FAQ
Common questions about KYRA MDR, answered.
1. What is MDR?
Managed Detection and Response (MDR) is a cybersecurity service that combines technology and human expertise to monitor, detect, and respond to threats across your IT environment.
Unlike traditional security products that only alert, MDR provides:
- 24/7 monitoring of your security events
- AI-powered threat detection and classification
- Guided incident response with actionable recommendations
- Proactive threat hunting to find hidden threats
KYRA MDR is a cloud-native MDR platform built specifically for the Korean market, with support for Korean compliance frameworks (ISMS-P) and local communication channels (KakaoTalk).
2. How is KYRA MDR different from a SIEM?
| SIEM | KYRA MDR | |
|---|---|---|
| Focus | Log aggregation and search | Threat detection and response |
| Setup | Months of rule tuning | Works out of the box |
| Staffing | Requires dedicated SOC team | AI-powered, minimal staffing needed |
| Alerts | High volume, many false positives | Prioritized, AI-triaged alerts |
| Response | Alert only | Detection + response guidance + automation |
| Cost | Hardware + licenses + SOC staff | Subscription-based, predictable pricing |
KYRA MDR can complement an existing SIEM or replace it entirely for organizations that don’t have a dedicated security operations team. Most Korean SMBs (중소기업) find MDR more cost-effective than building an in-house SOC.
3. What data do you collect?
KYRA MDR collects security-relevant telemetry from:
- Network devices: Firewall logs (FortiGate, Palo Alto, etc.), switch/router syslog
- Endpoints: Windows Security events, Sysmon logs, Linux auth/audit logs
- Cloud: AWS CloudTrail, Azure Activity Logs, GCP Audit Logs
- Applications: Web server logs, authentication logs, database audit logs
- Email: Microsoft 365 / Google Workspace email security events
We collect security metadata only — not the content of files, emails, or communications. All data is encrypted in transit (TLS 1.3) and at rest (AES-256).
4. Is my data encrypted?
Yes. KYRA MDR uses defense-in-depth encryption:
| Layer | Encryption | Details |
|---|---|---|
| In transit | TLS 1.3 | All data between collector and platform |
| At rest | AES-256 | All stored data in the platform |
| Backup | AES-256 | All backup data is encrypted |
| API | TLS 1.3 + JWT | API calls authenticated and encrypted |
Data is stored in Korean data centers (Seoul region) to comply with Korean data sovereignty requirements (개인정보보호법). For enterprise customers, dedicated tenancy and bring-your-own-key (BYOK) options are available.
5. Does KYRA MDR support ISMS-P compliance?
Yes. KYRA MDR provides built-in support for ISMS-P (정보보호 및 개인정보보호 관리체계) compliance:
- Control mapping: Security controls mapped to ISMS-P certification requirements
- Evidence collection: Automated evidence gathering for audit readiness
- Compliance dashboard: Real-time view of your compliance posture
- Gap analysis: Identify missing controls and remediation steps
- Audit reports: Generate compliance reports for auditors
Additional frameworks supported: ISO 27001, SOC 2, PCI-DSS, NIST CSF, GDPR, CCPA, TISAX, CMMC.
6. How fast is alert response?
| Metric | Target |
|---|---|
| Detection | < 1 minute from event ingestion |
| AI Triage | < 30 seconds after detection |
| Critical Alert Notification | < 5 minutes |
| Analyst Review (PRO/CUSTOM) | < 15 minutes for Critical, < 1 hour for High |
| Incident Report | < 4 hours for Critical incidents |
The AI engine classifies and prioritizes alerts in near real-time. For Critical and High severity alerts, notifications are sent immediately via your configured channels (email, KakaoTalk, Slack, webhook).
7. Can I export my data?
Yes. KYRA MDR supports multiple export options:
- Log Search: Export search results as CSV or JSON
- Reports: Download incident reports, compliance reports, and executive summaries as PDF
- API: Use the REST API to programmatically retrieve alerts, incidents, and event data
- SIEM Integration: Forward processed alerts to your SIEM via syslog or webhook
- Data Retention: When your subscription ends, you can request a full data export before data is deleted
We do not lock your data in. You always retain ownership of your security data.
8. What are the plan limitations?
KYRA MDR offers four tiers — FREE, MDR, PRO, and CUSTOM:
| Feature | FREE | MDR | PRO | CUSTOM |
|---|---|---|---|---|
| Price | $0 | $230/mo | $600/mo | Negotiated |
| Events per second (EPS) | 50 | 500 | 2,000 | Unlimited |
| Daily ingestion | 500 MB | 5 GB | 20 GB | Unlimited |
| Data retention | 7 days | 90 days | 180 days | 365+ days |
| Collectors | 1 | 1 | 3 | Unlimited |
| Endpoints | 40 | 120 | 350 | Unlimited |
| Users | 3 | 25 | 50 | Unlimited |
| AI Alert Triage | Summary only | Full (99% FP filter) | Full (99% FP filter) | Full (99% FP filter) |
| Support | Community/docs | Email (24hr) | Dedicated (4hr SLA) | Dedicated (1hr SLA) |
| Compliance | — | Basic ISMS-P | ISMS-P + SOC 2 | Multi-framework |
MDR Annual prepay: $1,380/yr (50% off).
To upgrade, go to Console > Settings > Billing or contact kyra@seekerslab.com.
9. Can I receive notifications via KakaoTalk?
Yes. KYRA MDR supports KakaoTalk (카카오톡) notifications for alert and incident updates.
Setup
- Go to Console > Settings > Notifications
- Select KakaoTalk as a notification channel
- Log in with your KakaoTalk account to authorize
- Configure which alert severities trigger notifications
Supported Channels
| Channel | Alert Types |
|---|---|
| KakaoTalk (카카오톡) | Critical, High, Medium alerts |
| All alert levels, daily/weekly digests | |
| Slack | Critical, High alerts (real-time) |
| Microsoft Teams | Critical, High alerts (real-time) |
| Webhook | Custom integrations |
| SMS (문자) | Critical alerts only (CUSTOM tier) |
10. How do I cancel my subscription?
You can cancel your subscription at any time:
- Go to Console > Settings > Billing
- Click Cancel Subscription
- Select a reason (optional feedback)
- Confirm cancellation
After cancellation:
- Your account remains active until the end of the current billing period
- You can download your data during this time
- After the billing period ends, data is retained for 30 days before permanent deletion
- You can reactivate at any time during the retention period
For enterprise contracts, contact your account manager or email kyra@seekerslab.com.
Still Have Questions?
- Email: kyra@seekerslab.com
- General inquiries: kyra@seekerslab.com
- KakaoTalk: Search “KYRA MDR” and add our support channel
- Console: https://kyra-mdr-console.seekerslab.com — use the in-app chat for real-time support
- Documentation: Browse the full docs