Every MDR vendor promises 24/7 detection, AI, and fast response. The differences that decide whether you sleep at night are the ones the sales deck skips. Here are the questions that separate an MDR partner from an alert forwarder.
Managed Detection & Response is now a crowded category, and most providers describe themselves in near-identical language. To compare them meaningfully you have to get past the brochure and ask about the operating reality - what they watch, what they're allowed to do, and what you're actually accountable for after signing.
1. “Detection and response” - but who does the responding?
The single most important question: when something bad happens at 3am, who takes the action, and do they need to wake me up first? Many “MDR” services detect and then email you an alert - leaving the response to your team. That's managed detection, not managed response. Ask specifically:
- Will you contain a host, disable an account, or block an IP on my behalf, or only recommend it?
- What actions are pre-authorised, and what needs my sign-off first?
- How is that authority scoped so you can act fast without breaking my business?
2. What's actually in scope - and what's a blind spot
An MDR that only watches endpoints will miss identity attacks, cloud misconfiguration, and lateral movement across your SaaS. Modern intrusions live in identity and cloud. Map their coverage against where your risk actually is:
- Endpoints and servers (the table stakes)
- Identity - Entra ID / Okta sign-in and token abuse
- Cloud - AWS/Azure/GCP control-plane activity
- SaaS and email - the most common initial-access path
- Network and, where relevant, OT/ICS
3. The metrics that matter (and the ones that don't)
Vendors love to quote how many events they ingest. That's a vanity number. Ask for the outcomes:
MTTD and MTTR - mean time to detect and to respond - are the only latency numbers that describe how much damage an attacker can do before you stop them.
Ask what their median MTTR is for a confirmed critical incident, whether that figure includes response or just notification, and how they measure false-positive rate. A service that floods you with low-quality alerts is a service you'll eventually ignore.
4. Onboarding, tuning, and the “first 90 days”
Detection quality depends on your context - your normal, your crown-jewel systems, your business hours. Ask how they learn your environment, who tunes out the noise, and how quickly. A provider that runs generic rules with no baselining will bury you in false positives for months.
5. What happens on a real incident
Push past detection into the messy part. If they confirm a ransomware precursor on a domain controller at 2am, what is the concrete sequence of events? Who calls whom, what gets contained automatically, what evidence is preserved for later forensics or insurance, and how do they hand off to your team and your incident-response plan? If they can't walk you through that story crisply, they haven't rehearsed it.
6. The commercial questions
- Pricing model: per endpoint, per user, or per data volume - and how does the bill move as you grow or during an incident spike?
- Contract lock-in: can you export your data and detections if you leave?
- Human ratio: is there a real analyst behind the automation, or is “24/7” just a dashboard?
The short version
Good MDR is measured by what it stops, not what it sees. Anchor your comparison on response authority, coverage of identity and cloud, and honest MTTR, and most of the field sorts itself out quickly. If you'd like a vendor-neutral checklist tailored to your stack - or a look at how our own 24×7 SOC handles these - we're happy to talk it through.
← Back to Insights