Among the three things Forrester tells prospective buyers to consider in its current evaluation of this market, one contradicts almost every vendor pitch in the category.
Generative AI's impact on providers shows, but its benefits for customers are less clear.
Read that again with the commercial model in mind. MDR is sold as a subscription, priced by endpoints, users, or data volume. If AI makes the provider's analysts substantially more productive, the provider's cost of delivery falls. Whether anything reaches the customer depends entirely on competitive pressure, and Forrester is saying the evidence for that is thin so far.
That is a useful thing to know before a renewal conversation.
Why this market exists
The economics of a security operations centre are brutal at small and mid scale.
Round-the-clock coverage requires enough analysts for three shifts plus holidays, sickness, and turnover, which in practice means eight to twelve people minimum. Those people are expensive, difficult to hire, and difficult to retain, because the work is repetitive most of the time and intense occasionally.
Below a certain size, no organisation can justify that. Above it, many still cannot justify staffing the overnight shift with anyone senior enough to make a good decision at three in the morning.
MDR solves this by spreading those analysts across many customers. Forrester's framing describes the service as helping teams detect, investigate, respond, and recover from attacks ranging from commoditised malware to sophisticated nation-state techniques.
The important part of that sentence is the range. A provider watching hundreds of environments sees attack patterns before any individual customer does, which is a genuine advantage that no internal team of any size can replicate.
Inside The Forrester Wave: Managed Detection And Response Services, Q1 2025
Published on 27 February 2025, the evaluation scored ten providers against twenty one criteria across current offering, strategy, and market presence.
CrowdStrike placed as a Leader with the highest possible scores in ten criteria spanning strategy and current offering, including managed investigation, threat hunting, analyst experience, vision, innovation, and pricing flexibility and transparency. Forrester noted its ability to detect across endpoint, extended, and identity detection surfaces.
Red Canary placed as a Leader, also taking the highest possible scores in ten criteria including detection engineering, threat hunting, analyst experience, dashboards and reporting, vision, innovation, and community.
Expel placed as a Leader, with Forrester highlighting its balance of human-led investigation and software-enabled platforms as a differentiator.
Three Leaders out of ten. Compare that against the Q1 2021 edition, which scored fifteen providers against nineteen criteria: Arctic Wolf, Binary Defense, CrowdStrike, Cybereason, deepwatch, eSentire, Expel, FireEye, Kudelski Security, NCC Group, Rapid7, Red Canary, Secureworks, SentinelOne, and Trustwave.
Fifteen to ten in four years, with criteria rising slightly. A market consolidating while the bar goes up.
Forrester also runs a separate evaluation of this market in Europe, where the buying requirements differ enough to warrant distinct research.
Detection as code
The first of Forrester's three buyer considerations is that providers scale through strong detection engineering via detection as code.
That phrase describes something specific and it is the mechanism that separates providers that scale from providers that do not.
Detection logic, the rules and analytics that identify malicious behaviour, was traditionally written by analysts, tuned per customer, and maintained by hand. That approach works at ten customers and collapses at a thousand, because every new detection is a bespoke artefact and every false positive requires manual tuning somewhere.
Detection as code treats that logic as software. It is version-controlled, peer-reviewed, tested against known attack data before deployment, and shipped through a pipeline. A new detection developed in response to an emerging technique is written once, validated, and deployed across the entire customer base within hours.
For a buyer this matters in two measurable ways. It determines how quickly a provider responds to a novel technique, and it determines whether detections improve or accumulate. A provider without engineering discipline builds up thousands of rules of unknown quality that nobody dares delete.
The question worth asking is how detections are tested before deployment and how many were retired in the last year. The second number tells you whether anyone is maintaining the estate.
The proactive shift
Forrester's second consideration is that security posture improvement matters as much as detection and response, and its framing is that detection and response alone is no longer enough because customers now demand proactivity.
That is a meaningful expansion of scope. The original MDR proposition was reactive by design: something bad happens, we notice, we tell you, we help you stop it.
Proactive means reducing the number of things that can happen. Exposure management, attack surface visibility, configuration weaknesses, identity hygiene, and vulnerability prioritisation all sit in that space.
The logic is sound from both sides. A provider watching an environment continuously sees the weaknesses that produce the alerts it keeps handling, and fixing them reduces its own workload. A customer paying for detection would rather have fewer things to detect.
It also creates the same structural tension visible in every managed service. A provider paid to detect and respond has a volume of work that its own preventive advice reduces. Whether that matters depends on pricing structure, and it is worth understanding whether your agreement rewards the provider for a quieter environment or bills for a busier one.
The AI question, stated plainly
Return to Forrester's third consideration, because it is the one that should shape a negotiation.
AI is genuinely transforming MDR delivery. Alert triage, enrichment, correlation across telemetry, summarising an incident timeline, drafting the investigation narrative, and suggesting containment actions are all tasks where machine assistance produces real gains. Providers report faster mean time to respond, and that is credible.
Forrester's scepticism is not about whether the technology works for the provider. It is about whether the customer sees the benefit.
Three ways the benefit could reach a customer, in descending order of how often it actually does.
Faster response, which is measurable and does reach customers when it happens. This is the strongest claim and it is worth asking for evidence rather than assertion.
Better coverage, meaning more telemetry analysed rather than sampled, or detections that would previously have been too expensive to run. Real, and harder to verify.
Lower price, which is where the gap sits. If a provider's analyst can now handle three times the alert volume, the delivery cost per customer has fallen substantially, and the subscription price generally has not.
CrowdStrike's maximum score in pricing flexibility and transparency is notable in this context. Transparency is the criterion that lets a buyer have this conversation at all, because you cannot negotiate against a cost structure you cannot see.
The practical position for a renewal is to ask directly what proportion of triage is now automated, how that has changed since the last contract, and how the pricing reflects it. A provider that has publicly claimed AI-driven efficiency in an analyst evaluation has supplied the premise for the question.
What the R actually means
The single largest practical difference between MDR providers is not detection quality. It is what happens after detection, and buyers consistently underweight it.
At one end, the provider alerts you. A well-written, enriched, contextualised alert arrives with a recommendation, and your team acts. That is detection with advice, and at three in the morning it means someone on your side has to wake up, understand, and decide.
At the other end, the provider acts. It isolates the host, disables the account, blocks the destination, and tells you afterwards. Containment happens in minutes without waiting for anyone.
The second is far more valuable and requires something organisations find genuinely difficult, which is granting a third party authority to take disruptive action in your production environment without asking first.
That authority has to be scoped in advance: which actions, on which systems, under what conditions, with what exclusions. The exclusions matter most. Isolating a laptop is routine. Isolating a domain controller, a trading system, or a hospital's clinical workstation during a shift is a different decision, and the boundary needs to be drawn while everyone is calm rather than during an incident.
The evaluation question that follows is not whether a provider offers response but what it is contractually permitted to do in your environment by default, how quickly the authority can be extended during an incident, and what the escalation path looks like when the answer needs a human on your side at four in the morning.
What decides whether this works
MDR is one of the more genuinely successful outsourcing arrangements in enterprise technology, because the economics are honest. Most organisations cannot staff a competent round-the-clock security operation, and a shared one delivers better outcomes than an underfunded internal attempt.
What determines whether a specific engagement works is less about the provider and more about two things on the customer side.
Telemetry coverage, because a provider can only detect what it can see. An MDR service watching endpoints while your identity provider, cloud control plane, and SaaS applications go uninstrumented is defending a portion of your estate. Expanding coverage usually costs more, which is why it does not happen, and which is why compromises progress through the blind spots.
And the internal counterpart, because MDR does not remove the need for someone on your side who understands the environment, can answer questions during an incident, and can make decisions the provider is not authorised to make. Organisations that buy MDR expecting to have no security function discover that the service works considerably better with one.
Neither of those is something a Wave placement tells you, and both matter more than the difference between the providers at the top.
Analyst Source
Forrester Research
Category definition, vendor inclusion, and evaluation findings in this article draw on Forrester's coverage of managed detection and response, scored in Q1 2021 against 19 criteria covering 15 providers and in Q1 2025 against 21 criteria covering 10 providers, across current offering, strategy, and market presence. Forrester evaluates this market separately in Europe.
Source research
Forrester does not endorse any provider named here, and tier placement should not be read as a recommendation to buy.