At some point every growing company faces the same procurement question: alerts are firing, nobody is watching them at night, and NIS2 or a customer contract now demands proof of monitoring. The three answers on the table are MDR, an MSSP, or building your own SOC. The labels sound interchangeable. They are not, and buying the wrong one typically costs a year and a six-figure budget before anyone notices.
What is the difference between MDR, an MSSP, and an in-house SOC?
MDR (Managed Detection and Response) is an external team that investigates and contains threats for you, working from endpoint and identity telemetry. An MSSP (Managed Security Service Provider) operates security tooling and forwards alerts, leaving investigation to you. An in-house SOC is your own staffed monitoring function. The practical difference is who acts when something fires at 03:00.
The MSSP model dates from the early 2000s: firewall management, IDS monitoring, log retention, monthly reports. MDR emerged in the mid-2010s around EDR agents, when it became possible to see process-level activity on every endpoint and contain a host remotely. Today the labels blur because many MSSPs have rebranded as MDR without changing their operating model.
One question cuts through the branding: when a credible detection fires at night, does the provider isolate the machine themselves, or do they open a ticket?
- ▸MDR: detects, triages, hunts, contains. Sensor-centric, built on EDR/XDR.
- ▸MSSP: manages tools, monitors output, escalates. Tool-centric, built on SIEM and appliances.
- ▸In-house SOC: all of the above, plus the hiring, tooling, and retention problems.
What does MDR actually include, and what does it usually not?
A typical MDR service includes 24/7 human triage of EDR/XDR alerts, scheduled threat hunting, and active containment - isolating hosts, disabling accounts, blocking hashes - under pre-agreed rules of engagement. It usually does not include full incident response beyond containment, deep forensics, compliance evidence preparation, security engineering, or log sources outside the provider's sensor stack.
The market reference points are services like CrowdStrike Falcon Complete, SentinelOne Vigilance, Sophos MDR, and Microsoft Defender Experts for XDR, plus dozens of regional providers building on those platforms. Judge any of them on the same three axes:
- ▸Time-to-triage SLA: how fast a human looks at a critical alert - minutes matter more than marketing.
- ▸Containment authority: can they isolate a host or disable an account without waking you, and is that pre-authorization written down?
- ▸Hunting cadence: is threat hunting a scheduled deliverable with published hypotheses, or a word in the brochure?
Watch the scope gaps: SaaS audit logs (Microsoft 365, Google Workspace), network appliances, custom applications, and OT environments are frequently outside the sensor stack. Forensics and litigation-grade investigation usually require a separate retained incident response contract.
What does an MSSP do, and where does the model still fit?
An MSSP operates and monitors security infrastructure: firewalls, SIEM, email gateways, vulnerability scanners, sometimes the whole network edge. Response typically ends at an escalation ticket. The model still fits when your pain is running tools rather than investigating alerts - co-managed SIEM, compliance log retention, firewall change management - but it does not substitute for a response capability.
The failure mode is well known: a ticket titled Suspicious PowerShell arrives at 03:14, and the investigation it needs is precisely the capability you outsourced because you did not have it. Alert forwarding without investigation moves the hardest work to the least equipped party.
Where an MSSP genuinely earns its keep:
- ▸Co-managed SIEM: they run the Microsoft Sentinel or Elastic platform and its health; your engineers keep detection content and business context.
- ▸Regulated log retention: storage, integrity, and audit trails for reporting obligations.
- ▸Device fleets: firewall and gateway management at a scale you cannot justify staffing.
What does staffing an in-house SOC actually take?
Covering one seat 24/7 typically takes four to five full-time analysts once shifts, holidays, sickness, and attrition are counted. A minimally credible SOC - two analysts per shift, a lead, and a detection engineer - lands around ten to twelve people. At typical EU salaries, that is often EUR 700,000 to 1.5 million per year before any tooling.
The shift arithmetic is unforgiving: a week has 168 hours, and a full-time analyst covers about 40 of them before leave, training, and turnover. Then add the roles that make the monitoring worth anything:
- ▸Tier 1 and Tier 2 analysts to triage and investigate.
- ▸A detection engineer to write and tune rules - without one, the SOC drowns in false positives within months.
- ▸A SOC lead for escalation, quality, and vendor management.
- ▸Tooling: SIEM licensing (ingest-based pricing grows with log volume, not headcount), EDR seats, SOAR, threat intelligence feeds.
Tier 1 burnout and attrition are persistent, widely reported problems across the industry, which is why the pragmatic pattern for mid-size companies is hybrid: keep detection engineering and business context in-house, buy the night and weekend eyes.
How do MDR, MSSP, and SOC costs compare in 2026?
MDR is typically priced per endpoint or per user per month, commonly somewhere in the EUR 5-20 per endpoint range depending on scope, SLAs, and whether the EDR license is bundled. A 300-endpoint company often lands between EUR 25,000 and 70,000 a year. MSSP contracts track devices and log volume. An in-house 24/7 SOC is effectively a seven-figure annual commitment.
Treat these as budgeting anchors, not quotes - pricing varies widely by country, vendor, and negotiation:
- ▸MDR: per-endpoint or per-user subscriptions; onboarding fees in the low thousands; contract minimums that can price out very small fleets.
- ▸MSSP: small device fleets from roughly EUR 1,000-5,000 per month; SIEM-inclusive deals scale with daily ingest (GB per day), and ingest grows faster than headcount.
- ▸In-house: salaries as above, plus SIEM ingest that can reach six figures on its own at scale, EDR, SOAR, and continuous training.
- ▸Hidden line items everywhere: retained incident response, log storage for regulatory reporting, and the internal engineering time to onboard log sources properly.
Why is NIS2 pushing EU companies toward 24/7 monitoring?
NIS2 obliges in-scope essential and important entities to have incident-handling capability among their risk-management measures, and to report significant incidents on tight clocks: an early warning within 24 hours of awareness and an incident notification within 72 hours. Meeting those deadlines with nobody watching telemetry outside business hours is genuinely difficult, which makes monitoring duty the main EU driver of MDR purchases in 2026.
Two more forces compound it. Management bodies carry personal accountability for approving and overseeing these measures, which concentrates minds at board level. And supply-chain provisions mean large customers now cascade monitoring and reporting expectations into supplier contracts, so companies far below the formal thresholds are being pulled in commercially.
National transposition timelines and details vary across member states - verify what applies to you against your national law and the primary EU texts rather than vendor summaries. For the engineering side of compliance, see NIS2 in 2026: Turning the Directive into an Engineering Backlog and The NIS2 Engineering Checklist: 40 Controls Mapped to Evidence.
Which option fits your size and risk profile?
For most companies under roughly 500 employees with no regulatory mandate for an internal SOC, MDR plus a retained incident-response agreement is the sensible buy. Choose an MSSP when the pain is operating tooling rather than investigating alerts. Build in-house only above roughly 2,000 employees, in heavily regulated sectors, or when telemetry cannot leave your environment.
A rough map by scenario:
- ▸20-100 staff: bundled MDR on your existing stack (Microsoft, or an EDR vendor's own service), plus an IR retainer. Skip the SIEM for now.
- ▸100-500 staff: MDR for endpoints and identity, plus co-managed SIEM to cover the SaaS and cloud logs the sensors miss.
- ▸500-2,000 staff: hybrid - in-house detection engineering and context, outsourced 24/7 triage.
- ▸2,000-plus, regulated, or sovereignty-constrained: in-house SOC, or an EU-resident MDR with contractual data residency; where telemetry is stored becomes a procurement criterion, not a detail.
Whichever you buy, someone internal must own the relationship, the asset inventory, and the response decisions no provider can take for you - a part-time security leader is often that person, as covered in Do You Need a vCISO? A Decision Guide for Growing Companies. AI-assisted triage is also starting to shift Tier 1 economics on both sides of the build-versus-buy line - see AI Agents in the SOC: Augmenting Tier 1 Without Automating Mistakes.
What should you check before signing an MDR or MSSP contract?
Before signing, confirm who performs containment and under what written pre-authorization, which log sources are actually in scope, the time-to-triage SLA for critical alerts, whether hunting is a scheduled deliverable, where your telemetry is stored and processed, how you exit with your data, and whether the provider can operate inside your 24-hour and 72-hour reporting duties.
A concrete due-diligence list:
- ▸Ask for a redacted sample investigation report - it shows the real quality of the analysis you are buying.
- ▸Request their MITRE ATT&CK coverage mapping for your specific stack, not a generic matrix.
- ▸Get a named escalation path and test it during onboarding, not during an incident.
- ▸Have them join one tabletop exercise in the first quarter; how a provider behaves there predicts how they behave at 03:00 - our guide to Incident Response Playbooks That Teams Actually Use covers how to run one.
- ▸Check exit terms: alert history, detection content, and onboarding documentation should leave with you.
How TuniCyberLabs helps
We are an engineering firm, not a reseller: we run vendor-neutral MDR and MSSP selections, design and tune detection stacks on Microsoft Sentinel, Elastic, and Wazuh, build the NIS2 evidence trail around whichever provider you choose, and deliver co-managed monitoring for EU and North African companies from our Tunisian engineering base. If you are weighing these three options against a real budget, talk to us - we will tell you honestly which one you do not need.
