Ask three providers for security monitoring and you will get three acronyms back. They are used loosely, sometimes deliberately, and the differences only become obvious during an incident, which is the worst time to discover them.
SOC: the team, not the service
A Security Operations Centre is the facility and the people. Analysts watching feeds from your environment, around the clock, with the tooling to investigate what they see.
A SOC is a capability rather than an outcome. The question that matters is what it is permitted to do. A SOC that can only notify you has moved the problem to your inbox, which at 2am on a Sunday is not where it gets solved.
MSSP: managed security services, broadly
A Managed Security Services Provider runs security tooling on your behalf: firewalls, endpoint protection, email filtering, sometimes log collection. It is the oldest of the three terms and the widest.
The historical weakness of the MSSP model is alert forwarding. Tools generate alerts, the alerts are passed on, and triage lands with the customer. When the volume is high, alerts get ignored, which is how a genuine detection goes unread for days.
MDR: detection and response as an outcome
Managed Detection and Response is defined by what happens after something is found. Threats are detected, triaged by a person, and contained. The account is disabled, the device isolated, the session revoked, while the investigation continues.
MDR is the model most organisations actually want, because it is the one that includes the part you cannot easily do yourself at three in the morning. What varies enormously between providers is coverage.
The questions that separate them
- What is monitored? Endpoint only, or endpoint, identity, network and cloud? Identity is where most modern intrusions happen, and endpoint-only monitoring will miss them.
- Who triages? A person, or a rule? Automated triage alone produces either noise or silence, and both end badly.
- What can you do without calling us? Pre-agreed containment is the difference between a contained incident and a documented one.
- What happens at 2am on a public holiday? Ask specifically. Coverage gaps are usually at the edges.
- What do we get afterwards? A readable account of what happened and what would prevent a repeat, not a ticket number.
Why identity coverage matters most
The pattern behind a large share of Australian incidents is not malware. It is valid credentials, taken through a convincing sign-in page, used out of hours by someone who then looks around quietly for days.
Nothing about that resembles a virus, so endpoint tooling has nothing to catch. Detecting it means correlating behaviour across identity, endpoint, network and cloud. A single unusual sign-in is noise. The same sign-in followed by a privilege change and access to a file share is not.
Where it fits with everything else
Detection is one layer. Reducing how often anyone has to detect anything is the job of the Essential Eight, and shrinking the number of credentials that get away in the first place is the job of awareness training. Run together, each makes the others cheaper.
REDD delivers managed detection and response from a 24x7 Security Operations Centre across endpoint, identity, network and cloud, as part of a wider managed security program. If you want to know what is genuinely covered in your environment today, ask us to walk through it.