CIS Managed Extended Detection and Response (CIS MxDR)
CIS Managed Extended Detection and Response™ (CIS MxDR™) is a managed extended detection and response service, currently available for Microsoft Defender for Endpoint Plan 2. This provides the 24x7x365 security service U.S. State, Local, Tribal, and Territorial (SLTT) government entities need to detect, investigate, and respond to threats across their environment. Powered by MS-ISAC threat intelligence and existing security investments, CIS MxDR delivers expert analyst triage, escalation, and guided remediation through an around-the-clock U.S.-based Security Operations Center (SOC), giving SLTTs the protection of a full SOC without the cost and complexity of building one themselves.
CIS MxDR is a fully managed security service that monitors your environment around the clock, so your team acts on real threats instead of chasing alerts.
One Tool to See the Whole Picture
Most security teams aren't understaffed on tools. They're understaffed on time. CIS MxDR connects to the security infrastructure your organization already has, cuts through the noise, and delivers only what your team needs to act on, with expert guidance on what to do next.
Unified Telemetry Collection. CIS MxDR launches with Microsoft Defender for Endpoint and expands to ingest signals from firewall, network, identity, cloud, and email sources as the service grows. One connection. Continuous coverage.
Expert Analyst Review. Every escalation is reviewed and validated by a U.S.-based CIS SOC analyst before it reaches your team. No raw alert dumps, no quesswork. Only confirmed findings with clear remediation steps.
Built for SLTTs. Not adapted from enterprise. CIS MxDR is purpose-built for SLTTs and is backed by the trust of the MS-ISAC and threat context drawn from thousands of SLTT peer organizations. No commercial vendor can replicate that view.
What No Commercial Vendor Can Offer
The CIS Advantage
MS-ISAC Threat Intelligence. Detection logic is shaped by real attack data across thousands of states, counties, cities, school districts, and tribes. That means this data tuned to public sector attacks, not those aimed at the private sector.
Vendor-Agnostic by Design. Launching with Microsoft Defender for Endpoint and expanding across network, identity, cloud, and email. No rip-and-replace required, MxDR maximizes the investments you already have.
No Upsell. No Conflict. The Center for Internet Security is a nonprofit. There's no licensing ecosystem to protect, no quota to hit. Guidance is conflict-free and driven entirely by your security outcomes.
Visibility. CIS's position across the SLTT community produces threat context no single agency could achieve alone, attacks seen on one member inform defenses for all.
Minimal Operational Disruption. Customer-executed onboarding, guided by CIS. Telemetry connectors configured per source, no new technology to deploy, and no burden on lean IT teams day-to-day.
Get CIS MxDR Today
Once you confirm your Microsoft Defender for Endpoint license, CIS handles the rest.
On day one, CIS will:
- Begin 24x7x365 ingestion monitoring, and analyst-led triage of Defender signals immediately applying MS-ISAC cross-agency threat intelligence.
- Tune detection logic for your organization .
- Deliver the first structured incident report within the initial coverage period.

