SOC

MSSP

A Managed Security Service Provider (MSSP) operates specific security services for its clients, such as firewalls or monitoring.

A Managed Security Service Provider (MSSP) operates security services for its clients, like firewalls, monitoring or vulnerability scans. Its focus is usually on operating technology rather than on investigating attacks.

How it works

An MSSP takes on specific tasks that internal IT would normally handle. Typical services include firewall management, patch monitoring, log monitoring, and vulnerability scanning. When an Alert is generated, the MSSP often informs the client via a ticket or email. The investigation and response then remain the client's responsibility.

For example, monitoring might report several failed VPN login attempts. The MSSP opens a ticket with this notification. The client's IT team must then investigate if it was an attack and which account was affected.

What to look out for

  • Scope of services: Does 'monitoring' mean just forwarding Alerts or also investigating and containing threats?
  • Response times: Do they apply to the initial notification or to a specific containment action?
  • Alert quality: Many tickets without context can create noise for your team.
  • Responsibilities: Who decides during the night if a server should be isolated?

How it differs from a SOC and MDR

A SOC or MDR service investigates Alerts and takes direct action. An MSSP can offer a SOC, but this is not always the case. The title therefore says little about the actual scope of services. The service description in the contract is the decisive factor.

When an MSSP is a good fit

An MSSP is suitable if you mainly want to outsource operational tasks. Examples include managing firewall rules, patch management or backup monitoring. Detection and response for targeted attacks requires a SOC or an MDR service. Many organisations combine both approaches, which makes a clear interface essential. Define who informs whom and who executes technical containment. Document this process and practise it in a tabletop exercise.

How we implement it

We do not operate firewalls for clients. Instead, we operate the SOC, including detection and response. We work with your existing tools and your operations partner.