CIOPages
All RFP packages

RFP Package · Cybersecurity & Identity

Managed Detection & Response (MDR) RFP questions and template

122 questions, 10 demo scenarios and a five-vendor scorecard for choosing Managed Detection & Response (MDR) software, in one Excel workbook.

What this package is for

Use it to run a Managed Detection & Response (MDR) software selection, from the first long list to the final scorecard.

What the category covers. Questions for buying a managed detection and response service: who may contain a threat and when, detection and hunting quality, triage, analyst staffing, time commitments, telemetry and tool model, identity, cloud, SaaS and OT coverage, investigation records, incident response and co-managed operations. Bought by security leaders and CISOs choosing a provider to watch and act in their environment around the clock.

A selection usually runs in three rounds. The package has questions for each:

  • RFI, to the long list. 27 questions screen out products that lack something you need.
  • RFP, to the shortlist. 61 questions ask how each product does the work.
  • Deep dive, to the finalists. 34 questions ask for proof on your own data.

10 demo scenarios tell each vendor what to load and what to show, so every product does the same work in front of you. 100 due-diligence questions cover security, integration, implementation and exit. The scorecard weights the answers and ranks up to five vendors.

Each question comes with why it matters, what a good answer looks like and the red flags, so the people scoring the replies know what to look for.

3 questions from the package

From the RFI round. The first shows part of the guide each question carries; the workbook adds follow-ups, how to verify the answer, a priority and a weight.

1. Which containment actions can your analysts execute in our environment on pre-approved authority, without contacting us first?

Why it matters. If the provider can only recommend actions, a confirmed threat waits for the buyer's on-call staff to act. Ransomware can spread across hosts during that wait.

Good answer
  • Names each action individually, for example host isolation, process kill, file quarantine, account disable, session revocation and network block.
  • States the tool or control through which each action is executed.
  • States the default approval setting for each action and whether the buyer can change it.
Red flags
  • Describes the service as alerting with recommended actions, with no actions the provider executes itself.
  • Says response capability 'depends on the deployment' without listing actions.
  • Lists actions only as marketing categories with no tool or default setting attached.

2. Do your detections run on raw event telemetry from our sources, or only on alerts that our existing security tools have already generated?

Why it matters. A service that only watches tool alerts cannot detect activity those tools do not flag, such as misuse of valid credentials or attacker use of built-in system utilities.

3. Describe the human-led threat hunting your analysts perform in our telemetry, as distinct from automated detection rules and scheduled queries.

Why it matters. If hunting means automated queries run across all customers, activity that matches no rule in the buyer's environment goes unexamined. The buyer then pays for a capability it does not receive.

Capability areas

Response Authority & Active Containment (15)

Covers the containment actions the provider can take without waiting for approval (host isolation, process kill, account or session disable, network block), how that authority is scoped per asset class, approval workflows for the remaining actions, and rollback of a containment action. Excludes full incident remediation and recovery, which belong to IRF.

Detection Engineering & Coverage (13)

Covers how the provider builds, tests, maps and maintains detection content across adversary techniques, how custom detections are added for our environment, and how coverage gaps are reported. Excludes proactive hunting (HNT) and alert triage (TRI).

Threat Hunting & Threat Intelligence (9)

Covers human-led, hypothesis-driven hunting beyond automated alerts, the cadence and scope of hunts in our telemetry, hunt readouts, and how original intelligence from the provider's investigations feeds detection content. Excludes rule-based detection authoring (DET).

Alert Triage & False-Positive Validation (11)

Covers how alerts are enriched, validated and either suppressed or escalated before they reach us, the evidence provided of the filtering ratio, tuning and suppression governance, and how we can challenge a closed alert. Excludes the investigation record of confirmed incidents (INV).

SOC Staffing & Operating Model (12)

Covers 24/7 follow-the-sun staffing, analyst tiers and qualifications, named versus pooled analysts, shift handover, escalation to our on-call contacts, and what happens when contacts cannot be reached. Excludes contractual time commitments (SLA) and shared-operations tooling for co-managed models (COM).

Detection & Response Time Commitments (10)

Covers how the provider defines, measures, reports and commits to time to detect, time to analyst contact and time to contain a confirmed threat, plus remedies when those commitments are missed. Excludes generic product support SLAs, which belong to the support-operations module.

Telemetry Sources & Tool Model (12)

Covers whether the service runs on our existing tools or on a provider-supplied stack, the endpoint, identity, email, network and log sources it ingests, parsing and health monitoring of each source, and how much of our current tool investment can be kept. Excludes generic APIs and SSO (integration module) and environment-specific detection depth (ENV).

Identity, Cloud, SaaS & OT Coverage (10)

Covers detection and response depth for identity providers, cloud control planes and workloads, SaaS applications, unmanaged devices and OT/ICS networks, including which response actions are available in each environment. Excludes basic source onboarding (TEL).

Investigation Transparency & Reporting (10)

Covers the record of what analysts examined, concluded and did during an investigation (timeline, evidence, actions, rationale), our access to that record, incident and periodic service reporting, and executive-level summaries. Excludes alert filtering metrics (TRI).

Incident Response, Forensics & Recovery (11)

Covers what happens after containment: whether full IR and digital forensics are included or billed separately, retainer hours, forensic collection and evidence handling, remediation and recovery support, and breach warranty terms including what voids them. Excludes initial containment authority (RAU).

Co-Managed Operations & Collaboration (9)

Covers working alongside our in-house team: shared case views, ticketing and chat integration for incidents, customer-authored runbooks and detections, our analysts' access to the provider's console, and the division of duties during an incident. Excludes fully outsourced staffing (SOC).

Demo scenarios

Each scenario lists the data to load before the demo, then the steps to show, and the questions it scores.

  1. Off-hours detection, contact and containment on a test host
  2. Ransomware precursor on two asset classes
  3. Compromised identity with a stolen session token
  4. Walk-through of a recently closed investigation
  5. Onboarding one of our log sources
  6. Hypothesis-led threat hunt on our telemetry
  7. Abuse of a cloud control plane
  8. Co-managed incident with an unanswered on-call contact
  9. Escalation from containment to full incident response
  10. Timeline reconstruction from a staged intrusion

Due diligence

The workbook carries the screening questions from these modules. Each module is also sold on its own.

Questions about this package

How many Managed Detection & Response (MDR) RFP questions are there?

122 solution questions in 11 capability areas: 27 for the RFI, 61 for the RFP and 34 deep-dive questions for the finalists. The workbook adds 100 due-diligence questions on security, integration, implementation and exit.

What comes with each question?

Why it matters, good-answer signals, red flags, follow-up questions, how to verify the answer (a demo step, a test or a document), and a suggested priority and weight for scoring.

Can I edit the questions?

Yes. The workbook is an ordinary Excel file. Change, add or remove questions, and change the weights; the scorecard recalculates.

Which license do I need?

The Enterprise License covers any number of evaluations inside one organization. The Consultancy License covers use with any number of clients. Neither allows reselling or republishing the questions.

Before you shortlist

The buyer guide compares the products in this category and what decides between them.

Buyer Guide
Managed Detection & Response (MDR)

For the business side of the same change: