A managed security service provider runs your security monitoring and response for a recurring fee, usually from a security operations center staffed around the clock.
It is the managed services model narrowed to one job: watching for a threat and acting on it at three in the morning. The phrase that decides the contract is round the clock, because covering one seat for every hour of the week takes about five analysts.
- An MSSP is a managed service provider whose service is security
- The core is a security operations center: monitoring, detection, response
- 24 hour cover for one seat needs about five analysts, which is the real economics
- MDR is a narrower product; an MSSP is a company that may sell it
- Response authority, not alert volume, is what separates the contracts
On this page
The serviceWhat managed security service providers actually sell
Strip the marketing off the service list and four things are left. The rest is packaging.
Monitoring. Log data from endpoints, servers, firewalls, identity systems and cloud tenants lands in one place and something watches it. This is where the acronym SIEM lives.
The question worth asking is not whether monitoring is included, it is which log sources are in the price and which cost extra, because log volume is how most managed security services are metered.
Detection. Rules, threat intelligence feeds and behavioral models that turn raw event data into alerts. This is threat detection, and it is the part MSSPs differentiate on.
Every provider claims this and the quality varies enormously, so the useful question is how many alerts a month a client of your size actually receives and how many turn out to be real.
Response. What the MSSP security operations center is allowed to do when a security event is real. There is a wide gap between a provider that emails you an alert and one that is authorized to isolate a machine at two in the morning without waking anyone. That authority is written into the contract or it does not exist.
Reporting and compliance evidence. The security artifacts an auditor or a cyber insurer asks for. Often the reason the contract was signed in the first place, and frequently the part nobody reads until the audit.
Beyond those four, MSSPs sell vulnerability management, penetration testing, phishing simulation, email and data security, identity protection and virtual security leadership. Those are real services and none of them is the core. The core is somebody watching, and being allowed to act.
The arithmeticWhy round the clock costs what it costs
Every provider page says twenty four seven. The arithmetic behind that phrase is simple and almost nobody prints it.
A week has 168 hours. A full time security analyst covers about 40 of them. Covering a single seat continuously therefore takes 4.2 people before anyone takes a holiday, gets sick, attends training or leaves. Real rotas run at about five, and an MSSP security operations center that can escalate needs more than one seat covered.
At the Bureau of Labor Statistics median wage for information security analysts, $129,180 in May 2025, that is a payroll of about $650,000 a year before tools, before the SIEM license, before management.
This is the honest argument for buying managed security services rather than building them, and it is a better argument than the ones usually made, because it is arithmetic instead of threat statistics.
It cuts the other way too. If a provider quotes $2,000 a month for genuine round the clock cover, that provider is spreading one rota across many organizations, which is exactly the right business model, or it is not staffing a rota at all.
Both are possible and only one is acceptable, so the question to ask is how many analysts are on shift at three in the morning, and where.
The acronymsMSSP, MDR, SOC and MSP
Four labels, sold interchangeably, meaning different things in a contract.
MSSP. A company. A managed security service provider sells managed security services, usually across threat monitoring, detection, response, compliance and often a few adjacent products.
MDR. A product. Managed detection and response is a narrower service focused on endpoint and network data with a response commitment attached. Many MSSPs sell MDR; many pure MDR vendors are not MSSPs, because they do not touch compliance, email or identity.
SOC. A capability, not a company. The security operations center is where threat monitoring and response happen, and it is where the tools live. An MSSP without one is reselling somebody else's, which is fine if it says so and a problem if it does not.
MSP. The general case. A managed service provider runs your technology, including a security baseline: multi factor authentication, endpoint protection, patching and backups. That baseline is cybersecurity hygiene rather than managed security services, and treating it as though it were the same thing is the most common and most expensive misreading in this market.
The practical rule: an MSP keeps the doors locked, and a managed security service provider watches the building.
PricingWhat managed security services cost
| Buyer | Monthly range | What it usually buys |
|---|---|---|
| Under 100 staff | $500 to $10,000 | Bundled monitoring, endpoint, log retention |
| 100 to 250 staff | $10,000 to $30,000 | A named SOC service, SIEM management, response scope |
| Per endpoint | $10 to $75 / endpoint / mo | Endpoints, servers, appliances, cloud workloads |
| Incident work beyond retainer | $250 to $450 / hour | The clause that decides a bad month |
| Building it in-house | $650,000+ / year | Roughly five security analysts at the median wage, before tools |
The ranges above are directional, read from published managed security services pricing guides in September 2026, and quotes to real organizations vary far wider than any table suggests. Two numbers matter more than the headline.
The first is the metering unit. Per user, per device and per gigabyte of log data produce very different bills for the same organization, and a provider that will not tell you which one applies has already answered a different question.
The second is the incident clause. Nearly every retainer caps included response hours, and the overage rate is where a serious breach turns a predictable contract into an unpredictable one. Ask what happens in the worst month, not the average one.
The limitsWhat an MSSP will not do
Fix the thing that let the threat actor in. Threat detection and response is not remediation. Rebuilding a domain, patching the estate and closing the hole are usually the MSP's job or yours, and the handoff between the two companies is where incidents stall.
Own your security risk decisions. An MSSP will tell you what it sees and what it recommends. Accepting the residual risk, funding the fix and signing off the exception stay with you.
Cover data it cannot see. Log sources not in the contract are not monitored, and this is the single most common gap in cybersecurity coverage. A cloud tenant, a line of business application or a remote site left out of scope is invisible no matter how good the security operations center is.
Make your organization compliant. Managed security services produce evidence. A framework still needs policy, process and somebody inside who owns it.
EvidenceHow to tell a real SOC from a dashboard
Every item here is a document or a demonstration, because every provider will describe itself the same way.
Ask how many analysts are on shift at three in the morning, and in which country. A specific answer is a good sign whatever the answer is. A vague one is the whole review.
Ask for the response authority in writing. What can the provider do without calling you: isolate a host, disable an account, block a domain. If the answer is nothing, you have bought an alerting service.
Ask for a real incident report, redacted. Not the sales dashboard. The document a client received after something actually happened, with the timeline in it.
Ask what is in scope and, specifically, what is not. Get the log source list. Then check it against your own inventory rather than against their template.
Ask about alert volume for an organization your size. A provider that cannot say is not measuring it, and alert fatigue is the failure mode that quietly voids the entire arrangement.
Ask who owns the SIEM tenant and the historical log data. If the tools and the data both belong to the provider, changing MSSPs means losing your own history at the moment you most want it.
PitfallsWhere businesses go wrong
Assuming the MSP already does this. A security baseline is not security monitoring. This is the misreading that costs the most and it is the easiest to check: ask your current provider, in writing, who is watching and when.
Buying on alert volume. More alerts is not more security, it is more noise, and MSSPs know that a busy dashboard demonstrates well.
Leaving the incident rate uncapped. The retainer looks predictable until the month it is not.
Splitting security response across two businesses with no named handoff. An MSSP that detects and an MSP that remediates is a normal arrangement and works only when both contracts name who calls whom.
Treating compliance as the goal. MSSPs hired to produce evidence will produce evidence. Whether anything is actually being watched is a separate question, and it needs to be asked separately.
ComparisonMSSP, MDR, an MSP baseline, or your own SOC
| Criterion | MSSP | MDR product | MSP baseline | In-house SOC |
|---|---|---|---|---|
| What it covers | Threat monitoring, response, compliance | Endpoint and network data | Prevention controls only | Whatever you staff |
| Round the clock | Included, verify the rota | Usually included | No | Needs about 5 in-house analysts |
| Response authority | Negotiable, put it in writing | Defined by the product | None | Yours |
| Compliance evidence | Usually included | Partial | No | Yours to produce |
| Typical cost | $500 to $30,000 / mo | Per endpoint, per month | Inside the IT fee | $650,000+ / year |
| Best at | 100+ staff, or regulated | A specific detection gap | Every business, as a floor | Large or high risk |
| Biggest risk | Scope gaps in log sources | Mistaken for full coverage | Mistaken for monitoring | Staffing it honestly |
The last row is the one to read twice. Three of these four fail the same way, by being mistaken for something broader than they are, and only one of them fails because it is hard to run.
FAQFrequently asked questions
What is a managed security service provider?
A company that runs threat monitoring, detection and incident response for client organizations under a recurring contract, usually from a security operations center staffed around the clock, and usually with compliance reporting attached.
What does MSSP stand for?
Managed security service provider. It is the cybersecurity specialization of the managed services model, so all MSSPs are managed service providers and most managed service providers are not MSSPs.
What is the difference between an MSP and an MSSP?
Scope and job. An MSP runs your technology and maintains a cybersecurity baseline. An MSSP watches for threats and responds to them. The baseline is prevention, the managed security service is detection and response, and one does not include the other.
What is the difference between an MSSP and MDR?
MDR is a product, managed detection and response, focused on endpoint and network data with a defined response commitment. MSSPs are companies that may sell MDR alongside threat monitoring, compliance, email and identity services.
How much does an MSSP cost?
Provider guides published in 2026 put it at roughly $500 to $10,000 a month under a hundred staff and $10,000 to $30,000 from a hundred to 250, with per endpoint pricing of $10 to $75. Quotes vary wider than that, and the metering unit matters more than the headline. The guides are named on the cybersecurity services page.
Is an MSSP worth it for small businesses?
It depends on regulation and on what a security incident would cost, not on headcount alone. A company under fifty people with no compliance obligation is usually better served by getting the security baseline right first, because security gaps you have not closed produce alerts you cannot act on.
What is a security operations center?
The team and tools that watch security data and respond to threats in it. It is a capability rather than a company, and an MSSP either runs its own or resells access to somebody else's.
Do MSSPs actually stop threats?
They shorten the time between something happening and somebody acting, which is the variable that decides how bad an incident becomes. Whether they can act at all depends on the response authority written into your contract.
What should be in an MSSP contract?
The log sources in scope, the metering unit, the response authority and what the provider may do without calling you, the escalation path with names, the included incident hours and the overage rate, who owns the tools and the historical log data, and the exit terms.
How do I know an MSSP has a real SOC?
Ask how many analysts are on shift at three in the morning and in which country, ask for a redacted incident report from a real event, and ask for alert volume figures for a client of your size. All three are answerable and vague answers are the finding.
Can an MSP and an MSSP work together?
That is the most common arrangement for businesses above about a hundred people. It works when both contracts name the handoff: who detects, who remediates, who calls whom, and within how long.
What does 24/7 monitoring really mean?
It should mean a staffed rota. A week has 168 hours and an analyst covers about 40, so one continuously covered seat is roughly five people. Providers achieve it by spreading one rota across many clients, which is legitimate, or by not staffing it, which is not.
Is an MSSP cheaper than building a security team?
For almost all organizations below enterprise scale, yes. Round the clock cover for one seat is about five in-house security analysts. At the Bureau of Labor Statistics median wage of $129,180, the internal option starts near $650,000 a year before tools.
How do I find a managed security service provider I can check?
Confirm the business exists as a registered entity, that the phone reaches somebody who knows it, and that any certification claimed is confirmed by its issuer rather than by the company. Our directory of providers publishes the record of those checks on every listing.
How does MSSP pricing work?
MSSP pricing is metered in one of three ways: per user, per endpoint or device, or a flat monthly fee for a defined scope. Log volume and retention are often charged on top. The unit matters more than the headline number, because the same company can look cheap per endpoint and expensive per user.
Keep readingRelated concepts
Read next · Managed IT What Is an MSP, and What Are You Actually Buying The general case: a provider that runs IT broadly and keeps a security baseline, which is not the same as watching for a threat. Open this next10 min- Identity and access · 16 min What Is MFA? The first control in any baseline, and part of what an MSP already covers before an MSSP is worth buying.
- Network security · 14 min What Is a Firewall? One of the log sources an MSSP monitors, and one worth checking is actually in the contract scope.
- Managed IT · 9 min What a vCIO Is, and the Question to Ask Before Buying One The general technology role, and where it stops.