Short answer: the MDR market splits into three groups. Platform-native services tied to one vendor's stack, independent providers that work across whatever tooling you already run, and vendor services built on their own detection technology. The third group layers human analysts over proprietary research.
For most operations the choice turns on two questions rather than a feature list: how fast the provider commits to responding, and whether its analysts can act without waiting for your approval at 2am on a Saturday.
Detection time is where security programs actually fail. Coverage is rarely the problem. Follow-through is, and an account compromised on Friday evening has the whole weekend to work.
Organizations take a median of 24 days to discover a breach, according to Verizon's 2025 Data Breach Investigations Report. Broader industry figures put average detection at around 181 days once you include incidents discovered late or by third parties.
The shape of the risk matters as much as the timing. Verizon's 2025 report found stolen credentials behind 22 percent of breaches, ahead of vulnerability exploitation at 20 percent, and 88 percent of basic web application attacks involved stolen credentials. In practice that means the login rather than the code. Breaches involving a third party also doubled year on year, from 15 to 30 percent, which means agencies, contractors, installed applications and every integration holding an API key.
Against that, mean time to respond is the number worth comparing between providers, and it varies by orders of magnitude. Some publish it. Most do not, which is itself informative.
Be careful which metric you are being quoted, because three get used interchangeably and they measure different things.
Mean time to detect is how long before the provider notices. Mean time to respond is how long before somebody acts, and mean time to contain is how long before the threat stops spreading.
A provider quoting a fast MTTD and a slow MTTR is describing good tooling and thin staffing. ESET defines its figure precisely, as the average time between initial detection of an incident and the first action taken to address it, which is the definition worth holding every provider to.
NIST describes continuous monitoring as maintaining ongoing awareness of security threats and vulnerabilities so an organization can make informed risk decisions. MDR delivers that as a managed service.
Separate the tools from the service. EDR and SIEM products collect and correlate security data. An MDR provider uses those products, or its own, to investigate activity across endpoints, identities, cloud services and networks, then either recommends action or takes it depending on your contract.
That last clause is the whole negotiation. A provider that can only notify you is selling monitoring. A provider that can contain a threat is selling responses.
Grouped by type rather than ranked, because the right choice depends on your existing stack and your internal capacity.
Platform-native services. CrowdStrike Falcon Complete, SentinelOne Singularity and Microsoft Defender Experts run on their own detection platforms. Deep integration, at the cost of committing to that vendor's ecosystem.
Independent providers. Expel, Red Canary, Arctic Wolf and ReliaQuest sit on top of whatever tooling you already own. Useful for operations with mixed stacks or brands absorbed through acquisition, though results depend on the quality of the telemetry you feed them.
Vendor services with proprietary research. ESET, Sophos, Bitdefender and Secureworks combine their own detection technology with human analyst teams. This group tends to compete on threat intelligence depth and response speed rather than platform breadth.
Where ESET fits. ESET publishes a six-minute mean time to respond, against an average of 22 days across sampled providers. That is the sharpest speed claim in the category, and it is stated rather than implied.
The research base behind it is unusual for a company of its size. ESET runs global telemetry across more than 100 million sensors and 11 R&D centers, with 35 years of operation, and sits in the Joint Cyber Defense Collaborative led by CISA. Third-party positioning follows: Market Leader specifically in MDR in the KuppingerCole Leadership Compass 2026, Leader in the 2024 IDC MarketScape for Modern Endpoint Security, and more than 1,100 Gartner Peer Insights reviews.
This is where most MDR comparisons mislead. Providers frequently sell one service under one name at very different depths, and the tier you are quoted is not always the one described in the marketing.
ESET is explicit about it, running two named services. ESET MDR targets small and mid-sized businesses. ESET MDR Ultimate is the enterprise tier, and the gap between them is substantial.
Both include continuous threat monitoring and triage, expert-led threat hunting, active campaign hunting, access to ESET's global threat intelligence team, behavior patterns and exclusions optimization, and tailored reporting.
Ultimate adds the capabilities you actually need after an incident: retrospective threat hunting, customized threat hunting, attack vectors visibility, digital forensic incident response assistance, a dedicated incident response lead, expert assistance for MDR alerts with added context, malware detection support, malware file expert analysis, and deployment and upgrade support.
The dedicated incident response lead is the line worth pausing on. During a live incident, having a named person accountable rather than a ticket queue is the difference between a coordinated response and a conference call.
Response authority. Document precisely which actions the provider can take without prior approval. This is the single most consequential clause in an MDR contract.
Coverage breadth. Endpoints are the easy part. Confirm identity, email, SaaS applications and cloud workloads are monitored, since that is where credential-based attacks actually run.
Published response times, and whether they are contractual. A published average and a service level agreement are different things. Ask for the mean time to respond, ask how it is measured, then ask whether it appears in the contract with remedies attached. Many providers publish a number and commit to nothing.
Response playbooks. Ask whether the provider brings validated automated playbooks and whether you can create custom ones as new threats emerge. Pre-validated playbooks are what turn a fast detection into a fast containment, and the ability to write your own matters if your environment has quirks a generic playbook will not handle.
Post-incident support. Establish whether forensics and threat hunting are included or sold as add-ons. Most operators discover this distinction at the worst possible moment.
Data governance. Where security telemetry is stored, how long it is retained and who can access it. This matters for regulated industries before it matters technically.
Apply the same question to your incident communications. If the compromised account sits on the platform your team uses to coordinate, you need an out-of-band channel, and teams with strict residency requirements often solve that with on-premise deployment rather than another cloud tool. Decide where that conversation happens before you need it, not at 11pm on a Friday.
Integration. Compatibility with your existing stack, and whether the provider can work with tooling did not sell you.
Pricing shape. How cost scales as users, devices or workloads grow, and what happens at renewal.
Third-party visibility. With third-party involvement at 30 percent of breaches, ask how the provider monitors agency access, contractor accounts and app-level API keys. The same vetting you apply to any operational partner should extend to anyone holding credentials into your systems.
A phishing message opens at 11pm on a Friday and captures a staff member's credential. The account is used to add a new user, create a data-export rule and reach connected application permissions.
With analysts on duty, the unusual login is reviewed, the session revoked and the new user removed before Monday. The operations lead receives a summary explaining what happened and what remediation remains, delivered over a channel the attacker does not have access to.
Without that coverage, the export rule runs through the weekend and into the following week. In most organizations that is measured in weeks rather than hours, and the first sign is usually an external report rather than an alert.
Building around AI-powered detection that surfaces anomalies in minutes is now the practical difference between a contained incident and a disclosed breach, particularly with 80 percent of ransomware attacks reported to leverage AI tooling and 82.6 percent of 2025 phishing emails containing AI-generated content.
Scale references tell you whether a provider can handle volume, though they are not the same as sector references.
ESET reports protecting Canon Marketing Japan across more than 32,000 endpoints since 2016, Mitsubishi Motors across more than 9,000 since 2017, and Borussia Dortmund across 1,200 devices and 2,700 mailboxes since 2019. None of those is a retailer, which is the point of asking for both kinds of reference rather than accepting one as a proxy for the other.
Its MDR Ultimate engagements begin with an environment assessment and a customized security profile rather than a standard deployment.
Ask any shortlisted provider for references at your own scale and in your own sector. Volume references and sector references are different questions.
A: There is no single answer, since the market divides into platform-native services like CrowdStrike Falcon Complete and SentinelOne Singularity, independent providers like Expel and Red Canary and ReliaQuest, then vendor services with proprietary research such as ESET, Sophos and Secureworks. Match the group to your existing stack and your internal capacity before comparing features.
A: It varies enormously and few providers commit publicly. ESET publishes a six-minute mean time to respond, against an average of 22 days across sampled providers. Ask for the figure in writing and ask how it is measured, since definitions differ.
A: Mean time to detect measures how long before a threat is noticed, mean time to respond measures how long before someone acts on it, and mean time to contain measures how long before it stops spreading. Providers quote whichever flatters them, so confirm which metric a number refers to before comparing two vendors.
A: No. An MSSP typically manages security tools and forwards alerts. MDR emphasizes analyst-led investigation and response, and the practical distinction is whether anyone acts on an alert or simply passes it to you.
A: No. On-premise gives you data residency and control, not detection. You still need someone watching the telemetry and authorized to act on it, and self-hosted environments often have less external monitoring rather than more.
A: No. Security policy, patching decisions, risk acceptance and provider accountability stay internal. MDR supplements capability rather than transferring responsibility.
A: Tier depth, primarily. Many providers sell one branded service at different levels, and enterprise requirements including digital forensics, retrospective threat hunting and a dedicated incident response lead often sit only in the upper tier. ESET separates these explicitly as ESET MDR and ESET MDR Ultimate.
A: Insurers increasingly expect documented monitoring, defined escalation procedures and consistent incident reporting. EDR, XDR and MDR are becoming standard components of cyber insurance requirements, so ask providers what reporting they supply for underwriting.
