Guide Cybersecurity

SOC vs MDR: what they are, and which one your business needs

Vendors use "SOC" and "MDR" almost interchangeably in their marketing, but they describe different things. A SOC is a function. MDR is one way of buying that function without building it yourself. This guide covers what each actually does, what round-the-clock monitoring costs to build in-house versus outsource, and how to tell a good MDR provider from a dashboard with a support line attached.

20 September 2026
10 min read
Key takeaways
  • A SOC is the function: the people, process, and tooling that watch for threats and respond to them. MDR is a service model that delivers that function without an internal team.
  • Covering a single 24/7 SOC seat internally needs five to six analysts once holiday, sick leave, and shift rotation are accounted for, not one person on a rota.
  • UK MDR pricing for mid-market businesses typically runs £8–20 per user per month, well below the cost of a single internal SOC analyst before any tooling is added.
  • Detection and response speed matters more than the feature list: ask a provider for their mean time to detect and respond, and what they can do without waiting for your sign-off.
  • MDR replaces threat monitoring and response. It does not replace patching, helpdesk support, or general IT management, most businesses still need both.

What a SOC actually does

A Security Operations Centre (SOC) is the function inside an organisation responsible for continuously watching for security threats and responding when one appears. It is not a room, a product, or a single tool, though large enterprises often build a physical one. It is the combination of people, documented process, and technology working together around the clock.

A working SOC does four things on a continuous loop. It collects logs and telemetry from endpoints, network devices, cloud platforms, and applications, usually through a Security Information and Event Management (SIEM) platform. It correlates that data to surface anomalies. It triages the alerts that correlation produces, separating genuine threats from noise. And it investigates and responds to the ones that turn out to be real, from an isolated infected laptop through to an active intrusion.

Building this in-house has traditionally meant hiring analysts, licensing a SIEM, and running shifts to cover nights and weekends. That is a substantial commitment, which is why most organisations below enterprise scale never had a SOC at all until managed alternatives made the function available as a service.

What MDR is, and how it differs from a SOC

Managed Detection and Response (MDR) is a vendor-delivered service that provides the SOC function using the provider's own analysts and tooling rather than yours. Most MDR services are built around an Endpoint Detection and Response (EDR) agent installed on your devices, sometimes extended to cloud and identity signals as Extended Detection and Response (XDR). The provider's analysts watch what that tooling surfaces, twenty-four hours a day, and act on it.

The distinction that matters is response, not monitoring. Plenty of services describe themselves as MDR while only alerting: an analyst sees something suspicious and emails your IT team a ticket. True MDR includes agreed authority to act without waiting for that email to be read, isolating a compromised device from the network, killing a malicious process, or disabling a compromised account, within minutes rather than hours.

Check what "response" actually means

Before signing anything, ask the provider to describe exactly what they can do on your network without contacting you first, and what requires your sign-off. A service that always waits for approval before acting is monitoring with a support line, not MDR. The value of MDR is contained in the minutes it saves at 3am when nobody is awake to approve anything.

SOC vs MDR vs MSSP vs SIEM

These four terms get used loosely and interchangeably, which makes vendor comparisons harder than it needs to be. They describe different layers of the same problem.

1
SIEM
The tooling. A platform that collects and correlates logs from across your environment. It is software, not a service, and produces alerts that still need a human to review them.
2
SOC
The function. The people and process that watch what the SIEM (or other tooling) surfaces and decide what to do about it, whether built in-house or delivered by a provider.
3
MSSP
Managed Security Service Provider. A broad umbrella term for any outsourced security service, from firewall management to log forwarding. Historically weighted toward alerting rather than active response.
4
MDR
A specific type of managed service built on EDR or XDR technology, combining continuous detection with agreed, active human-led response. The narrowest and most response-focused of the four terms.

Why most businesses can't build their own 24/7 SOC

The arithmetic of round-the-clock coverage defeats most in-house plans before the tooling budget is even discussed. A single seat covered continuously requires more than one person on a rota. Once you account for annual leave, sick leave, weekends, and the fact that nobody can safely work every night shift indefinitely, a genuinely resilient 24/7/365 seat needs five to six analysts, not one.

In the UK, an entry-level SOC analyst typically earns £28,000–38,000. A Tier 2 analyst capable of real investigation, not just alert acknowledgement, runs £40,000–55,000. A Tier 3 or lead analyst who can handle genuine incidents sits at £60,000–80,000 or higher. Multiply even the lower end of that range across the headcount needed for continuous coverage and the salary bill alone passes six figures before a single tool is licensed.

Tooling adds further cost on top of headcount. SIEM licensing is typically priced by data volume ingested, and costs scale with the size of your environment rather than staying fixed. EDR licensing is priced per endpoint. Threat intelligence feeds, case management software, and on-call escalation tooling add more. None of this is optional if the SOC is meant to function rather than exist on paper.

5–6
analysts typically needed to staff one 24/7/365 SOC seat with genuine leave cover
£8–20
typical UK MDR cost per user per month for mid-market businesses
£80K+
typical minimum salary cost of a single Tier 2 SOC analyst before tooling

Against that backdrop, MDR pricing for mid-market UK businesses typically runs £8–20 per user per month depending on scope and response commitments, sometimes higher where a strict SLA or regulated-sector coverage is required. For most businesses below several hundred staff, that is the difference between a service that is affordable and a function that never gets built at all.

What a good MDR service actually includes

Pricing pages make MDR services look interchangeable. In practice, the difference between a strong provider and a weak one shows up in six areas.

Genuine 24/7/365 coverage. Not "monitored during business hours with an on-call escalation," but analysts actively watching alerts around the clock, including bank holidays.

A managed EDR or XDR agent. The provider deploys, tunes, and maintains the detection technology itself, rather than expecting your IT team to keep an agent healthy across every device.

Threat hunting, not just alert response. The strongest providers proactively look for signs of compromise that automated rules miss, rather than waiting for a tool to fire an alert.

Pre-agreed containment authority. A documented, signed-off list of actions the provider can take without contacting you first: isolating a host, disabling an account, blocking a malicious domain.

Reporting with context. A monthly report that explains what was investigated and why it mattered, not a page of alert counts with no narrative.

A defined handoff to remediation. MDR detects and contains. Rebuilding a compromised machine, resetting the environment, and fixing the underlying gap that let the incident happen is typically your IT team or MSP's job. Know where that line sits before you need it.

The metrics that separate good MDR from a dashboard

Two numbers matter more than any feature list: mean time to detect (MTTD) and mean time to respond (MTTR). MTTD measures how long a threat sits undetected in your environment. MTTR measures how long it takes to contain it once found. Ask any provider for both figures, in writing, and be wary of one that cannot produce them.

These numbers are not academic. Research such as IBM's annual Cost of a Data Breach Report has consistently found that breaches which take longer to identify and contain cost organisations substantially more, with average identification-and-containment timelines across recent years typically exceeding 200 days for businesses without effective detection in place. (IBM Cost of a Data Breach Report) A provider whose MTTR is measured in minutes rather than hours is not a marketing detail, it is the entire point of paying for MDR instead of relying on log review after the fact.

The question is not whether you need monitoring. Every business already generates the logs. The question is whether anyone is watching them at 3am, and what they are allowed to do if something is wrong.

How to evaluate an MDR provider

Once shortlisted providers all claim 24/7 coverage and rapid response, these questions separate the ones that deliver from the ones that describe.

What can you do without asking me first? Get the containment authority in writing before signing. A vague answer here is the single biggest red flag in an MDR evaluation.

What percentage of alerts get human review? A provider relying almost entirely on automated triage with minimal human oversight is closer to a monitored tool than a managed service.

Where is the SOC, and how many analysts are on shift overnight? Ask directly rather than accepting a marketing claim. A skeleton overnight team changes what "24/7" actually means in practice.

Can it ingest what you already run? If you already have an EDR agent, cloud logging, or identity provider in place, confirm the provider can work with it rather than forcing a full replacement.

What happens after containment? Confirm who does the remediation and rebuild work once a threat is contained, and make sure that party is named and available before an incident, not decided during one.

Frequently asked questions

Is MDR the same as antivirus or EDR?

No. EDR (Endpoint Detection and Response) is the technology installed on your devices that generates detection data. MDR is the managed service built around that technology, the analysts who watch what it surfaces and act on it. You can run EDR without MDR, but then someone on your own team has to review its alerts, including overnight. MDR exists to remove that burden.

How much does MDR cost for a small business?

UK mid-market pricing typically runs £8–20 per user per month, though scope, response commitments, and regulated-sector requirements can push this higher. Get quotes based on your actual user and device count rather than a generic per-seat estimate, and confirm whether the EDR agent licence is included in that price or billed separately.

Can our existing IT provider or MSP add MDR on top of what they already do?

Some can, often by partnering with or reselling a specialist MDR platform rather than running the SOC themselves. That can work well, but ask specifically who is actually watching alerts at 3am and what authority they have to act, rather than assuming your MSP's helpdesk doubles as a security operations team. The two functions require different skills and different staffing models.

Do we still need our own IT team if we have MDR?

Yes. MDR covers detection and response to security threats. It does not cover patching, helpdesk tickets, asset management, or rebuilding a machine after an incident is contained. Most businesses run MDR alongside an in-house IT function or MSP, with a documented handoff for who does what once a threat has been dealt with.

Ryland Deakin
About the author
Lead Consultant, Cyvra · CISM · CompTIA Security+ · MCP

Ryland has delivered cybersecurity, compliance, and IT management programmes for regulated organisations across the UK and the Netherlands for over 20 years, including senior roles at Microsoft, ING, IPsoft, PPHE and more. View full profile

Talk to Cyvra

Work out whether you need a SOC, MDR, or both

We help UK and Netherlands businesses decide between in-house monitoring, MDR, and hybrid models, then design the logging architecture and incident response playbook to back whichever one you choose.

Disclaimer: This article is for general informational purposes only and does not constitute legal, regulatory, or professional advice. Cyvra makes no warranty as to the accuracy or completeness of this content, which may not reflect the most current regulatory developments. Readers should seek independent legal and regulatory advice appropriate to their specific circumstances. Cyvra accepts no liability for any loss arising from reliance on this content.