Insights

MDR, SOC and MSSP: What the Terms Actually Mean

REDD · 2026-09-20

Ask three providers for security monitoring and you will get three acronyms back. They are used loosely, sometimes deliberately, and the differences only become obvious during an incident, which is the worst time to discover them.

SOC: the team, not the service

A Security Operations Centre is the facility and the people. Analysts watching feeds from your environment, around the clock, with the tooling to investigate what they see.

A SOC is a capability rather than an outcome. The question that matters is what it is permitted to do. A SOC that can only notify you has moved the problem to your inbox, which at 2am on a Sunday is not where it gets solved.

MSSP: managed security services, broadly

A Managed Security Services Provider runs security tooling on your behalf: firewalls, endpoint protection, email filtering, sometimes log collection. It is the oldest of the three terms and the widest.

The historical weakness of the MSSP model is alert forwarding. Tools generate alerts, the alerts are passed on, and triage lands with the customer. When the volume is high, alerts get ignored, which is how a genuine detection goes unread for days.

MDR: detection and response as an outcome

Managed Detection and Response is defined by what happens after something is found. Threats are detected, triaged by a person, and contained. The account is disabled, the device isolated, the session revoked, while the investigation continues.

MDR is the model most organisations actually want, because it is the one that includes the part you cannot easily do yourself at three in the morning. What varies enormously between providers is coverage.

The questions that separate them

Why identity coverage matters most

The pattern behind a large share of Australian incidents is not malware. It is valid credentials, taken through a convincing sign-in page, used out of hours by someone who then looks around quietly for days.

Nothing about that resembles a virus, so endpoint tooling has nothing to catch. Detecting it means correlating behaviour across identity, endpoint, network and cloud. A single unusual sign-in is noise. The same sign-in followed by a privilege change and access to a file share is not.

Where it fits with everything else

Detection is one layer. Reducing how often anyone has to detect anything is the job of the Essential Eight, and shrinking the number of credentials that get away in the first place is the job of awareness training. Run together, each makes the others cheaper.

REDD delivers managed detection and response from a 24x7 Security Operations Centre across endpoint, identity, network and cloud, as part of a wider managed security program. If you want to know what is genuinely covered in your environment today, ask us to walk through it.

Talk to the team behind the insights

Thirty minutes with a REDD engineer. Straight answers about your IT, security and AI, no pitch deck.

Get in touch

Tell us what is running your business

Send the basics and a REDD engineer will come back to you within one business day. Prefer to talk? Call 1300 697 333.

Thanks. Your enquiry is on its way, and a REDD engineer will come back to you within one business day.

Your details go to the REDD team and nowhere else.

1300 697 333 Book a consult