Back to Blog
Managed Services
4 min read

Choosing an MDR Provider: The Questions That Separate Them

Every provider claims 24/7 monitoring and expert analysts. The evaluation criteria that actually distinguish them, and the demo request that reveals the most.

GuardsArm Team

Security Experts

September 25, 2026

Evaluating MDR providers

Every MDR proposal says the same things: 24/7 monitoring, expert analysts, advanced threat detection, rapid response. The marketing has converged, so the evaluation has to go past it.

What follows is the set of questions that actually produce different answers from different providers.

Marketing has converged
Every provider claims the same things
Ask for a real incident
The most revealing and least-asked question
Sector fit is safety
Generic containment is unsafe in clinical settings

The criteria that matter, weighted

MDR evaluation criteria, weightedResponse authority, time to human contact and detection engineering are the decisive criteria. Onboarding, reporting and exit terms follow.Response authorityWhat they may do without asking — the core of the serviceTime to human contactNot time to automated alertDetection engineeringNew detections written, or a static rule setOnboarding and tuningThe first sixty days decide the outcomeReporting qualitySomething an executive will actually readExit terms and data returnLock-in, assessed before signing
The top three separate providers; the bottom three prevent regret.

Response authority is first for a reason. It is the difference between a service that stops incidents and one that describes them. Get the authorised action list in the contract: host isolation, account disable, IP blocking, process termination — which of these may they do without contacting you, and under what conditions?

Time to human contact matters more than time to alert. An automated email in ninety seconds is not a response; a qualified analyst on the phone in fifteen minutes is.


Questions that produce differentiated answers

QuestionWhat you are testing
Walk me through a real incident from last quarterWhether they have operational stories or only slides
What may you do on my systems without asking?Response authority, in concrete terms
Who writes your detections, and how many did you add last year?Detection engineering, or a static vendor rule set
What is your analyst retention rate?Whether the expertise stays
What happens in the first 60 days?Onboarding rigour, and tuning commitment
What is your false positive rate after tuning?Whether they measure their own noise
Which of my log sources will you not ingest?Coverage gaps before they surprise you
On exit, what data do I get and in what format?Lock-in

The first question is the most revealing and the least often asked. A provider who genuinely operates a SOC can tell that story fluently. One who cannot usually pivots to describing their platform.


Proof, not claims

Run a proof of value on your own estate
Thirty days on a representative subset reveals alert quality, communication style and whether tuning actually happens. It is worth more than every reference call combined, and a confident provider will agree to it.

Ask for a trial or a proof of value on a subset of your estate. Thirty days on a representative sample tells you more than any reference call. Watch for alert quality, how they communicate, and whether tuning actually happens.

Call references that resemble you. Same size, same sector, same complexity. A glowing reference from an organisation ten times your size, with a dedicated security team, tells you little about the service you will get.

Ask the references the awkward question: what has gone wrong, and how did the provider handle it? Every provider has had a bad incident. How they behaved is the useful information.


Contract terms worth negotiating

  • Response time commitments by severity, with the clock starting at detection, and a stated remedy if missed
  • Ingestion allowance and overage rate, so next year's invoice is predictable
  • Termination and data return — your historical logs, in a usable format
  • Named escalation contacts on both sides
  • Reporting cadence and format, including something an executive can read
  • Tuning commitment during onboarding, with a defined end state

See MDR pricing for how these terms show up in the numbers, and MDR versus MSSP if you are not yet sure which model you are buying.


Sector fit matters more than it appears

A provider who has never worked in a clinical environment will recommend containment actions that are unsafe there. Isolating a workstation in a theatre or disabling an account mid-procedure has consequences that a generic playbook does not consider.

Ask how they handle containment where an action could affect safety or continuity. The answer distinguishes a provider who understands your environment from one applying a standard runbook.


Where to start

Write the authorised action list you want before you speak to anyone. It is one page, it forces you to decide how much autonomy you are willing to grant, and it turns a vague evaluation into a concrete comparison.

GuardsArm provides MDR with defined containment authority and sector-aware playbooks. See MDR services or book a scoping call.

Written by GuardsArm Team

Our team of cybersecurity experts brings decades of combined experience in penetration testing, compliance auditing, and incident response. We're dedicated to helping organizations strengthen their security posture.

Take the next step on “Choosing an MDR Provider: The Questions That Separate Them”

Talk to the GuardsArm team about how these services apply to your environment.