Every MDR vendor promises 24/7 detection, AI, and fast response. The differences that decide whether you sleep at night are the ones the sales deck skips. Here are the questions that separate an MDR partner from an alert forwarder.

Managed Detection & Response is now a crowded category, and most providers describe themselves in near-identical language. To compare them meaningfully you have to get past the brochure and ask about the operating reality - what they watch, what they're allowed to do, and what you're actually accountable for after signing.

1. “Detection and response” - but who does the responding?

The single most important question: when something bad happens at 3am, who takes the action, and do they need to wake me up first? Many “MDR” services detect and then email you an alert - leaving the response to your team. That's managed detection, not managed response. Ask specifically:

2. What's actually in scope - and what's a blind spot

An MDR that only watches endpoints will miss identity attacks, cloud misconfiguration, and lateral movement across your SaaS. Modern intrusions live in identity and cloud. Map their coverage against where your risk actually is:

3. The metrics that matter (and the ones that don't)

Vendors love to quote how many events they ingest. That's a vanity number. Ask for the outcomes:

MTTD and MTTR - mean time to detect and to respond - are the only latency numbers that describe how much damage an attacker can do before you stop them.

Ask what their median MTTR is for a confirmed critical incident, whether that figure includes response or just notification, and how they measure false-positive rate. A service that floods you with low-quality alerts is a service you'll eventually ignore.

4. Onboarding, tuning, and the “first 90 days”

Detection quality depends on your context - your normal, your crown-jewel systems, your business hours. Ask how they learn your environment, who tunes out the noise, and how quickly. A provider that runs generic rules with no baselining will bury you in false positives for months.

5. What happens on a real incident

Push past detection into the messy part. If they confirm a ransomware precursor on a domain controller at 2am, what is the concrete sequence of events? Who calls whom, what gets contained automatically, what evidence is preserved for later forensics or insurance, and how do they hand off to your team and your incident-response plan? If they can't walk you through that story crisply, they haven't rehearsed it.

6. The commercial questions

The short version

Good MDR is measured by what it stops, not what it sees. Anchor your comparison on response authority, coverage of identity and cloud, and honest MTTR, and most of the field sorts itself out quickly. If you'd like a vendor-neutral checklist tailored to your stack - or a look at how our own 24×7 SOC handles these - we're happy to talk it through.

← Back to Insights