Platform

HexaCore, The unified resilience core HexaSOC, AI agentic SOC & MDR HexaInt, Cyber & dark-web intelligence HexaOT, OT & ICS security HexaComply, Compliance & TPRM HexaAI, AI security & governance HexaCustody, Digital content custody HexaStrike, Agentic offensive security HexaMatrix, ATT&CK coverage & mapping HexaView, Multi-tenant customer portal

Solutions

Managed Detection & Response, 24/7 AI-agentic detection & response Co-Managed SOC, Your team and ours, one operation Detection Engineering, Coverage you can measure Incident Response Retainer, A hand on the wheel before you need it Penetration Testing, See your estate the way attackers do Red & Purple Teaming, Offence that hardens your defence Continuous Security Validation, Validate continuously, not annually Cyber Crisis Tabletop & War-Gaming, Rehearse the bad day Continuous Threat Exposure Management, From a list of vulns to a plan Cyber Risk Quantification, Risk as a number the board can use Managed Threat Intelligence, Signal, not noise Digital Risk & Brand Protection, Protect your name where you cannot see Managed OT & IoT Monitoring, Security for systems that cannot go down OT/ICS Assessment, Know your OT before an attacker does Compliance as a Service, Gap assessment to certification Third-Party & Supply-Chain Risk Management, Risk does not stop at your perimeter Virtual CISO & Governance Advisory, Executive security leadership, on tap AI Security & Governance, Govern the AI you are adopting Managed Content Custody, Custody for your crown jewels

Industries

Maritime, Fleets, ports and shore-side IT Media & Entertainment, Pre-release content and production Casino & Gaming, Platform integrity and player trust Financial Services, DORA, resilience and fraud Critical National Infrastructure, Converged IT and OT estates Manufacturing, Plants, PLCs and supply chain Healthcare, Clinical systems and patient data Pharmaceutical & Life Sciences, Research IP, GxP and data integrity Energy & Utilities, Generation, grid and SCADA Government, Sovereign data and assurance

Partners

Partner programme, Refer, resell or white-label Cyber Dockside AI, Maritime, exclusive partner TeamLogic IT, US channel partner Walking Comet, Australia, casino & gaming Copla, GRC technology partner Nexovern, Runtime AI sensor partner

Learning

Learning Hub: explainers, guides and briefings

Company

About HexaShield Contact Book a meeting Client Login Book a demo
Guide

Twelve questions to ask an MDR provider

The questions that separate providers quickly, including the three most will not answer straight.

Updated August 2026 · 7 minute read

Before the demo

Most MDR evaluations are decided by the demo, which is the part every provider has optimised. These questions are more useful because they are harder to rehearse.

The twelve

1. What happens to an alert that nobody escalates? The honest answer describes the service. If low-severity alerts are closed automatically at volume, say so; that may be fine, but you should know.

2. How was your coverage figure measured? Claimed from datasheets, or demonstrated by testing? The difference is the whole question.

3. Who owns containment at 3am, and what may they do without me? Get the specific list, in writing, per environment.

4. What happens when a log source stops shipping? Silent detection failure is the most common way monitored organisations get hit.

5. Can you cover operational technology, and how? If the answer involves scanning, ask what their insurer thinks.

6. What do I see, and when? Ask for the analyst view, not the executive dashboard.

7. How do detections get written and tuned, and by whom? A service that only consumes vendor rules is a reseller with a rota.

8. Show me a case you got wrong. Everyone has them. How a provider talks about theirs is the single most informative moment in an evaluation.

9. What is the escalation path into my team, and who decides? Ambiguity here surfaces during an incident, which is the worst possible time.

10. What happens at renewal if I want to leave? Ask specifically about detections, tuning and case history: what leaves with you.

11. Do you compete with me or my partners? Relevant for MSPs and anyone selling security onward.

12. What would make you tell me I do not need this? The answer tells you whether you are talking to advisers or to a quota.

The three most will not answer straight

Questions two, eight and twelve. Coverage measurement, because most providers have not measured it. A case they got wrong, because the instinct is to protect the sale. And what would make them say no, because most commercial models cannot accommodate that answer.

A provider who answers all three plainly is worth more of your time than one with a better demo.

FAQ

Questions, answered

What if a provider will not answer question eight?
Press once, then draw your conclusion. Every security operation has cases it called wrong; that is the nature of the work. A provider who cannot discuss one is either not looking, or has decided you cannot handle the truth, and neither bodes well for how an actual incident will be handled.

Want this applied to your estate?

Tell us what you are protecting and where you feel exposed. We will map it to the right capabilities and set up a walkthrough.