Market position current as of 3 September 2026.
The word to interrogate when buying managed detection and response is “response.” Gartner’s own Market Guide for MDR Services requires that a qualified provider offer immediate remote mitigation, investigation, and containment beyond alerting and notification, and a substantial part of this market does not meet that bar while using the same three letters. Some services detect and notify you. Some will isolate a host, disable an account, or kill a process without asking. Those are different purchases with different price points, and the difference only becomes visible at two in the morning during an actual incident. We recommend you make every provider state, in writing, exactly which actions they will take unilaterally and which require your approval, because that single answer separates the market more cleanly than any feature comparison will.
Disclosure: Mindcore provides managed security services, so we are a participant in this market rather than a neutral observer of it. This page sets out how to evaluate MDR providers, including where we are a reasonable fit and where a large pure-play provider is the better answer.
Overview
- There is no Magic Quadrant for MDR. Gartner covers the category through an annual Market Guide that names representative vendors and sets evaluation criteria rather than ranking anyone.
- “Response” ranges from notification to unilateral containment. Get the specific actions in the contract.
- Endpoint-only coverage misses where attacks now live. Identity and cloud telemetry matter as much as the endpoint.
- MDR contains, it does not remediate. Root cause, rebuilds, and closing the gap remain someone else’s job.
- Onboarding decides the value. The tuning period determines whether your team reads the alerts a year from now.
The 5 Why’s
This is written for IT directors, security leads, and CISOs at organizations between roughly one hundred and a few thousand employees that cannot staff a security operations function internally. A week has 168 hours, an internal team covers a fraction of them, and the alerts that matter arrive during the hours nobody is watching. That gap is what MDR exists to fill.
The trigger is usually external. An insurer’s renewal application asks whether you have 24/7 monitoring. A customer’s vendor risk assessment asks the same. An auditor asks who reviews security alerts. A regulator or a framework requires continuous monitoring. Occasionally the trigger is an incident that nobody noticed for weeks, which is the most persuasive version and the most expensive way to reach this decision.
Sector conditions shape the requirements. Healthcare organizations need coverage that accounts for clinical systems where containment actions carry patient safety implications. Manufacturers need providers who understand that isolating a device on a production network can create a safety event. Financial services firms carry examiner expectations about monitoring and retention. Defense and aerospace suppliers need to know where analysts are located, since access to environments holding export-controlled technical data by non-US persons is a compliance problem regardless of intent.
The consequence of buying badly is a service that satisfies a questionnaire and produces alerts nobody acts on, renewed annually because cancelling it would mean explaining why it was bought.
What Counts as MDR, and What Analyst Research Actually Exists
The category has no legal definition and four distinct delivery models, which is why providers sound identical in a first meeting.
Endpoint vendor services, where your EDR vendor operates its own platform on your behalf. Deep integration with that platform, and your MDR and your endpoint choice become the same decision, so switching one means switching both.
Pure-play MDR providers, telemetry-agnostic services built as a security operations business. Usually broader source coverage and more flexibility, with integration work required.
MSSP and managed IT providers delivering MDR, which is where we sit. The advantage is that the party watching your environment is the party who can also fix what it finds. The tradeoff is scale: a regional provider does not have the threat research organisation of a global pure-play.
Platform-bundled services included with a broader security or productivity suite, often cost-effective for organizations already licensed at the right tier and narrower in telemetry scope.
On analyst research, there is no Gartner Magic Quadrant for MDR, and any vendor page implying otherwise is overstating. What exists is more useful than a ranking anyway. Gartner publishes an annual Market Guide for MDR Services which defines the category, names representative vendors, and states what a qualified service must deliver: 24/7 human-led staffing with monitoring, hunting, and threat intelligence skills; immediate remote mitigation, investigation and containment beyond alerting; human-led engagement with your data daily rather than periodically; findings framed in business risk rather than recited tool output; and validation of your requirements through an RFP and a proof of concept. That is a procurement checklist written by the analyst house, and it is more actionable than a quadrant position. Alongside it, IDC publishes a MarketScape assessment specifically for midmarket MDR services, KuppingerCole publishes a Leadership Compass, Gartner Peer Insights carries customer reviews identifiable by sector, and MITRE runs ATT&CK evaluations that provide genuine technical comparison. Participation in MITRE is voluntary, so absence is not damning, and headline detection coverage percentages say little about speed or quality of response.
One caution about your own research. The pages ranking for MDR comparisons are largely written by MDR providers ranking themselves first. The technical descriptions are often accurate. The ordering carries no information, and that applies to this page too, which is why it does not contain one.
What Does “Response” Actually Mean in Your Contract?
It means whatever the contract says, and the range is wide enough that two services at similar prices can behave completely differently during an incident.
At the weaker end, the provider detects, investigates, and notifies you, and every containment action waits for your approval. That is monitoring with an analyst attached, and it is a legitimate service for organizations with staff available to act. It is not what most buyers picture, and at three in the morning it means someone on your team has to wake up, understand the situation, and act.
At the stronger end, the provider takes defined actions unilaterally: isolating an endpoint from the network, disabling a compromised account, terminating a session, killing a process, blocking a hash. Those actions are what contain an incident inside the window that matters, and they require you to have granted permission in advance and agreed the boundaries.
Where the line should sit depends on your environment rather than on your risk appetite. Office-based organizations can generally authorise broad unilateral containment, because the worst case of an unnecessary host isolation is an inconvenienced employee. Manufacturers and healthcare providers cannot, because isolating the wrong device can stop a line or affect patient care, which means the containment matrix has to be built with plant engineering or clinical leadership in advance and will legitimately be narrower. Organizations running critical production systems often land on a hybrid: full unilateral authority in the corporate environment, notification and approval in the operational environment, with a named on-call decision maker on your side. Whatever the answer, it belongs in an authorisation matrix rather than in a conversation, and it should be tested during onboarding rather than during an incident.
What we recommend you do about it:
- Get the specific action list in writing. Isolate, disable, terminate, block. Which of these, in which environments, without asking.
- Ask for mean time to contain, not mean time to detect. Detection speed matters far less if containment waits for a callback.
- Build the authorisation matrix by environment. Corporate, production, and clinical systems warrant different answers.
- Name your on-call decision maker. Every approval-required model needs a person reachable at any hour.
- Test containment during onboarding. A tabletop or a live test in a controlled window. Do not discover the workflow during a real incident.
Does the Telemetry Cover Where Attacks Actually Happen?
Increasingly not, if the service is endpoint-only. The attack patterns that matter most now run through identity, and an endpoint agent does not see them.
The technique reshaping this is session theft. Malware or a phishing page harvests an authenticated session token, and the attacker resumes a logged-in session without a password and without triggering multi-factor authentication, because the authentication already happened. Nothing malicious runs on an endpoint. To an endpoint-focused service, that is an ordinary authenticated session. Catching it requires identity provider telemetry, sign-in risk signals, and cloud application logs, which means asking a provider precisely which sources it ingests rather than accepting a claim of comprehensive coverage. Our own view of this shift is set out in our cybersecurity practice, and it is the same argument that reorders ransomware defence away from recovery and toward access control.
The right telemetry mix depends on where your estate actually lives. Cloud-first organizations should weight identity and SaaS coverage above network telemetry, since that is where both the work and the attacks are. Organizations with a large on-premises footprint and remote access for staff or vendors need network and edge coverage, because exposed remote access remains a dominant entry path and appliance exploitation does not appear on an endpoint. Manufacturers need to ask specifically whether operational technology telemetry is in scope, and to be sceptical of yes, since monitoring a production network requires passive collection and a different skill set. Two further questions belong here regardless of estate: how long logs are retained, since discovery frequently comes weeks after the access, and whether you can export your own data, since a provider transition is much harder when the history stays behind.
What we recommend you do about it:
- Ask for the ingested source list, by name. Endpoint, identity provider, cloud applications, network, email, and operational technology.
- Weight identity coverage heavily. Stolen sessions bypass the controls most organizations assume are protecting them.
- Confirm log retention length and cost. Short default retention undermines any late investigation.
- Require data portability. Your telemetry and case history should be exportable in a usable format.
- Do not accept a general claim of full coverage. Sources are enumerable, so have them enumerated.
What Does MDR Not Do?
Remediate, patch, rebuild, or fix the condition that allowed the incident. That distinction is the most consequential thing on this page and the one most often discovered after purchase.
Containment stops the bleeding. It isolates the host, disables the account, ends the session. What it does not do is determine why the account was compromised, rebuild the machine, patch the vulnerability that was exploited, correct the permission that let an attacker move laterally, or restore the affected data. Those are engineering and operations tasks, and MDR providers are not staffed for them. Some now market remediation capability, and the sensible question is whether that means guided instructions for your team or hands actually doing the work in your environment, because those are very different offerings.
Which means MDR assumes a recipient with capacity to act. Organizations with a capable internal IT team can absorb that, and the arrangement works well. Organizations without one need to pair the monitoring with somebody who can execute, whether that is a managed IT provider, a co-managed arrangement, or an incident response retainer with a firm that will show up. This is the honest case for buying monitoring from a provider who also runs your environment, as we do through managed security services and ShieldHQ: the party who detects it is the party who can fix it, and no handoff is required at the worst moment. It is also where a large pure-play provider is genuinely the better choice, because organizations with mature internal security operations and demanding threat research requirements will get more from a specialist with a global research organisation than from a regional provider, and that is worth saying plainly.
What we recommend you do about it:
- Decide who remediates before you buy monitoring. Internal team, managed provider, or retainer. Any answer beats discovering the gap mid-incident.
- Clarify what “remediation” means in the proposal. Guidance for your team, or work performed in your environment.
- Ask what happens after containment. The handoff process, the report, and who owns root cause.
- Weigh integrated against specialist honestly. One party detecting and fixing, versus deeper threat research. Both are defensible.
- Hold a retainer if you have no internal capacity. Contracting incident response under pressure costs time you will not have.
Security Operations Expertise from Matt Rosenthal
In 30 years of building security programs, I have watched organizations buy monitoring and assume it included fixing. What I have seen firsthand is a company with a competent MDR service receiving a clean, accurate containment notification at two in the morning, and nothing happening for nine hours because nobody had decided who acts on it. Our team asks who remediates before we discuss who monitors, and we will tell a client with a mature internal security function that a large specialist provider suits them better than we do. Decide who answers the call before you decide whose call it is. See our managed security services and cybersecurity services.
How to Run the Selection
Use the analyst criteria as your requirements document rather than building one from scratch. Gartner’s Market Guide already states what a qualified service delivers, and turning those five points into RFP questions gives you a comparable basis across very different providers.
Then add the four questions that separate this market in practice. Which containment actions will you take without asking me, and in which environments. Which telemetry sources do you ingest, by name. How long is my data retained and can I export it. And who remediates after you contain, on your side or mine.
Then run a proof of concept, which the analyst guidance also recommends, and pay attention to onboarding rather than to the demo. The tuning period determines whether your team is reading alerts in twelve months or ignoring them, and a provider’s willingness to invest in that period tells you more about the relationship than any capability slide. Ask where analysts are located while you are at it, since for organizations holding export-controlled data that is a compliance question rather than a preference. This same monitoring and access-control shift is why we scope MDR alongside broader compliance work rather than as a standalone tool purchase.
If you can list your telemetry sources but cannot say who acts on an alert at three in the morning, close that gap before signing anything. Schedule a consultation to work through your monitoring and response model.
