An online business considering managed detection and response should distinguish seeing an alert from taking action to contain a threat. Coverage is meaningful only when the monitored systems and authorised response are clear.
The decision that deserves the closest review
Ask which endpoints, cloud accounts and logs are monitored. Compare service hours, escalation and response authority. Review what happens to systems the provider cannot directly control and whether incident cleanup is included or separately charged.
A hypothetical example
A provider detects suspicious access during the weekend. The business needs to know who can approve containment and whether the agreement allows the provider to act without waiting for an unavailable contact.
Test the working process
Monitoring, escalation and containment are separate capabilities. Compare the systems covered, service hours and authority to respond.
Subscription and total implementation cost
Build a budget for the intended period with the expected users, data and integrations. Include setup, migration, training, support and any usage-related charges. Record renewal pricing and exit costs separately. A plan’s entry price is not a useful comparison if the required workflow needs a different tier.
| Comparison item | Question to resolve |
|---|---|
| Monitored endpoints and data sources | Which systems are outside monitoring scope? |
| Service hours and response authority | Who authorises containment after hours? |
| Containment, cleanup and separate incident charges | Does the price include incident cleanup? |
Run a demonstration of the required process in the actual quoted tier. Ask which changes would trigger a higher subscription, additional consultancy or a new contract.
A practical trial and procurement brief
Create a short trial script using sanitised representative records. Allocate a person to validate the output, permissions and exports. Include the team that will operate the system and, where relevant, the accountant, legal or security adviser who must review the results.
Test detection, escalation and containment separately
Explain the online business’s systems and the events it expects the provider to monitor. Ask which sources are included and how incomplete coverage is handled. Identify the people available to receive alerts and approve action outside normal working hours.
Use a hypothetical alert to compare investigation, escalation and authority to contain it. Review pricing for the relevant systems and service hours, then ask about changes as the business grows. A monitored event is more useful when the agreement and internal process identify who must act next.
Use the UK team’s actual workflow, roles and expected usage as the basis for the service comparison.
A mistake to avoid
Equating round-the-clock alerting with round-the-clock active remediation.
Implementation, responsibility and leaving the service
Agree who owns configuration, migration checks and support escalation. Plan an exit while the supplier is still cooperating: identify usable exports, deletion procedures and removal of administrative access. Test important changes before rolling them out. A service that can be bought quickly can still be expensive to unwind if records and responsibilities are unclear.
Questions before choosing
Can MDR guarantee that no incident occurs?
No service should be treated as that guarantee; compare measurable scope, response and retained controls.
Does monitoring automatically mean the provider can contain an incident?
Ask about authority, included response and escalation. Detection and permission to take action are distinct elements of the proposed service.
Sources and further reading
Research date: 6 October 2026. Refer to the current linked guidance and written provider or adviser terms when making a decision.