All guides

// guide

What is the difference between a managed SOC, MDR and an MSSP?

These terms blur together in the market, and different providers mean different things by them. That is not necessarily dishonesty — the field moved quickly and the vocabulary never settled. But it does mean you cannot infer from the name what you will get.

The terms, without the marketing

MSSP — Managed Security Service Provider — is the broadest term. It originally described a provider that runs and maintains security products for you: firewall, antivirus, VPN. The emphasis is on managing the tool.

A managed SOC describes a monitoring centre operated on your behalf: somebody collects logs and alerts from the environment, filters, investigates and reports. The emphasis is on continuous watching and investigation.

MDR — Managed Detection and Response — grew up to stress what an MSSP did not always include: not only detecting and reporting, but acting. The emphasis is on the response.

What actually separates them: who decides and who acts

The practical difference is not in the definitions but in two questions: who decides what to do, and who carries it out.

At one end, the provider detects and reports, and every action is yours. At the other, the provider is authorised to isolate a machine or disable an account themselves, without waiting for approval. Between the two ends sits a whole range of arrangements.

Both are legitimate, and choosing between them depends on several things: how quickly you need someone to act, how much damage a wrong action could cause, and who in your organisation is authorised to approve taking a system offline at two in the morning.

The question that establishes it

Instead of asking "are you MDR or a managed SOC?", ask: "exactly what will you do yourselves when you detect an infected machine at three in the morning, and what will you wait for us to do?"

The answer defines the service in practice, and it also reveals very quickly whether the provider has thought about it or only about the label.

What to check in a proposal

Which systems are covered by the monitoring, and what is left out. Endpoint-only monitoring is not the same as monitoring that also covers identities, cloud and email.

What happens when a real incident is found — who handles it, to what extent, and what is defined as out of scope.

What permissions the provider is given in your environment, and who approves their use.

What the routine reporting looks like, and who in your organisation is meant to read it.

Do not buy by acronym. Ask what the provider will do themselves at three in the morning, and what they will wait for you to do.