- A SOC is the function: the people, process, and tooling that watch for threats and respond to them. MDR is a service model that delivers that function without an internal team.
- Covering a single 24/7 SOC seat internally needs five to six analysts once holiday, sick leave, and shift rotation are accounted for, not one person on a rota.
- UK MDR pricing for mid-market businesses typically runs £8–20 per user per month, well below the cost of a single internal SOC analyst before any tooling is added.
- Detection and response speed matters more than the feature list: ask a provider for their mean time to detect and respond, and what they can do without waiting for your sign-off.
- MDR replaces threat monitoring and response. It does not replace patching, helpdesk support, or general IT management, most businesses still need both.
What a SOC actually does
A Security Operations Centre (SOC) is the function inside an organisation responsible for continuously watching for security threats and responding when one appears. It is not a room, a product, or a single tool, though large enterprises often build a physical one. It is the combination of people, documented process, and technology working together around the clock.
A working SOC does four things on a continuous loop. It collects logs and telemetry from endpoints, network devices, cloud platforms, and applications, usually through a Security Information and Event Management (SIEM) platform. It correlates that data to surface anomalies. It triages the alerts that correlation produces, separating genuine threats from noise. And it investigates and responds to the ones that turn out to be real, from an isolated infected laptop through to an active intrusion.
Building this in-house has traditionally meant hiring analysts, licensing a SIEM, and running shifts to cover nights and weekends. That is a substantial commitment, which is why most organisations below enterprise scale never had a SOC at all until managed alternatives made the function available as a service.
What MDR is, and how it differs from a SOC
Managed Detection and Response (MDR) is a vendor-delivered service that provides the SOC function using the provider's own analysts and tooling rather than yours. Most MDR services are built around an Endpoint Detection and Response (EDR) agent installed on your devices, sometimes extended to cloud and identity signals as Extended Detection and Response (XDR). The provider's analysts watch what that tooling surfaces, twenty-four hours a day, and act on it.
The distinction that matters is response, not monitoring. Plenty of services describe themselves as MDR while only alerting: an analyst sees something suspicious and emails your IT team a ticket. True MDR includes agreed authority to act without waiting for that email to be read, isolating a compromised device from the network, killing a malicious process, or disabling a compromised account, within minutes rather than hours.
Before signing anything, ask the provider to describe exactly what they can do on your network without contacting you first, and what requires your sign-off. A service that always waits for approval before acting is monitoring with a support line, not MDR. The value of MDR is contained in the minutes it saves at 3am when nobody is awake to approve anything.
SOC vs MDR vs MSSP vs SIEM
These four terms get used loosely and interchangeably, which makes vendor comparisons harder than it needs to be. They describe different layers of the same problem.
Why most businesses can't build their own 24/7 SOC
The arithmetic of round-the-clock coverage defeats most in-house plans before the tooling budget is even discussed. A single seat covered continuously requires more than one person on a rota. Once you account for annual leave, sick leave, weekends, and the fact that nobody can safely work every night shift indefinitely, a genuinely resilient 24/7/365 seat needs five to six analysts, not one.
In the UK, an entry-level SOC analyst typically earns £28,000–38,000. A Tier 2 analyst capable of real investigation, not just alert acknowledgement, runs £40,000–55,000. A Tier 3 or lead analyst who can handle genuine incidents sits at £60,000–80,000 or higher. Multiply even the lower end of that range across the headcount needed for continuous coverage and the salary bill alone passes six figures before a single tool is licensed.
Tooling adds further cost on top of headcount. SIEM licensing is typically priced by data volume ingested, and costs scale with the size of your environment rather than staying fixed. EDR licensing is priced per endpoint. Threat intelligence feeds, case management software, and on-call escalation tooling add more. None of this is optional if the SOC is meant to function rather than exist on paper.
Against that backdrop, MDR pricing for mid-market UK businesses typically runs £8–20 per user per month depending on scope and response commitments, sometimes higher where a strict SLA or regulated-sector coverage is required. For most businesses below several hundred staff, that is the difference between a service that is affordable and a function that never gets built at all.
What a good MDR service actually includes
Pricing pages make MDR services look interchangeable. In practice, the difference between a strong provider and a weak one shows up in six areas.
Genuine 24/7/365 coverage. Not "monitored during business hours with an on-call escalation," but analysts actively watching alerts around the clock, including bank holidays.
A managed EDR or XDR agent. The provider deploys, tunes, and maintains the detection technology itself, rather than expecting your IT team to keep an agent healthy across every device.
Threat hunting, not just alert response. The strongest providers proactively look for signs of compromise that automated rules miss, rather than waiting for a tool to fire an alert.
Pre-agreed containment authority. A documented, signed-off list of actions the provider can take without contacting you first: isolating a host, disabling an account, blocking a malicious domain.
Reporting with context. A monthly report that explains what was investigated and why it mattered, not a page of alert counts with no narrative.
A defined handoff to remediation. MDR detects and contains. Rebuilding a compromised machine, resetting the environment, and fixing the underlying gap that let the incident happen is typically your IT team or MSP's job. Know where that line sits before you need it.
The metrics that separate good MDR from a dashboard
Two numbers matter more than any feature list: mean time to detect (MTTD) and mean time to respond (MTTR). MTTD measures how long a threat sits undetected in your environment. MTTR measures how long it takes to contain it once found. Ask any provider for both figures, in writing, and be wary of one that cannot produce them.
These numbers are not academic. Research such as IBM's annual Cost of a Data Breach Report has consistently found that breaches which take longer to identify and contain cost organisations substantially more, with average identification-and-containment timelines across recent years typically exceeding 200 days for businesses without effective detection in place. (IBM Cost of a Data Breach Report) A provider whose MTTR is measured in minutes rather than hours is not a marketing detail, it is the entire point of paying for MDR instead of relying on log review after the fact.
The question is not whether you need monitoring. Every business already generates the logs. The question is whether anyone is watching them at 3am, and what they are allowed to do if something is wrong.
How to evaluate an MDR provider
Once shortlisted providers all claim 24/7 coverage and rapid response, these questions separate the ones that deliver from the ones that describe.
What can you do without asking me first? Get the containment authority in writing before signing. A vague answer here is the single biggest red flag in an MDR evaluation.
What percentage of alerts get human review? A provider relying almost entirely on automated triage with minimal human oversight is closer to a monitored tool than a managed service.
Where is the SOC, and how many analysts are on shift overnight? Ask directly rather than accepting a marketing claim. A skeleton overnight team changes what "24/7" actually means in practice.
Can it ingest what you already run? If you already have an EDR agent, cloud logging, or identity provider in place, confirm the provider can work with it rather than forcing a full replacement.
What happens after containment? Confirm who does the remediation and rebuild work once a threat is contained, and make sure that party is named and available before an incident, not decided during one.