A buyer’s guide · Operating since 2002
Most organisations already pay somebody to keep IT working. The question that brings people to this page is whether that arrangement also covers security, and the honest answer is usually that it covers some of it — the part that looks like maintenance.
A managed security service provider operates your security controls: firewall policy, endpoint tooling, email security, identity enforcement, vulnerability management. Not the products, the administration of them, which is the part that quietly stops happening when it belongs to a team with a backlog.
MSP vs MSSP
The difference is not the catalogue. It is the reflex.
Put an MSP’s service list beside an MSSP’s and they overlap enough to look like competitors. They are not. They are measured on different numbers, and the numbers only conflict when something is actually wrong — which is the moment you find out which one you bought.
Restoring fast is the right instinct, most of the time
A failed disk, a corrupted database, a bad update: restore from backup, get people working, close the ticket. That reflex is correct, it is what an MSP is paid for, and an organisation without it suffers constantly.
None of what follows is a criticism of that. It is a description of the one scenario where the instinct betrays you.
Under attack, the same instinct destroys the answer
Rebuilding the machine wipes the evidence of how they got in. If the way in was a stolen credential or a forgotten VPN account rather than the machine itself, the intrusion simply returns — and the second time, they know the environment.
Somebody has to be willing to say the server stays offline while the scope is established. That sentence is unpopular, it is the job, and it is the difference between the two lanes above.
The five models
MSP, MSSP, managed SOC, MDR and in-house
The first column is the one that separates them. Everything else follows from what a provider is measured on.
Scroll the table sideways →
| Model | Measured on | What it owns | What it will not do | Who it suits |
|---|---|---|---|---|
| MSP Managed IT / managed service provider |
Time to restore service | Service desk, endpoints, patching, servers, cloud tenancy, connectivity, procurement. | Watch for an intruder, or hold a compromised machine offline while somebody works out what happened. | Almost everyone. This is the baseline IT function. |
| MSSP Managed security service provider |
Time to certainty | Security controls as operated systems — firewall policy, endpoint tooling, email gateway, VPN and identity enforcement, patch verification. | Necessarily watch your logs 24×7. Device management and detection are separate purchases and are often confused. | Organisations with security tooling that nobody is really administering. |
| Managed SOC / SOCaaS | Time to verified incident | Detection. Collection, correlation, triage and investigation by analysts, around the clock. | Administer your firewalls or run your patching. It watches; it does not build. | Anyone whose exposure means an intrusion must be found at 3 a.m., not on Monday. |
| MDR | Time to contain | Detection plus a defined set of response actions on the telemetry the provider supports. | Cover sources outside its own tooling, or manage the estate the telemetry comes from. | Teams wanting containment included rather than advised. |
| In-house | Whatever you choose to measure | Everything, including the recruitment and the rota. | Come cheaply at 24×7 — the constraint is five to six people per role, not the tooling. | Organisations at a scale where the crossover has genuinely arrived. |
Most mid-sized organisations end up with an MSP and detection, not an MSSP and nothing. The middle row is worth buying when your controls exist but nobody is really administering them — which is more common than it sounds, because tooling gets bought in a project and then belongs to no one.
The actual work
What an MSSP operates, day to day
None of this is dramatic. All of it decays without someone whose job it is, and the decay is invisible until the week it matters.
Firewall and perimeter policy
Rule lifecycle, change review, version currency, and the annual cleanup of the rules nobody remembers adding.
Rule bases decay. Every firewall over five years old contains permit rules for systems that were decommissioned, and each one is a path.
Endpoint tooling
Deployment coverage, policy tuning, exclusion review, and confirming the agent is actually running — not merely licensed.
Licence count and installed count diverge quietly. The gap is always on the machines that matter, because those are the ones with change control.
Email security
Gateway policy, authentication records, quarantine review, and the reporting path for staff.
Email is the delivery mechanism for most of what follows. Most of the loss, though, is a finance process failure rather than a filter failure.
Identity and remote access
MFA enforcement coverage, conditional access, dormant account review, and privileged account inventory.
The account that survives a rebuild is how the second incident happens. Identity is where containment either works or does not.
Vulnerability and patch verification
Scanning, prioritisation against what is actually reachable, and confirming that the patch landed.
“Patched” from a console and “patched” on the host disagree more often than anyone expects.
Evidence and reporting
Control state, change history and exception records assembled as you go, in the form an auditor asks for.
Reconstructing a year of control evidence in audit week is the task that quietly does not get done.
Straight answers
What buyers get wrong about managed security services
An MSP and an MSSP have opposite reflexes under attack
Not opposite catalogues — those overlap heavily. An MSP is measured on time to restore, and that is the correct measure for a failed disk. Under attack it is the wrong one: rebuilding the box destroys the evidence and hands it back with the intruder still holding the credential that got them in. The diagram above is one real incident answered both ways.
An MSSP does not necessarily watch anything
This is the most expensive misunderstanding in the category. Managing security devices and monitoring for intrusions are separate purchases. A provider can competently administer your firewall, endpoint and email tooling and still have nobody looking at a screen at 2 a.m. If you need detection, you are buying a managed SOC, and it is a different line on the quote.
“Is security included, or is it a separate line?”
Ask your current IT provider this and read the answer carefully. “We handle security” usually means antivirus is deployed and the firewall has a support contract. That is device hygiene. It is worth having and it is not detection, not response, and not assurance.
One provider can do both, under one condition
We do both, so take this as an interested party being specific rather than modest. It works when the two functions are separately staffed and separately measured. It fails when the same engineer is on both rotas, because under pressure the restore-fast reflex wins every time — it is the one they are judged on and the one the customer is shouting for.
“Who tells us to stay down?”
The most revealing question you can put to any provider. Somebody has to be willing to say the server stays offline for another six hours because the scope is not established yet. If nobody in the arrangement owns that sentence, the decision defaults to whoever wants the service back, which is everybody.
You may not need an MSSP at all
If a competent IT provider already administers your controls, your estate is small and uniform, and your realistic exposure is commodity ransomware rather than a targeted intrusion, then hardening what you have and buying detection directly is a better use of the money than a second management layer. Adding a provider to manage tooling that is already managed buys a report.
Before you sign
Ten questions for any managed security provider
Use these on us and on everyone else. Question two is the one that most often reveals that a contract does not contain what the buyer thought it did.
Which specific devices and consoles do you administer, by name?
Not “perimeter security”. The named firewall pair, the endpoint console, the mail gateway, the VPN. Anything not on that list is yours, and the gap between what a buyer assumed and what the contract says is where most disappointment lives.
Is anyone watching, and at what hours?
The single most important question on this page. Device management does not imply monitoring. Ask what happens between 6 p.m. and 9 a.m., and whether the answer is an analyst or an email that gets read on Monday.
What can you do without asking us?
Push a firewall rule, isolate a machine, disable an account. Whatever needs your approval will wait for someone to answer the phone, and the whole value of a fast provider disappears in that wait. Get the pre-authorised list in writing.
How does a rule change get reviewed, and who can request one?
Firewall rule bases decay through accumulated emergency changes that nobody revisited. Ask for the review cadence and the removal process, not just the approval process.
How will you prove the agent is actually running everywhere?
Ask for installed-versus-expected as a reported number, monthly. Licence count is not coverage, and the machines that drift are consistently the ones under change control.
Where does your responsibility stop and our IT provider’s begin?
Write this down before signing, because it is the thing that gets argued about during an incident. The dangerous items are patching, backups and identity, which both sides routinely assume the other owns.
When you find something, who do you call, and what do they decide?
A named person and a named decision. “We will raise a ticket” is not an escalation path at 2 a.m.
What do we get monthly, and would it satisfy an auditor?
Control state, changes made, exceptions open, coverage figures. A report of tickets closed describes your provider’s workload, not your security posture.
What do we get back, and in what form?
Configurations, rule bases, documentation, log history. Controls administered inside a provider’s tenancy without exportable configuration are a lock-in you will discover at renewal.
What do you think we should not buy from you?
Ask everyone this, including us. A provider who answers “nothing” is selling a catalogue. A useful answer names something and explains what would serve you better.
Working with us
How we run this
We sell both sides of the argument on this page — managed IT and managed security. That is exactly why the separation below is stated as a commitment rather than left implied.
Separate teams, separate targets
Our NOC and SOC are different people with different measures. The engineer restoring your service is not the analyst deciding whether it is safe to restore it.
Someone owns “stay down”
A named analyst is empowered to hold a system offline while scope is established, and is not measured on uptime. Without that, the decision defaults to whoever is loudest.
Multi-vendor by default
We operate what you already own where it is fit for purpose. Where we suggest replacing something we will say what it costs to run, not just to buy.
Coverage as a number
Installed versus expected, reported monthly, for every control we administer. Licence counts are not coverage.
Evidence as you go
Control state and change history assembled continuously, in the form an auditor asks for — not reconstructed in audit week.
Questions we get asked
Managed security services, answered
What is a managed security service provider (MSSP)?
A provider that operates your security controls as a service — firewall policy, endpoint tooling, email security, identity enforcement, vulnerability management — rather than selling you the products and leaving you to administer them. The important thing to understand before buying is that operating controls and watching for intrusions are separate functions. Many MSSPs sell both; the acronym itself only promises the first.
What is the difference between an MSP and an MSSP?
An MSP keeps IT working and is measured on how fast service is restored. An MSSP assumes somebody is trying to break in and is measured on how quickly it can be certain about what happened. Under a normal outage those goals agree. Under an attack they conflict directly: restoring a server from backup in two hours meets the MSP’s target and destroys the evidence, and if the way in was a credential rather than the machine, the same intrusion returns within days. The diagram on this page walks one incident through both reflexes.
Can the same company be our MSP and our MSSP?
Yes, and we are both, so treat this as an interested party being precise. It works when the two functions are separately staffed and separately measured. It stops working when the same engineer sits on both rotas, because under pressure the restore-fast reflex wins — it is the one they are judged on. The question to ask any combined provider is which named person is empowered to say the server stays offline, and whether that person’s targets are about uptime.
What is the difference between an MSSP and MDR?
An MSSP administers your controls. MDR detects and responds, on the telemetry the provider’s own tooling produces. They solve different problems and are frequently sold as alternatives, which they are not. An estate with well-managed controls and no detection is blind; an estate with excellent detection and unmanaged controls generates alerts about problems that better administration would have prevented.
What is the difference between an MSSP and a SOC?
A SOC is a function — analysts, process and tooling whose job is finding intrusions. An MSSP is a commercial arrangement for operating security products. An MSSP may run a SOC, may subcontract one, or may not have one at all. This is worth asking directly rather than inferring, because the marketing language is nearly identical. Our own detection service is described at managed SOC services and SOC as a Service.
Does an MSSP include 24×7 monitoring?
Not by definition, and this is the assumption that causes the most trouble. Plenty of MSSP contracts cover business-hours administration of security devices with an out-of-hours emergency number. If round-the-clock detection matters to you, it must be specified explicitly, and you should ask whether 24×7 means an analyst investigating or an alert queue somebody reviews in the morning.
What does an MSSP actually do day to day?
Mostly unglamorous administration that decays without attention: firewall rule review, endpoint agent coverage, mail gateway policy, MFA enforcement gaps, dormant privileged accounts, patch verification, and assembling the evidence of all of it. The value is not dramatic. It is that these things stay done, which is exactly what does not happen when they are one more item on an internal team’s list.
When do we not need an MSSP?
When a competent IT provider already administers your controls properly, your estate is small and uniform, and your realistic threat is commodity ransomware rather than a targeted intrusion. In that case buying detection directly is a better use of the budget than adding a management layer over tooling that is already managed. We would rather say that than sell you a monthly report.
Does MSSP mean anything else?
Yes, and it causes real confusion in search. In healthcare, MSSP is the Medicare Shared Savings Program, which is unrelated to security. If you are comparing providers it is worth using the full phrase — managed security service provider — because a great deal of what the bare acronym returns is about accountable care organisations.
How does an MSSP fit with our internal IT team?
Usually as the layer that owns the security controls your team does not have time to administer, while your team keeps the estate and the users. The boundary that must be explicit is patching, backups and identity, because both sides routinely assume the other owns them. Write it down before signing; it is the thing that gets argued about mid-incident.
Do you work with our existing IT provider?
Regularly, and it is a common arrangement. What we ask for is a written split of responsibilities and a named contact on their side who can act during an incident. Where it goes wrong is not friction between providers — it is the assumption on both sides that the other one had patching or backups covered.
Are you vendor-locked?
No. We are certified across several vendors and will operate what you already own where it is fit for purpose. Replacing working tooling to suit a provider’s preferred stack is a cost to you and a convenience to them; where we do recommend a change, we will tell you what it is worth and what it will cost to run.
What about compliance?
Control evidence is a by-product of operating controls properly, provided it is assembled as you go. That is the part that fails — not the controls, but the record of them, reconstructed in audit week from memory and email. What we produce monthly is intended to be usable directly. See compliance services for the frameworks.
How do we start?
With a review of what you already have, because the answer is often that the tooling is adequate and unadministered. That review tells you whether the gap is management, detection or assurance, and those are three different purchases. We would rather scope the right one than sell all three.
Next step
Start by finding out what is already unmanaged
Before buying anything, it is worth knowing which of your existing controls nobody is actually administering. That review usually finds the tooling is adequate and the ownership is not — and it tells you whether your real gap is management, detection or assurance. Those are three different purchases, and we would rather scope the right one than sell all three.
Related
Also part of the firewall lifecycle: virtual CISO services · incident response retainer.



