Start with coverage
Ask which identities, devices, cloud services and log sources are included. Find out what remains outside the service, who owns those gaps and how changes are reviewed.
Understand the response model
An alert is only the beginning. Ask who investigates, who contacts your organisation, who can authorise containment and what happens outside normal working hours. Request written response targets and escalation arrangements.
Make the commercial scope clear
Identify licence costs, data ingestion, storage, onboarding and any incident work charged separately. Compare proposals using the same device counts, data volumes and coverage assumptions.
Ask for useful evidence
Request an example report, a description of quality assurance and relevant delivery credentials. Agree how service improvements and unresolved findings will be tracked.
