From MDR to MDIR: intelligence enters the defence lifecycle
MDIR (Managed Detection, Intelligence and Response) is the term Fortgale uses to name the evolution of MDR: cyber threat intelligence integrated into every phase of the defence lifecycle, from detection to response. Knowing the adversary gives weight to every alert, makes response faster and more effective, and allows offensive actions to be anticipated. A service that stops at the alert belongs to the previous generation of defence.
Why intelligence enters the defence lifecycle
The history of detection & response is a steady shift of the centre of gravity: first you detected (EDR), then you correlated (XDR), then human operation 24·7 was added (MDR). The next step is not another technology: it is knowledge of the adversary inside the operational flow. This is what Fortgale calls MDIR, Managed Detection, Intelligence and Response.
The reason lies in how attacks actually work. A cyber attack is not something: it is someone. It has infrastructure, recurring techniques, preferred sectors, a history. Defending without knowing who attacks means treating every alert as an isolated fact, all with the same weight, all verified from zero. With intelligence in the loop, every signal is read against what is known about the adversary: understanding first, action second.
- 287adversary groups and attack tools profiled
- <15 minmedian TTD · telemetry to alert
- <30 minmedian TTC · detection to action
- >90%alert noise cut by day 30
What changes with intelligence in the flow
The effect is measurable, not abstract. Every alert acquires weight: a valid-account access (T1078) is an ordinary signal until its command infrastructure matches a group targeting your sector; prioritisation moves from generic severity to relevance for your context, which is how alert noise drops by more than 90% within the first month. Response becomes faster and more effective: knowing the adversary means knowing their TTPs, where they will attempt persistence, which accounts they will hunt, how they exfiltrate; containment becomes targeted instead of generic. Offensive actions can be anticipated: an attack follows a kill chain, and recognising the actor at the third move means knowing the fourth and the fifth. Prediction is not an AI promise: it is the product of adversary profiles built on field-observed TTPs, applied by a European SOC team operating since 2017 from Milan, with detection under 15 minutes and containment under 30 as median times.
Intelligence in the flow means understanding, and understanding means valid defence. A service that only talks about alerts, how many it generates and how many it forwards, belongs to the previous generation of defence: the one that handed the customer the work of understanding.
A term we propose, a substance we prove
To be explicit: MDIR is not an industry standard, and the acronym circulates with more than one expansion. Fortgale adopts and defends it in this form, Managed Detection, Intelligence and Response, because it names precisely the evolution we pursue: intelligence as the centre of gravity of the managed service. The acronym is only worth what the I can prove. Ask any provider, Fortgale included, for evidence: how many adversaries profiled and from which sources, how intelligence enters triage and response, which real cases document it. Read more: What is MDR and Cyber Threat Intelligence, where that knowledge is built.
A cyber attack is not something: it is someone. Knowing them, anticipating their moves, stopping them in time: MDIR is the name of that sequence. Knowing the adversary is the first act of defence. Stopping it in time is the second.
The centre of gravity shifts: from the alert to understanding the adversary
| Stage | Centre of gravity | Typical output |
|---|---|---|
| EDR | Detect on the endpoint | Alerts |
| XDR | Correlate across domains | Correlated alerts |
| MDR | Manage detection and response 24·7 | Closed incidents |
| MDIR | Integrate intelligence into every phase | Closed incidents, knowing the adversary |
In Operation Storming Tide containment, eradication, exfiltration and ransomware prevented: the response was decisive because it was guided by knowledge of the adversary, their TTPs and their infrastructure. That is the intelligence in the operational loop that the term MDIR makes explicit.
Read the analysis →Frequently asked.
What does MDIR mean?
MDIR stands for Managed Detection, Intelligence and Response. It is the term Fortgale uses to name the evolution of the MDR model: cyber threat intelligence not as an accessory feed, but as a structural component of the defence lifecycle. Intelligence exists to understand the attacker and the attack, to respond to the incident in the best way, and to anticipate offensive actions.
What is the difference between MDR and MDIR?
The position of intelligence. In many MDR services CTI is a purchased stream of IOCs that arrives downstream. In the MDIR model intelligence sits inside the operational flow: it enriches detection by giving weight to every alert, it guides response because the analyst knows who they are facing and how they operate, and it feeds prediction of the next moves along the kill chain.
Is MDIR an industry standard?
No, and it is worth being explicit: the acronym circulates with more than one expansion and no third-party body defines it. For Fortgale the I means Intelligence, and that is the direction we pursue. What matters is verifiable beyond the name: 287 adversary groups and attack tools profiled, intelligence applied in the triage of every alert, detection and containment times measured.
Is intelligence not already included in every MDR?
A feed of indicators is not intelligence in the loop. The difference is between receiving a list of IOCs and holding adversary profiles built on field-observed TTPs, kept alive by real incidents and applied in triage, response and prediction. The question to ask any provider: how does intelligence enter your operational decisions, from which sources, with what evidence?
From theory to a real operation.
What you read here, Fortgale runs every day with a European SOC 24·7·365: 287 tools and actors profiled, <30 min median containment. Explore the service: Fortgale MDR service.
Related resources: What is MDR · Cyber Threat Intelligence · Incident Response
A technical conversation, not a funnel.
Leave your details: an analyst calls you back within one business day. European SOC, same time zone, proprietary intelligence on the actors active across the EU.