Start from a neutral baseline and add what matters to you. Criteria are labeled by source — the platform baseline is architecture-neutral; buyer-contributed criteria are shown separately.
Build your evaluation
no account needed
Match on your requirements
no account needed
This evaluation is stored in your browser only. We cannot see it, and it is not tied to any account. Save it to a link or create an account to keep it across devices — you can export it at any time either way.
1. Weight what matters
99 criteria
baselineWhat telemetry and environments does the service cover (endpoint, network, cloud, identity, SaaS, email, OT), is it bring-your-own-tools or the provider's own stack, and how broad is the integration set?
baselineDescribe what 'response' actually includes — does the SOC actively contain/remediate (isolate hosts, disable accounts) or only notify and recommend? What actions are taken on your behalf, and with what guardrails?
baselineWhat are the contractual detection/response SLAs (MTTD/MTTR), is the SOC genuinely 24/7 (and follow-the-sun), and what is the analyst-to-customer model?
baselineHow is AI/automation used in triage and investigation, and where do human analysts intervene? What is automated versus analyst-led?
baselineIs the service delivered on the provider's own platform or on your SIEM/EDR, who owns the data and detections, and what lock-in exists if you leave?
baselineIs proactive threat hunting included (hypothesis-driven versus alert-driven), and what threat intelligence and custom detection engineering underpin detections?
baselineWhat is the onboarding timeline, and how are detections tuned over time to reduce false positives?
baselineWhat visibility do you get (portal, raw alerts, full investigation detail, reporting), and provide customer-validated outcome metrics.
baselineWhat is the pricing model — per endpoint, per GB of log ingestion, per user, or a flat enterprise fee — and how does cost change as the customer's environment or data volume grows significantly during the contract term?
baselineDoes the service generate compliance-ready evidence from MDR activity (e.g., SOC 2 continuous-monitoring control evidence, incident-response-capability proof for an audit), or does the customer need to manually compile evidence from raw MDR reports?
baselineIs a breach-coach/incident-response retainer bundled with the MDR service or a separate paid add-on, and if a confirmed major incident occurs, does the SOC team escalate directly into a formal IR engagement, or does the customer need to separately engage a different IR firm?
baselineWhat is the MDR provider's own false-positive/alert-fatigue rate for their analyst team, and how is that measured — does the provider publish or share internal SOC performance metrics, or only customer-facing summary reports?
baselineDetail where the analyst SOC team and customer data are physically located and processed (onshore, offshore, follow-the-sun across regions), and what data-residency guarantees exist for customers with regulatory constraints on where security data can be processed.
baselineWhat is the customer communication cadence during an active, in-progress major incident — real-time updates via a dedicated channel, or periodic scheduled status reports — and what is the actual time-to-first-notification once the SOC identifies a likely major incident?
baselineDoes the service extend to OT/ICS-specific environments with appropriate specialized detection content, or is coverage limited to standard IT endpoints/cloud/identity with no OT-aware detection logic?
baselineExplain the offboarding/transition process if the customer switches MDR providers — what data, detection rules, and historical incident records does the customer retain or receive in a portable format, versus what stays locked in the outgoing provider's platform?
baselineServer Down Response: on-site within four hours for crucial infrastructure failures.
baselineEstablish a tenant-resident 24x7x365 Managed Detection and Response (MDR) service within the agency's Microsoft 365 tenant, providing full operational control of the SOC function, including onboarding of all entitled devices for approximately 2,500 M365-licensed users.
baselineManage all detection, response, and tuning activities within the agency's tenant, delivering Tier 1 endpoint detection, containment, and remediation services, with all telemetry, rules, alerts, playbooks, and configurations residing within the tenant for portability and continuity.
baselineDesign the architecture with future expansion in mind, including integration of identity, network, and infrastructure logs to support broader correlation and detection capabilities.
baselineClearly identify any Microsoft licensing requirements that exceed entitlements of the G3 or F3 baseline licenses, balancing entitlements/capabilities, required capabilities, and projected costs.
baselineProvide 24x7x365 monitoring, triage, containment, and remediation of endpoint threats using Microsoft Defender and related tools, with clearly defined escalation paths for Tier 2+ incidents; may propose optional Tier 2 capabilities such as advanced investigation, threat hunting, or root cause analysis.
baselineOperate entirely within the agency's Microsoft 365 tenant, ensuring all telemetry, rules, alerts, playbooks, and configurations are accessible to agency staff and remain under agency ownership (Tenant-Resident SOC Operations).
baselineEnsure agency cybersecurity personnel have real-time access to the same data, alerts, dashboards, and tools used by the vendor (Co-Managed Visibility and Access).
baselineDevelop, implement, and continuously refine detection rules, alert thresholds, and automated response playbooks tailored to the agency's environment and risk profile (Detection Engineering and Tuning).
baselineDeliver regular reports that go beyond activity metrics to include actionable insights, trends, and recommendations for improving the agency's security posture and internal processes.
baselineMaintain up-to-date documentation of all configurations, rules, playbooks, and procedures, and provide knowledge transfer to agency staff to support long-term operational maturity.
baselineImplement all MDR operations — telemetry ingestion, analytics rules, alerting, playbooks, and automation — within the agency's Microsoft 365 tenant; no telemetry or operational data shall be exported to vendor-owned infrastructure or third-party platforms without prior written approval (Microsoft Tenant Residency).
baselineUtilize Microsoft-native tools and services, including Microsoft Defender for Endpoint, Microsoft Sentinel, Microsoft Defender for Office 365, and Microsoft Purview Audit.
baselineIf proposing Microsoft Purview Audit (Premium) or Microsoft Defender for Identity, clearly identify associated licensing requirements/costs, justify operational benefits, and state which capabilities would be unavailable or degraded without them.
baselineLeverage Microsoft Intune as part of the endpoint protection and response architecture, including onboarding devices into Defender for Endpoint, enforcing security baselines, deploying configuration profiles, and supporting automated remediation actions.
baselineSupport integration of telemetry sources including endpoint telemetry (Windows/iOS/Android), M365 audit logs, Azure AD sign-in/activity logs, AD identity/authentication logs, DNS/DHCP logs, firewall logs, and server infrastructure telemetry.
baselineIdentify any additional Microsoft licensing requirements necessary to support the proposed solution (Licensing Awareness).
baselineDevelop and deliver a detailed implementation plan, including timelines, milestones, roles and responsibilities, and communication protocols (Project Planning and Kickoff).
baselineEnroll all in-scope Windows 11 endpoints for up to 2,500 users into Microsoft Defender for Endpoint using Microsoft Intune or alternative methods, and validate telemetry flow into Microsoft Sentinel.
baselineProvide continuous monitoring, triage, and containment of endpoint threats with clearly defined escalation paths for Tier 2+ incidents (Ongoing 24x7x365 Monitoring and Response).
baselinePerform real-time investigation and response to alerts, including device isolation, user suspension, and other containment actions within pre-approved parameters (Alert Investigation and Containment).
baselineDemonstrate the ability to support differentiated response strategies and risk tolerances across departments (e.g., public safety) and collaborate with agency staff to define and maintain these profiles over time.
baselineAssign qualified personnel to all MDR operational roles (implementation engineers, SOC analysts, incident responders) with relevant cybersecurity experience and industry-recognized certifications (e.g., CISSP, GCIA, GCIH, SC-200); be prepared to provide documentation of staff qualifications, certifications, and background clearances.
baselineMeet incident response timelines: initial triage of high-severity alerts within 15 minutes, containment actions within 30 minutes (if in scope), escalation to agency staff (Tier 2+) within 1 hour.
baselineProvide 24x7x365 MDR coverage including weekends/holidays with real-time alerting and response for all in-scope endpoints (Service Availability).
baselineProvide monthly service review meetings, optional weekly operational summaries, and immediate notification of critical incidents or breaches (Reporting Cadence).
baselineUse secure, agency-approved communication channels, shared access to dashboards/alerts/documentation, and named points of contact for both vendor and agency teams.
baselineDocument all configurations, rules, playbooks, and procedures, keep documentation updated as changes are made, and review quarterly (Documentation Standards).
baselineIn the event of disengagement, ensure all tooling, telemetry, and automation remain fully functional within the agency's tenant, with complete documentation and knowledge transfer to support uninterrupted operations (Exit and Continuity Planning).
baselineDemonstrate strong familiarity with and operational alignment to NIST SP 800-61 Rev. 2, CIS Controls (v8+), and applicable regulatory frameworks including HIPAA, PCI DSS, and CJIS Security Policy.
baselineProvide a summary of at least five (5) distinct customer engagements demonstrating MDR experience comparable in size/scope/structure, including at least 2 public sector/municipal clients and at least 2 hybrid/cloud-native M365 co-managed tenant-resident deployments.
baselineProvide a Company Profile summarizing organizational background, relevant expertise, and capacity to support the described services, including organizational structure, scale of operations, and public sector experience with Microsoft-native security solutions.
baselineIdentify key personnel to be assigned to the engagement (implementation engineers, SOC analysts, incident responders, project managers), including relevant experience, certifications (e.g., SC-200, GCIH, CISSP), and role-specific responsibilities.
baselineProvide a high-level narrative describing the proposer's approach to delivering the Scope of Work, including onboarding, configuring/tuning detection capabilities, implementing co-managed operations, and supporting long-term security operations maturity.
baselineProvide a functional demonstration of a solution representative of the MDR Services during the evaluation period, emphasizing Tier 1 response workflows, escalation handoffs, and co-management operations.
baselineComplete a detailed price proposal for delivery of MDR Services, including all one-time and recurring costs, excluding add-ons/value-added services not required for successful delivery.
baselineConfirm that your organization is a managed security services provider (MSSP) as defined, and indicate the number of years of experience your organization has in providing MSS for the financial/banking sector.
baselineDemonstrate at least 10+ years of proven experience providing Managed Detect and Response Services for the Financial/Banking sector, and be able to provide SOC1/SOC2 certifications upon notice.
baselineProvide a proven team of experienced security professionals certified in the latest threat detection and response technologies, and provide continuous reports on the status of the Managed Detect and Response Services.
baselineUse the latest threat detection and response technologies including SIEM, EDR/MDR, and threat intelligence platforms with a well-defined process for detecting and responding to security threats and vulnerabilities.
baselineProvide 24/7 cybersecurity threat and vulnerability monitoring with an expert team who can identify, isolate, and perform forensic analysis on possible impacts from attacks or vulnerabilities.
baselineProvide MDR with the ability to quickly triage, investigate, alert, and respond to incidents.
baselineDemonstrate ability and capacity to contain threats, isolate and block known threats, and stop attackers earlier in the cyber kill chain to prevent lateral spread.
baselineDescribe the organization, length of time providing MSS, brief overview of proposed services, an explanation of tiered service levels, and any awards/recognition received as an MSSP.
baselineDescribe demonstrated 10+ years of MSS experience for financial/banking clients, indicating client names, related tasks, hyperlinks to relevant products, and when work was performed.
baselineProvide names of principals and key staff responsible for the housing finance agency's matters, with resumes and descriptions of relevant qualifications and experience.
baselineProvide a list of Key Performance Indicators (KPIs) used to measure success, and whether performance targets were met.
baselineDescribe any innovative technology solutions or best practices to be provided, with hyperlinks to relevant products.
baselineProvide an explanation of the methodology, strategy, and workflow to be utilized, together with procedures to ensure compliance with federal/State requirements.
baselineProvide a plan for communication and measuring contract performance.
baselineIdentify any tasks listed in the Scope of Services that the Proposer is NOT capable of providing.
baselineState the required lead-time needed to begin an engagement after contract award.
baselineProvide a project plan with estimated timelines and the housing finance agency's resources required to stand up and fully implement the solution based on the environment/device information provided.
baselineWhat technologies do you use for your Managed Security Services solution? Do you use your own technology, third-party products, or a combination of both? Describe the technologies, products, and tools used to deliver each proposed service, and describe any patents your technology has been awarded.
baselineWhat does 'Response' and 'Remediation' mean to you as an MDR provider? Provided there is a response agreement from the housing finance agency, what MDR actions can your company take on behalf of the housing finance agency?
baselineIn the face of growing threats, what is the average time it takes your teams to detect, understand, and contain a threat?
baselineWhat is your process for adding new devices into your solution, and how does your solution incorporate unsupported devices?
baselineDo you have a customized escalation process for alerts? If so, explain.
baselineDo you manage devices on behalf of your clients? If so, describe your device management capabilities and service tiers.
baselineDescribe your reporting capabilities and provide example screenshots of the portal UI for the proposed services.
baselineDo you have a separate portal interface for clients, or is it the same interface that the SOC analysts use?
baselineDescribe your implementation services, including your normalization and tuning process.
baselineWhat is the extent of your coverage across cloud, on-premise, users, etc.?
baselineWhat resources will you need from us during implementation and throughout the contract?
baselineDescribe any additional solution services your Managed Security Services can offer.
baselineMonitor the agency's network security equipment and core servers to provide real-time analysis of perimeter/internal services through aggregation and analysis of gathered information; gather data from monitored devices, forward it to a secure operations center, filter/data-mine the data in real time, and report findings to agency personnel based on predefined trigger/escalation thresholds.
baselineFocus on actionable events for customer notification and real-time monitoring schemes that reduce/prioritize the volume of data requiring quick analysis; apply knowledge of external threats and of the types/numbers of attacks encountered across all monitored customer devices to add value to alert analysis for the agency.
baselineProvide a Managed Detection & Response (MDR) or similar solution.
baselineComplete the RFP's Functional/System Requirements document, indicating for each numbered requirement line item whether it is Fully supported (Y), supported via Third-party software (3P), requires Customization (C), planned Future functionality (F), or Not supported (N); for 3P, C, or F responses, explain the third-party relationship/customization nature/future release timing and provide a cost estimate on the Pricing Worksheet.
baselineFor Hosted or Subscription pricing options, provide details on the level of hosting services provided (e.g., DBA, upgrade support, backup services, system monitoring), contractual terms (minimum contract length, performance guarantees, service level guarantees), and hardware/infrastructure-related costs; if the service is offered indirectly through a hosting partner, disclose the partner and the terms of the agreement between that partner and the vendor.
baselineIndicate the recommended infrastructure required for the proposed solution; include information on cloud or hosted implementation options, including a review of integration and security options; and submit hardware, database, and operating system requirements for the server, peripherals, and mobile devices.
baselineProposer must deliver 24x7 SOC monitoring and incident response, management of the agency's Microsoft Sentinel SIEM platform (configuration and log integration), alert triage/investigation/remediation support and post-incident analysis, security process development and documentation, annual tabletop exercises for incident response testing, and a block of 80 professional services hours for strategic advisory — all within a maximum annual budget of $150,000.
baselineProposals must describe the staffing model in sufficient detail for the agency to evaluate capacity, response capability, and continuity — a shared-services SOC operating model is acceptable provided the MSSP can consistently meet all SLAs (e.g., 15-minute critical alert acknowledgement) and clearly identifies analysts, roles, and escalation paths assigned to the agency's account.
baselineContinuous 24x7x365 monitoring is required for all alert severities, not just critical/high after business hours; the MSSP is expected to provide incident coordination, triage, investigation, root cause analysis, and remediation support (within defined authority boundaries) as part of SOC operations, with full forensic investigation/malware analysis available via the professional services block if requested.
baselineVulnerability management (scanning, assessment, remediation tracking, patching) is explicitly out of scope for this MSSP engagement, though limited case-by-case advisory support may be provided via the professional services block.
baselineProposer must meet minimum SLAs applying to all security alerts and incidents managed through the SOC: 15-minute critical acknowledgement, 30-minute investigation start, 60-minute notification (referenced targets); must document preferred notification methods (phone/SMS/email/ticketing) in an escalation matrix developed during onboarding.
baselineProposer must identify staffing roles/escalation tiers and disclose any subcontractors; core SOC monitoring and SIEM management may NOT be subcontracted; offshore resources are explicitly prohibited (US-based delivery only).
baselineProposer must list organizational and staff certifications relevant to the engagement including but not limited to CISSP, GCIA, GCED, GCIH, and Microsoft Security certifications (Sentinel, Defender, Azure Security).
baselineVendor must provide on-site support within eight (8) hours of request, primarily for incident response/DFIR activities, containment actions during active incidents, and critical technical support (not routine/non-incident-related support); the agency anticipates 6-12 onsite incidents annually with most response handled remotely.
baselineVendor must itemize one-time setup/onboarding/deployment/configuration/integration costs separately from ongoing annual recurring service costs, and may include an optional Security Awareness Training offering priced separately (not counted toward the $150,000 annual budget cap).
baselineContractor shall provide enterprise cybersecurity and network monitoring support services in a managed services model, furnishing all management, supervision, labor, processes, and associated support necessary to meet continuous monitoring objectives.
baselineTask Area 2: Contractor shall provide integrated 24x7x365 SOC/NOC support to monitor, analyze, triage, escalate, coordinate and report on cybersecurity and network events; perform event intake, triage, initial analysis and escalation per defined priorities/SLAs/SOPs; and provide network monitoring for outages, degradations and anomalous behaviors with cyber/network event correlation.
baselineContractor shall provide a Staffing Plan identifying proposed labor categories, coverage model, qualifications, certifications, continuity approach, and surge/backup support strategy, demonstrating ability to maintain adequate staffing including continuous 24x7x365 coverage throughout the period of performance.
Signing up adds sharing with your team, sending this as an RFP to vendors, and private document sharing. Nothing above is taken away, and nothing here is sent anywhere until you choose to.
Platform baseline
neutral · staff-reviewed
RFIWhat telemetry and environments does the service cover (endpoint, network, cloud, identity, SaaS, email, OT), is it bring-your-own-tools or the provider's own stack, and how broad is the integration set?Answer key — what a strong answer shows
Strong answers state telemetry breadth, whether the service works on your existing tools (BYO) or requires their stack, and quantify integrations. Probe coverage of identity, cloud, and SaaS specifically.
RFPDescribe what 'response' actually includes — does the SOC actively contain/remediate (isolate hosts, disable accounts) or only notify and recommend? What actions are taken on your behalf, and with what guardrails?Answer key — what a strong answer shows
Evidence-backed answers distinguish active response (containment/remediation) from notify-only, list the authorized actions, and describe approval gates — the single biggest differentiator in MDR.
RFIWhat are the contractual detection/response SLAs (MTTD/MTTR), is the SOC genuinely 24/7 (and follow-the-sun), and what is the analyst-to-customer model?Answer key — what a strong answer shows
Look for explicit, contractual SLAs (not aspirational), a real 24/7 staffing model, and clarity on whether you get a named/dedicated team or a shared pool.
Sources:
How vendors compare
balanced · vendor-sourced
Neutral strengths and gaps for each vendor in this category, drawn from vendors' own public materials — included so the questions above favor no single vendor. Gaps reflect capabilities not emphasized in public materials, not rankings.
Vendor
Strengths
Gaps / watch-outs
Arctic WolfAI-generated from public sourcesThe starting point for every profile: auto-generated by 0-Doubt from public vendor materials, and not yet confirmed by the vendor or an independent analyst. Nothing here is hidden or overstated — it simply has not been reviewed yet.Where every profile starts, before the vendor or an analyst has reviewed it. A higher label means a more independent source — not a better product.How trust works →(source)
Concierge security-operations model with a named team, broad telemetry coverage, and strong onboarding and tuning.
Opinionated platform model; deep customer-controlled detection engineering is less central than the managed concierge approach.
Binary DefenseAI-generated from public sourcesThe starting point for every profile: auto-generated by 0-Doubt from public vendor materials, and not yet confirmed by the vendor or an independent analyst. Nothing here is hidden or overstated — it simply has not been reviewed yet.
From other buyers
crowdsourced · anonymized
💬
No buyer-contributed criteria yet
Verified buyers can suggest criteria (anonymized before pooling).
RFIHow is AI/automation used in triage and investigation, and where do human analysts intervene? What is automated versus analyst-led?Answer key — what a strong answer shows
Strong answers are transparent about what automation handles (triage, enrichment, correlation) and where humans decide, rather than implying full autonomy.
RFIIs the service delivered on the provider's own platform or on your SIEM/EDR, who owns the data and detections, and what lock-in exists if you leave?Answer key — what a strong answer shows
Look for clarity on the platform model, data/detection ownership, and portability — some MDRs leave you with nothing transferable if you exit.
RFIIs proactive threat hunting included (hypothesis-driven versus alert-driven), and what threat intelligence and custom detection engineering underpin detections?Answer key — what a strong answer shows
Strong answers describe a proactive hunting cadence, the intel sources behind detections, and whether custom detections are engineered for your environment.
RFPWhat visibility do you get (portal, raw alerts, full investigation detail, reporting), and provide customer-validated outcome metrics.Answer key — what a strong answer shows
Prefer full transparency into investigations and raw data plus customer-validated outcome metrics (dwell time, escalation rates) over a black-box service and vendor benchmarks.
RFIWhat is the pricing model — per endpoint, per GB of log ingestion, per user, or a flat enterprise fee — and how does cost change as the customer's environment or data volume grows significantly during the contract term?Answer key — what a strong answer shows
Look for transparent, predictable scaling economics; log-volume-based pricing that spikes when the customer expands logging coverage (which is otherwise good security practice) creates a perverse cost incentive to under-log.
RFPDoes the service generate compliance-ready evidence from MDR activity (e.g., SOC 2 continuous-monitoring control evidence, incident-response-capability proof for an audit), or does the customer need to manually compile evidence from raw MDR reports?Answer key — what a strong answer shows
Native compliance-evidence generation from real MDR activity is materially more valuable than raw incident reports requiring manual compilation work for every audit cycle.
RFIIs a breach-coach/incident-response retainer bundled with the MDR service or a separate paid add-on, and if a confirmed major incident occurs, does the SOC team escalate directly into a formal IR engagement, or does the customer need to separately engage a different IR firm?Answer key — what a strong answer shows
A seamless MDR-to-IR escalation path (same provider, no re-engagement friction) is materially faster during an actual major incident than needing to source and onboard a separate IR firm mid-crisis.
RFIWhat is the MDR provider's own false-positive/alert-fatigue rate for their analyst team, and how is that measured — does the provider publish or share internal SOC performance metrics, or only customer-facing summary reports?Answer key — what a strong answer shows
A provider willing to share their own internal analyst performance/accuracy metrics demonstrates more operational transparency than one offering only polished customer-facing summaries.
RFPDetail where the analyst SOC team and customer data are physically located and processed (onshore, offshore, follow-the-sun across regions), and what data-residency guarantees exist for customers with regulatory constraints on where security data can be processed.Answer key — what a strong answer shows
Strong answers give specific SOC locations and concrete data-residency guarantees; a vendor unable or unwilling to disclose analyst-team location is a red flag for regulated customers.
RFIWhat is the customer communication cadence during an active, in-progress major incident — real-time updates via a dedicated channel, or periodic scheduled status reports — and what is the actual time-to-first-notification once the SOC identifies a likely major incident?Answer key — what a strong answer shows
Look for a concrete, real-time communication commitment; a vendor whose only communication during a live incident is a scheduled weekly report is materially too slow for genuine crisis response.
RFIDoes the service extend to OT/ICS-specific environments with appropriate specialized detection content, or is coverage limited to standard IT endpoints/cloud/identity with no OT-aware detection logic?Answer key — what a strong answer shows
OT/ICS environments require materially different detection logic (different protocols, different 'normal' baselines) — a provider claiming full-environment coverage without OT-specific expertise may miss real OT-targeted attacks.
RFPExplain the offboarding/transition process if the customer switches MDR providers — what data, detection rules, and historical incident records does the customer retain or receive in a portable format, versus what stays locked in the outgoing provider's platform?Answer key — what a strong answer shows
A vendor with a genuine, documented offboarding-data-portability process reduces real vendor lock-in risk; one with no clear answer here likely makes switching providers costly and disruptive.
RFPServer Down Response: on-site within four hours for crucial infrastructure failures.
RFPEstablish a tenant-resident 24x7x365 Managed Detection and Response (MDR) service within the agency's Microsoft 365 tenant, providing full operational control of the SOC function, including onboarding of all entitled devices for approximately 2,500 M365-licensed users.
RFPManage all detection, response, and tuning activities within the agency's tenant, delivering Tier 1 endpoint detection, containment, and remediation services, with all telemetry, rules, alerts, playbooks, and configurations residing within the tenant for portability and continuity.
RFPDesign the architecture with future expansion in mind, including integration of identity, network, and infrastructure logs to support broader correlation and detection capabilities.
RFPClearly identify any Microsoft licensing requirements that exceed entitlements of the G3 or F3 baseline licenses, balancing entitlements/capabilities, required capabilities, and projected costs.
RFPProvide 24x7x365 monitoring, triage, containment, and remediation of endpoint threats using Microsoft Defender and related tools, with clearly defined escalation paths for Tier 2+ incidents; may propose optional Tier 2 capabilities such as advanced investigation, threat hunting, or root cause analysis.
RFPOperate entirely within the agency's Microsoft 365 tenant, ensuring all telemetry, rules, alerts, playbooks, and configurations are accessible to agency staff and remain under agency ownership (Tenant-Resident SOC Operations).
RFPEnsure agency cybersecurity personnel have real-time access to the same data, alerts, dashboards, and tools used by the vendor (Co-Managed Visibility and Access).
RFPDevelop, implement, and continuously refine detection rules, alert thresholds, and automated response playbooks tailored to the agency's environment and risk profile (Detection Engineering and Tuning).
RFPDeliver regular reports that go beyond activity metrics to include actionable insights, trends, and recommendations for improving the agency's security posture and internal processes.
RFPMaintain up-to-date documentation of all configurations, rules, playbooks, and procedures, and provide knowledge transfer to agency staff to support long-term operational maturity.
RFPImplement all MDR operations — telemetry ingestion, analytics rules, alerting, playbooks, and automation — within the agency's Microsoft 365 tenant; no telemetry or operational data shall be exported to vendor-owned infrastructure or third-party platforms without prior written approval (Microsoft Tenant Residency).
RFPUtilize Microsoft-native tools and services, including Microsoft Defender for Endpoint, Microsoft Sentinel, Microsoft Defender for Office 365, and Microsoft Purview Audit.
RFPIf proposing Microsoft Purview Audit (Premium) or Microsoft Defender for Identity, clearly identify associated licensing requirements/costs, justify operational benefits, and state which capabilities would be unavailable or degraded without them.
RFPLeverage Microsoft Intune as part of the endpoint protection and response architecture, including onboarding devices into Defender for Endpoint, enforcing security baselines, deploying configuration profiles, and supporting automated remediation actions.
RFPSupport integration of telemetry sources including endpoint telemetry (Windows/iOS/Android), M365 audit logs, Azure AD sign-in/activity logs, AD identity/authentication logs, DNS/DHCP logs, firewall logs, and server infrastructure telemetry.
RFPIdentify any additional Microsoft licensing requirements necessary to support the proposed solution (Licensing Awareness).
RFPDevelop and deliver a detailed implementation plan, including timelines, milestones, roles and responsibilities, and communication protocols (Project Planning and Kickoff).
RFPEnroll all in-scope Windows 11 endpoints for up to 2,500 users into Microsoft Defender for Endpoint using Microsoft Intune or alternative methods, and validate telemetry flow into Microsoft Sentinel.
RFPProvide continuous monitoring, triage, and containment of endpoint threats with clearly defined escalation paths for Tier 2+ incidents (Ongoing 24x7x365 Monitoring and Response).
RFPPerform real-time investigation and response to alerts, including device isolation, user suspension, and other containment actions within pre-approved parameters (Alert Investigation and Containment).
RFPDemonstrate the ability to support differentiated response strategies and risk tolerances across departments (e.g., public safety) and collaborate with agency staff to define and maintain these profiles over time.
RFPAssign qualified personnel to all MDR operational roles (implementation engineers, SOC analysts, incident responders) with relevant cybersecurity experience and industry-recognized certifications (e.g., CISSP, GCIA, GCIH, SC-200); be prepared to provide documentation of staff qualifications, certifications, and background clearances.
RFPMeet incident response timelines: initial triage of high-severity alerts within 15 minutes, containment actions within 30 minutes (if in scope), escalation to agency staff (Tier 2+) within 1 hour.
RFPProvide 24x7x365 MDR coverage including weekends/holidays with real-time alerting and response for all in-scope endpoints (Service Availability).
RFPProvide monthly service review meetings, optional weekly operational summaries, and immediate notification of critical incidents or breaches (Reporting Cadence).
RFPUse secure, agency-approved communication channels, shared access to dashboards/alerts/documentation, and named points of contact for both vendor and agency teams.
RFPDocument all configurations, rules, playbooks, and procedures, keep documentation updated as changes are made, and review quarterly (Documentation Standards).
RFPIn the event of disengagement, ensure all tooling, telemetry, and automation remain fully functional within the agency's tenant, with complete documentation and knowledge transfer to support uninterrupted operations (Exit and Continuity Planning).
RFPDemonstrate strong familiarity with and operational alignment to NIST SP 800-61 Rev. 2, CIS Controls (v8+), and applicable regulatory frameworks including HIPAA, PCI DSS, and CJIS Security Policy.
RFPProvide a summary of at least five (5) distinct customer engagements demonstrating MDR experience comparable in size/scope/structure, including at least 2 public sector/municipal clients and at least 2 hybrid/cloud-native M365 co-managed tenant-resident deployments.
RFPProvide a Company Profile summarizing organizational background, relevant expertise, and capacity to support the described services, including organizational structure, scale of operations, and public sector experience with Microsoft-native security solutions.
RFPIdentify key personnel to be assigned to the engagement (implementation engineers, SOC analysts, incident responders, project managers), including relevant experience, certifications (e.g., SC-200, GCIH, CISSP), and role-specific responsibilities.
RFPProvide a high-level narrative describing the proposer's approach to delivering the Scope of Work, including onboarding, configuring/tuning detection capabilities, implementing co-managed operations, and supporting long-term security operations maturity.
RFPProvide a functional demonstration of a solution representative of the MDR Services during the evaluation period, emphasizing Tier 1 response workflows, escalation handoffs, and co-management operations.
RFPComplete a detailed price proposal for delivery of MDR Services, including all one-time and recurring costs, excluding add-ons/value-added services not required for successful delivery.
RFPConfirm that your organization is a managed security services provider (MSSP) as defined, and indicate the number of years of experience your organization has in providing MSS for the financial/banking sector.
RFPDemonstrate at least 10+ years of proven experience providing Managed Detect and Response Services for the Financial/Banking sector, and be able to provide SOC1/SOC2 certifications upon notice.
RFPProvide a proven team of experienced security professionals certified in the latest threat detection and response technologies, and provide continuous reports on the status of the Managed Detect and Response Services.
RFPUse the latest threat detection and response technologies including SIEM, EDR/MDR, and threat intelligence platforms with a well-defined process for detecting and responding to security threats and vulnerabilities.
RFPProvide 24/7 cybersecurity threat and vulnerability monitoring with an expert team who can identify, isolate, and perform forensic analysis on possible impacts from attacks or vulnerabilities.
RFPProvide MDR with the ability to quickly triage, investigate, alert, and respond to incidents.
RFPDemonstrate ability and capacity to contain threats, isolate and block known threats, and stop attackers earlier in the cyber kill chain to prevent lateral spread.
RFPDescribe the organization, length of time providing MSS, brief overview of proposed services, an explanation of tiered service levels, and any awards/recognition received as an MSSP.
RFPDescribe demonstrated 10+ years of MSS experience for financial/banking clients, indicating client names, related tasks, hyperlinks to relevant products, and when work was performed.
RFPProvide names of principals and key staff responsible for the housing finance agency's matters, with resumes and descriptions of relevant qualifications and experience.
RFPProvide a list of Key Performance Indicators (KPIs) used to measure success, and whether performance targets were met.
RFPDescribe any innovative technology solutions or best practices to be provided, with hyperlinks to relevant products.
RFPProvide an explanation of the methodology, strategy, and workflow to be utilized, together with procedures to ensure compliance with federal/State requirements.
RFPProvide a plan for communication and measuring contract performance.
RFPIdentify any tasks listed in the Scope of Services that the Proposer is NOT capable of providing.
RFPState the required lead-time needed to begin an engagement after contract award.
RFPProvide a project plan with estimated timelines and the housing finance agency's resources required to stand up and fully implement the solution based on the environment/device information provided.
RFPWhat technologies do you use for your Managed Security Services solution? Do you use your own technology, third-party products, or a combination of both? Describe the technologies, products, and tools used to deliver each proposed service, and describe any patents your technology has been awarded.
RFPWhat does 'Response' and 'Remediation' mean to you as an MDR provider? Provided there is a response agreement from the housing finance agency, what MDR actions can your company take on behalf of the housing finance agency?
RFPIn the face of growing threats, what is the average time it takes your teams to detect, understand, and contain a threat?
RFPWhat is your process for adding new devices into your solution, and how does your solution incorporate unsupported devices?
RFPDo you have a customized escalation process for alerts? If so, explain.
RFPDo you manage devices on behalf of your clients? If so, describe your device management capabilities and service tiers.
RFPDescribe your reporting capabilities and provide example screenshots of the portal UI for the proposed services.
RFPDo you have a separate portal interface for clients, or is it the same interface that the SOC analysts use?
RFPDescribe your implementation services, including your normalization and tuning process.
RFPWhat is the extent of your coverage across cloud, on-premise, users, etc.?
RFPWhat resources will you need from us during implementation and throughout the contract?
RFPDescribe any additional solution services your Managed Security Services can offer.
RFPMonitor the agency's network security equipment and core servers to provide real-time analysis of perimeter/internal services through aggregation and analysis of gathered information; gather data from monitored devices, forward it to a secure operations center, filter/data-mine the data in real time, and report findings to agency personnel based on predefined trigger/escalation thresholds.
RFPFocus on actionable events for customer notification and real-time monitoring schemes that reduce/prioritize the volume of data requiring quick analysis; apply knowledge of external threats and of the types/numbers of attacks encountered across all monitored customer devices to add value to alert analysis for the agency.
RFPProvide a Managed Detection & Response (MDR) or similar solution.
RFPComplete the RFP's Functional/System Requirements document, indicating for each numbered requirement line item whether it is Fully supported (Y), supported via Third-party software (3P), requires Customization (C), planned Future functionality (F), or Not supported (N); for 3P, C, or F responses, explain the third-party relationship/customization nature/future release timing and provide a cost estimate on the Pricing Worksheet.
RFPFor Hosted or Subscription pricing options, provide details on the level of hosting services provided (e.g., DBA, upgrade support, backup services, system monitoring), contractual terms (minimum contract length, performance guarantees, service level guarantees), and hardware/infrastructure-related costs; if the service is offered indirectly through a hosting partner, disclose the partner and the terms of the agreement between that partner and the vendor.
RFPIndicate the recommended infrastructure required for the proposed solution; include information on cloud or hosted implementation options, including a review of integration and security options; and submit hardware, database, and operating system requirements for the server, peripherals, and mobile devices.
RFPProposer must deliver 24x7 SOC monitoring and incident response, management of the agency's Microsoft Sentinel SIEM platform (configuration and log integration), alert triage/investigation/remediation support and post-incident analysis, security process development and documentation, annual tabletop exercises for incident response testing, and a block of 80 professional services hours for strategic advisory — all within a maximum annual budget of $150,000.
RFPProposals must describe the staffing model in sufficient detail for the agency to evaluate capacity, response capability, and continuity — a shared-services SOC operating model is acceptable provided the MSSP can consistently meet all SLAs (e.g., 15-minute critical alert acknowledgement) and clearly identifies analysts, roles, and escalation paths assigned to the agency's account.
RFPContinuous 24x7x365 monitoring is required for all alert severities, not just critical/high after business hours; the MSSP is expected to provide incident coordination, triage, investigation, root cause analysis, and remediation support (within defined authority boundaries) as part of SOC operations, with full forensic investigation/malware analysis available via the professional services block if requested.
RFPVulnerability management (scanning, assessment, remediation tracking, patching) is explicitly out of scope for this MSSP engagement, though limited case-by-case advisory support may be provided via the professional services block.
RFPProposer must meet minimum SLAs applying to all security alerts and incidents managed through the SOC: 15-minute critical acknowledgement, 30-minute investigation start, 60-minute notification (referenced targets); must document preferred notification methods (phone/SMS/email/ticketing) in an escalation matrix developed during onboarding.
RFPProposer must identify staffing roles/escalation tiers and disclose any subcontractors; core SOC monitoring and SIEM management may NOT be subcontracted; offshore resources are explicitly prohibited (US-based delivery only).
RFPProposer must list organizational and staff certifications relevant to the engagement including but not limited to CISSP, GCIA, GCED, GCIH, and Microsoft Security certifications (Sentinel, Defender, Azure Security).
RFPVendor must provide on-site support within eight (8) hours of request, primarily for incident response/DFIR activities, containment actions during active incidents, and critical technical support (not routine/non-incident-related support); the agency anticipates 6-12 onsite incidents annually with most response handled remotely.
RFPVendor must itemize one-time setup/onboarding/deployment/configuration/integration costs separately from ongoing annual recurring service costs, and may include an optional Security Awareness Training offering priced separately (not counted toward the $150,000 annual budget cap).
RFPContractor shall provide enterprise cybersecurity and network monitoring support services in a managed services model, furnishing all management, supervision, labor, processes, and associated support necessary to meet continuous monitoring objectives.
RFPTask Area 2: Contractor shall provide integrated 24x7x365 SOC/NOC support to monitor, analyze, triage, escalate, coordinate and report on cybersecurity and network events; perform event intake, triage, initial analysis and escalation per defined priorities/SLAs/SOPs; and provide network monitoring for outages, degradations and anomalous behaviors with cyber/network event correlation.
RFPContractor shall provide a Staffing Plan identifying proposed labor categories, coverage model, qualifications, certifications, continuity approach, and surge/backup support strategy, demonstrating ability to maintain adequate staffing including continuous 24x7x365 coverage throughout the period of performance.
Where every profile starts, before the vendor or an analyst has reviewed it. A higher label means a more independent source — not a better product.
Human-driven MDR with hypothesis-based threat hunting and counterintelligence/DRP on the NightBeacon platform.
Human-led service heritage; turnkey automation-first simplicity is emphasized less.
Blackpoint CyberAI-generated from public sourcesThe starting point for every profile: auto-generated by 0-Doubt from public vendor materials, and not yet confirmed by the vendor or an independent analyst. Nothing here is hidden or overstated — it simply has not been reviewed yet.Where every profile starts, before the vendor or an analyst has reviewed it. A higher label means a more independent source — not a better product.How trust works →(source)
MSP-focused MDR with patented detection logic and fast, native active response across a bundled stack (cloud, EDR, SIEM).
MSP/bundle orientation; very-large-enterprise BYO-tool integration is less central.
Critical StartAI-generated from public sourcesThe starting point for every profile: auto-generated by 0-Doubt from public vendor materials, and not yet confirmed by the vendor or an independent analyst. Nothing here is hidden or overstated — it simply has not been reviewed yet.Where every profile starts, before the vendor or an analyst has reviewed it. A higher label means a more independent source — not a better product.How trust works →(source)
MDR with contractual SLAs, a transparent investigation queue (CORR), broad bidirectional integrations, and MobileSOC.
Detection-and-response orchestration focus; proprietary-stack/own-EDR depth is less central than tool integration.
DeepwatchAI-generated from public sourcesThe starting point for every profile: auto-generated by 0-Doubt from public vendor materials, and not yet confirmed by the vendor or an independent analyst. Nothing here is hidden or overstated — it simply has not been reviewed yet.Where every profile starts, before the vendor or an analyst has reviewed it. A higher label means a more independent source — not a better product.How trust works →(source)
Managed security on the Guardian platform spanning MDR, CTEM, and managed EDR with agentic AI enrichment.
Breadth across managed services; very-deep proactive hunting is emphasized less than platform-led detection.
HuntressAI-generated from public sourcesThe starting point for every profile: auto-generated by 0-Doubt from public vendor materials, and not yet confirmed by the vendor or an independent analyst. Nothing here is hidden or overstated — it simply has not been reviewed yet.Where every profile starts, before the vendor or an analyst has reviewed it. A higher label means a more independent source — not a better product.How trust works →(source)
Approachable managed detection for SMB and mid-market across endpoint, identity, and SIEM, with strong ease of use.
SMB/mid-market focus; very-large-enterprise telemetry breadth and custom detection engineering are less central.
OntinueAI-generated from public sourcesThe starting point for every profile: auto-generated by 0-Doubt from public vendor materials, and not yet confirmed by the vendor or an independent analyst. Nothing here is hidden or overstated — it simply has not been reviewed yet.Where every profile starts, before the vendor or an analyst has reviewed it. A higher label means a more independent source — not a better product.How trust works →(source)
MXDR purpose-built for Microsoft security environments with conversational, automation-assisted response (ION).
Microsoft-ecosystem focus; multi-vendor/non-Microsoft stack parity is less central.
Red CanaryAI-generated from public sourcesThe starting point for every profile: auto-generated by 0-Doubt from public vendor materials, and not yet confirmed by the vendor or an independent analyst. Nothing here is hidden or overstated — it simply has not been reviewed yet.Where every profile starts, before the vendor or an analyst has reviewed it. A higher label means a more independent source — not a better product.How trust works →(source)
Detection-engineering depth and high-fidelity detections across endpoint, cloud, and identity, with transparency into the detection logic.
Detection-and-response focus; full managed-firewall/concierge breadth is less central than detection quality.
ReliaQuestAI-generated from public sourcesThe starting point for every profile: auto-generated by 0-Doubt from public vendor materials, and not yet confirmed by the vendor or an independent analyst. Nothing here is hidden or overstated — it simply has not been reviewed yet.Where every profile starts, before the vendor or an analyst has reviewed it. A higher label means a more independent source — not a better product.How trust works →(source)
GreyMatter platform that normalizes telemetry across your existing tools (BYO), with agentic AI investigation and detect-at-source.
Platform-overlay model assumes you keep your tools; fully turnkey 'we run everything' simplicity is less central.
eSentireAI-generated from public sourcesThe starting point for every profile: auto-generated by 0-Doubt from public vendor materials, and not yet confirmed by the vendor or an independent analyst. Nothing here is hidden or overstated — it simply has not been reviewed yet.Where every profile starts, before the vendor or an analyst has reviewed it. A higher label means a more independent source — not a better product.How trust works →(source)
24/7 MDR with strong threat research (TRU) and proactive response, as the originator of the MDR category.
Opinionated managed model; customer-owned-SIEM/BYO-tool flexibility is less central.