Resource Hub

Manufacturing Security

What Manufacturers Should Ask an MDR Provider

The managed detection and response market is crowded, ranging from genuinely capable security teams to thin resellers of a monitoring tool with minimal human oversight behind it.

By Ahmed HegaziFounder & Principal Security Consultant|2 min read

The Problem

The managed detection and response market is crowded, ranging from genuinely capable security teams to thin resellers of a monitoring tool with minimal human oversight behind it. Manufacturers evaluating providers often cannot tell the difference from a sales pitch alone, and the wrong choice is not discovered until an incident happens and the provider does not respond the way the contract implied.

Why it Matters Operationally

Manufacturing environments include operational technology that most MDR providers were never actually built to handle. A provider without OT experience may recommend or take actions, like aggressively isolating a device, that make sense in an office but interrupt production in a plant. Picking a provider based on price or a polished dashboard, without verifying real response capability and manufacturing familiarity, can leave a plant with the appearance of protection and very little of the substance.

The Simple Explanation

The gap between a strong and a weak MDR provider usually comes down to three things: whether their coverage actually extends into OT-adjacent systems or stops at standard IT endpoints, whether they can take real containment action within minutes or only alert and wait for the customer to act, and whether their analysts have any manufacturing or ICS background or are entirely generalist. Asking specific, detailed questions during evaluation reveals far more than any marketing page.

Practical Checklist

  • Does coverage extend to OT-adjacent systems, including historians and engineering workstations
  • What is the actual answer for legacy HMI machines that cannot run a standard endpoint agent
  • What actions can the provider take without waiting for customer approval, and how fast
  • Are there documented, differentiated response playbooks for IT versus OT incidents
  • Is the SOC staffed by the provider's own analysts or an unnamed third party
  • Do analysts have any manufacturing or ICS/OT security background
  • Can the provider show a sample incident report demonstrating real investigation depth
  • Can the provider speak to cyber insurance underwriting requirements

What You Can Do Now

Before your next renewal or a new evaluation, send this checklist directly to any provider you are considering and ask for specific, written answers rather than general assurances. A provider unwilling or unable to answer in detail is telling you something important on its own.

When Outside Help Makes Sense

If your organization does not have the internal security expertise to evaluate these answers technically, it is reasonable to bring in an independent advisor for the evaluation itself, or to use a structured reference framework like this checklist to keep the comparison consistent across vendors rather than relying on impressions from a sales call.