Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Choose a managed detection and response (MDR) provider by checking whether it can see the activity that matters in your environment, investigate it, reach the right people, and take the response actions you authorize. Compare coverage and service-level agreements (SLAs) using the same definitions, then test the complete service path in a controlled exercise. A broad integration list, an ATT&CK coverage percentage, or a fast-sounding response promise is not enough on its own.

1. Define what the provider must protect and do

Start with your environment and operating boundaries—not a vendor’s list of supported products. Document the systems and business services that matter, the threats you are most concerned about, the tools you already own, and the work your internal team can handle. That lets you distinguish a real service gap from a feature you would be paying for twice.

Build an inventory around business risk

Include the assets and telemetry sources that are relevant to your organization, such as:

  • User endpoints and servers, including important operating environments.
  • Identity systems, email, cloud workloads, and business applications.
  • Network telemetry and operational technology (OT), where applicable.
  • Existing endpoint detection and response (EDR), extended detection and response (XDR), security information and event management (SIEM), and ticketing tools.

Mark critical business services, likely threat scenarios, compliance obligations, acceptable data locations, and incident contacts. Also record which containment actions the provider may take independently and which require your approval. Identify after-hours coverage and specialist response needs your staff cannot meet.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
FortiGate-40F Firewall Appliance - 5 Gigabit Ethernet RJ45 Ports, Ideal for Small Businesses (Appliance Only, No Subscription) (FG-40F)
  • Compact and Efficient Design: The FortiGate 40F is designed for small to mid-sized businesses and enterprise branch offices, featuring a compact, fanless desktop form factor that ensures quiet operation and minimizes space usage.
  • Robust Connectivity Options: Equipped with 5 GE RJ45 ports, including 1 WAN port and 4 internal ports, this model provides essential connectivity and flexibility for various network configurations in a small-scale environment.
  • High-Performance Security: Offers up to 1 Gbps IPS throughput and 600 Mbps threat protection throughput, using Fortinet’s purpose-built security processor technology to deliver industry-leading performance and protection for SSL encrypted traffic.
  • Advanced Threat Protection: Integrated with Fortinet’s AI-powered FortiGuard Labs, the FortiGate 40F offers comprehensive cybersecurity, identifying and mitigating both known and unknown threats to maintain robust security across your network.
  • Simplified Management and Deployment: Features a user-friendly management console that provides comprehensive network automation and visibility, coupled with Zero Touch Integration with Fortinet’s Security Fabric for easy deployment.

Account for selection and operating requirements

NIST SP 800-35 treats security-service selection, implementation, and management as a lifecycle. Its 2003 guidance discusses factors including service arrangements, provider qualifications, operational requirements and capabilities, experience, viability, employee trustworthiness, and the provider’s ability to protect the organization’s systems and information. It is broad security-service guidance, not an MDR-specific standard.

Use those factors alongside your own requirements. For example, a provider might offer a technically capable service that is unsuitable because its data handling, integrations, operating model, or response authority do not fit your organization.

2. Make detection coverage concrete

Ask every candidate to map your actual assets and telemetry to its service. “We support this product” does not establish that your deployment is monitored, that an analyst can investigate it, or that the provider can respond through it. Coverage can depend on licensing, sensors, configuration, deployment mode, integrations, and the specific work included in the service.

Request an asset-and-telemetry coverage matrix

Have the provider fill out a matrix for each relevant asset class and data source. Require evidence or a precise explanation for each answer; do not accept an integration logo as proof of operational coverage.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
What to record Questions for the provider
Asset or data source Which of our endpoints, identities, email systems, cloud services, applications, network sources, or OT systems are included?
Prerequisites Which agent, product license, connector, deployment mode, permissions, and configuration are required?
Telemetry and detection What data is collected, what types of activity can be detected, and what cannot be seen?
Investigation and response Can analysts correlate this source with other sources? Which response actions are supported, and who is allowed to perform them?
Dependencies and exclusions What depends on another tool, customer access, approval, or a separately purchased service? Which assets or situations are out of scope?
Data handling Where is data processed and stored, how long is it retained, and what contractual terms apply to location and handling?
Coverage health How are offline assets, missing sensors, failed connectors, and misconfigurations identified, reported, and corrected?

Compare the completed matrices across candidates. Look for breadth of relevant sources, completeness across your environment, ability to investigate activity across domains, integration with your existing tools, applicable data-residency terms, and a clear process for surfacing and fixing gaps. A provider can list many integrations while still omitting an important asset or response action in your specific deployment.

Rank #2
FortiGate-60F Network Security Appliance Plus 1 Year FortiGuard Unified Threat Protection (UTP) and FortiCare Premium (FG-60F-BDL-950-12)
  • HARDWARE PLUS SECURITY SERVICES: FortiGate-60F Firewall Appliance bundled with 1 year of FortiCare Premium and FortiGuard Unified Threat Protection.
  • UNIFIED THREAT PROTECTION (UTP): Secures against advanced online threats with comprehensive web filtering and anti-botnet technologies.
  • OPTIMIZED FOR MEDIUM-SIZED BUSINESSES: Tailored for businesses needing robust security without the infrastructure of larger enterprises.
  • RELIABLE CUSTOMER SUPPORT: FortiCare Premium ensures high-quality support and service continuity.
  • EFFECTIVE PROTECTION: Employs advanced filtering technologies to safeguard against sophisticated threats.

Separate platform capability from provider authority

A security product’s technical ability to isolate a device or disable an account does not prove that the MDR team is permitted to do so. Confirm the product’s deployment mode, provider permissions, customer approval requirements, playbooks, and the actions available during an incident. Put the allowed actions and approval path in writing.

Microsoft’s Defender Experts documentation illustrates how service scope can depend on configuration: it says eligible Defender products must be licensed and properly deployed, and that active-mode products are fully covered while passive-mode products may be non-actionable. For passive-mode products, the documentation describes guided response as possible but provider remediation as unavailable. Those are Microsoft-specific conditions, not a general rule for MDR services. Microsoft also lists service prerequisites and exclusions, which should be checked against the buyer’s actual setup.

CIS provides a different example: its public service page describes endpoint deployment, continuous SOC monitoring, and access to incident-response assistance, and limits eligibility to U.S. state, local, tribal, and territorial government entities. That restriction applies to the described CIS service and should not be generalized to other providers.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

3. Write SLAs around distinct operational events

Require the proposal and contract to distinguish detection, acknowledgment, investigation, customer notification, containment, remediation, and platform availability. They are different events; one “response time” can conceal where time is actually spent. For each commitment, define its start and stop events, applicable hours, severity rules, customer dependencies, evidence, and remedy for a miss.

Compare each clock on the same terms

Measure Define before comparing proposals
Detection What event starts measurement, what counts as detection, and how are missed detections handled or reviewed?
Acknowledgment Does the clock start with an event, an alert, or the provider’s receipt of an alert? What qualifies as acknowledgment?
Investigation Does the commitment cover starting an investigation or reaching a finding? What constitutes completion, and how is a complex case treated?
Customer notification Is the clock measured from detection, confirmation, or severity assignment? Which channel and contacts are used?
Containment Does the measure cover recommending, initiating, or completing an approved action? How do approval and access dependencies affect the clock?
Remediation Which remediation work is the provider responsible for, and what is outside its scope?
Platform availability How is portal or service availability measured, and how is it reported separately from incident handling?

Also specify severity levels, who assigns them, business hours and holidays, escalation contacts, notification channels, exceptions, customer dependencies, reporting evidence, and the consequence of missing each contractual commitment. Ask what happens if the provider fails to detect an event or escalates it incorrectly, and how corrective service improvements are documented.

Rank #3
Sale
GL.iNet GL-MT5000 Brume 3 Wired VPN Security Gateway NO Wi-Fi
  • 【Up to 1100 Mbps VPN Speed 】 Hardware-accelerated WireGuard and OpenVPN-DCO deliver up to 1100 Mbps VPN throughput, over 3× faster than Brume 2 for smooth remote access and file transfers.
  • 【Three 2.5G Ports & Multi-WAN】Tri-port 2.5GbE design with flexible WAN LAN configuration supports multi-gigabit wired setups, dual-ISP Multi-WAN and failover to keep home and SOHO networks online.
  • 【Stealth VPN Obfuscation】VPN obfuscation disguises VPN traffic as regular HTTPS, helping you evade blocking, bypass restrictive networks and maintain stable, private connections.
  • 【DPI protection】Deep Packet Inspection with visual dashboards blocks adult/gambling/malicious sites, while SQM and QoS prioritize gaming, calls, and video when bandwidth is tight
  • 【OpenWrt & USB 3.0 Expansion】OpenWrt with 1GB DDR4 and 8GB eMMC lets you install plugins and build VPN, ad-blocking or NAS, while USB 3.0 Type‑C connects high-speed storage or 4G/5G dongles

Do not assume that a stated target is binding. Label each measure as a contractual SLA or a service-level objective (SLO), and ask what remedy follows a missed SLA. CRITICALSTART’s 2024 buyer guide recommends contractual SLAs for detection, response, and containment rather than relying on SLOs; this is vendor-authored purchasing guidance, not evidence of an industry-wide standard.

A surfaced NTT Samurai MDR service description distinguishes portal availability from incident reporting and measures reporting after severity determination. The document is marked superseded, so it can illustrate why contract definitions matter but should not be used as a current or typical benchmark.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Set targets from your impact and operating model

The reviewed material establishes no universal numerical MDR response target. Set any target according to the business impact of delay, your threat scenarios, your internal team’s capacity, and the provider’s actual service scope. Before comparing numbers in two proposals, make sure they measure the same event under the same clock rules and operating hours.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

4. Test the entire service path safely

A provider’s claim should be tested against an authorized, repeatable exercise—not an uncontrolled action against production systems. Scope the exercise to relevant systems and behaviors, and make sure the provider and your own team understand what is permitted.

Agree on authorization and safety controls

Before execution, document the time window, included and excluded assets, test contacts, safety controls, stop conditions, and the provider and customer actions that are allowed. Use synchronized time sources and capture evidence so elapsed time and handoffs can be reviewed consistently.

Rank #4
Ubiquiti Cloud Gateway Ultra (UCG-Ultra)
  • Runs UniFi Network for full-stack network management
  • Manages 30+ UniFi Network devices and 300+ clients
  • 1 Gbps routing with IDS/IPS
  • Multi-WAN load balancing
  • 0.96" LCM status display

Follow each behavior from telemetry to response

  1. Confirm the required telemetry was available from the system where the behavior was exercised.
  2. Check whether the provider detected it and whether the alert was meaningful and contextualized.
  3. Review how analysts triaged, investigated, and correlated the activity with other available evidence.
  4. Verify that the correct contacts were notified through the agreed channels.
  5. Confirm whether the agreed containment action was initiated or completed, and measure it using the contract’s defined clock.
  6. Record missed detections, false positives, escalation delays, customer dependencies, and corrective owners; retest after remediation or material changes.

MITRE ATT&CK Evaluations can help organize questions about behavior and technique coverage, detection precision, speed, alert context, and false-positive validation. Its Enterprise round-8 page describes a structured, scenario-specific evaluation; results are not a universal guarantee or a substitute for testing the buyer’s environment. The page described publication as planned for December 2026, so its schedule and results status are time-sensitive.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Treat ATT&CK mapping as a way to structure evidence, not as a single score for protection. Ask for evidence at the technique and alert level, together with false-positive context, and interpret it in light of the behaviors relevant to your organization and the telemetry actually deployed.

5. Evaluate the service relationship and full cost

Coverage and SLAs will not reveal whether the provider can operate effectively with your team over time. Ask for a demonstration using likely workflows, references from comparable customers, sample reports, escalation runbooks, and an onboarding plan with milestones. Request information about SOC staffing and analyst qualifications, customization, incident management, and how the service scales as your environment changes.

Review data processing and residency terms, integration details, contract exit provisions, and how data is returned or handled at the end of the service. Make pricing assumptions explicit, including implementation, required licenses or tools, asset or data-volume thresholds, optional response services, and incident-retainer fees. Compare the total cost of delivering the scope you need—not just the headline service price.

KPMG’s 2023 MDR selection guide recommends evaluating experience and capabilities, service quality and pricing, staffing, data collection and hosting, integration with existing tools, customization, onboarding, reporting, SLAs, incident management, and references. It is advisory guidance rather than a comparative market study, so use it as a checklist rather than a ranking of providers.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

6. Use a consistent decision record

For each candidate, retain the completed coverage matrix, proposed SLA definitions, exercise results, data-handling terms, onboarding plan, references, and cost assumptions. Note unresolved gaps and who owns each one. This gives stakeholders a shared basis for deciding whether to accept a limitation, fund a change, or reject the proposal, and prevents a persuasive demonstration from standing in for evidence about day-to-day service.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.