection quality.
  • Guided ESET MDR onboarding helps customers maximize value, with our expert guidance ensuring that organizations activate, deploy, and use the service effectively from day one.

Breaking down a myth: MDR is plug-and-play

Unlike traditional software products that can be installed and configured in hours, MDR is a service built around the combination of technology, people, and processes. Its effectiveness depends on how well those three elements are aligned with the customer’s environment.

So, ESET MDR, for example, is effective because:

  • It offers round-the-clock protection all year round, delivered in multiple languages.
  • It is based on globally sourced ESET telemetry and supported by human agents trained on the latest ESET Threat Intelligence and tech know-how.
  • It boasts a mean time to respond of six minutes, compared to the weeks or months response and recovery take.
  • Its Active Incident Support provides rapid, expert assistance in English for active ongoing security incidents.
  • It is based on detections made, and rules triggered inside ESET PROTECT XDR, with its AI-powered engine hastening response even more.

For all of this to work, MDR requires extensive visibility (provided via the ESET PROTECT XDR connection), which pulls telemetry from the client’s environment to ESET’s systems. This, of course, wouldn’t be possible without said systems being covered by the XDR in question, otherwise there would be a lot of…accidental or deliberate blind spots, so to speak. A legacy server or even an unpatched virtual machine could very well turn out to be the vector of an attack, for example, which is why coverage should be top priority. 

In a nutshell, having an incomplete picture of the entire environment doesn’t do much for detection quality, in fact, it actively degrades it for a lack of input. Sure, organizations may choose to exclude certain assets because of technical limitations, regulatory requirements, business decisions, and the like, but the key is ensuring that at least those coverage gaps are documented and regularly reviewed as the environment evolves. 

Elsewise, resilience is out of the question.

Building a foundation for effective MDR

For analysts to identify threats accurately, they must first understand what they are protecting. Without that foundation, even the best defenders may lack the context necessary to distinguish genuine threats from routine business activity. Really, who’s to say that SimpleHelp or Atera RMM activity in business systems is genuine? Unless those tools are known and used in-house or by a contracted MSP, they could be signs of malicious behavior, one which threat actors often rely on for stealth.

Related: Threat actors using legitimate IT tools to blend in.

But “wait a minute,” you say, “I have some ESET PROTECT modules running on my systems; I should be okay.” Sure, to a point. But who’s to say the adversary won’t try and deploy an EDR killer to cripple your basic protection? Vulnerable drivers, which those EDR killers use, are tricky to detect. And while some products like ESET PROTECT XDR contain useful detection rules for early prevention, they won’t trigger on invisible systems.

Even ESET PROTECT XDR requires the deployment of protection agents to selected systems for telemetry. 

All in all, strong security outcomes depend not only on buying the right solution, but on deploying, activating, and configuring it correctly. While ESET MDR teams do proactively communicate this, there’s room for improvement—and we have just the solution.

Guided ESET MDR onboarding

What can’t be achieved organically requires special care. We’ve seen that especially with smaller SMBs and mid-market organizations that often face a tough reality: they want to stay secure, but they don’t understand how. The ideal security is the one that is the most aligned to their way of working, filling in resource (human/tech) gaps for fast containment and even faster response. For a good price too.

How to do that? ESET is already very competitive on multiple fronts here. We offer an attainable ESET MDR service with a six-minute response time. Six minutes…if all the systems are onboarded. To facilitate this, the company has developed ESET MDR Guided Onboarding, because monitored protection is only as effective as the environment in which it operates.

“The key advantage of the new guided onboarding service is its ability to reduce risks associated with incomplete or ineffective MDR enrollment, adding an additional layer of prevention,” said Gabriel Balla, Product Manager at ESET, “What our ESET MDR customers receive is an assurance that their service has been activated correctly, with further guidance on how to operate it.”

How it works

To get the most out of ESET MDR, the onboarding session is delivered through a live call with an assigned delivery engineer, to last approximately one hour. During the session, the customer should perform all the required steps, while the ESET delivery engineer instructs and guides them through the process. However, the engineer does not take over the customer environment or complete the work on the customer’s behalf. 

“The role of the engineer is to guide, explain, validate direction, and help the customer move through the set-up with confidence. This distinction is incredibly important. Guided onboarding is NOT a full deployment service; it is structured advisory support that helps the customer complete onboarding correctly, and in full," added Balla.

In other terms, it’s practical advice with a live (on call) guided experience.

“We won’t do this for you, but we’ll work alongside you to build the full picture and help you navigate the future with confidence,” summarized Balla.

What are the benefits of ESET’s guided MDR onboarding?

The benefits of onboarding are obvious:

  • Faster time to protection: The sooner systems are connected and monitored, the sooner security teams can begin identifying potential threats. Effective onboarding accelerates the transition from deployment to active protection by ensuring visibility is established quickly and comprehensively.
  • Reduced misconfiguration risk: Every organization operates differently. What may appear suspicious in one environment can be completely normal in another. With onboarding, the customer will understand how to better protect their own unique environment.
  • Better early posture: With an enhanced understanding of their protected environment and the service that covers it, customers can more easily connect the dots and see threats early.
  • Greater customer confidence: The customer will better understand what MDR does, what they can get out of their deployment in practical terms, and the measures they can take to confidently enjoy their service.

In addition to the above, the result is also to be found in stronger long-term outcomes. A properly onboarded customer is better positioned to “see” what’s happening inside their systems. Moreover, they also mature, so to speak, improving their approach to their own resilience via an understanding of security tech and the value it brings.

Availability of ESET MDR Guided Onboarding

ESET MDR Guided Onboarding will be available from September 30 in the U.S., Italy, and Slovakia as part of ESET’s gradual rollout of its new B2B offering built for the AI era.

The service will be offered as part of ESET PROTECT Premium Plus, and as an add-on to ESET PROTECT Premium. 

For customers on outgoing tiers, ESET Deployment & Upgrade remains available as an alternative. It can be purchased as an add-on to any currently available subscription tier and is also included in the new offering under ESET PROTECT Ultimate and ESET PROTECT Ultimate Plus.

Security starts before the first alert

The value of an MDR service is determined long before an alert appears on analysts’ dashboards. When assessing MDR providers, companies usually focus on technology, analytics, and response capabilities. It makes total sense. But while those factors are important, they only deliver their full value when a service is correctly applied and tailored to a customer’s requirements.

Often, this can’t be done independently from a cybersecurity vendor’s side—that’d usually require a completely different form of service. An MDR service cannot protect what it cannot see, and it cannot respond effectively without understanding the environment it serves. That is why onboarding is the first step, the foundation upon which effective cybersecurity is built.

See how ESET MDR performs when properly onboarded with some stories from our security analysts.

COMPLEXITY_GDN_970x250

FAQ: ESET MDR Guided Onboarding

Why is guided onboarding crucial for MDR?

MDR services rely on ensuring needed visibility into your environment. Onboarding helps ensure the systems that matter most are connected, monitored, and configured correctly so analysts can detect and respond to threats effectively.

How long does ESET’s guided onboarding session take?

The onboarding session typically lasts about one hour and is conducted through a live call with an assigned ESET delivery engineer.

Will the ESET engineer deploy and configure everything for us?

No. Guided onboarding is an advisory service. The ESET engineer provides instructions, recommendations, and validation, while your team performs the required configuration steps within your environment.

What are the main benefits of guided onboarding?

Key benefits include accelerated protection, reduced configuration risks, better visibility across the environment, and increased confidence in using the MDR service effectively.

What happens if some devices or systems are not onboarded?

Systems that are not onboarded may become visibility gaps. Without telemetry from those assets, threats can be harder to detect, investigate, and contain potentially increasing overall risk.