
Choosing an MDR Provider: The Questions That Separate Them
Every provider claims 24/7 monitoring and expert analysts. The evaluation criteria that actually distinguish them, and the demo request that reveals the most.
GuardsArm Team
Security Experts

Every MDR proposal says the same things: 24/7 monitoring, expert analysts, advanced threat detection, rapid response. The marketing has converged, so the evaluation has to go past it.
What follows is the set of questions that actually produce different answers from different providers.
The criteria that matter, weighted
Response authority is first for a reason. It is the difference between a service that stops incidents and one that describes them. Get the authorised action list in the contract: host isolation, account disable, IP blocking, process termination — which of these may they do without contacting you, and under what conditions?
Time to human contact matters more than time to alert. An automated email in ninety seconds is not a response; a qualified analyst on the phone in fifteen minutes is.
Questions that produce differentiated answers
| Question | What you are testing |
|---|---|
| Walk me through a real incident from last quarter | Whether they have operational stories or only slides |
| What may you do on my systems without asking? | Response authority, in concrete terms |
| Who writes your detections, and how many did you add last year? | Detection engineering, or a static vendor rule set |
| What is your analyst retention rate? | Whether the expertise stays |
| What happens in the first 60 days? | Onboarding rigour, and tuning commitment |
| What is your false positive rate after tuning? | Whether they measure their own noise |
| Which of my log sources will you not ingest? | Coverage gaps before they surprise you |
| On exit, what data do I get and in what format? | Lock-in |
The first question is the most revealing and the least often asked. A provider who genuinely operates a SOC can tell that story fluently. One who cannot usually pivots to describing their platform.
Proof, not claims
Ask for a trial or a proof of value on a subset of your estate. Thirty days on a representative sample tells you more than any reference call. Watch for alert quality, how they communicate, and whether tuning actually happens.
Call references that resemble you. Same size, same sector, same complexity. A glowing reference from an organisation ten times your size, with a dedicated security team, tells you little about the service you will get.
Ask the references the awkward question: what has gone wrong, and how did the provider handle it? Every provider has had a bad incident. How they behaved is the useful information.
Contract terms worth negotiating
- Response time commitments by severity, with the clock starting at detection, and a stated remedy if missed
- Ingestion allowance and overage rate, so next year's invoice is predictable
- Termination and data return — your historical logs, in a usable format
- Named escalation contacts on both sides
- Reporting cadence and format, including something an executive can read
- Tuning commitment during onboarding, with a defined end state
See MDR pricing for how these terms show up in the numbers, and MDR versus MSSP if you are not yet sure which model you are buying.
Sector fit matters more than it appears
A provider who has never worked in a clinical environment will recommend containment actions that are unsafe there. Isolating a workstation in a theatre or disabling an account mid-procedure has consequences that a generic playbook does not consider.
Ask how they handle containment where an action could affect safety or continuity. The answer distinguishes a provider who understands your environment from one applying a standard runbook.
Where to start
Write the authorised action list you want before you speak to anyone. It is one page, it forces you to decide how much autonomy you are willing to grant, and it turns a vague evaluation into a concrete comparison.
GuardsArm provides MDR with defined containment authority and sector-aware playbooks. See MDR services or book a scoping call.
Written by GuardsArm Team
Our team of cybersecurity experts brings decades of combined experience in penetration testing, compliance auditing, and incident response. We're dedicated to helping organizations strengthen their security posture.
Take the next step on “Choosing an MDR Provider: The Questions That Separate Them”
Talk to the GuardsArm team about how these services apply to your environment.


