Cybersecurity

EDR, MDR, XDR, SIEM and MSSP explained

Security is sold in acronyms, and the acronyms overlap enough that quotes for very different things look comparable. This page sets out what each one is, what it actually does, what it replaces, and which one answers the problem you have rather than the one a vendor sells.

The acronyms

What each one is, and what it does for you

Two distinctions carry most of the meaning. Whether a human is watching it, and whether it covers only endpoints or everything. Nearly every difference below reduces to one of those.

Antivirus

What it is. Signature-based software that blocks known malware on a device. It is the oldest layer and it still works against commodity threats. Microsoft Defender is included with Windows and is genuinely capable.

What it does for you. Stops the known and the automated. It does not detect an attacker who is using legitimate tools and valid credentials, which is how most serious intrusions now proceed.

EDR, endpoint detection and response

What it is. Software on the endpoint that records behaviour rather than matching signatures, so it detects the pattern of an attack and lets somebody investigate and contain it. It produces alerts and a timeline.

What it does for you. Catches what antivirus misses and gives you the ability to respond. It assumes somebody is reading the alerts, which is the assumption that most often turns out to be false.

XDR, extended detection and response

What it is. EDR widened beyond the endpoint to take in identity, email, cloud and network signals, correlated in one place so that related events across systems appear as a single incident rather than five unrelated alerts.

What it does for you. Reduces the noise and shortens investigation, because the correlation is done for you. Still a tool rather than a service, and still needs somebody watching.

MDR, managed detection and response

What it is. A service rather than a product. A provider operates the detection tooling and staffs a team that investigates alerts around the clock and responds on your behalf, usually with agreed authority to isolate a device at three in the morning.

What it does for you. Answers the question of who is watching out of hours. This is the single most common gap in Australian mid-market security, and the reason organisations that already own good tooling still get breached.

SIEM, security information and event management

What it is. A platform that collects logs from across the estate, correlates them and retains them. Modern platforms add automated response, which is where SOAR sits.

What it does for you. Gives you the record, and the ability to prove what happened, which several compliance regimes require. It is expensive to run well, generates substantial noise untuned, and needs people. Frequently bought when MDR was the actual requirement.

SOC as a service

What it is. A subscription to a security operations centre, staffed and monitoring on your behalf. In practice the difference from MDR is scope: SOC as a service usually implies broader coverage and log management, MDR usually centres on detection and response.

What it does for you. Provides the people and the process without recruiting a team. Ask precisely what is covered and what happens when something is found, because the terms are used loosely across vendors.

MSSP, managed security service provider

What it is. The broadest term. A provider running some part of your security operations, which might be firewalls, email filtering, patching, monitoring, or all of it. MDR is a specific service, MSSP is a category of provider.

What it does for you. Useful when you want one party accountable across several security functions. Because the term is so broad, the scope in the contract matters more than the label.

vCISO, virtual chief information security officer

What it is. Access to senior security leadership without hiring a full time executive. Strategy, risk decisions, board reporting, framework selection and vendor oversight, delivered part time.

What it does for you. Answers who owns security as a decision rather than as a task. It is what most mid-market organisations need before they need more tooling, and it is the least sold of everything on this page.

Side by side

Product or service, and who is watching

The row that matters most is the second one. A tool nobody is monitoring is a licence, not a defence.

EDR XDR MDR SIEM SOC as a service vCISO
Product or service Product Product Service Product Service Service
Who is watching it You You The provider, 24/7 You The provider, 24/7 Not a monitoring role
Scope Endpoints Endpoints, identity, email, cloud Depends on the contract Everything that produces a log Broad, defined in the contract Strategy and governance
Answers What happened on this device How these events connect Someone investigates and responds What happened, and proof of it Ongoing operations What we should do and why
Needs your people Yes Yes Minimal Yes, and tuning Minimal No
Typical buyer Any size with IT capability Mid-market and enterprise Mid-market without a security team Regulated or large Mid-market to enterprise Mid-market without a CISO

Choosing

The two questions that decide

Most security shortlists compare products that are not alternatives to each other. These two questions sort that out before anyone quotes.

Do you have somebody watching, out of hours?

If not, buying better tooling changes very little. An alert nobody reads until Monday has not prevented anything. This question is what separates EDR, XDR and SIEM, which are products you operate, from MDR and SOC as a service, which include people.

Tooling or people

Do you know what you should be doing?

If security decisions currently have no owner, or the board is asking questions nobody can answer, the gap is leadership rather than technology. A vCISO engagement usually costs less than the tooling being considered and frequently establishes that half of it is unnecessary.

Decisions or tools

How we help

Sorting the shortlist before anybody quotes

We are vendor funded, so the service costs your business nothing.

01

Establish what you already own

Microsoft 365 E3 and E5 include a substantial amount of this, and much of it is switched off. We audit entitlements before recommending a purchase, and it regularly removes a line from the shortlist.

02

Separate the tooling question from the people question

These get bundled into one requirement and quoted as one number. They are different decisions with different costs and they are worth taking separately.

03

Match the service to the actual gap

Out of hours coverage, compliance evidence, alert fatigue and no owner are four different problems with four different answers. Naming the gap first shortens everything after it.

04

Compare providers on response, not features

For anything with people in it, the question is what happens when something is found. Who acts, under what authority, how fast, and what they are permitted to do without ringing you first.

05

Negotiate and stay involved

We hold the vendor relationships, so pricing, scope and the response terms are negotiated by somebody who reads these contracts regularly.

Common questions

Questions about security services

What Australian organisations ask us

What is EDR?

Endpoint detection and response. Software on laptops and servers that records behaviour rather than matching known malware signatures, so it can detect the pattern of an attack and let somebody investigate and contain it. It is a product, and it assumes somebody is reading the alerts it produces.

What is MDR, and how is it different from EDR?

Managed detection and response is a service. A provider runs the detection tooling and staffs a team that investigates alerts around the clock and responds on your behalf. EDR is the tool, MDR is the tool plus the people. Organisations that own EDR and still get breached are usually missing the second half.

What is XDR, and do we need it over EDR?

Extended detection and response widens EDR beyond the endpoint to include identity, email, cloud and network signals, correlated so related events appear as one incident. It reduces noise and shortens investigation. It is still a product, so if nobody is watching your current alerts, XDR will not fix that.

Do we need SIEM or MDR?

SIEM gives you log collection, correlation and retention, which several compliance regimes require, and it needs people to tune and watch it. MDR gives you people watching. If the driver is a compliance obligation to retain and produce logs, that points to SIEM. If the driver is that nobody is watching, that is MDR. Buying SIEM to solve an MDR problem is common and expensive.

What is the difference between MDR and an MSSP?

MDR is a specific service, detection and response with people attached. MSSP is a category of provider that might run firewalls, email security, patching, monitoring or all of it. Because MSSP is so broad, compare the contracted scope rather than the label.

What is a vCISO?

A virtual chief information security officer. Senior security leadership on a part time basis: strategy, risk decisions, board reporting, choosing a framework and overseeing vendors. It is usually what a mid-market organisation needs before it needs more tooling, and it commonly costs less than the products under consideration.

We are vendor funded and completely free to your business. Always focused on the right outcome.

Find out which of these you actually need.

Most security shortlists we review compare products that are not alternatives, and include at least one thing the business already owns. Answer six questions and we will sort it before anybody quotes you.

Book a Call

Independent guidance at no cost to your business.

Read further on this

The pages and articles that answer the next question a buyer usually asks.