top of page

Verpa Consulting

  • Facebook
  • LinkedIn

Navigating the MDR Landscape: How to Choose the Best Managed Detection and Response Provider

  • Apr 3
  • 3 min read



We've spent years deep in the MDR (Managed Detection and Response) world selling for and against every major player in the space. That kind of experience teaches you a lot, especially when you’re constantly comparing notes with former colleagues who now work at those same providers. We all “talk shop” about what actually works, what doesn’t, and how each vendor positions itself in the market.


The one area where most MDR providers fall flat? Deployment.


Some are plain awful. Others are mediocre at best. But here’s the hard truth I’ve learned the hard way: any deployment only performs as well as the buying team supports it. Time and again, projects drag on not because the provider is slow, but because the customer simply didn’t have the internal staff available to grant access, join meetings, or assist with the rollout. It’s ironic: they hire an MDR service to reduce workload and risk, yet the very first step fails because they’re too stretched to help make it happen.


That’s why people keep reaching out to me asking, “How do I pick the right MDR provider?”

At Verpa Consulting, we help organizations navigate this exact challenge every day. We’ve seen the good, the bad, and the ugly from the inside. While we can’t promise a one-size-fits-all answer (cybersecurity never works that way), here are two battle-tested tips that will immediately separate the strong providers from the rest.


1. The Heart of Any MDR Provider Is Its SOC—Dig Deep

Everything else is marketing. The real engine is the Security Operations Center (SOC).

If a vendor claims they run “SOCs that follow the sun,” GREAT! - then ask for the physical addresses. Then Google Earth them - you might be shocked. Ask exactly how many analysts are staffed in each location. Dig into their attrition rate. Ask how they combat alert fatigue and analyst burnout. These aren’t “nice-to-know” questions; they’re make-or-break.

A few years ago, a close friend who runs SOC operations did the math on what it actually takes to run a legitimate 24/7/365 SOC. When you factor in sick days, PTO, vacation coverage, leadership overhead, escalation tiers, and quality control, you need at least 15 full-time analysts minimum to keep things from falling apart. Anything less, and someone is getting burned out or worse, alerts are going unanswered. And always ask how they scale as they add clients to match with that "explosive growth." The math needs to...well...math. And don't fall for the AI answer. While we agree that AI has helped tremendously with some of the menial tasks, a SOC still needs "eyes on glass" and people to do the work.

Don’t accept vague answers. The best providers will be transparent because they’re proud of their teams.


2. Test Them When It Matters Most—Call the SOC at 2 a.m.

This one is simple, free, and incredibly revealing.

Call the SOC late Saturday night or early Sunday morning (think 2:00 a.m. their local time). See how quickly they pick up. See how professional and calm the analyst sounds. Ask a real (but non-emergency) question about your environment.

Then send a follow-up email at the same odd hour and time how long it takes for a human reply.

You’ll be shocked how many “24/7” operations suddenly feel very different at 2 a.m. The providers who truly have their act together will respond quickly and competently. The ones that don’t… well, you just saved yourself a world of pain.


There’s a Lot More You Can (and Should) Do

These two tips are just the start. In a full evaluation, you should also be looking at:

  • Real-world mean-time-to-respond (MTTR) metrics (not just marketing slides)

  • How well they integrate with your existing tools

  • Quality and depth of their threat intelligence

  • References from companies in your industry and size

  • How they handle post-incident communication and lessons learned


At Verpa Consulting, we maintain an up-to-date list of the strongest MDR providers and the ones to approach with caution. We’ve helped dozens of organizations cut through the noise, avoid costly mistakes, and land with the right long-term partner.


If you’re evaluating MDR options right now or just want an independent second opinion reach out. I’d be happy to share what we’ve learned and talk through how Verpa can help you move faster and with far more confidence.


Drop me a note. The cyber landscape is tough enough without guessing on your most important security partner.


~ JP Pataky

Vice President, Cybersecurity Practice Leader | Sales - Marketing - Channel Management

Verpa Consulting, LLC

 

 
 
 

Comments


bottom of page