The ransomware alert arrived at 1:47am. The MDR provider responded within minutes — at least, that is what the proposal promised.
The question nobody asked during procurement was simple: responded how?
That confusion appears more often than most security teams would like to admit. Many MDR services promise detection, investigation, and response. The difficult part is that providers can mean very different things when they use the word “response.”
Understanding those differences matters, because they often shape the value an organization ultimately receives from its MDR investment. For European teams balancing NIS2 obligations, hybrid environments, and growing response expectations, those operational differences become even harder to evaluate during procurement.
MDR pricing in Europe: guide and comparison toolkit
Response ownership, threat hunting scope, investigation depth, pricing benchmarks, and provider comparison worksheets for European MDR buyers.
Download the guideWhat you’ll learn:
Many MDR services detect threats in similar ways. The differences usually appear after the alert is generated.
| Stage | What happens | Where MDR providers usually differ |
|---|---|---|
| Detection | Suspicious activity is identified | Detection quality and visibility |
| Investigation | Analysts determine whether the threat is real | Investigation depth and analyst involvement |
| Containment | Action is taken to stop the threat | Endpoint isolation, response ownership, approval workflows |
| Recovery | Systems return to normal operations | Incident coordination and remediation support |
Every MDR provider participates somewhere in this chain. The difficult part is that providers do not all stop at the same point. Some investigate and escalate. Some investigate and help contain. Some actively participate throughout the incident.
That is why two MDR services can promise “response” while delivering very different operational experiences. Findings such as the ENISA Threat Landscape continue to show that organizations containing incidents more quickly typically experience lower breach impact.
MDR response models typically fall into four categories. The difference between them is not how threats are detected — it is how much investigation, containment, and incident response the provider performs after a threat is discovered.
| MDR model | What the provider does | What the customer still owns |
|---|---|---|
| Detection only | Detects threats and generates alerts | Investigation, containment, and response |
| Investigation support | Validates threats and provides guidance | Response actions and containment decisions |
| Assisted response | Investigates threats and supports containment | Final approval and some response activities |
| Active response | Investigates and performs approved response actions | Strategic oversight and business decisions |
All four models can legitimately be sold as MDR. That is why comparing MDR services based only on detection capabilities rarely tells the whole story. The real difference often appears during a live incident, when somebody must decide who investigates, who contains, and who coordinates the response.
The difference between €15 and €35 per endpoint often looks obvious during procurement. The more expensive difference is usually hidden. It appears when a threat is detected and the customer discovers that investigation, containment, or incident coordination are not included at the level they expected.
One of the most common MDR buying mistakes is assuming that every MDR service actively responds once a threat is detected. In practice, many providers stop at investigation and escalation. A lower-priced MDR service is not necessarily a bad service — the challenge is understanding whether the price reflects reduced response ownership, limited threat hunting, or operational responsibilities that remain with the customer team.
That is why experienced buyers look beyond detection coverage and ask a much simpler question: “What exactly happens after a threat is discovered?”
Compare MDR providers the operational way
Response ownership, threat hunting scope, investigation depth, and containment capabilities — side by side.
Download the guideTwo MDR providers can detect the same threat and still operate very differently once an investigation begins. The differences usually appear around ownership.
| Operational activity | Provider A | Provider B |
|---|---|---|
| Threat investigation | Included | Limited |
| Threat hunting | Continuous | Periodic |
| Endpoint isolation | Included | Customer approval required |
| Incident coordination | Included | Customer-owned |
| Ransomware response support | Included | Separate service |
| After-hours response | Active | Escalation only |
These differences rarely appear in headlines, feature lists, or sales presentations. Most become visible only when teams start asking detailed operational questions.
Most MDR evaluations eventually arrive at the same question: “What happens if this becomes a real incident?” Before signing, experienced teams typically make sure they can answer the following:
For a deeper provider evaluation process, see the How to Choose Your Cybersecurity Provider, European Edition guide, with additional operational questions, red flags, and vendor comparison frameworks.
Most MDR providers can detect threats. The bigger differences usually appear after detection — where investigation depth, containment ownership, threat hunting, and incident coordination start separating one MDR service from another. Understanding those operational differences before signing is often easier than discovering them during an active incident.
Need a second opinion before signing?
Q-Sec helps European organizations evaluate MDR providers beyond feature lists — response ownership, threat hunting maturity, containment capabilities, and hidden operational risks.
Talk to a Q-Sec expertMost MDR services watch for threats, investigate suspicious activity, and help security teams decide what to do next. The important part is that not every provider handles response the same way once a real incident begins.
Many organizations pay somewhere between €12 and €40 per endpoint each month for MDR services, while more response-focused programs often exceed €10,000–€15,000 monthly. The biggest pricing differences usually come from investigation depth and response ownership rather than monitoring alone.
Usually not the dashboard. The biggest differences tend to appear around analyst involvement, threat hunting, containment support, and who owns the response process when something serious happens.
Sometimes yes, sometimes no. One provider may actively help contain a threat, while another may stop at investigation and escalation. That is why experienced buyers always ask what “response” means operationally.
For many organizations, MDR provides access to experienced analysts and around-the-clock threat monitoring without the cost of building a full internal security operations team. The value often comes from faster investigations and fewer blind spots.