What does an MDR service actually provide?
Managed detection and response, MDR, is a service in which a provider's analysts monitor security telemetry from a customer's environment, investigate alerts, and take or direct response actions. It usually runs on an endpoint detection and response platform, often extended to identity, email and cloud logs. It sits between buying a security tool and running a security operations centre: the provider supplies the people and the process, and in most cases the platform.
The term covers very different services. Some providers watch endpoints only and send an email when something fires. Others cover identity, mail and cloud, contain threats themselves within minutes, and hand over to incident response when an intrusion is confirmed. The contract decides which one you have bought, so the questions belong before signature.
What will the service see?
Coverage comes first. Many Microsoft 365 compromises never touch an endpoint: an attacker signs in with a stolen session token, creates an inbox rule and sends invoices. An MDR service watching endpoints alone will not see that attack.
- Which telemetry sources are in scope: endpoints, servers, Entra ID sign-ins, Microsoft 365 audit and mail, Azure or AWS control plane, firewalls, SaaS applications?
- Does the service use the platform you already license, such as Defender for Endpoint or Defender for Business, or does it require its own agent?
- How are new devices and accounts brought into coverage, and how is coverage reported each month?
- What detections are written by the provider, and how are they tuned to your environment?
What can the analysts do without asking?
Ransomware operators can move from initial access to encryption in hours. A provider that detects quickly and then waits for a customer to answer the phone at 3am loses most of the value. Pre-authorised actions settle that in advance.
Ask for the list of actions the analysts may take on their own authority: isolating a host, disabling an account, revoking sessions, blocking a hash or a domain, removing a mail rule. Ask which require your approval, and how approval is sought out of hours. Ask for the escalation contacts the service holds and how often it checks they are current.
How is response time measured?
Response time clauses measure different events. Time to acknowledge an alert, time to begin investigation, time to notify the customer and time to contain are four different numbers, and a fifteen-minute figure for the first says nothing about the last.
Ask for the definitions, the service levels for each, and the measured performance against them over the last year. Ask how severity is assigned, since a service level that applies only to critical alerts depends on who decides what is critical. Ask what the analyst staffing looks like overnight and on public holidays, and whether the analysts working your alerts know your environment.
What happens when an intrusion is confirmed?
Detection and response stops at a boundary, and full incident response often sits on the other side of it. Ask where the MDR service ends: does it include root-cause investigation, scoping of data accessed, eradication and recovery, or does it hand over to a separate incident response team at an hourly rate?
If it hands over, ask to whom, at what rates, and whether that firm sits on your cyber insurer's panel. Ask what evidence the MDR service preserves and for how long, and whether it will support the Notifiable Data Breaches assessment, the 72-hour ransomware payment report under the Cyber Security Act 2024, and SOCI Act reporting where it applies. The provider does not make those decisions, and its records feed them.
Where do the data and the analysts sit?
Security telemetry contains personal information: names, email addresses, IP addresses, sometimes message content. Sending it offshore is a disclosure under Australian Privacy Principle 8, and the organisation remains accountable for how the overseas recipient handles it.
Ask where the telemetry is stored and processed, where the analysts who access it are located, which subcontractors are involved, and how long data is retained. Organisations handling government data or working toward an IRAP-assessed system should ask whether the service itself has been assessed and at what classification.
How do you leave?
Exit terms are easiest to negotiate before signature. Ask who owns the detection rules and tuning built for your environment, whether the platform licences are in your name or the provider's, what notice period applies, and how telemetry and investigation records are returned or destroyed at the end. A provider that holds the platform licences can leave you without endpoint protection on the day the contract ends.
Ask for reporting that would let you judge the service at renewal: alerts handled, true and false positives, response times against the service levels, coverage gaps and recommendations closed.
How do you compare MDR pricing?
MDR is usually priced per endpoint or per user per month, sometimes with a platform licence included and sometimes on top of licences the customer already holds. Two quotes at similar headline prices can buy very different services. Normalise them before comparing.
List what each quote covers in telemetry sources, response actions, hours of coverage and incident response hours. Note which licences you would buy from the provider and which you already own, and price the incident response that sits outside each service at a realistic number of hours for one serious incident a year. The cheapest quote for endpoint-only alerting can cost more in the year it misses a mailbox compromise.
How do you test a provider before you sign?
Ask for a sample monthly report and a redacted incident report from a real engagement. The monthly report shows what the provider measures and how plainly it writes. The incident report shows what the analysts did, how fast, and how they explained it to a customer.
Run a short proof of value where the provider allows it. Deploy the service on a subset of devices and accounts for a few weeks, then run a benign test with your own staff or a penetration tester: a suspicious sign-in from an unusual country, a new inbox forwarding rule, an encoded PowerShell command on a test machine. Record what the provider detected, when it told you, and what it did. Those results are a better guide than any service level clause.
Speak to a reference customer of a similar size in Australia, and ask them about the last incident the provider handled for them and how the provider performed at renewal.
What should be in place before you buy?
An MDR service works on top of a configured environment. Logs retained long enough to investigate, conditional access closing the obvious sign-in paths, endpoint protection deployed everywhere, and an incident response plan naming who decides. Without those, the provider spends its time on noise the configuration should have removed.
Black Shard helps organisations choose and govern security suppliers inside a vCISO engagement, including writing the requirements for an MDR tender and reading the responses against them. It also runs incident response for Australian organisations, and its managed IT service operates Microsoft 365, Azure and Cloudflare to a documented baseline. Requirements and scope are set on a free 30-minute scoping call.