Forrester's current title for this market adds a word to the pasted name: Managed Detection And Response Services. The newest edition, The Forrester Wave: Managed Detection And Response Services, Q1 2025, is the third installment, and its central finding is that the name itself is now half wrong. "While MDR was born as a reactive service, it needs to become more proactive."

The report that tested four attacks: The Forrester Wave: Managed Detection And Response Services, Q1 2025

VP, principal analyst Jeff Pollard announced the evaluation on February 27, 2025, with senior research associate Liam Holloway, and the blog reads like an audit log of the process behind it: roughly forty thousand words of vendor text read, thirteen and a half hours of demonstration briefings, thirteen and a half hours of customer reference calls, four hundred plus slides, forty six case studies, and quotes assessed for ten thousand endpoints priced from four hundred thousand dollars to over a million.

Every provider was run through four live attack scenarios: an insider threat posing as a new hire, an account takeover in a SaaS platform, social engineering of the help desk, and software supply chain poisoning. Pollard's advice to buyers is to use exactly these four scenarios as their proof-of-concept templates.

The market context is blunt. MDR is "fragmented," with legacy managed security service providers entering the space and muddying the definition, and the report's two biggest trends are detection engineering and security posture management.

The two confirmed Leaders and their different proofs

CrowdStrike announced a Leader placement, ranking highest of all vendors in the Strategy category with the highest possible scores in managed investigation and threat hunting. The endpoint-native vendor's managed service is the scale argument: telemetry from the platform it already sells, triaged by the service it runs on top.

Red Canary announced a Leader placement, one of three Leaders in the edition, with the highest possible scores in ten criteria including detection engineering, threat hunting, analyst experience, dashboards and reporting, vision, innovation, and community. Forrester credited its "deep pedigree in threat intelligence" and its bet that detection as code is "the only way to scale detection meaningfully as an MDR provider."

The third Leader placement has not surfaced publicly, and this article assigns no tiers the record does not support.

The shift from reactive to proactive

Pollard's sentence deserves to be read twice: "While MDR was born as a reactive service, it needs to become more proactive."

The criteria now grade posture, not just response. Exposure management, attack surface management, and system prioritization sit alongside detection and response in the evaluation, because the market learned that finding the attack after it starts is the expensive way to run a security service.

And the scaling mechanism the report names is detection as code. Detection rules written, versioned, and tested like software, shipped across the customer base, instead of analyst-written signatures decaying in isolation. That methodological shift, more than any tool, is what the report says separates the scalable providers from the rest.

For the buyer, detection as code has a contractual consequence. A provider that ships detection as code can show you the test coverage behind the rules watching your estate, and the change history of every rule since deployment. A provider that cannot is running the older model, analyst craft without an audit trail, and the scorecard now treats that distinction as the difference between tiers.

The genAI finding the vendors did not want

The report's third trend is the most quietly damning: generative AI's impact is visible in provider offerings, but its benefits for customers remain less clear.

One provider's own roundtable made the point in public. Expel reported high marks for detection engineering and improvements in managed investigations, and a 1 of 5 on generative AI usage, which it described as an intentional decision. The scorecard rewarded the restraint, which is the rarest finding in any AI-adjacent evaluation this year.

For a buyer, the lesson is to ask what the AI actually does in the service, not whether it exists. A provider that cannot explain its AI's role in triage is selling marketing, and the scorecard knows the difference.

The European sibling scorecard

Three quarters after the global edition, Forrester published The Forrester Wave: Managed Detection And Response Services In Europe, Q3 2025, scoring eleven vendors on twenty six criteria, and its finding is the one European buyers need verbatim: data centers in the EU are no longer sufficient. Providers must demonstrate data processing locations, data pathways, analyst locations, language capabilities, and cross-border containment procedures.

CrowdStrike took a Leader placement in Europe too, ranking highest in both Strategy and Current Offering. ESET announced a Strong Performer placement on localized threat intelligence, EU tenancy, and local language capabilities.

Three questions for the service that claims it is proactive

Which posture work is in the contract, not the marketing deck? The report says posture management is now as important as detection. Ask which exposure management and prioritization outputs you receive, on what cadence, and who is accountable for the fixes.

Show me your four scenarios. Pollard's demo list is the buyer's test script. Insider threat, SaaS takeover, help-desk social engineering, supply chain poisoning. Run each in your environment before signing.

What does the AI do, and who watches it? The report found benefits unclear and rewarded one provider's restraint. Ask for a specific, testable claim about AI in your service tier, with the human oversight structure named.

Analyst Source

Forrester Research

Category definition, vendor inclusion, and evaluation findings in this article draw on The Forrester Wave: Managed Detection And Response Services, Q1 2025, the third installment of the evaluation, announced by VP, principal analyst Jeff Pollard with senior research associate Liam Holloway on February 27, 2025. CrowdStrike and Red Canary have publicly announced Leader placements, the latter one of three Leaders, and the third has not surfaced publicly. The evaluation's central themes are detection engineering with detection as code, the shift from reactive to proactive posture management, and unclear customer benefits from generative AI. A European edition, The Forrester Wave: Managed Detection And Response Services In Europe, Q3 2025, scored 11 vendors on 26 criteria, with CrowdStrike a Leader and ESET a Strong Performer.

Source research

Forrester does not endorse any vendor named here, and tier placement should not be read as a recommendation to buy.

The adjacent shortlist item is Enterprise Email Security: of the thirty seven customer references Forrester interviewed for this evaluation, only two ran a single email security vendor, which reframes the entire category as a market built on deliberate redundancy.

Buyers evaluating this should also weigh Managed Detection And Response Services, the closest coverage already published on this site: forrester's own buyer guidance undercuts the AI pitch: providers are getting measurably more efficient, and there is little evidence yet that any of that efficiency is reaching customer pricing.