3 questions from the package
From the RFI round. The first shows part of the guide each question carries; the workbook adds follow-ups, how to verify the answer, a priority and a weight.
1. Which containment actions can your analysts execute in our environment on pre-approved authority, without contacting us first?
Why it matters. If the provider can only recommend actions, a confirmed threat waits for the buyer's on-call staff to act. Ransomware can spread across hosts during that wait.
Good answer
- Names each action individually, for example host isolation, process kill, file quarantine, account disable, session revocation and network block.
- States the tool or control through which each action is executed.
- States the default approval setting for each action and whether the buyer can change it.
Red flags
- Describes the service as alerting with recommended actions, with no actions the provider executes itself.
- Says response capability 'depends on the deployment' without listing actions.
- Lists actions only as marketing categories with no tool or default setting attached.
2. Do your detections run on raw event telemetry from our sources, or only on alerts that our existing security tools have already generated?
Why it matters. A service that only watches tool alerts cannot detect activity those tools do not flag, such as misuse of valid credentials or attacker use of built-in system utilities.
3. Describe the human-led threat hunting your analysts perform in our telemetry, as distinct from automated detection rules and scheduled queries.
Why it matters. If hunting means automated queries run across all customers, activity that matches no rule in the buyer's environment goes unexamined. The buyer then pays for a capability it does not receive.
Capability areas
Response Authority & Active Containment (15)
Covers the containment actions the provider can take without waiting for approval (host isolation, process kill, account or session disable, network block), how that authority is scoped per asset class, approval workflows for the remaining actions, and rollback of a containment action. Excludes full incident remediation and recovery, which belong to IRF.
Detection Engineering & Coverage (13)
Covers how the provider builds, tests, maps and maintains detection content across adversary techniques, how custom detections are added for our environment, and how coverage gaps are reported. Excludes proactive hunting (HNT) and alert triage (TRI).
Threat Hunting & Threat Intelligence (9)
Covers human-led, hypothesis-driven hunting beyond automated alerts, the cadence and scope of hunts in our telemetry, hunt readouts, and how original intelligence from the provider's investigations feeds detection content. Excludes rule-based detection authoring (DET).
Alert Triage & False-Positive Validation (11)
Covers how alerts are enriched, validated and either suppressed or escalated before they reach us, the evidence provided of the filtering ratio, tuning and suppression governance, and how we can challenge a closed alert. Excludes the investigation record of confirmed incidents (INV).
SOC Staffing & Operating Model (12)
Covers 24/7 follow-the-sun staffing, analyst tiers and qualifications, named versus pooled analysts, shift handover, escalation to our on-call contacts, and what happens when contacts cannot be reached. Excludes contractual time commitments (SLA) and shared-operations tooling for co-managed models (COM).
Detection & Response Time Commitments (10)
Covers how the provider defines, measures, reports and commits to time to detect, time to analyst contact and time to contain a confirmed threat, plus remedies when those commitments are missed. Excludes generic product support SLAs, which belong to the support-operations module.
Telemetry Sources & Tool Model (12)
Covers whether the service runs on our existing tools or on a provider-supplied stack, the endpoint, identity, email, network and log sources it ingests, parsing and health monitoring of each source, and how much of our current tool investment can be kept. Excludes generic APIs and SSO (integration module) and environment-specific detection depth (ENV).
Identity, Cloud, SaaS & OT Coverage (10)
Covers detection and response depth for identity providers, cloud control planes and workloads, SaaS applications, unmanaged devices and OT/ICS networks, including which response actions are available in each environment. Excludes basic source onboarding (TEL).
Investigation Transparency & Reporting (10)
Covers the record of what analysts examined, concluded and did during an investigation (timeline, evidence, actions, rationale), our access to that record, incident and periodic service reporting, and executive-level summaries. Excludes alert filtering metrics (TRI).
Incident Response, Forensics & Recovery (11)
Covers what happens after containment: whether full IR and digital forensics are included or billed separately, retainer hours, forensic collection and evidence handling, remediation and recovery support, and breach warranty terms including what voids them. Excludes initial containment authority (RAU).
Co-Managed Operations & Collaboration (9)
Covers working alongside our in-house team: shared case views, ticketing and chat integration for incidents, customer-authored runbooks and detections, our analysts' access to the provider's console, and the division of duties during an incident. Excludes fully outsourced staffing (SOC).
Questions about this package
How many Managed Detection & Response (MDR) RFP questions are there?
122 solution questions in 11 capability areas: 27 for the RFI, 61 for the RFP and 34 deep-dive questions for the finalists. The workbook adds 100 due-diligence questions on security, integration, implementation and exit.
What comes with each question?
Why it matters, good-answer signals, red flags, follow-up questions, how to verify the answer (a demo step, a test or a document), and a suggested priority and weight for scoring.
Can I edit the questions?
Yes. The workbook is an ordinary Excel file. Change, add or remove questions, and change the weights; the scorecard recalculates.
Which license do I need?
The Enterprise License covers any number of evaluations inside one organization. The Consultancy License covers use with any number of clients. Neither allows reselling or republishing the questions.