Image coming soon

TrendAI Vision One™ - Managed Detection and Response (MDR)

SKU:
TV1-MDR-001
Availability:
Usually ships in 7 days

Description

TrendAI Vision One Managed Detection and Response (MDR)

TrendAI Vision One MDR is a 24/7/365 service where TrendAI analysts monitor your environment, investigate high-risk alerts and give you a step-by-step remediation plan. It covers five attack surfaces from one console: email, endpoints, servers, cloud workloads and network.

Read this before you compare it with other MDR services. TrendAI MDR investigates, contains and tells you exactly what to do. It does not include incident response. TrendAI is explicit about this: onsite and remote IR services are a separate engagement. If you need someone to carry out the full cleanup for you, that is a different purchase.

What the service does

Detection

  • 24/7 monitoring that filters alerts down to those needing investigation.
  • Continuous sweeps for indicators of compromise and indicators of attack, including those shared through US-CERT and third-party disclosures.
  • Follow-the-sun SOC coverage across North America, Europe and Asia-Pacific.

Investigation

  • Analysts build a full picture of the attack: root cause, attack vector, dwell time, spread and impact.
  • You receive detailed incident reports and can work directly with the analyst during the investigation.
  • Backed by TrendAI global threat research.

Response

  • Containment actions include endpoint isolation, process kill, network containment, account disable and file quarantine.
  • First response is configurable: analysts can act automatically against your playbook, or escalate for your approval.
  • Step-by-step remediation plans with custom cleanup tools, plus automatic IoC generation to block repeat attacks.
  • Monthly reports summarising case activity.

Which subscription you need

Subscription Covers
MDR for Users, Servers and Workload Security Endpoints, servers, cloud workloads. Messaging is included, so mailboxes are not counted separately
MDR for Networks Network detection, licensed separately

You still need the underlying TrendAI Vision One XDR licences for the products being monitored. MDR is the managed service layer on top, not a replacement for the platform.

How it compares with Sophos MDR

Nuformat sells both, so here is the honest comparison rather than a pitch for one.

Capability TrendAI Vision One MDR Sophos MDR Plus
24/7 monitoring and investigation Yes Yes
Active containment Yes Yes
Attack surfaces in base price Five: email, endpoint, server, cloud, network Endpoint-led, extended via integrations
Full incident response Not included, separate retainer Included, no hourly caps
Response commitment Service Level Objectives, not published 60 min for 90% of high-severity cases
Analyst model Pooled across customers Dedicated IR lead during an incident
Alert history in console 180 days Varies by plan

The short version: TrendAI covers more attack surfaces in the base price and gives you a single console across all five. Sophos commits contractually to a response time and does the cleanup for you. Which matters more depends on whether your constraint is breadth of coverage or having someone finish the job.

What you need to run it

  • TrendAI Vision One XDR licences on the products being monitored.
  • A licence count matching your users, servers or network sensors.
  • Onboarding, which TrendAI runs as a defined process.

Note that extended data retention beyond the standard period is priced separately, as is incident response.

Frequently asked questions

What is TrendAI Vision One MDR?

It is a 24/7/365 managed detection and response service where TrendAI analysts monitor activity data from your TrendAI products, investigate high-risk threats, and provide recommended actions. It covers email, endpoints, servers, cloud workloads and network from the Vision One console.

Does TrendAI MDR include incident response?

No. TrendAI states that the MDR service does not include incident response services, either onsite or remote. Investigations are limited to data from the MDR-licensed products. Full incident response is a separate engagement. If you need the provider to carry out end-to-end remediation, compare this against Sophos MDR Plus, which includes it.

What is the difference between TrendAI MDR and Sophos MDR?

TrendAI covers five attack surfaces in the base price, email, endpoint, server, cloud and network, from one console. Sophos MDR Plus includes full incident response with no hourly caps and a contractual 60-minute response target for 90 percent of high-severity cases, which TrendAI does not publish. TrendAI provides Service Level Objectives rather than formal SLAs.

Does TrendAI MDR cover email?

Yes. Messaging is included in the MDR for Users, Servers and Workload Security subscription, and mailboxes are not counted separately in your licence total. You do still need the XDR licences for messaging.

Can TrendAI analysts act without asking me first?

Yes, if you configure it that way. First response is configurable: analysts can act automatically against a playbook you define, or escalate to you for approval before acting. Containment actions include endpoint isolation, process kill, network containment, account disable and file quarantine.

How long is alert history kept?

The Vision One console provides 180 days of alert history in the Workbench, with full query access to platform data. Extended data retention beyond the standard period is priced separately.

Get TrendAI MDR quoted by Nuformat

Nuformat sells and supports both TrendAI and Sophos, so we have no reason to push you toward either. Send us your user, server and network counts and we will price TrendAI MDR, compare it against the Sophos equivalent, and tell you which we would actually put in for your situation.

Request a quote

TrendAI Vision One range · Sophos MDR

Service details as published by TrendAI in product documentation and service FAQs. Coverage, subscriptions and response model confirmed against vendor sources. Pricing and availability confirmed by Nuformat at the time of quotation.