Forrester's guidance to European buyers in this market contains a sentence that should end a lot of vendor conversations early.
Having data centres in the EU is hardly sufficient in today's regulatory and geopolitical climate.
Every provider selling into Europe has a slide with a map on it showing Frankfurt, Dublin, Amsterdam. Forrester's position is that the map answers one question out of four, and the other three are where sovereignty actually lives.
The four tests
Forrester names what buyers should require a provider to demonstrate, and each one closes a gap that a data centre location leaves open.
Where data is processed. Storage location and processing location are different things. Telemetry can rest in Frankfurt and be analysed by a platform component running elsewhere, and the analysis is processing.
Data pathways and access mechanisms. Who can reach the data, through what route, under whose credentials, and with what logging. A support engineer with production access from outside the region is an access pathway regardless of where the disks sit.
Analyst locations and language capabilities. This is the one buyers consistently miss. A managed service is people watching telemetry, and those people are somewhere. If the analyst investigating an alert on a Dutch hospital's network is working from another continent, they are reading data about identifiable individuals from that jurisdiction, and no amount of local infrastructure changes that. Language matters for the same practical reason: an analyst who cannot read the content of an alert in the local language is working from metadata.
And how cross-border containment actions are carried out. An analyst in one jurisdiction issuing a command that isolates a machine in another is acting across a border, and both the authority and the record of it need to survive scrutiny.
Together those describe a service architecture rather than a hosting arrangement, and they are considerably harder to satisfy than a regional deployment.
Superficial adjustments
Forrester's framing of how the market responded is unusually direct. European customers now place greater emphasis on sovereignty, localisation, speed, automation, and resilience, and while some providers have adapted their frameworks and service delivery models to embed these, others offer only superficial adjustments.
That is an analyst firm saying, in the announcement of its own evaluation, that a portion of the vendors in it are performing compliance rather than delivering it.
The distinction is practically detectable. A provider that adapted its delivery model has European analysts on European shifts, a documented data flow, and a containment authority model that accounts for jurisdiction. A provider that adjusted superficially has a European data centre, a compliance page, and the same global follow-the-sun operation behind it.
The second is not necessarily unacceptable. It may be entirely fine for an unregulated business with no sensitive data. It is a serious problem for the sectors Forrester singles out, meaning healthcare, finance, and the public sector, where sovereignty and localisation requirements are strict.
Inside The Forrester Wave: Managed Detection And Response Services In Europe, Q3 2025
The evaluation is Forrester's second focused on this market, following a 2023 edition, and scored eleven vendors against twenty six criteria: Accenture, CrowdStrike, eSentire, ESET, EY, Kudelski Security, NCC Group, Obrela, Orange Cyberdefense, Sophos, and WithSecure.
eSentire placed as one of only two Leaders, with Forrester positioning it for organisations wanting rapid data source integrations and an integrated exposure management offering.
Two Leaders in an eleven-vendor field is a narrow top tier, and it is consistent with Forrester's observation that adaptation has been uneven.
The vendor list itself is the most informative part. Compare it to Forrester's global MDR evaluation, which scored ten providers dominated by American security vendors. ESET is Slovak. Obrela is Greek. Orange Cyberdefense is French. WithSecure is Finnish. Sophos and NCC Group are British. Kudelski Security is Swiss.
More than half the European field is European-headquartered, and several of those names do not appear in the global evaluation at all. That is the same pattern visible in Forrester's European cybersecurity consulting research, where the vendor set became measurably more European as sovereignty requirements hardened.
It is also why the global evaluation is not a substitute here. A Leader in the global market may not be a Leader in Europe, and several credible European providers were never in the global consideration set.
Note too that Accenture and EY appear. Consultancies competing in a managed security service evaluation reflects the fact that European buyers increasingly want the detection service connected to the compliance and resilience programme around it, which is advisory territory.
The tripartite pressures
Forrester describes European CISOs leaning on MDR providers to handle three simultaneous pressures: complex regulation, economic volatility, and agile threat actors.
Regulation is the distinctive one. European security leaders operate under overlapping regimes covering network and information security, operational resilience in financial services, critical entity protection, and data protection, each with its own scope, incident reporting timelines, and supervisory authority.
The reporting obligations are the part that touches MDR directly. Several regimes require notification of significant incidents within tight windows, which means the provider's incident classification, evidence collection, and reporting output are feeding a regulatory process rather than an internal one. A provider that produces a good technical report on its own schedule is not the same as one that produces a report suitable for a supervisor within the required window.
Economic volatility explains why organisations are buying a service rather than building a team. Building a security operations centre is a multi-year commitment to headcount at a moment when European budgets are under pressure and security talent is scarce and expensive.
And Forrester's framing that European leaders expect providers to enable operational resilience, because they lack internal capability for region-specific advanced threats and for coordinating cross-border response, describes a scope well beyond alerting.
Cross-border response coordination is worth dwelling on. A multinational incident spanning three countries involves three regulators, potentially three notification regimes, three sets of local counsel, and staff in three time zones. A provider that has done this before is selling coordination experience, which is not a technical capability and does not appear in a feature comparison.
Beyond extended detection
Forrester notes that the market has moved past the point where extended detection and response was considered a differentiator.
That is worth registering because XDR was the dominant marketing frame in this category for several years. Correlating signal across endpoint, network, identity, and cloud was the thing vendors competed on, and it is now assumed.
What replaced it, on Forrester's account, is resilience: not merely detecting and responding but sustaining operations through an incident and recovering afterwards. That includes forensics, which brings us to the test Forrester recommends.
The test worth running
Forrester's suggested evaluation method is the most useful thing in the research and it costs nothing to run.
Ask a provider to walk you through a real incident, demonstrating how telemetry was collected, how quickly containment was executed, and whether forensics required a separate handoff.
That last clause is the trap, and it is well set. Many providers detect and contain competently and then hand you off to a separate incident response engagement, frequently on a separate contract at a separate rate, when you need to understand what actually happened.
The moment you discover that boundary should not be during an incident. A regulator asking what data was accessed, a customer asking whether their information was affected, or an insurer asking for the forensic record are all questions that arrive after containment, and if answering them requires a new statement of work and a new team learning your environment from scratch, the response was half a service.
Forrester's guidance to choose providers that weave endpoint coverage, threat intelligence, and other telemetry into insights that inform security strategy and reduce containment delays points at the same integration requirement from the preventive side.
AI, with the European qualifier
Forrester's caution on AI in this market is pointed: vendors have positioned it as the panacea for everything that ails security, and while it does shorten incident timelines, the nuances matter.
Its specific recommendation is to favour vendors that can demonstrate how AI enables containment actions and configuration updates with appropriate human oversight.
The phrase doing the work is human oversight, and it lands differently in Europe than elsewhere.
Automated containment is autonomous software taking a consequential action, and where that action affects an identifiable person's access or systems, European regulatory expectations around automated decision-making and human involvement become relevant. The provider needs to be able to show what the automation is permitted to do unsupervised, where a human sits in the loop, and how the decision is recorded.
That is a governance question rather than a capability question, and it is the one to press. A vendor that can demonstrate the boundary has thought about it. One that describes autonomous response as an unqualified benefit has not been asked yet.
What this changes about a shortlist
The practical consequence of all of this is that a European MDR shortlist should be built differently from a global one.
Start from the sovereignty position rather than from capability, because it eliminates candidates rather than ranking them. If your sector or your data cannot tolerate processing or analyst access outside the region, a substantial portion of the market is out before any comparison happens.
Establish the regulatory reporting requirement early, since a provider whose incident output does not fit your supervisory obligations creates work rather than removing it.
Test the forensics boundary, using Forrester's real-incident walkthrough.
And treat local presence as evidence rather than as marketing. Analyst locations, language coverage, and the countries where a provider has actually handled incidents are checkable facts, and the providers who have made those investments will answer without hesitation.
Analyst Source
Forrester Research
Category definition, vendor inclusion, and buyer guidance in this article draw on Forrester's coverage of managed detection and response in Europe. The Q3 2025 Wave is Forrester's second evaluation focused on this market, following a 2023 edition, and scored 11 vendors against 26 criteria. Forrester evaluates the global MDR market separately, with a distinct and only partially overlapping vendor set.
Source research
- Announcing The Forrester Wave: Managed Detection And Response Services In Europe, Q3 2025
- The Forrester Wave: Managed Detection And Response Services In Europe, Q3 2025
- The Forrester Wave: Managed Detection And Response Services, Q1 2025
Forrester does not endorse any provider named here, and tier placement should not be read as a recommendation to buy.