What Is Managed Detection and Response? MDR vs MSSP
Buying managed detection and response is buying people, not software. The question that separates two quotes at the same price is which systems the provider can see, and what they are allowed to do at three in the morning without calling you first.

At 2:40 in the morning an account belonging to someone in your finance team signs in from a hosting provider two time zones away. Eleven minutes later it opens a shared drive it has never touched, and starts working through it folder by folder. Somebody has to see that, decide it is not a late night on vacation, and end the session. None of that is a software problem. Software raised the alert in the first sixty seconds; the next four hours are a staffing problem, and staffing at 2:40 in the morning is what a company either has or does not.
Managed detection and response is the arrangement companies buy when the answer is "does not". It is also one of the most expensive lines on a mid-sized company's security budget, and one of the least well specified, because almost every provider describes the same capability list in the same words. What actually differs between two quotes is narrower and more boring than the brochures: which systems the provider is fed, how a suspicious event gets judged, and what the provider is permitted to do about it before anyone answers the phone.
What Is Managed Detection and Response?
Managed detection and response is a subscription service in which an outside provider takes on three jobs your company would otherwise have to staff: watching security telemetry continuously, deciding which of the resulting alerts represent a real attack, and acting to stop the ones that do.
The three jobs are worth separating, because a provider can be strong at one and absent at another, and the word "managed" hides which.
Coverage. The provider ingests data from your systems. How much of your estate that covers is a contractual question rather than a technical one, and the gap between "endpoint MDR" and "MDR across identity, cloud and email" is the largest difference in scope between two services that share a name.
Judgment. Detection produces far more candidates than incidents. Somebody has to look at the sign-in from a new country and know that the same account also created an inbox rule ten minutes later, which is the difference between a false positive and an incident. This is the expensive part, and the part vendors describe least concretely.
Authority. When judgment lands on "this is real", something has to happen inside your environment. Whether the provider does it, or writes you a ticket about it, decides what you are actually buying.
The reason the category exists is a number, and it is the strongest argument any MDR provider has, though few of them cite it.
Read those three together and the case is arithmetic rather than rhetorical. More than half of breached organizations did not find their own breach, the average one ran for eight months, and every month it ran added cost. MDR is sold against the 247 days, and the honest version of the pitch is that it moves that number rather than eliminating it.
The threats driving those numbers are the ordinary ones. IBM recorded phishing as the top initial attack vector for the fourth consecutive year, with voice and SMS phishing used in 17 percent of attacks and producing the highest average breach cost of any vector at USD 5.29 million. Thirty-nine percent of breached organizations reported that ransomware crews had reached their systems, up from 24 percent in 2023. None of that is exotic. It is a stolen password used at two in the morning, and nobody watching.
How Managed Detection and Response Works
The service runs as a loop, and the loop is the same at every provider even though the marketing names differ. Telemetry arrives, detection logic fires, a human decides, an action is taken, and the whole thing is written down so the next one is faster.
- Attacker signs inA valid password, from an address your company has never used
- Telemetry reaches the providerEndpoint agent, identity provider logs, cloud audit trail
- Detection firesA rule or model flags the sign-in as anomalous. So do forty other things tonight
- Analyst triagesRanks it, discards the forty, pulls the account history. Minutes, not hours
- InvestigationWhat else did the account touch, from where, and is any other account doing the same
- Containment and handbackSession revoked, host isolated, your team briefed with what was found
Two things about that sequence matter more than the rest.
The first is that detection is the commodity. Every serious provider runs behavioral analytics, a threat intelligence feed and a detection library mapped to MITRE ATT&CK techniques, and they will all catch the loud attack. The volume problem is what separates them: a mid-sized company generates far more candidate events in a day than anyone can read, and a service that escalates too many of them trains you to ignore it, which is a failure mode indistinguishable from having no service at all.
The second is that triage speed is a contractual number and should be treated as one. Providers publish a time to acknowledge, a time to investigate and sometimes a time to contain, and those three commitments describe the service far better than any capability list. A fifteen-minute acknowledgement with a four-hour investigation window is a different product from a fifteen-minute acknowledgement with a one-hour containment commitment, at a similar price.
Proactive threat hunting sits alongside the loop rather than inside it. Hunting means an analyst going looking for attacker behavior that no rule flagged, working from a hypothesis rather than an alert. It is genuinely valuable and it is also the easiest thing for a provider to claim and never do, so it belongs on the list of things to ask for evidence of rather than the list of things to assume.
What an MDR Service Covers
MDR is only as good as what it is fed, and coverage is where two services diverge most while sounding identical. This is the table to build during an evaluation, filled in from the contract rather than the datasheet.
| Telemetry source | What it catches | Usually included? |
|---|---|---|
| Endpoint agent on laptops and servers | Malware execution, credential theft tooling, ransomware staging, lateral movement | Yes, this is the core of almost every MDR service |
| Identity provider and single sign-on logs | Impossible travel, MFA fatigue, new device enrollment, token theft | Often, and it is the source that catches the attack described at the top of this page |
| Cloud platform audit logs | New admin roles, storage made public, resources spun up for mining | Sometimes, and frequently at extra cost per subscription |
| Email and collaboration platform | Inbox rules, mass forwarding, mailbox exfiltration after a compromise | Sometimes |
| Network traffic and firewall logs | Command and control traffic, data leaving in volume, scanning from inside | Varies widely, and often needs a sensor you pay for |
| SaaS applications holding your data | Bulk record export, permission changes, unusual API use | Rarely, and this is where a lot of this year's incidents happened |
That last row deserves attention. The 2026 Verizon Data Breach Investigations Report found 48 percent of breaches now involve third parties, following a 60 percent jump in third-party supply chain breaches. A service watching only your laptops is watching the place a shrinking share of incidents actually happens.
Just as important is what MDR does not do, because the gaps get filled by nobody when the contract is signed on the assumption that they are covered. MDR does not patch your systems. It does not configure your firewall or your identity provider. It does not run vulnerability scanning unless you bought that separately, which matters because the DBIR found 31 percent of breaches now begin with vulnerability exploitation, the first time in nineteen years it has overtaken stolen credentials as the leading entry point. It does not train your staff to recognize a phishing email. And it does not do the recovery: restoring systems, notifying regulators and customers, and dealing with the legal consequences remain yours in almost every contract on the market.

What MDR Providers Are Allowed to Do Without Asking
This is the question that separates the market, and the one buyers most often discover the answer to during an incident.
Three arrangements exist, and all three are sold as "response".
Notify only. The provider investigates and sends you a ticket, a call or a message. Everything after that is your team's work. This is cheaper and it is a legitimate service, but at 2:40 in the morning it is worth exactly as much as your on-call rota is.
Response with approval. The provider recommends an action and waits for a named person to approve it. Reasonable on paper, and it reintroduces the delay the service exists to remove, unless the approval path is staffed as continuously as the monitoring is.
Delegated authority. The provider takes agreed actions immediately and tells you afterward: isolating a host, killing a process, revoking sessions, disabling an account, blocking an address. This is what most buyers assume they are getting, and it is the arrangement that actually compresses the containment half of those 247 days.
The boundaries need writing down, and this is not a preference. NIST's incident response guidance makes the point directly: where a third party performs response activities, that is a shared responsibility arrangement in which you have transferred some of your own responsibilities, and the division belongs in the contract, covering information flows, the authority to act on your behalf, and the restrictions, such as whether the provider may deactivate a service to contain an incident without calling you first. That guidance is in SP 800-61r3, and it is the single most useful page to read before signing anything.
The practical version is a short list agreed in advance: which actions the provider takes without asking, which need a call, who they call, what happens when that person does not answer, and which systems are exempt because isolating them would stop the business. That list belongs in your own incident response plan, not only in the provider's runbook, because the plan is what your team reads at 2:40 in the morning.
MSSP vs MDR
The two categories overlap enough that some providers sell both under one brand, and the distinction that matters is not technological.
Put plainly: an MSSP manages tools and tells you what they said. An MDR provider hunts for attackers and does something about them. A company that needs someone to run its firewalls, its email filtering and its patching needs an MSSP, and that need is real. A company that has tools nobody is watching needs MDR. Plenty of companies need both, which is why the combined offering exists.
One piece of evidence complicates the usual vendor framing, and it is worth putting on the table because every competing article on this subject is written by an MDR vendor. In IBM's data, breaches identified by a managed security service provider cost an average of USD 4.86 million, which is 2.6 percent below the global average and lower than the USD 5.01 million average for breaches identified by an organization's own internal team. MSSP-identified breaches also took 230 days to identify and contain, against 268 days when the attacker disclosed it and 281 when a third party did. IBM's category does not split MSSPs from MDR providers, so the figures cannot settle a comparison between the two. What they do settle is the more important question: an outside party watching your systems performs a great deal better than nobody watching them.
The risk of outsourcing is real and documented. CISA, the FBI, the NSA and their counterparts in the United Kingdom, Australia, Canada and New Zealand issued a joint advisory on threats to managed service providers and their customers after attackers repeatedly used provider access as a route into multiple customer networks at once. Their recommendations translate directly into contract terms: require multi-factor authentication on every provider account that touches your environment, specify in writing whether the provider or you own hardening, detection and incident response, define how and when you get told about an incident affecting you, keep provider accounts out of your internal administrator groups, and audit those accounts so they are disabled when they are not in use.
Managed EDR vs MDR
This pair confuses buyers more than any other, because managed EDR is sold as MDR by companies that only do endpoints.
An EDR agent on every laptop records what runs on that machine and can isolate it from the network. Managed EDR means a provider operates that one product for you: tuning it, reading its alerts, and responding to what it finds. The scope is a single telemetry source, and the ceiling is what that source can see.
MDR is the broader arrangement. It usually includes an endpoint agent, and it adds identity, cloud, email and network data, correlates across all of them, and takes response actions across more than one system.
The difference is not academic, because a large share of today's attacks never put a file on a laptop. An attacker who talks a help desk into resetting a password, signs in to a cloud service, creates an inbox rule and exports customer records has done nothing an endpoint agent can see, because no endpoint was involved. IBM's data shows social engineering, such as impersonating help desk staff, in 13 percent of attacks at an average cost of USD 5.23 million. Managed EDR is a real product and a reasonable purchase for a company whose data lives on its laptops and servers. It is the wrong purchase for a company whose data lives in a SaaS platform, and the sales conversation rarely makes that distinction for you.
The clean test: ask which sources the service ingests. If the answer is one, you are buying managed EDR whatever the invoice says.
SIEM vs MDR
A SIEM is a product. MDR is a service. That is the whole answer, and the confusion comes from the fact that most MDR providers run a SIEM inside their own service.
A SIEM collects log data from everything you run, standardizes it, correlates across sources, and raises an alert when a pattern matches a rule. It is the archive and the alarm. It does not investigate, decide, or act, and it does not staff a night shift. Bought alone, a SIEM produces alerts that somebody in your company has to answer, and the entire failure mode of the SIEM market is organizations that bought excellent alerting and never staffed the answering.
MDR delivers the alerting and the answering as one service. The provider owns the platform, which may be a SIEM, an XDR product, or both, and you never see the licensing.
Between the two sits managed SIEM, which is often mistaken for MDR. A provider runs the platform, tunes the rules and keeps the data flowing, then sends the alerts to you. It solves the operating burden and leaves the staffing problem exactly where it was. One further consequence of the product-versus-service line is worth settling before signing: with a SIEM you own the log data and the detection content, and with MDR you often do not.
Is MDR the Same as a SOC?
No, but they can be the same thing wearing different clothes.
A security operations center is the function: the people, shifts and procedures responsible for monitoring, investigating and responding. An in-house SOC is that function staffed by your employees. MDR is that function bought from a provider who staffs it across many customers at once. So MDR does not replace the idea of a SOC, it supplies one.
The distinction that survives is context rather than activity. An in-house SOC knows your business: which server matters at month end, which contractor legitimately signs in from abroad, which alert is the same false positive as last Tuesday. An MDR provider knows attacks better, because it sees hundreds of environments where your team sees one, and it is the only affordable way for most companies to have anyone awake at 3am.
How Much Does Managed Detection and Response Cost?
Providers price MDR per endpoint or per user per month, sometimes with a floor that makes small deployments expensive per seat. Published pricing is rare and quotes vary by more than most buyers expect, but the variables that move the number are consistent: how many telemetry sources are connected, whether identity and cloud are included or extra, how long log data is retained, what the response authority is, whether an incident response retainer is bundled, and how tight the service level commitments are.
Rather than repeat a price range nobody can stand behind, the useful comparison is against the alternative, and the alternative is hiring. Continuous coverage is the constraint. A genuine 24/7 rota, with holidays, sickness and turnover accounted for, takes five to six analysts. The Bureau of Labor Statistics puts the median annual wage for information security analysts at $129,180 as of May 2025, with employment projected to grow 21 percent from 2025 to 2035, which is the part that makes the hiring plan harder every year rather than easier. Five analysts at the median, before employer taxes, benefits, recruitment, tooling and management, is a salary line above $600,000 a year to cover nights and weekends.
That arithmetic is why the category exists and why MDR quotes that look expensive next to a software subscription look cheap next to a rota. It is also why the honest recommendation for a small company is often not to buy MDR at all yet.
How to Choose an MDR Provider
Capability lists are nearly identical across providers, so they cannot separate anyone. These questions can, and the answers vary sharply.
Key takeaways
- MDR is an outsourced service that watches your telemetry continuously, investigates what it finds, and takes agreed containment actions. It is people plus a platform, not a product you install.
- The average breach takes 247 days to identify and contain, and only 38 percent are found by the organization's own team. That gap is what MDR is sold against.
- Coverage is contractual. Endpoint-only MDR misses the identity and SaaS attacks where a growing share of incidents now happen.
- Response authority is the real differentiator. Notify-only, response-with-approval and delegated authority are three different products often sold under one name.
- An MSSP manages your tools and alerts you. MDR hunts intrusions and contains them. Many companies need both, and some providers sell both.
- Managed EDR watches one telemetry source. A SIEM is a product that alerts and does not answer. MDR supplies the answering.
- The comparison that decides the purchase is MDR against hiring five analysts for a 24/7 rota, at a median wage of $129,180 each.
- MDR does not patch, configure, train your staff, or run your recovery. Those stay with you unless the contract says otherwise.
Common questions
What does MDR stand for?
Managed detection and response. Managed means an outside provider runs it, detection means finding attacker activity in your systems, and response means acting to contain it. The name is accurate, which is unusual in this market, and each of the three words is worth checking against what a given contract actually delivers.
What is the difference between managed EDR and MDR?
Managed EDR is a provider operating one endpoint product on your behalf, so its ceiling is whatever that agent can see on laptops and servers. MDR ingests several sources, typically endpoint plus identity, cloud, email and sometimes network, correlates across them, and responds across more than one system. If a service ingests a single source, it is managed EDR whatever it is called.
What is a SIEM vs MDR?
A SIEM is a product that collects logs, correlates them and raises alerts. MDR is a service that includes the analysts who answer those alerts. Most MDR providers run a SIEM or an XDR platform inside their service and never show it to you. A SIEM bought alone leaves the staffing problem untouched, which is the most common way SIEM projects disappoint.
What is the difference between MSSP and MDR?
An MSSP manages security technology on your behalf, such as firewalls, email gateways and patching, and escalates alerts to you. MDR is narrower and outcome focused: find intrusions across your telemetry and contain them under agreed authority. MSSPs are usually device or tool priced and multi-year; MDR is usually priced per endpoint or per user.
What is the difference between an MDR and a SOC?
A SOC is the function of monitoring, investigating and responding. MDR is that function bought as a service rather than staffed in-house. So MDR does not replace a SOC, it provides one. The difference that persists is context: your own team knows your business better, and a provider knows attacks better because it sees hundreds of environments.
Is CrowdStrike an MDR or EDR?
Both, as separate products. CrowdStrike is best known for its endpoint detection and response platform, which is software you or your provider operate, and it also sells a managed service in which its own analysts run detection and response for you. Several vendors follow this pattern, so the product name never answers the question. Ask whether analysts at the vendor are watching your environment, and what they may do without asking.
Who are the top MSSPs in the United States?
There is no single answer, because the market splits by size, sector and region: the firms serving large regulated enterprises are rarely the right fit for a 200-person company, and vice versa. The useful filter is checkable attestations such as SOC 2 or ISO 27001, named experience in your sector, published scope, and how quickly they answer a first inquiry. Our ranked lists apply those checks nationally and across ten metros.
How much does MDR cost?
Providers quote per endpoint or per user per month, and published pricing is rare because the variables move it so much: how many telemetry sources are connected, log retention, response authority, service level commitments, and whether an incident response retainer is bundled. The comparison that matters is against the alternative, and a 24/7 in-house rota takes five to six analysts at a median wage of $129,180 each.
Does MDR replace my IT team?
No, and a contract sold on that basis will disappoint. MDR covers detection, investigation and containment. Patching, configuration, backups, user support, recovery after an incident and regulatory notification remain with your team or your IT provider. MDR also works considerably better when one person inside the company owns the relationship and keeps the list of connected systems honest.
Can an MDR provider contain a threat without asking me first?
Only if your contract says so. Three arrangements exist: notify only, response with approval, and delegated authority where the provider acts immediately and tells you afterward. NIST's incident response guidance treats this as a shared responsibility that belongs in writing, including which actions are permitted, who gets called, and which systems are exempt because isolating them would stop the business.
Is MDR worth it for a small business?
It depends on what is already in place. For a company under about 50 people with no dedicated security person, multi-factor authentication everywhere, patched and managed laptops, tested backups and email filtering close more risk per dollar and should come first. Above that size, with data that would hurt to lose and nobody covering nights, MDR is usually the next purchase rather than a bigger firewall.
On this page
- What Is Managed Detection and Response?
- How Managed Detection and Response Works
- What an MDR Service Covers
- What MDR Providers Are Allowed to Do Without Asking
- MSSP vs MDR
- Managed EDR vs MDR
- SIEM vs MDR
- Is MDR the Same as a SOC?
- How Much Does Managed Detection and Response Cost?
- How to Choose an MDR Provider

Daniel Reyes
Daniel Reyes is a CISSP who spent twelve years in security operations, most recently leading a detection and response team for a mid-sized healthcare group in Texas. He reviews every resource and breach report on Cyber Security Firms for technical accuracy before it publishes.
Most of the people he has trained arrived having been told too much: a dozen acronyms, six vendors, and no clear idea which risk was theirs. His approach is to explain what an attack actually does before naming the tool that stops it, on the basis that most breaches start with something a reader could have recognised.