Every managed detection and response conversation I have ever sat in starts in the wrong place. Someone asks which provider is best. The better question, and the one that actually determines whether the engagement works, is what you are buying: a second security stack with people attached, people to operate the stack you already pay for, or a provider who leaves your sensors alone and takes the layer above them. Those are different products sold under one name, and the architecture you pick predicts the outcome far more reliably than the logo does.
The reason this matters more now than it did five years ago is that the typical mid-market organisation already owns the telemetry. If you hold Microsoft 365 E5, you have Defender for Endpoint, Defender for Identity, Defender for Office, Defender for Cloud Apps and Entra ID Protection, and every one of those is producing signal whether or not anyone is reading it. Business Premium shops are in a similar position at a smaller scale. The gap is almost never sensors. The gap is that nobody is awake at three in the morning, and nobody has the practice to know which of the night’s alerts is the one that matters.
That reframes the purchase. You are not shopping for detection. You are shopping for operators, and for the authority those operators will hold inside your tenant.
Three architectures wearing the same label
The field divides cleanly into three shapes once you stop reading the marketing and start reading the integration documentation. The first shape brings its own agent and its own platform. You deploy their sensor, their console becomes the place where security happens, and their analysts work in a system they built. Arctic Wolf sits here, as does CrowdStrike, and so do most of the names that come up in a mid-market procurement conversation. The second shape brings no technology at all. The provider connects to what you already run, works your Defender and Entra signal from inside your tenant, and sells nothing but judgement and hours. Expel is the clearest example, and Red Canary was until Zscaler bought it. The third shape is the vendor of your stack offering to operate it themselves, which in a Microsoft estate means Defender Experts.
Each shape carries a different cost structure and a different failure mode. Own-platform providers give you a coherent product where detection, response and tooling were designed together, and charge you a second time for capability you already licensed. Operate-your-stack providers cost less in duplicated licensing and are only ever as good as the telemetry you bought them; hire one on top of a Defender for Endpoint Plan 1 estate and you have paid for analysts who cannot see much. First-party sits closest to the signal and inherits the platform’s blind spots wholesale.
Those three shapes divide on a single question, which is whether the provider brings technology with them. A second question has become just as important since, and it cuts across the three rather than sitting beside them: which layer of your estate does the provider take over. For most of this market the answer is your sensors, or nothing at all. For a growing number it is neither. Palo Alto’s managed service is the clearest case, which is why it gets a profile later in this series: your endpoint agents stay exactly where they are and keep producing signal, while the analytics and retention layer above them becomes theirs. On the older question that places it nowhere in particular, since it brings a platform but no sensors, and the three shapes have no room for a provider who does one without the other. That is the point rather than a flaw in the scheme. That is also not a milder version of buying a second stack. It is a different commitment, because the thing being displaced is the one decision most organisations have not yet made deliberately. When the security data platform was an afterthought this distinction did not matter much. It matters now.
There is a fourth category worth naming so you can set it aside. The large systems integrators and incident response firms, Mandiant and Kroll and the consulting arms of the global outfits, also sell managed detection. They sell it to organisations with an existing security function and a budget line for retained expertise, which is a different buyer with a different problem. If that is you, this series is not aimed at you.
A fifth grouping has appeared more recently and deserves a sentence rather than a section. Network vendors now sell the security operations centre alongside the network path. Cato bundles optional managed detection onto its single-vendor secure access platform, and Todyl runs detection, network security, logging and compliance through one agent aimed squarely at managed service providers. The logic is real: collapsing the stack into one contract genuinely removes the double-pay problem. The cost is concentration of a kind I would want stated out loud before signing, because one vendor then holds both your network path and the authority to act inside your environment.
One name deserves more than a passing mention without getting a profile of its own. Sophos is the largest pure-play provider in this market by customer count, a position it consolidated by absorbing Secureworks in early 2025 and folding the Taegis platform into its own portfolio. What makes it architecturally interesting is a pricing decision rather than a technical one. Taegis remains genuinely open, ingesting from Microsoft Defender, CrowdStrike, SentinelOne and others, and it can be deployed as a detection-only sensor against telemetry you already produce. But licences for their own endpoint agent are now included with every subscription at no additional cost, which puts a steady commercial thumb on the scale in favour of replacing what you have. Openness that costs money alongside replacement that is free is not neutrality. It is a funnel with good manners, and the pattern is worth recognising because this will not be the last time you meet it.
The contract term that decides everything
Response authority is the real product, and it is the thing least discussed in the sales cycle. The question is simple to ask and surprisingly hard to get answered: at three in the morning, without calling anyone, what is this provider permitted to do inside my tenant? Can they isolate a host? Disable an account? Kill a process on a production server? And when they are wrong, which they will be at some point, what does the contract say happens next?
You are not buying detection. You are delegating the authority to act, and the shape of that delegation is the architecture decision.
The answers across the field span a genuinely wide range, and the range is the most useful thing I found. At one end sit providers whose analysts take direct remediation action within an agreed scope without waiting for approval, reaching into affected systems, removing persistence and restoring the machine to a known-good state. That is a real service and for some organisations it is exactly right, but it means an external team has hands on your production estate and the dial has essentially one setting. At the other end sits a model where authority is a permission you grant and can withdraw, where the default is that the provider investigates and hands you a recommended action to execute yourself, and where every action they do take is logged in your own console rather than in theirs.
Between those poles are the interesting designs. One provider licenses each automated action separately and lets you attach guardrails to each: lists of accounts that must never be disabled, machines that must never be contained, files that must never be deleted, with hard exclusions preventing action against privileged accounts entirely. Another sells hands-on-keyboard response as a distinct annual add-on scoped to specific groups of endpoints you nominate, so authority is bought and bounded rather than assumed. A third makes it a per-playbook decision at configuration time. These are not marketing differences. They are architectural positions on how much of your incident response you are prepared to delegate, and they should be evaluated as such.
Two consequences follow that rarely make it into a comparison table. The first is that response authority requires standing credentials. Every one of these integrations lands as an application registration in your tenant with response-grade permissions and a client secret held by a third party, and the rotation, scope and review of that credential quietly becomes your governance problem rather than theirs. The second is that some actions have no undo. At least one provider states plainly in its own documentation that a deleted file cannot be recovered through its tooling and that a killed process cannot be restored. I have more confidence in a vendor that writes that down than in one whose documentation implies everything is reversible.
What the marketed number measures
Every provider publishes a time. Almost none of them publish the same time. One headline figure of roughly seven minutes measures mean time to ticket, which is the interval between a signal arriving and a human writing something down. It is a real operational metric and it says nothing about containment. Another vendor publishes thirteen minutes without defining the endpoints of the measurement. A third declines to publish a response service level at all and offers a breach warranty instead, which is a fundamentally different commercial instrument: not a promise to act quickly but an insurance-backed promise to pay if the outcome is bad. A fourth measures median time to contain, which is the number you actually wanted, and is consequently rare.
Read the definition, not the digit. And accept that the genuinely binding commitments, the ones with teeth and remedies, live in the contract rather than on the website. Where that is true I will say so throughout this series rather than pretending the public material answers a question it does not.
This is not your zero trust programme
Managed detection and response gets sold into zero trust budgets, and the two are routinely conflated in ways that confuse both. Zero trust is an access architecture. It is a set of tenets about never granting implicit trust based on network position, a policy model with decision and enforcement points, and a long programme of work across identity, devices, data, applications, infrastructure and network. Managed detection is an operations capability. It is people and process watching what the architecture produces.
The relationship is real but it is not the one the pitch implies. Detection and response is not a pillar of the CISA maturity model; it delivers what that model calls the cross-cutting capabilities, the visibility and analytics and the automation and orchestration that run across every pillar. On Microsoft’s current framing it maps to the security operations pillar. Either way the direction of dependence is the same: zero trust generates the signal and the enforcement points, and detection and response is the function that reads them and acts.
The federal guidance makes this less optional than it sounds. The NIST tenets require continuous monitoring of asset integrity and the collection of telemetry to improve posture over time. An organisation that has adopted assume-breach as a design principle and has nobody staffed to detect a breach has adopted a posture rather than a programme. For most organisations in the size range this site writes for, staffed means a third party, which is precisely why this decision deserves the same architectural care as the identity design that preceded it.
There is a genuine collision worth flagging early. At least one provider on this shortlist now sits inline in the Entra authentication flow as an external authentication method, making risk-based allow, block and step-up decisions on live sign-ins. That is not a detection service riding your stack. That is a second conditional access plane in front of the one you built, and the interaction with your existing policy set is an architecture question rather than an integration detail. I will take that up properly in its own article.
A market that will not hold still
Eighteen acquisitions closed in this market between the third quarter of 2024 and the first quarter of 2026, across a field of roughly six hundred providers. Sophos absorbed Secureworks. Zscaler bought Red Canary. Arctic Wolf took the Cylance endpoint business off BlackBerry and renamed it. LevelBlue consolidated Trustwave and Alert Logic under one roof. A cyber insurer bought a detection vendor. Three separate forces are driving it: platform companies buying operations capability, providers buying each other for scale, and technology grabs for automation.
This has two practical consequences for anyone evaluating. The first is that a shortlist is a perishable document. The provider you are diligencing today may be a business unit inside a larger platform by the time your contract renews, and the acquiring vendor’s strategic interest may not match the one you bought. That is not hypothetical: one of the providers in this series had elevated customer churn disclosed on its new parent’s earnings call within two quarters of the deal closing. The second consequence is methodological. Because ownership, product naming and packaging move this fast, everything factual in this series carries a read date, and every article carries a review date. Where I could not verify something from current first-party material, I say so rather than repeating what a vendor asserts.
One clarification on the analyst material, since it comes up in every procurement discussion. Gartner does not publish a Magic Quadrant for managed detection and response. It publishes a Market Guide, which lists representative vendors and does not rank them. Any vendor claiming Leader placement in a Gartner quadrant for this category is describing something that does not exist. Forrester does publish a ranked evaluation, and where a provider’s placement in it is relevant I will cite the edition and the date. Those citations are dated facts about a published document, not my endorsement, and they are no substitute for evaluating the provider against your own environment.
What comes next
The articles that follow profile eight providers against the same set of questions: what they run, who holds authority and on what terms, how they land in a Microsoft tenant, how deep they go on identity, what you end up paying for twice, what they contribute to or replace in your zero trust posture, and what their artificial intelligence claims actually amount to on inspection. Arctic Wolf, Microsoft Defender Experts, CrowdStrike Falcon Complete, Huntress, Expel, Red Canary under Zscaler, Critical Start, and Palo Alto Unit 42 Managed XSIAM. They are not ranked and they will not be. They were chosen because between them they occupy every architectural position that matters, and because they are the names that come up when a client asks me this question out loud.
The evaluation starts before any of them, though, with an honest accounting of what your own tenant already produces and retains. A managed detection provider inherits your logging gaps on day one, and no amount of analyst quality compensates for signal you never collected.
MDR
Next: [MDR 2] Arctic Wolf: The Concierge and the Open Platform ›




