NIS2 incident response checklist: 7 updates most plans need
The ransomware alert arrived at 1:47am. The MDR provider responded within minutes — at least, that is what the proposal promised.
The question nobody asked during procurement was simple: responded how?
- Did somebody investigate the alert?
- Did somebody isolate the endpoint?
- Did somebody contact the customer team?
- Or did an automated notification simply appear in an inbox while the threat continued moving through the environment?
That confusion appears more often than most security teams would like to admit. Many MDR services promise detection, investigation, and response. The difficult part is that providers can mean very different things when they use the word “response.”
Understanding those differences matters, because they often shape the value an organization ultimately receives from its MDR investment. For European teams balancing NIS2 obligations, hybrid environments, and growing response expectations, those operational differences become even harder to evaluate during procurement.
MDR pricing in Europe: guide and comparison toolkit
Response ownership, threat hunting scope, investigation depth, pricing benchmarks, and provider comparison worksheets for European MDR buyers.
Download the guideWhat you’ll learn:
- Why MDR providers define response differently
- What usually happens after a threat is detected
- The most common MDR response models buyers encounter
- Where MDR operational responsibilities often differ
- What experienced teams clarify before signing an MDR contract
What happens after a threat is detected?
Many MDR services detect threats in similar ways. The differences usually appear after the alert is generated.
| Stage | What happens | Where MDR providers usually differ |
|---|---|---|
| Detection | Suspicious activity is identified | Detection quality and visibility |
| Investigation | Analysts determine whether the threat is real | Investigation depth and analyst involvement |
| Containment | Action is taken to stop the threat | Endpoint isolation, response ownership, approval workflows |
| Recovery | Systems return to normal operations | Incident coordination and remediation support |
Every MDR provider participates somewhere in this chain. The difficult part is that providers do not all stop at the same point. Some investigate and escalate. Some investigate and help contain. Some actively participate throughout the incident.
That is why two MDR services can promise “response” while delivering very different operational experiences. Findings such as the ENISA Threat Landscape continue to show that organizations containing incidents more quickly typically experience lower breach impact.
The four MDR response models buyers commonly encounter
MDR response models typically fall into four categories. The difference between them is not how threats are detected — it is how much investigation, containment, and incident response the provider performs after a threat is discovered.
| MDR model | What the provider does | What the customer still owns |
|---|---|---|
| Detection only | Detects threats and generates alerts | Investigation, containment, and response |
| Investigation support | Validates threats and provides guidance | Response actions and containment decisions |
| Assisted response | Investigates threats and supports containment | Final approval and some response activities |
| Active response | Investigates and performs approved response actions | Strategic oversight and business decisions |
All four models can legitimately be sold as MDR. That is why comparing MDR services based only on detection capabilities rarely tells the whole story. The real difference often appears during a live incident, when somebody must decide who investigates, who contains, and who coordinates the response.
The MDR cost buyers rarely see on the proposal
The difference between €15 and €35 per endpoint often looks obvious during procurement. The more expensive difference is usually hidden. It appears when a threat is detected and the customer discovers that investigation, containment, or incident coordination are not included at the level they expected.
One of the most common MDR buying mistakes is assuming that every MDR service actively responds once a threat is detected. In practice, many providers stop at investigation and escalation. A lower-priced MDR service is not necessarily a bad service — the challenge is understanding whether the price reflects reduced response ownership, limited threat hunting, or operational responsibilities that remain with the customer team.
That is why experienced buyers look beyond detection coverage and ask a much simpler question: “What exactly happens after a threat is discovered?”
Compare MDR providers the operational way
Response ownership, threat hunting scope, investigation depth, and containment capabilities — side by side.
Download the guideWhere MDR operational responsibilities often differ
Two MDR providers can detect the same threat and still operate very differently once an investigation begins. The differences usually appear around ownership.
| Operational activity | Provider A | Provider B |
|---|---|---|
| Threat investigation | Included | Limited |
| Threat hunting | Continuous | Periodic |
| Endpoint isolation | Included | Customer approval required |
| Incident coordination | Included | Customer-owned |
| Ransomware response support | Included | Separate service |
| After-hours response | Active | Escalation only |
These differences rarely appear in headlines, feature lists, or sales presentations. Most become visible only when teams start asking detailed operational questions.
What experienced teams clarify before signing an MDR contract
Most MDR evaluations eventually arrive at the same question: “What happens if this becomes a real incident?” Before signing, experienced teams typically make sure they can answer the following:
- Who owns containment during an active incident?
- Which response actions are included by default?
- Is endpoint isolation included or treated as a separate service?
- How often is threat hunting performed?
- What happens outside business hours?
- At what point does incident response become a separate engagement?
- Is support available for NIS2 reporting and incident documentation?
- Which operational responsibilities remain with the customer team?
For a deeper provider evaluation process, see the How to Choose Your Cybersecurity Provider, European Edition guide, with additional operational questions, red flags, and vendor comparison frameworks.
Wrapping things up
Most MDR providers can detect threats. The bigger differences usually appear after detection — where investigation depth, containment ownership, threat hunting, and incident coordination start separating one MDR service from another. Understanding those operational differences before signing is often easier than discovering them during an active incident.
Need a second opinion before signing?
Q-Sec helps European organizations evaluate MDR providers beyond feature lists — response ownership, threat hunting maturity, containment capabilities, and hidden operational risks.
Talk to a Q-Sec expertFAQ
What do MDR services actually do?
Most MDR services watch for threats, investigate suspicious activity, and help security teams decide what to do next. The important part is that not every provider handles response the same way once a real incident begins.
What does an MDR service usually cost?
Many organizations pay somewhere between €12 and €40 per endpoint each month for MDR services, while more response-focused programs often exceed €10,000–€15,000 monthly. The biggest pricing differences usually come from investigation depth and response ownership rather than monitoring alone.
What makes one MDR provider more expensive than another?
Usually not the dashboard. The biggest differences tend to appear around analyst involvement, threat hunting, containment support, and who owns the response process when something serious happens.
Do MDR providers actually respond to threats?
Sometimes yes, sometimes no. One provider may actively help contain a threat, while another may stop at investigation and escalation. That is why experienced buyers always ask what “response” means operationally.
Is MDR worth it for a mid-sized company?
For many organizations, MDR provides access to experienced analysts and around-the-clock threat monitoring without the cost of building a full internal security operations team. The value often comes from faster investigations and fewer blind spots.