Q-Sec Blog

MDR services explained: what happens after a threat is detected?

Written by V. Garbar | 22 Jun, 2026

The ransomware alert arrived at 1:47am. The MDR provider responded within minutes — at least, that is what the proposal promised.

The question nobody asked during procurement was simple: responded how?

  • Did somebody investigate the alert?
  • Did somebody isolate the endpoint?
  • Did somebody contact the customer team?
  • Or did an automated notification simply appear in an inbox while the threat continued moving through the environment?

That confusion appears more often than most security teams would like to admit. Many MDR services promise detection, investigation, and response. The difficult part is that providers can mean very different things when they use the word “response.”

Understanding those differences matters, because they often shape the value an organization ultimately receives from its MDR investment. For European teams balancing NIS2 obligations, hybrid environments, and growing response expectations, those operational differences become even harder to evaluate during procurement.

MDR pricing in Europe: guide and comparison toolkit

Response ownership, threat hunting scope, investigation depth, pricing benchmarks, and provider comparison worksheets for European MDR buyers.

Download the guide

What you’ll learn:

  • Why MDR providers define response differently
  • What usually happens after a threat is detected
  • The most common MDR response models buyers encounter
  • Where MDR operational responsibilities often differ
  • What experienced teams clarify before signing an MDR contract

What happens after a threat is detected?

Many MDR services detect threats in similar ways. The differences usually appear after the alert is generated.

StageWhat happensWhere MDR providers usually differ
DetectionSuspicious activity is identifiedDetection quality and visibility
InvestigationAnalysts determine whether the threat is realInvestigation depth and analyst involvement
ContainmentAction is taken to stop the threatEndpoint isolation, response ownership, approval workflows
RecoverySystems return to normal operationsIncident coordination and remediation support

Every MDR provider participates somewhere in this chain. The difficult part is that providers do not all stop at the same point. Some investigate and escalate. Some investigate and help contain. Some actively participate throughout the incident.

That is why two MDR services can promise “response” while delivering very different operational experiences. Findings such as the ENISA Threat Landscape continue to show that organizations containing incidents more quickly typically experience lower breach impact.

The four MDR response models buyers commonly encounter

MDR response models typically fall into four categories. The difference between them is not how threats are detected — it is how much investigation, containment, and incident response the provider performs after a threat is discovered.

MDR modelWhat the provider doesWhat the customer still owns
Detection onlyDetects threats and generates alertsInvestigation, containment, and response
Investigation supportValidates threats and provides guidanceResponse actions and containment decisions
Assisted responseInvestigates threats and supports containmentFinal approval and some response activities
Active responseInvestigates and performs approved response actionsStrategic oversight and business decisions

All four models can legitimately be sold as MDR. That is why comparing MDR services based only on detection capabilities rarely tells the whole story. The real difference often appears during a live incident, when somebody must decide who investigates, who contains, and who coordinates the response.

The MDR cost buyers rarely see on the proposal

The difference between €15 and €35 per endpoint often looks obvious during procurement. The more expensive difference is usually hidden. It appears when a threat is detected and the customer discovers that investigation, containment, or incident coordination are not included at the level they expected.

One of the most common MDR buying mistakes is assuming that every MDR service actively responds once a threat is detected. In practice, many providers stop at investigation and escalation. A lower-priced MDR service is not necessarily a bad service — the challenge is understanding whether the price reflects reduced response ownership, limited threat hunting, or operational responsibilities that remain with the customer team.

That is why experienced buyers look beyond detection coverage and ask a much simpler question: “What exactly happens after a threat is discovered?”

Compare MDR providers the operational way

Response ownership, threat hunting scope, investigation depth, and containment capabilities — side by side.

Download the guide

Where MDR operational responsibilities often differ

Two MDR providers can detect the same threat and still operate very differently once an investigation begins. The differences usually appear around ownership.

Operational activityProvider AProvider B
Threat investigationIncludedLimited
Threat huntingContinuousPeriodic
Endpoint isolationIncludedCustomer approval required
Incident coordinationIncludedCustomer-owned
Ransomware response supportIncludedSeparate service
After-hours responseActiveEscalation only

These differences rarely appear in headlines, feature lists, or sales presentations. Most become visible only when teams start asking detailed operational questions.

What experienced teams clarify before signing an MDR contract

Most MDR evaluations eventually arrive at the same question: “What happens if this becomes a real incident?” Before signing, experienced teams typically make sure they can answer the following:

  • Who owns containment during an active incident?
  • Which response actions are included by default?
  • Is endpoint isolation included or treated as a separate service?
  • How often is threat hunting performed?
  • What happens outside business hours?
  • At what point does incident response become a separate engagement?
  • Is support available for NIS2 reporting and incident documentation?
  • Which operational responsibilities remain with the customer team?

For a deeper provider evaluation process, see the How to Choose Your Cybersecurity Provider, European Edition guide, with additional operational questions, red flags, and vendor comparison frameworks.

Wrapping things up

Most MDR providers can detect threats. The bigger differences usually appear after detection — where investigation depth, containment ownership, threat hunting, and incident coordination start separating one MDR service from another. Understanding those operational differences before signing is often easier than discovering them during an active incident.

Need a second opinion before signing?

Q-Sec helps European organizations evaluate MDR providers beyond feature lists — response ownership, threat hunting maturity, containment capabilities, and hidden operational risks.

Talk to a Q-Sec expert

FAQ

What do MDR services actually do?

Most MDR services watch for threats, investigate suspicious activity, and help security teams decide what to do next. The important part is that not every provider handles response the same way once a real incident begins.

What does an MDR service usually cost?

Many organizations pay somewhere between €12 and €40 per endpoint each month for MDR services, while more response-focused programs often exceed €10,000–€15,000 monthly. The biggest pricing differences usually come from investigation depth and response ownership rather than monitoring alone.

What makes one MDR provider more expensive than another?

Usually not the dashboard. The biggest differences tend to appear around analyst involvement, threat hunting, containment support, and who owns the response process when something serious happens.

Do MDR providers actually respond to threats?

Sometimes yes, sometimes no. One provider may actively help contain a threat, while another may stop at investigation and escalation. That is why experienced buyers always ask what “response” means operationally.

Is MDR worth it for a mid-sized company?

For many organizations, MDR provides access to experienced analysts and around-the-clock threat monitoring without the cost of building a full internal security operations team. The value often comes from faster investigations and fewer blind spots.