Buying Guides7 min read
The Cybersecurity Buying Guide: How to Choose an MDR or Managed Security Provider
A practical, vendor-neutral guide to buying managed security: deciding what job you are actually hiring for, decoding the acronym maze, the questions that separate real response from alert forwarding, how the pricing behaves, and the exit terms that protect your logs.
By Software Results Advisory Team
Nobody buys cybersecurity calmly. Every vendor pitch opens with breach statistics, every product is the missing critical layer, and a mid-size company can be presented with forty tools that each claim to be the one that matters. The result is predictable: stacks full of overlapping licenses, no one watching the alerts, and a budget that feels enormous while the actual question goes unanswered. That question is not which product to buy. It is who notices an intruder, and what they are allowed to do about it, at 3 a.m. on a Saturday.
This guide is how we evaluate security providers as advisors, written down so it is useful even if you run the process alone. None of it requires buying anything from us.
Decide what job you are hiring for
Security purchases go wrong at the first step more than any other category, because "we need better security" is not a job description. Before looking at a single vendor, decide which of these outcomes you are actually buying, in order:
- Detection and response. Someone watches your environment around the clock, decides which alerts are real, and contains threats before they spread. This is the core job, and for most companies the first one worth funding.
- A hardened front door. Email security, multi-factor enforcement, and identity protection. Most intrusions still start with a mailbox or a stolen credential, not an exotic exploit.
- Evidence for a framework. SOC 2, HIPAA, CMMC, PCI, or a customer questionnaire. This is a compliance project that overlaps security but is not the same purchase.
- Proof your recovery works. Backups that someone has actually restored from, and a tested plan for the day the answer is "wipe it and rebuild."
- Assessment and strategy. Penetration testing, risk assessment, or fractional security leadership to sequence all of the above.
Providers who excel at one of these are routinely mediocre at the others, whatever the brochure says. Deciding the job first cuts the field dramatically and turns every later conversation from a pitch into an interview.
Map your surface before you shop
A proposal can only be judged against the thing it is supposed to protect. Before quotes arrive, write down your actual attack surface in one page: endpoint count, identity count and provider, email platform, cloud tenants, anything exposed to the internet, and any operational technology that would stop the business if it stopped.
Then hold every proposal against that page. The pattern we see most often is coverage concentrated where tools are easy to deploy, meaning laptops, while identities and cloud tenants go unwatched. That inversion is exactly backwards from where incidents actually start today. A provider who asks hard questions about your identity provider and cloud logging before quoting is showing you their operation; one who quotes off an endpoint count alone is showing you theirs too.
The acronym maze, decoded
Security vendors have invented an alphabet of service names, and the labels do not mean the same thing from one provider to the next. What matters underneath is three questions: what is watched, who watches it, and what the watcher is authorized to do.
- EDR is tooling on the endpoint that detects and records. It is a sensor, not a service.
- MDR adds the humans: a staffed function that triages what the sensors see and responds. The word "response" is where the definitions diverge, and the next section is about pinning it down.
- XDR extends detection beyond endpoints to identity, email, and cloud signals. Useful when real, marketing when not; ask what data sources are actually ingested.
- SOC-as-a-service sells the watch floor itself, usually log-driven and broader in scope, sometimes monitor-only.
- MSSP is the umbrella term for outsourced security operations of any depth, from firewall babysitting to full response.
- vCISO is fractional leadership: strategy, sequencing, and audit-facing ownership, not a monitoring service.
None of these labels belongs on a shortlist. Scopes do. Two services with the same acronym can differ more than two with different ones, which is why we compare what providers actually do rather than what they call it.
The question that separates real response from alert forwarding
If you take one thing from this guide, take this: the dividing line in managed security is containment authority. When a provider detects a live threat, do they isolate the machine, kill the session, and disable the account on their own authority, or do they send you an email about it?
A service that ends with an alert in your inbox is monitoring. It has value, but it is not response, and at 3 a.m. the difference is the whole product. Pin it down in writing:
- What they do unilaterally, and what waits for you. The right answer is a pre-agreed matrix: contain first and notify for clear threats, ask first for disruptive actions on critical systems. Vague answers here predict vague incidents.
- Detection-to-containment time, measured. Not the marketing SLA; the numbers from their last quarter, reported the way you would see them as a customer.
- The first hour, on paper. Ask for a redacted incident report from a real client. What actually happened, in what sequence, decided by whom? This single document tells you more than any demo.
- Whose SOC it is. In-house or white-labeled, staffed where, in what time zones, with what turnover. White-label is not automatically bad, but you should know whose people hold your keys and make your 3 a.m. decisions.
- What happens to your existing tools. A provider who builds on licenses you already own, or prices their replacement explicitly, is being honest about total cost. A proposal that requires ripping everything out for the vendor's own agent on day one is a strategy, and you should price it as one.
How the pricing actually behaves
Security services price on the thing they protect: per endpoint for EDR and MDR, per user for email security and awareness training, per asset or log volume for SIEM and SOC services, per engagement for testing and vCISO work. A few mechanics are worth knowing before you negotiate:
- The per-endpoint range is wide because scope is wide. Endpoint-anchored MDR commonly runs somewhere between five and twenty dollars per endpoint per month. The low end often watches and recommends; the high end contains on your behalf and covers identity and cloud. The headline number means nothing until you know which one you are buying.
- Log-volume pricing needs a forecast. SIEM and SOC services priced on ingestion can double when you onboard a chatty new data source. Ask what drives volume in environments like yours and what the overage terms are, before signature.
- Bundled licenses cut both ways. Tooling included in the service simplifies the bill, but it also means leaving the provider means losing the tooling. Know which licenses are yours and which evaporate at exit.
- Total cost of coverage is the honest comparison. Add up every overlapping tool and service touching the same surface. The most common finding in a stack review is the same layer purchased twice, and rationalizing that overlap frequently funds the upgrade to real around-the-clock response.
- Read your cyber insurance policy first. It dictates minimum controls, sometimes approved vendors, and occasionally discounts. Buying without reading it invites both a coverage gap and a redundant purchase.
Compliance is a deliverable, not a synonym
If a framework is driving the purchase, make the provider prove the mapping: which controls their service satisfies, and what auditor-ready evidence it produces, control by control. "We help with compliance" is a sentence, not a mapping. The reverse trap matters just as much: passing an audit and stopping an intruder are different projects that share paperwork. Fund detection and response first, and let the evidence fall out of doing security properly, because the auditor's checklist has never contained an attacker.
Negotiate the exit while they still want you
Managed security has a hostage problem most buyers discover too late: your logs, detections, and configurations accumulate inside the provider's platform. Before signing, put the divorce terms in writing: your historical logs are exportable in a standard format, your configurations and runbooks are documented and returned, offboarding has a defined obligation and a capped fee, and any licenses you paid for transfer with you. A provider confident in their service agrees without friction. The ones who resist are telling you how the relationship ends, and in this category the switching pain lands precisely when you can least afford blind spots.
Red flags worth walking away from
- The pitch opens with fear and breach statistics instead of questions about your environment.
- "Response" turns out to mean an email to your inbox with a severity score.
- The proposal requires replacing every tool you own on day one.
- Nobody can produce a sample incident report, a sample monthly report, or measured containment times.
- The scope is silent on identity and cloud, or silent on what happens when you leave.
Where an advisor fits
You can run everything above yourself, and this guide is meant to make that genuinely possible. What an advisor adds is compression and pattern recognition: we already know which providers treat containment as their job rather than yours, which ones build on existing stacks honestly, and what companies with your profile actually pay, because we see the live quotes. The advice costs you nothing, the shortlist is not tilted toward any provider, and you sign directly with the one you choose.
If a security decision is on your calendar this year, or an insurance questionnaire just made one for you, a thirty-minute conversation is the cheapest due diligence you will do.
Frequently asked questions
Do we need MDR if we already have EDR?
EDR is the sensor; MDR is the person watching it. An EDR license detects and records, but at 3 a.m. on a Saturday somebody still has to read the alert, decide it is real, and contain the machine before the attacker moves. If your team genuinely staffs that around the clock, you may not need MDR. For almost everyone else, an unwatched EDR console is a smoke detector in an empty building, and MDR is the least expensive way to put a responder behind the tooling you already bought.
How much does MDR cost per endpoint?
Endpoint-anchored MDR for small and mid-size companies commonly lands somewhere between five and twenty dollars per endpoint per month, but the spread is scope, not generosity. The low end is often monitoring with recommendations; the high end can include full containment authority, identity and cloud coverage, and bundled tooling licenses. Broader SOC services price on log volume and can behave very differently. Compare what a responder is authorized to do and what surface is watched, not the per-endpoint headline.
What questions should we ask a security provider before signing?
Five cut deepest: What do you do about a live threat without waiting for us, and what needs our approval? What are your detection-to-containment times, measured and reported, not promised? Is your SOC in-house or white-labeled, and where is it staffed? Which of our existing tools do you build on, and which would you replace? And what do we get back if we leave: our logs, our configurations, our history? Providers with a real operation answer all five in writing without flinching.
Can a small company afford 24/7 security coverage?
Yes, and that is a recent development worth taking advantage of. A round-the-clock watch floor used to require building one; the managed security market now rents you the same capability priced per endpoint or per user. Most companies that think they cannot afford coverage are already spending the money on overlapping tools nobody watches. Rationalizing that overlap frequently funds real detection and response without moving the budget line.
Can an advisor really help us choose a security provider for free?
Yes. The advice costs you nothing: no invoice, no retainer, and no obligation, and it is not tilted toward any name on the list because we work across the whole market. You get a shortlist matched to your risk profile, your existing tools, and what your insurer and auditors require, benchmark pricing from live deals, and a second set of eyes on the scope and contract before you sign directly with the provider you choose.
Talk it through with a Technology Advisor
Tell us what you are looking at, or bring just the contract that worries you. An advisor replies within one business day. No cost, no obligation.
Two quick steps. No cost, no obligation.