What to verify in coverage, contracts and response authority before you sign an MDR agreement for a plant environment.
Manufacturing accounted for 27.7% of the cybersecurity incidents IBM X-Force observed in 2025, the fifth consecutive year the sector has topped every other industry.
The reason is structural. Plants run control systems that cannot be patched on a normal cycle, cannot absorb downtime and often sit on networks that also carry email, file shares and engineering drawings. Those same three conditions are what make ransomware in manufacturing so reliably profitable for attackers.
That combination is why manufacturers buy managed detection and response. It is also why a generic MDR contract tends to fail the first time it meets a production floor.
Most MDR pitches sound alike: a 24/7 security operations center, expert analysts and fast containment. The differences that decide outcomes live in the contract, the integration list and the question of what a provider is actually authorized to do on your systems at 3 a.m.
What MDR is, and what it is not
MDR combines continuous monitoring with human investigation and hands-on support during an incident. Scope varies widely between providers, so separate the service from the tools it runs on.
EDR and XDR are tools, not staffed services. Endpoint detection and response and extended detection and response collect security telemetry, raise alerts and automate some actions. A person still has to investigate the incident and drive the response.
Monitoring does not guarantee hands-on response. Managed security service providers may monitor and escalate alerts without touching your systems, though some do offer response. Compare contractual responsibilities instead of trusting the MDR or MSSP label.
Alerting is not response. An email saying a host is compromised is a notification. Isolating that host and disabling the compromised account are response actions. Neither one on its own proves the incident is closed.
Map what needs protection before you shortlist
Endpoint-only coverage leaves gaps that matter in a plant. Map every place an attacker could gain a foothold: laptops and servers, cloud workloads, identity services, email, network equipment and the OT and industrial control layer.
Ask each provider to walk the map source by source and state what it monitors and what it can act on. Those are different things. A provider that ingests identity logs but cannot disable an account is giving you visibility while leaving the response with your team.
Manufacturers should treat this as two maps rather than one, because the coverage answer for corporate IT and the coverage answer for the plant floor are rarely the same. Build the same coverage inventory you would use for any infrastructure audit, then run each provider against it.
Define response authority in the contract
Get specific about hands-on actions. Will the provider isolate a host, kill a malicious process, disable an account or block a malicious address without waiting for your approval?
In practice providers operate one of three models. Notify only, where the service investigates and hands you the incident. Full response, where the service executes remediation on its own authority. Or scoped response, where the service acts on a named subset of actions and escalates the rest.
Any of the three can work. What cannot work is discovering which one you bought during an incident. The contract should name the permitted actions, the approval rules and the escalation path, and it should let you set different rules for different asset groups.
Define when investigation starts, when your team gets notified and who owns containment and recovery. Response time is not resolution time. Request sample runbooks and a redacted incident report before signing, and check what happens when your primary contact is unreachable overnight.
[IMAGE 2: Security analyst reviewing an incident timeline and response actions on a dual-monitor workstation. Alt text: “Analyst reviewing MDR incident timeline and approved response actions”]
Check integrations against your actual stack
Some services are built around a single vendor’s tooling. Others accept telemetry from a broader mix of products, usually with limits. A supported integration may permit monitoring without permitting the provider to take action through it.
Check the scope at the subscription tier you are quoting, not the vendor’s overall compatibility page. Four questions settle most of it:
- Which identity, email and cloud sources are supported, and which of those allow response actions?
- Who owns the data platform, and who pays for storage and retention?
- Are third-party integrations included, capped or priced as add-ons?
- What do offboarding and data export look like when the contract ends?
Set service levels and reporting deadlines
Ask for written definitions of mean time to detect and mean time to respond, including exactly when each clock starts and stops. Clarify whether a stated figure is a contractual commitment or a historical average, because vendors publish both and rarely label which is which.
Reporting obligations add a second clock. Covered public companies generally must disclose a material cybersecurity incident on SEC Form 8-K within four business days of determining materiality. Other regimes use different triggers and windows, so confirm what applies with counsel.
Then check whether the provider can hand you an incident timeline and supporting evidence fast enough to meet that window. Buying MDR does not transfer your reporting responsibility.
What a tiered service model looks like in practice
Platform-native services suit organizations standardized on one ecosystem. Many services, platform-native ones included, are sold in tiers, which is worth examining closely because the tier you buy determines how much hunting and incident support you get.
ESET structures its service this way, across two subscriptions. ESET PROTECT MDR is aimed at small and mid-sized businesses. ESET PROTECT MDR Ultimate is aimed at enterprises and adds customized threat hunting, digital forensic incident response assistance and a dedicated incident response lead.
Both run 24/7 and pair AI-driven detection with human analyst investigation.
The detail worth borrowing as an evaluation question is how the service adapts to your environment. At the enterprise tier, each engagement begins with an assessment of the customer’s environment, infrastructure and needs, which is used to build an individual security profile.
Ask every finalist how they build that profile and how response authority can vary by asset group. If a provider cannot describe it, it does not have the granularity a plant environment needs.
Pricing models you will encounter
Expect per-user pricing, per-asset pricing and asset-bucket pricing where devices are grouped into bands. Compare quotes against one shared inventory and one shared set of coverage assumptions, or the numbers are not comparable.
Build a multi-year total that includes required base licenses, third-party monitoring add-ons, log retention, incident response retainers, after-hours charges and onboarding fees. Ask how the bill moves as headcount and device count grow.
The OT constraint that changes everything
Plants and critical infrastructure need procedures that IT-only providers do not carry by default. NIST’s Guide to Operational Technology Security, SP 800-82 Revision 3, exists precisely because OT carries performance, reliability and safety requirements that standard IT controls do not account for.
The practical consequence is that a response action which is routine on a laptop can be dangerous on a control system. Isolating a programmable logic controller can stop a line. Rebooting an operator workstation mid-batch can create a safety event.
Define IT and OT response procedures separately. Put operations staff in the approval chain for anything touching the plant floor, and require that emergency actions respect existing safety requirements. Ask which industrial protocols a provider can actually see, and which OT response actions it will and will not take.
The 30-minute evaluation call
Run the same script with every finalist, then confirm the answers in writing.
- Which hands-on response actions are included, and which need our approval?
- Which of our existing tools are covered at the quoted tier?
- Are there limits or surcharges for third-party telemetry?
- How long are logs retained, and how is evidence handed over?
- Can we see a sample runbook and a redacted incident report?
- How is the analyst team staffed overnight and on holidays?
- What does the executive report contain, and how often does it arrive?
- What are the offboarding and data export terms?
- Which industrial systems and OT response procedures do you support?
- Who performs, approves and receives updates about each response action?
Final checklist
Score each finalist yes or no and attach evidence to every yes. An unverified answer is an open item, not a capability.
- Response ownership defined in the contract, with per-asset-group rules
- Coverage matches your inventory across IT and OT
- Third-party tool support confirmed at your quoted tier
- Service-level definitions written down, with clocks defined
- Evidence delivery fast enough for your reporting deadlines
- Data export and offboarding terms agreed
- Executive reporting cadence agreed
- OT procedures documented separately, with operations in the approval chain
- Onboarding schedule and responsibilities documented
- Multi-year total cost including base licenses
Use the same scorecard for a platform-native service, an OT specialist and a tiered subscription offering. Then schedule a 90-day review to check coverage, escalation contacts and reporting against what was signed. MDR reduces operational workload, but someone inside the business still owns the relationship, the approvals and the follow-through.
Frequently asked questions
Is MDR different from an MSSP? Often, though the labels overlap. MDR generally implies investigation and hands-on response by analysts. Traditional MSSP arrangements lean toward monitoring and escalation. Read the contractual response obligations rather than the category name.
Do we still need EDR if we buy MDR? Yes, in almost every case. MDR services run on detection tooling, and most providers either require their own endpoint agent or a supported third-party one. Confirm whether the tool license is bundled or billed separately.
Can an MDR provider cover our OT network? Some can, many cannot, and a few can see OT traffic without being permitted to act on it. Ask specifically which industrial protocols are parsed, which control systems are in scope and which response actions the provider will execute on the plant floor.
Who is responsible for regulatory disclosure after an incident? You are. A provider can supply the timeline and forensic evidence, but the reporting obligation stays with your organization. Build the evidence-delivery requirement into the service levels.
How long should an MDR evaluation take? Budget six to ten weeks for a plant environment. That allows time for a coverage map, two reference calls, a runbook review and a legal pass on response authority and data terms.









