Managed security
How to choose an MDR provider: the questions that separate the services
A buyer's guide to managed detection and response for UK organisations: what a good service includes, the questions that separate providers, where your data goes, how pricing works, and the red flags to walk away from.
Most managed detection and response (MDR) services sound alike on a website: 24×7 monitoring, expert analysts, rapid response. The differences that matter only appear when you ask specific questions. Below are those questions, with what a good answer sounds like and the signs that should make you walk away. Use them with any provider, including us.
If you are still deciding whether MDR, a managed SIEM or a managed SOC is the right service, start with what each one is or the managed service selector, then come back to this.
What should an MDR service include as a minimum?
Four things, whoever provides it:
- Round-the-clock monitoring by people. Alerts are triaged by analysts at any hour, not just collected for the morning.
- Investigation. Someone works out whether an alert is real, what it touched and how it started.
- Response. Real threats are contained, within an authority you have agreed in advance.
- Reporting. You can see what was detected, what was done and how quickly, in a form your board and auditors can use.
A service missing any one of these is a different product: a detection tool, an alerting service, or out-of-hours cover.
Is it 24×7 with people, or alerting out of hours?
This is the first question to ask, because the wording on many proposals blurs it. "24×7 monitoring" can mean analysts watching around the clock, or it can mean an automated system that emails or rings you overnight and waits for business hours to investigate.
Ask directly: at 2am on a Sunday, who looks at a high-severity alert, how quickly, and what can they do about it? A good answer names a process and a response time you can hold them to in the contract.
What will they do without asking you?
Response is only fast if the authority to act is agreed before the incident. Ask for the list of actions the provider will take on its own, which typically includes:
- isolating an infected device from the network;
- disabling or forcing a password reset on a compromised account;
- blocking a malicious file, domain or address;
- ending a suspicious session.
Then ask what is escalated to you instead, how, and to whom. You should be able to tune this list to your business: a manufacturer may not want a production workstation isolated without a call; a law firm may want a compromised mailbox locked immediately.
What does it cover beyond endpoints?
Many intrusions now start with a stolen password rather than malware, so endpoint coverage alone leaves gaps. Ask which of these the service monitors and responds across:
- laptops, desktops and servers;
- identity: sign-ins, multi-factor authentication events and admin changes;
- email;
- cloud platforms and key business applications;
- network edge devices such as firewalls and VPNs.
Also ask whether the service works with the security tools you already run or requires its own. Either approach can work, but replacing tools you have paid for is a cost that should be visible in the comparison.
Who runs the service day to day?
It is common for the company you contract with to deliver part of the service through specialist partners or a platform vendor's own operations team. That is not a problem in itself. What matters is that you know who has access to your environment and data, and that one party is clearly accountable to you for the service levels in your contract, whoever does the work.
Ask: who are the analysts, where are they based, who is accountable if the service falls short, and how are those obligations passed down?
Where is your data held, and who can see it?
MDR services collect a great deal of telemetry, and some of it will be personal data under UK GDPR. Ask:
- where the data is stored and processed, and whether UK or EU hosting is available if you need it;
- how long it is kept, and whether that meets your own retention obligations;
- who can access it, including any sub-processors;
- if it leaves the UK, what transfer safeguards apply;
- what the data processing agreement says.
If you are in a regulated sector, check the arrangement against your own obligations, for example the FCA's outsourcing and operational resilience rules, or DORA's third-party requirements where they reach you.
What will your board and auditors receive?
Ask to see a sample monthly report. A useful one shows what was detected, what was done and how quickly, the recurring causes, and what would stop them happening again. Alert counts on their own tell a board very little.
If you need to evidence monitoring and incident response for ISO 27001, the UK NIS Regulations, DORA or NIS2, check that the reports and incident records will serve as that evidence without being rewritten.
How is MDR priced?
Common models charge per endpoint, per user, or by the volume of data ingested, sometimes with a separate charge for incident response beyond the initial containment. When comparing quotes:
- put every proposal on the same scope (devices, users, sources, retention);
- check what is excluded, especially full incident response and forensic work;
- check onboarding costs and minimum terms;
- ask how the price changes as you grow.
A lower price can reflect a narrower response commitment, so compare what each proposal will do, not just what it costs.
What happens when you leave?
Ask at the start, not at renewal. How long is the notice period? Will your data, incident history and reports be returned in a usable format? Will agents be removed cleanly? A good provider will answer these questions in writing before you sign.
Red flags
- "24×7" that turns out to mean out-of-hours alerting with next-day investigation.
- No written list of pre-approved response actions.
- Vague answers on who the analysts are or where your data is held.
- Reporting that only counts alerts.
- A price that excludes the response you assumed was included.
- Lock-in: long minimum terms with no clear exit or data return.
A shortlist checklist
Before you sign, you should be able to answer yes to each of these:
- Alerts are triaged by people around the clock, with a contracted response time.
- Pre-approved response actions are written down and tuned to your business.
- Coverage includes identity and email as well as endpoints.
- You know who does the work, where your data is held and who is accountable to you.
- You have seen a sample report your board would find useful.
- You have compared prices on the same scope, including exclusions.
- The exit terms are clear.
Where Threat Protect fits
Threat Protect is vendor-agnostic. We match the managed detection and response service to your environment rather than to a single platform, tell you which specialist provider runs the monitoring and where your data is held, agree the response authority with you during onboarding, and stay your single point of accountability throughout. The monitoring record then feeds straight into your continuous compliance evidence.
If you are comparing proposals now, book a 30-minute call and bring them with you. We will help you put them side by side on the questions above, including ours. For more on the service itself, see managed detection and response and what insurers ask about it at renewal.
Frequently asked
Questions readers ask before getting in touch.
- It depends on what is covered: the number of endpoints or users, which other sources are connected (identity, email, cloud), how much data is retained, and how much incident response is included. Compare providers on the same scope, and check what sits outside the price, such as full incident response or out-of-scope systems, before comparing totals.
- Often, yes. A smaller organisation is the least able to staff round-the-clock monitoring itself, and attackers favour nights and weekends because fewer people are watching. The deciding question is whether anyone would notice, and act on, a compromise at 2am on a Saturday.
- MDR is a specific service: detecting and responding to threats around the clock. An MSSP manages a broader range of security services, which may include MDR alongside managed firewalls, email security, SIEM and compliance support. Some organisations buy MDR on its own; others want one provider accountable for several services.
- Only if you have agreed it in advance. Good providers set out a list of pre-approved actions during onboarding, such as isolating a device or disabling an account, and escalate anything more disruptive to your nominated contacts. Without that agreement, response waits for someone to answer the phone.
- It is mostly a deployment exercise: new agents or integrations, a fresh baselining period, and agreed escalation paths. The risks sit in the handover window and in what you can take with you, so ask at the outset how your data, detection history and reports are returned when the contract ends.
Talk to us
Want to talk through how this applies to your company?
A 30-minute call with a senior advisor. No pitch. We will read your situation against what is in this piece and tell you the smallest sensible next step.