Key Takeaways
- MDR (Managed Detection and Response) watches primarily your endpoints; managed XDR (MXDR) correlates and responds across endpoint, email, identity, and cloud in one service, which matters because modern attacks move between those layers.
- Detection speed is the whole game: IBM puts the average breach at 194 days to detect and another 64 to contain, so a provider's real mean-time-to-respond, not its SLA promise, is what you are buying.
- If a vendor cannot show you an incident-level report with a timeline, root cause, the actions its analysts took, and MITRE ATT&CK mapping, you are buying a black box.
- Watch the pricing model, not just the number: per-endpoint pricing is predictable, while data-volume pricing can climb without warning as your log ingestion grows.
- Go managed if you have no 24/7 coverage, and choose MXDR over endpoint-only MDR if you run Microsoft 365 or Azure and need every layer watched.
- Ask one question first: is your "response" actual containment, or just a notification that leaves the work to us?
Dozens of providers sell "MDR," but the term now covers everything from a tool that emails you alerts to a team that contains a breach at 3 a.m., and the same three letters hide wildly different response scopes. This guide lays out what MDR and managed XDR actually mean, the capabilities that separate real response from alert forwarding, what the service costs, and the questions that expose a weak vendor before you sign. It's written for the person doing the evaluating at a 50-to-500-employee business in 2026, not for a boardroom.
What Is MDR, and What Is Managed XDR (MXDR)?
Managed Detection and Response (MDR) is an outsourced service that pairs security software with a team of analysts who monitor your environment, investigate threats, and respond to them on your behalf. Managed XDR (MXDR) is the broader version of that same service: it correlates signals across endpoint, email, identity, and cloud, rather than watching endpoints in isolation. The practical difference is coverage, and coverage is what decides whether a provider catches an attack or misses the part of it that happens somewhere it wasn't looking.
What MDR Includes
MDR gives you three things a standalone tool cannot: continuous monitoring, expert-led detection, and hands-on response. A dedicated team watches your systems around the clock, so a threat that surfaces at 2 a.m. on a holiday is seen when it happens, not on Monday morning. That team uses detection technology and current threat intelligence to separate real attacks from the noise, catching patterns that signature-based tools miss. When something is confirmed, the analysts act to contain and remediate it, rather than sending you an alert and leaving the work to your staff. That last point is the one that varies most between providers, and section 6 covers how to tell real response from a notification dressed up as one.
How Managed XDR Extends It
Managed XDR extends that same model across every layer of your environment at once, because attacks rarely stay in the layer where they start. A typical intrusion begins with a phishing email, moves to the compromised user's identity, spreads into cloud applications, and lands on an endpoint, and a service watching only endpoints sees the last step with no context for the first three. MXDR correlates activity across email, identity, cloud, and endpoints so a suspicious login in one place connects to a file access in another before either becomes a breach. For a business running Microsoft 365 and Azure, that cross-layer correlation is the difference between spotting lateral movement early and reconstructing it after the damage is done.
MDR vs MXDR vs EDR vs MSSP: Terms Defined
These four acronyms get used interchangeably in sales calls, but they describe different services with different response scopes. Here is what each one actually means.
The distinction that matters most for a mid-market business running Microsoft 365 with no 24/7 security team is response ownership. An EDR tool or an MSSP still leaves your staff to act on what surfaces, which fails the moment an attack lands outside business hours. MDR closes that gap but often only on endpoints, so an attacker who enters through email and moves to identity can slip through the layers it doesn't watch. For a Microsoft-run environment where threats cross from email to identity to cloud, MXDR is the model that matches the way attacks actually move, provided the provider covers every layer and owns the response rather than forwarding it.
Who Actually Needs MDR or MXDR
MDR and MXDR are not a fit for everyone, and the deciding factor is usually whether you can watch and respond to threats around the clock with the team you already have. Four groups typically can't, and each has a clear signal that tips the decision.
- Enterprise Security Teams
Large organizations turn to MDR to extend a security team that already exists but can't cover everything. The signal here is a capable in-house team spending its nights and weekends on alert triage instead of the strategic work only it can do; a provider absorbs the 24/7 monitoring so internal analysts focus on higher-value investigation.
- Small and Mid-Sized Businesses
For most SMBs and mid-market companies, MDR is the only realistic way to get enterprise-grade coverage without building a security operations center. The concrete signal is simple: no one is watching your environment between 6 p.m. Friday and 9 a.m. Monday. Building 24/7 coverage in-house means five or more analyst hires plus SIEM infrastructure, which is why the managed model exists, and it's the reason a business of 50 to 500 employees can get the same protection an enterprise runs for a fraction of the cost.
- MSPs and MSSPs
Managed service providers use MDR to offer security their clients demand without building a SOC of their own. The signal is a client base asking for 24/7 monitoring the MSP can't currently deliver; a white-label SOC built for MSP partners lets them add the service under their own brand with no capital outlay or security hiring.
- Regulated Industries
Businesses under HIPAA, PCI-DSS, or GDPR need MDR because those frameworks require continuous monitoring and documented response, not just preventive tools. The signal is any obligation to produce audit evidence of who accessed what and how an incident was handled; MDR supplies both the monitoring and the incident records that auditors expect. Healthcare is the clearest case, where most breaches start with a phishing email rather than malware, so coverage across email and identity, not just endpoints, is what the regulation effectively demands.
The Eight Capabilities That Separate Real MDR From Alert Forwarding
Every provider claims detection and response. The gap between a real MDR service and a glorified alert feed shows up in eight specific capabilities, and each one has a red flag that tells you the service stops short.
The baseline the 2025 Gartner Market Guide for MDR holds providers to is narrow and worth stating plainly: real MDR means 24/7 human-led staffing, immediate remote containment within preapproved limits, and a service that engages with your data every day, and a provider that cannot meet all three is offering monitoring, not managed response. Active containment is the line that separates the two. If a provider's "response" is a recommendation you still have to execute, you are carrying the risk the service was supposed to take off your hands, and that gap is widest at 3 a.m. on a weekend, which is exactly when attackers move.
What Transparent Remediation Reporting Looks Like
Transparent reporting is the clearest signal of whether a provider actually did the work or just watched it happen. Good threat remediation reporting shows you what was found, why it mattered, what the analysts did about it, and what you still need to do, at the level of the individual incident. A provider that can produce that on demand is accountable for its response; one that can't is asking you to take its word.
The Five Artifacts Every Incident Report Should Contain
A complete incident report answers five questions, and each one maps to an artifact you should expect to see:
- Detection timestamp and full timeline: When the threat was first seen, and every step from detection to containment in order, so you can measure real response time against the SLA you were sold.
- Root cause analysis: How the attacker got in and how far they moved, not just which alert fired, so the same gap doesn't get exploited twice.
- Analyst actions taken: The specific containment steps the provider executed on your behalf, such as isolating a host or revoking a session, distinct from steps left for your team.
- MITRE ATT&CK mapping: The attacker's techniques tied to the industry-standard framework, which turns a one-off incident into something your team and your auditors can interpret.
- Remediation plan with a named owner: The prioritized fixes that remain, each assigned to a specific person or team, so nothing falls into the gap between "provider handled it" and "we assumed they did."
CyberQuell delivers every confirmed incident as a written forensic report built on exactly these five artifacts, with the full timeline, root cause, analyst actions, and MITRE ATT&CK mapping in one document. That is the standard the section describes, not an upsell.
The Black-Box Test
The fastest way to expose a weak provider is to ask why a specific alert was or wasn't escalated. A transparent provider can show you the reasoning, the evidence, and the decision. A black-box provider gives you a monthly PDF of alert counts with no incident-level detail, no visibility into investigations as they happen, and no way to tell whether a quiet month means you were safe or means nothing was being watched closely. If you cannot see the work, you cannot verify the response, and you are paying for reassurance rather than security.
Seeing exactly what a provider found and how they handled it is easier when you know what your own environment looks like first, and a CyberQuell security assessment maps your current alert volume, coverage gaps, and response readiness so you can judge any MDR proposal against real baselines rather than promises.
What MDR and MXDR Actually Cost
MDR and MXDR are almost always quoted, not listed, because the price depends on how big your environment is and how much of it the provider has to watch. That makes the pricing model more important than any single number, because two providers can quote the same headline figure and bill you very differently as you grow. Here is how the pricing works, what tends to sit outside it, and how the cost compares to building the same coverage yourself.
The Three Pricing Models
Most providers price on one of three bases, and each behaves differently as your business scales:
- Per-endpoint: You pay for each device monitored. Predictable and easy to forecast, since the cost only moves when your device count does.
- Per-user: You pay for each person covered. Also predictable, and often a better fit when users have multiple devices, since it doesn't penalize a laptop-plus-desktop-plus-phone footprint.
- Data-volume: You pay for the amount of log data ingested and analyzed. This is the one to watch: as you add cloud services, identity logs, and network telemetry, ingestion grows, and the bill grows with it, sometimes without warning. At SIEM ingestion scale, data-volume pricing is the hardest of the three to forecast, and it can turn a low starting quote into an unpredictable annual cost.
Ask which model a provider uses before you compare quotes, because a cheaper per-endpoint number and a cheaper data-volume number are not comparable figures.
What's Usually Excluded
The subscription rarely covers everything, and the exclusions are where surprise costs live. Confirm in writing whether each of these is included or billed separately:
- Incident response retainers: Some providers include response in the subscription; others charge a separate retainer or a per-incident fee when a real breach hits.
- Digital forensics:Deep post-incident investigation is often a paid add-on rather than part of standard reporting.
- Log retention beyond a set window: Retention past the included period (frequently short) can carry an extra charge, which matters if your compliance obligations require longer.
- After-hours or higher-severity response tiers: "24/7" sometimes means monitoring around the clock but faster response only during business hours, with the premium tier priced separately.
A quote that looks lower than a competitor's is often lower because more of these sit outside it.
The In-House Comparison
The reason the managed model exists is that building equivalent coverage in-house is expensive in a way that is easy to underestimate. Round-the-clock coverage is 168 hours a week, and one analyst working a standard 40-hour week covers less than a quarter of that, so continuous single-seat coverage takes roughly 4.2 full-time analysts before you account for paid time off, holidays, sick leave, training, and backfilling attrition, and before you have more than one person on shift during an actual incident. Add SIEM infrastructure and detection engineering on top of those salaries, and first-year cost for a genuine 24/7 in-house security operation typically exceeds $300,000. Against that, a managed service delivers the same coverage for a fraction of the figure, with no hiring and no ramp-up.
The cost of not having that coverage is the other half of the math. IBM's Cost of a Data Breach report puts the average breach lifecycle at 241 days, 181 to identify and another 60 to contain, and every one of those days is time an attacker spends inside an environment nobody is actively watching. The question is not only what MDR costs, but what the gap it closes would have cost you.
Questions Vendors Hope You Won't Ask
Most vendor conversations stay on comfortable ground: features, dashboards, threat intelligence feeds. The questions that actually separate providers are the ones that expose where a service stops. Ask these eight, and watch how quickly a polished pitch either holds up or starts hedging.
- Is your "response" containment, or just notification? This is the single most important question, because "response" is the word providers stretch the most. If the answer is that they alert you and you act, you are buying monitoring, not managed response.
- What's your analyst turnover, and will I get a consistent pod or whoever's on shift? An analyst who knows your environment catches things a rotating stranger misses. High turnover and a random-shift model mean every incident starts from zero context.
- Do I get raw data access, or dashboard-only? Dashboard-only means you see what the provider chooses to show you. Raw access means you can verify their work and investigate independently when it matters.
- What triggers a per-incident fee on top of the subscription? Some providers include response in the price; others bill separately the moment a real incident starts, which is exactly when you have no leverage to negotiate.
- What happens to my custom detections if I leave? Detection rules tuned to your environment are valuable, and some providers treat them as their property. If you can't take them with you, you're locked in by your own security investment.
- Can you show me an actual redacted incident report? A provider proud of its reporting will show you a sample without hesitation. Reluctance here tells you the reporting is thinner than the sales deck implies.
- Who is on shift at 3 a.m. Sunday, and in what region? "24/7" can mean a full analyst team overnight or a skeleton crew forwarding alerts until morning. Ask where the coverage physically sits and who is actually awake during your off-hours.
- How do you price when my endpoint or data volume grows? The starting quote matters less than the scaling curve. A provider on data-volume pricing can look cheap at signup and expensive a year later, so get the growth math in writing before you commit.
If a provider answers all eight cleanly and puts the answers in the contract, you are talking to a real one. If the answers get vague, that vagueness is your data.
Integration With Your Existing Stack
A good MDR or MXDR provider layers on top of the tools you already run rather than forcing you to replace them. The mechanism is bi-directional API integration: the service ingests telemetry from your existing tools and can push response actions back through them, so you keep your investments and gain a managed team on top. If a provider requires ripping out what you have to deploy their preferred platform, that is a cost and a lock-in risk worth questioning before anything else.
Against a SIEM (Security Information and Event Management), MDR and MXDR fill the two gaps a SIEM leaves open. A SIEM collects and correlates log data well but doesn't investigate or respond on its own, so the provider adds the human analysis and the response layer that turn a stream of alerts into contained incidents.
Against an EDR (Endpoint Detection and Response) tool, the provider adds managed depth on top of the endpoint visibility you already have. Your EDR detects threats at the device level; the service brings 24/7 investigation and containment, including for the endpoint threats that would otherwise sit in a queue until someone noticed.
Against cloud platforms like AWS, Azure, and GCP, the provider extends monitoring to telemetry an on-premises setup never sees: misconfigurations, identity and access anomalies, and suspicious API activity. Cloud attacks look different from endpoint attacks, and a service correlating cloud signals with the rest of your environment catches the lateral movement between them.
What This Looks Like in a Microsoft Environment
If your business runs on Microsoft 365 and Azure, managed XDR has a concrete shape rather than a generic one, and knowing that shape tells you exactly what a provider should be doing. The correlation layer is Microsoft Sentinel, the cloud-native SIEM, which ingests logs from across your Microsoft 365 and Azure environment and ties events together into a single timeline. Detection sits with Microsoft Defender XDR, which spans endpoint, email, identity, and cloud applications, so a phishing email, the identity it compromises, and the endpoint it lands on via Microsoft Defender are seen as one attack rather than three disconnected alerts.
Between detection and a human analyst sits automated investigation and response (AIR), a Defender XDR capability that handles the first pass on common threats: it investigates an alert, decides whether it's real, and takes routine containment actions automatically. That means the obvious incidents are contained in seconds, and analysts spend their time on the ones that actually need judgment, which is what keeps a 15-minute response SLA realistic rather than aspirational.
The division of labor is clean, and it should be spelled out in any Microsoft-environment engagement. The provider owns detection engineering, the Sentinel and Defender configuration, 24/7 monitoring, and response. You keep tenant control: the provider operates inside your environment, but the keys stay with your IT admin. Nothing about the managed model requires handing over ownership of your Microsoft tenant.
This is also where the market is moving, which is worth knowing as a buyer. Platform vendors that historically sold stack-agnostic MDR now ship dedicated Microsoft variants, with at least one major provider launching an MDR-for-Microsoft offering in January 2026. When vendors build a product specifically for Microsoft-native telemetry, it's a signal that mid-market buying has concentrated there, and that a provider fluent in Sentinel and Defender is now the baseline expectation for a Microsoft shop, not a bonus.
How to Run the Selection: A 5-Step Process
Once you know what real MDR looks like, choosing a provider comes down to a repeatable process rather than a gut call. Run these five steps in order, and the shortlist narrows itself.
- Inventory what you're protecting. Count your endpoints, your users, and your compliance obligations, because those three numbers drive both the price you'll be quoted and the coverage you actually need. Walk into vendor conversations with them already in hand, or every quote you get back will be a guess.
- Shortlist by stack fit. Match providers to the environment you already run, since a service fluent in your tools reaches full value faster and misses less. If you run Microsoft 365 and Azure, weigh providers with genuine Sentinel and Defender depth first, rather than a generalist bolting Microsoft support on as an afterthought.
- Demand evidence, not promises. Ask for a sample redacted incident report and real mean-time-to-detect and mean-time-to-respond figures from actual engagements, not the SLA targets on the sales sheet. A provider that can show you its real numbers is confident in them; one that only quotes SLAs is selling you the goal, not the track record.
- Pilot before you commit. A paid pilot on your own environment tells you more than any demo, because it shows how the provider performs against your real traffic and your real alerts. Use it to test response times, reporting quality, and how the team communicates during an actual event.
- Lock the terms in the contract. Put response times by severity tier, data ownership, and offboarding in writing before you sign, so the commitments survive past the sales relationship. Confirm you can leave with your custom detections and your data, and that "24/7 response" is defined precisely enough to hold the provider to it.
Why CyberQuell's MXDR
Everything above is how to judge any provider. Here is how CyberQuell measures against it, in numbers rather than adjectives. CyberQuell's managed XDR service runs on Microsoft Sentinel and Defender XDR, carries a 15-minute response SLA on critical alerts, 24 hours a day, 365 days a year, and backs it with 99.9% uptime and analyst coverage that never goes to voicemail. Most environments go live within 72 hours of signing, with no hardware to install.
Every confirmed incident comes back as a written forensic report mapped to the MITRE ATT&CK framework, the same five-artifact standard section 7 described: timeline, root cause, analyst actions, technique mapping, and a remediation plan with an owner. You can test all of it before committing, through a 30-day paid pilot on your own environment rather than a demo on someone else's.
What that looks like in practice: in one engagement, a threat actor held persistent access to a client's Microsoft 365 mailbox for four months, survived multiple prior remediation attempts, and used that foothold to orchestrate fraudulent payment requests exceeding $150,000. CyberQuell's forensic investigation traced the persistence to stolen session tokens and malicious inbox rules that credential resets alone had never cleared, eradicated it, and closed the incident with zero financial loss.
Final Thoughts
The MDR market rewards providers who use the right words and punishes buyers who don't check what's behind them. Everything in this guide comes down to one habit: make providers prove the claim. "Response" should mean containment, "24/7" should mean staffed at 3 a.m. Sunday, "reporting" should mean an incident-level report you can actually read, and "included" should be written into the contract. A provider that answers those cleanly is rare, and worth the search. The decision in front of you now is whether your current setup would catch and contain an attack tonight, and if the answer is no, or you're not sure, that gap is the thing to close first.
If you want that judged against your real environment rather than a sales deck, book a call with CyberQuell. We'll map your current coverage, show you where the gaps are, and walk you through exactly what our 15-minute-SLA managed XDR would watch, on Microsoft Sentinel and Defender, with a 30-day pilot before you commit to anything.



