THREAT-WATCH logo

THREAT‑WATCH

MDR BUYER'S CHECKLIST

How to Evaluate an MDR Provider

A practical checklist for mid-market companies choosing a managed detection & response provider, including the NIS2 supply-chain questions a Greek buyer needs to ask that most generic vendor checklists skip.

Every MDR vendor's homepage says "24/7 monitoring" and "15-minute response." The questions below are the ones that actually separate a real security operation from a marketing page.

1. Detection & response capability

  • Is monitoring genuinely 24/7/365 with staffed analysts, or "business hours plus an on-call pager"?
  • Ask for real MTTD/MTTR numbers from their last quarter, not a marketing range.
  • Do they hunt for threats proactively, or only triage the alerts your existing tools already generate?
  • Are they vendor-agnostic, working with the EDR/SIEM/cloud stack you already have, or do they require a rip-and-replace onto their own tooling?

2. Team & staffing transparency

  • Who's actually on shift: dedicated analysts, or a shared queue spread across dozens of other clients?
  • What's the analyst-to-client ratio? A vague answer here is itself an answer.
  • During an active incident, is there a direct line to a senior analyst, or do you file a ticket and wait?
  • Can they support you in your own language and time zone for incident calls, not just email in a support portal?

3. Contract terms & SLAs

  • Are detection and response times written into the SLA with real penalties, or only stated as marketing targets?
  • If you leave, do you keep your logs, detection rules, and incident history, or does the provider keep them?
  • Which sub-processors (cloud infrastructure, SIEM vendor, ticketing system) touch your data, and are they disclosed?

4. Compliance & supply-chain fit

  • If you're in scope for NIS2, Article 21 makes the security of your suppliers your obligation, not just theirs. Will the provider hand you documentation an auditor will actually accept?
  • Will they help you hit the Article 23 reporting deadlines (24 hours / 72 hours / one month), or is that entirely on you?
  • Is the provider itself ISO 27001 or SOC 2 certified, and will they show you the certificate, not just claim it?

5. Cost structure & scaling

  • Is pricing per-endpoint, flat-fee, or tiered, and what happens to the bill when you add 50 endpoints mid-contract?
  • Is incident response included, or billed separately as a retainer you only discover you need after something's already gone wrong?

6. References & proof

  • Can they show you a real, redacted incident report, not a case-study slide?
  • Will they give you a client reference you can actually call, ideally in your sector or region?

This checklist reflects criteria we'd want answered as a buyer, plus the NIS2 Article 21 and Article 23 supply-chain obligations that apply if you're an in-scope Greek entity. General guidance, not legal advice.

Comparing us against this checklist?

Ask us every question above. We'll answer directly, including the ones other vendors dodge.