A managed detection and response review should begin with a practical question: when suspicious activity appears in your systems at 2am, who sees it, who investigates it, and who takes action? For a growing business, the answer cannot simply be “our IT person will look at it in the morning”. Delayed action can turn a compromised account, infected device or exposed cloud service into costly downtime.
Managed detection and response, usually called MDR, gives organisations access to security specialists, monitoring technology and an incident response process without building a full internal security operations centre. However, services that carry the MDR label can differ significantly. Some provide useful alerts; others investigate threats and actively contain them. Knowing the difference is essential before signing a contract.
What an MDR service should actually do
At its best, MDR combines continuous monitoring with human-led analysis and a defined response process. The service collects security signals from relevant parts of your environment, such as employee devices, servers, cloud platforms, identity systems, firewalls and email security tools. Detection technology identifies unusual behaviour, while analysts determine whether it represents a genuine threat.
That human assessment matters. A system may flag a login from an unfamiliar location, for example, but a trained analyst can assess whether it is a travelling employee, an authorised service account or a likely account takeover. This reduces the number of false alarms reaching your team and helps ensure urgent issues receive the right attention.
A capable provider should then follow an agreed process to investigate and respond. Depending on the service, this could include isolating an infected endpoint, disabling a compromised user account, blocking a malicious connection or giving your IT team clear instructions for immediate containment. The response boundary must be unambiguous. A provider that only notifies you is not offering the same level of protection as one that can take approved action.
Managed detection and response review: the questions that matter
The best review is not a comparison of feature lists. It is an assessment of whether the service will protect your business operations under pressure. Ask providers to explain their service in plain language, using scenarios relevant to your environment.
What is monitored, and what is excluded?
Many MDR packages are built around endpoint detection and response tools installed on laptops, desktops and servers. This is valuable, but endpoints are only one part of the attack surface. A business using Microsoft 365, cloud applications, remote access tools and managed firewalls may need visibility across those services as well.
Ask exactly which systems are included in the standard service and which require additional licences or integrations. Confirm whether coverage applies to remote workers, mobile devices, cloud workloads, privileged accounts and third-party access. A gap in visibility is often discovered after an incident, when it is most difficult to fix.
Coverage should also match your risk profile. A small office with a limited on-premises footprint may need a different service from a business processing sensitive customer data across several cloud platforms. More telemetry is not automatically better if no one can interpret it effectively, but monitoring the wrong areas creates false confidence.
Is there genuine 24/7 human monitoring?
Cyber incidents do not follow office hours. Confirm whether security analysts actively monitor and investigate alerts around the clock, including weekends and public holidays. Some services operate a 24/7 platform but reserve human investigation for business hours. Others use automated alerting overnight and escalate later.
Automation has a useful role in detecting patterns at speed, but it should not be presented as a substitute for skilled analysis. Ask who reviews high-severity alerts, where the security team is based, and how the provider maintains handovers between analysts. For European organisations, it is also sensible to understand where security data is processed and how the provider supports your data protection obligations.
What action can the provider take?
This is often the most important distinction in an MDR evaluation. Providers may describe response in different ways, so ask for a direct answer: can they contain a threat without waiting for your approval, and under what circumstances?
There is no single right model. Automatic isolation of a device can prevent ransomware spreading, but isolating the wrong machine could interrupt a critical user or service. Many businesses choose pre-approved actions for high-confidence threats, with an escalation route for decisions that could affect operations. The right arrangement balances speed with business control.
Your agreement should document who can authorise containment, how emergency contacts are reached, and what happens if no one responds. It should also specify whether the provider will assist with remediation after containment, such as removing persistence mechanisms, resetting credentials and verifying that affected systems are safe to return to service.
How quickly are threats investigated and escalated?
Do not rely on broad claims about rapid response. Request service level commitments for acknowledging, investigating and escalating serious incidents. A provider may detect an event quickly but take much longer to establish its impact or contact your team.
The quality of communication matters as much as the clock. During an incident, business leaders need clear answers: what happened, what has been affected, what action has been taken, what should staff do, and what risk remains? Technical detail should be available for IT teams, but it should not obscure the decision required.
Ask to see an anonymised incident report. A useful report explains the evidence, timeline, affected assets, containment actions and recommended next steps. Vague notifications containing only an alert name and severity score place too much burden on the customer.
Look beyond the technology platform
A well-known security product is not, by itself, an MDR service. The provider’s operational discipline, onboarding process and understanding of your environment determine whether the technology produces meaningful protection.
During onboarding, the provider should identify critical systems, map important users and accounts, configure integrations, establish escalation contacts and agree the response playbook. This is also the point to document business exceptions. A server that cannot be automatically isolated during trading hours, for example, needs a safer response plan than a standard workstation.
Ask how often the service is reviewed after go-live. Your technology estate will change as people join, cloud services are adopted, offices move or new suppliers gain access. Regular service reviews help maintain coverage and make security findings part of your wider IT improvement plan rather than a stream of disconnected alerts.
This joined-up approach is especially helpful for businesses without a large internal IT team. A managed IT partner that understands your network, devices, backups, cloud configuration and support processes can coordinate incident response with day-to-day operations. URBlink approaches cybersecurity as part of service continuity, so detection and response can sit alongside the practical work of maintaining secure, available systems.
Check what the price really covers
MDR pricing may be based on users, endpoints, servers, data volumes or a combination of these. A lower initial quote can become less attractive if it excludes servers, cloud identity monitoring, incident response support or out-of-hours assistance.
Request a clear breakdown of included tools, onboarding, monitoring, investigation, containment, reporting and remediation. Clarify whether emergency incident support is covered or charged separately. It is also worth asking about contract terms, minimum device numbers and how licensing changes when your workforce grows or contracts.
Cost should be considered against operational risk, not only against other security subscriptions. The financial effect of a serious incident may include lost staff time, interrupted customer service, recovery work, reputational damage and possible legal obligations. Nevertheless, the most expensive package is not always the right choice. A service should be proportionate to the systems, data and availability requirements it protects.
Warning signs during provider selection
Be cautious when a provider cannot explain its response process without relying on product marketing language. Other warning signs include unclear monitoring hours, no named escalation route, generic reports, uncertain data handling arrangements and a promise to “manage everything” without defining authority.
It is also reasonable to question a service that creates large volumes of alerts for your staff to sort through. MDR should reduce the pressure on internal teams by filtering noise, investigating credible threats and presenting decisions that need your attention. If your business still has to perform the security analysis, you may be paying for a tool rather than a managed outcome.
Before committing, involve the people responsible for operations, IT, data protection and business continuity. Their input will reveal practical constraints that a technical demonstration may miss, from essential systems that cannot be interrupted to key contacts who must be informed during an incident.
The right MDR provider should leave you with a clear, tested plan for difficult moments: what is being watched, who is responsible, how quickly action happens and how your business stays informed. That clarity is not an extra feature. It is the foundation of dependable protection.
