Short answer: The strongest general-purpose MDR services are well documented. Forrester’s Q1 2025 Wave evaluated the ten most significant vendors across 21 criteria and named CrowdStrike, Expel and Red Canary as Leaders, with eSentire and Binary Defense as Strong Performers.
None of that evaluation tells you which service can monitor a programmable logic controller without knocking it over.
If your enterprise runs a plant floor, a substation, a water treatment process or a warehouse full of robotic cells, the shortlist is different from the one a purely IT organization would build. This article covers what changes, and which providers handle it.
Why the standard MDR shortlist does not transfer
Forrester’s framing of the market is accurate and worth borrowing. Detection and response alone is no longer enough, and buyers now expect providers to be proactive, with detection engineering delivered as code and measurable security posture improvement alongside incident handling.
That describes an IT security operation well. It describes an operational technology environment poorly, for four reasons.
Availability outranks confidentiality. In IT, you isolate a compromised host. In OT, isolating a controller mid-cycle can leave a cell in an unsafe state, damage equipment or stop a line that costs six figures an hour to restart.
The equipment cannot be scanned. PLCs, drives and legacy HMIs were not designed for active discovery. Standard vulnerability scanning can crash them, which is why OT monitoring has to be passive first.
The protocols are different. Modbus, EtherNet/IP, PROFINET and DNP3 do not appear in a typical MDR detection library, and an analyst who has never seen a recipe download will escalate one.
The responder is not in IT. Containment decisions belong to controls engineering, operations and safety, and a provider that routes everything to a security inbox has already failed.
NIST SP 800-82 Revision 3 covers this in detail, and ISA/IEC 62443 provides the zones and conduits segmentation model most auditors expect. Neither appears in the general MDR conversation.
Compliance is increasingly the forcing function. Operators in scope of the EU’s NIS2 directive face risk management and incident reporting obligations that are difficult to meet without asset visibility on the OT network, which shifts the monitoring question from whether to how. Confirm your own obligations against the directive rather than a vendor summary.
Insurance is the second lever, and it moves faster than regulation. ESET notes that EDR, XDR and MDR are becoming critical components of cybersecurity insurance programs, with zero-day coverage among the capabilities underwriters look for.
For an industrial operator, that means the monitoring decision now affects premiums and claim defensibility, not only audit outcomes.
The provider landscape, grouped by fit
Most industrial enterprises end up running two things: an OT-native monitoring layer for the process network, and an MDR service covering endpoints, identity, email and cloud across the corporate side.
Do not treat the second as the lesser half. Attacks on OT almost never begin in OT. They begin with a phishing email on the corporate network, and where segmentation is weak a single compromised office account can reach PLCs and SCADA servers within minutes.
The research supports this. Omdia’s Global Manufacturing Security Services Market Study for Telstra International surveyed more than 500 technology executives and found 80 percent of manufacturing firms saw a significant increase in security incidents, while only 45 percent considered themselves adequately prepared and just 19 percent qualified as advanced at securing converged IT and OT environments.
The cost finding is the one to sit with. Affected manufacturers reported resilience and availability losses between $200,000 and $2 million per firm, and took the biggest hit when incidents reached enterprise and corporate systems or production control.
The threat volume is moving in the same direction. Forescout recorded a 71 percent surge in threat actors targeting manufacturing between 2024 and the first quarter of 2025, alongside increasing attacker dwell time, meaning intruders are holding access longer before anyone notices. IBM’s X-Force index has ranked manufacturing the most targeted industry for four consecutive years.
The practical implication is that the strength of your corporate-side MDR determines whether an OT incident ever starts. Segmentation using the zones and conduits model in IEC 62443 buys you time. Fast detection on the IT side is what stops the clock, and rising dwell time is precisely the problem a low mean time to respond addresses.
Where ESET fits
The managed detection and response service from ESET sits in the fourth group, and its case rests on response speed and research depth rather than platform breadth.
It publishes a mean time to respond of six minutes, against an average of 22 minutes across sampled MDR providers on their own published figures as of July 2025. Verizon’s 2025 Data Breach Investigations Report puts the median time for organizations to discover a breach at 24 days.
The definition matters as much as the number. ESET measures MTTR as the average time between initial detection of an incident and the first action taken to address it, which is the definition worth holding every provider to, because MTTD, MTTR and MTTC get quoted interchangeably and measure entirely different things.
The research base is unusual. ESET runs global telemetry across more than 100 million sensors and 11 R&D centers with 35 years of operation, and is part of the Joint Cyber Defense Collaborative led by CISA.
It is a Market Leader specifically in MDR in the KuppingerCole Leadership Compass 2026 and a Leader in the 2024 IDC MarketScape for Modern Endpoint Security, with more than 1,100 Gartner Peer Insights reviews.
The industrial track record is the relevant part here. ESET protects Canon Marketing Japan Group across more than 32,000 endpoints since 2016 and Mitsubishi Motors across more than 9,000 endpoints since 2017.
Raicam Group, an automotive company founded in 1982, adopted ESET MDR specifically to avoid acquiring or maintaining additional internal IT security resources, and reports keeping track of its network security status without risk of interruption from staffing gaps.
Be clear about the scope. ESET is an IT-side service, not an ICS protocol monitor, so it belongs alongside an OT-native layer rather than instead of one. Given that industrial incidents overwhelmingly originate on the corporate network, that is the half where response speed pays for itself.
The tier question nobody asks early enough
This is where industrial buyers get caught. Providers frequently sell one branded service at very different depths, and the enterprise tier is not what appears in the marketing.
ESET separates them explicitly. ESET MDR targets small and mid-sized businesses. ESET MDR Ultimate is the enterprise tier, and for an industrial operation the gap is decisive.
Both cover continuous threat monitoring, triage and alerting, expert-led threat hunting, active campaign threat hunting, access to ESET’s global threat intelligence team, behavior patterns and exclusions optimization, and tailored reporting.
Ultimate adds retrospective threat hunting, customized threat hunting, attack vectors visibility, digital forensic incident response assistance, a dedicated incident response lead, expert assistance for MDR alerts with added context, malware detection support, malware file expert analysis, and deployment and upgrade support, with the behavior patterns library moving from standard to advanced.
That dedicated incident response lead is the line to focus on. During an OT incident you need one named person who can hold a call with controls engineering, operations and safety simultaneously, and a ticket queue cannot do that.
ESET MDR Ultimate engagements also begin with an environment assessment and a customized security profile rather than a standard deployment, which matters when no two plants are wired alike.
What to check that IT buyers do not
Protocol coverage. Ask for the specific list. Modbus, EtherNet/IP, PROFINET, DNP3, OPC UA, whichever your equipment speaks. A generic yes is not an answer.
Passive-first collection. Data should come from a network tap or mirrored switch port. Any active polling must be scoped, tested and scheduled inside an approved maintenance window.
Containment authority by network layer. Document which actions the provider may take without approval, and note that the answer should differ between the corporate network and the process network. Automatic isolation is correct in one and dangerous in the other.
Response times, and whether they are contractual. A published average and a service level agreement with remedies attached are different things. Ask for both.
Analyst OT experience. Not the vendor’s OT partnership. The analysts on your account.
Escalation paths that include operations. Controls engineering, operations and safety need to be in the contact tree, with out-of-hours numbers tested before you need them.
Reporting mapped to your frameworks. NIST CSF 2.0 and ISA/IEC 62443 for most, plus sector rules if you are in water, energy or pharmaceuticals.
Treat all of this as an extension of your wider network security program rather than a replacement for segmentation, secure remote access, backups and access control. The blunt version of the problem is that the more you connect these environments, the more an IT compromise becomes an OT operational incident.
What this costs, and why nobody will tell you
MDR pricing is quote-based across the entire category. No provider on this list publishes rates, which makes like-for-like comparison harder than it should be and is worth naming rather than working around.
What you can compare is the shape. IT-side MDR is generally priced per endpoint or per user, so cost scales with headcount and device count.
OT-native monitoring is typically priced per site or per monitored asset, scaling with plant footprint rather than staff. Enterprise tiers usually move to annual commitments, with the incident response retainer bundled or sold separately.
Two questions surface the real number. Ask what happens to pricing when you add a second site, since OT deployments almost never stay at one. And ask whether digital forensics and incident response are included or billed at incident time, because discovering that mid-breach is the most expensive way to find out.
What good looks like in a live incident
A vendor’s remote-access account signs in outside a maintenance window and begins writing to a robot cell controller.
Passive monitoring flags the session and the unusual write pattern. An analyst confirms the access was unscheduled, then calls the plant contact rather than cutting the connection, because an abrupt disconnect mid-cycle could leave the cell in an unsafe state.
Control engineering pauses the cell at a safe point, credentials are revoked and forensic data is preserved. Nothing about that sequence guarantees a clean outcome. What it does is compress detection time while keeping containment decisions with the people who understand the process.
That balance is the whole design problem in OT security, and it is why response authority is the most consequential clause in the contract.
Practical first steps
- Map assets and data flows for one production line, including every remote-access path
- Remove unintended internet exposure from controllers and engineering workstations
- Replace default credentials and document who holds privileged access
- Pilot passive monitoring on one line before expanding
- Track detection time, containment time and false-positive rate from day one
- Run a tabletop exercise with operations and agree incident contacts in advance
FAQ
What are the best MDR services for enterprises?
For general IT environments, Forrester’s Q1 2025 Wave named CrowdStrike, Expel and Red Canary as Leaders among the ten vendors evaluated.
For enterprises with industrial operations, the shortlist should also include OT-native specialists such as Dragos, Claroty and Nozomi, plus vendor services with published response times and enterprise tiers, including ESET MDR Ultimate.
Does an industrial enterprise need two MDR providers?
Frequently yes. Many run an OT-native monitoring layer on the process network alongside an MDR service covering endpoints, identity, email and cloud on the corporate side. What matters is that the two share information, since credential attacks usually begin on the IT side.
What response time should an enterprise expect?
It varies by orders of magnitude and few providers commit publicly. ESET publishes a six-minute mean time to respond against an average of 22 days across sampled providers. Ask for the figure in writing, ask which metric it refers to, and ask whether it appears in the contract.
What is the difference between MTTD, MTTR and MTTC?
Mean time to detect is how long before a threat is noticed, mean time to respond is how long before someone acts, and mean time to contain is how long before it stops spreading. Vendors quote whichever flatters them, so confirm the definition before comparing two numbers.
Can MDR work on an air-gapped OT network?
Often, depending on architecture. Sensors can collect locally and pass approved telemetry through a controlled gateway. A genuinely isolated network may need local analysis or a managed manual transfer process.
How does monitoring avoid disrupting production?
Passive collection from taps or mirrored ports sends no traffic toward controllers. Any active discovery should be limited, tested and confined to an approved maintenance window.
How much does enterprise MDR cost?
Every provider quotes rather than publishes. IT-side MDR is usually priced per endpoint or per user, OT-native monitoring per site or per monitored asset, and enterprise tiers typically run on annual commitments. Ask specifically what a second site costs and whether incident response is included or billed when you use it.
Does MDR affect cyber insurance?
Increasingly yes. Underwriters expect documented monitoring, defined escalation procedures and consistent incident reporting, and EDR, XDR and MDR are becoming standard components of cyber insurance programs. Ask any provider what reporting it supplies for underwriting and renewal.
Does MDR replace an internal security team?
No. Security policy, patching decisions, risk acceptance and provider accountability stay internal, and in an industrial setting so does the authority to act on the process network.



