Buyer Guide · 2026

What cybersecurity should your MSP actually include?

EDR, MDR, SIEM, SOC — what is table stakes versus a premium add-on, how to read an MSP’s security stack, and how to spot what is missing before a breach finds it for you.

Quick answer

At minimum, your MSP should include MFA, EDR, email security, patching, and backups as table stakes. The capabilities that actually stop breaches — 24/7 MDR, a SIEM, and a staffed SOC — are usually premium add-ons, so confirm what is included before you assume you are covered.

Start here

Your MSP is now your security team

For most small and mid-sized businesses, the managed service provider that runs IT is also, by default, the security team. That makes the depth of an MSP’s security offering one of the most consequential things to evaluate — and one of the easiest to get wrong, because security capabilities hide behind a wall of acronyms and tier names that are easy to nod along to and hard to actually compare.

The stakes are not abstract. SMBs are now the most-targeted segment precisely because attackers assume their defenses are thinner, and cyber-insurance underwriters have responded by requiring specific controls — multi-factor authentication, endpoint detection and response, and managed monitoring — as a condition of coverage. If your MSP’s plan quietly omits those, you can be both uninsurable and exposed without realizing it.

This guide is a buyer’s decoder. It defines the core acronyms, separates what every competent MSP should include as table stakes from what is a legitimate premium add-on, and gives you a way to read a security stack and spot the gaps before an incident does. For how these same controls map onto regulatory frameworks, pair it with our MSP compliance guide.

The trap that catches everyone

Managed IT is not the same as managed security. A plan can keep your systems running smoothly — patched, backed up, supported — while leaving you wide open, because real security operations (detection, monitoring, and response) are a separate, often unbundled layer. Always ask what security is included versus what is sold separately.

Plain English

The security acronyms, decoded

You cannot evaluate what you cannot parse. These are the terms that appear on almost every MSP security proposal, in plain language — learn this table and the rest of the conversation gets much easier.

TermWhat it stands forWhat it actually does
EDREndpoint Detection & ResponseDetects and contains threats on laptops and servers that antivirus misses, and records activity for investigation
MDRManaged Detection & ResponseEDR plus a human team that monitors, investigates, and responds to alerts 24/7 so detection leads to action
SIEMSecurity Information & Event ManagementCollects and correlates logs from across your environment to surface suspicious patterns and keep an audit trail
SOCSecurity Operations CenterThe staffed, round-the-clock team that watches the tools, triages alerts, and runs incident response
XDRExtended Detection & ResponseDetection that extends beyond the endpoint to email, identity, and cloud, correlating signals across them
MFAMulti-Factor AuthenticationA second login factor that blocks the large majority of account-takeover attacks
ZTNA / SASEZero-Trust Network Access / Secure Access Service EdgeIdentity-based access that replaces legacy VPNs and secures a distributed workforce
SOARSecurity Orchestration, Automation & ResponseAutomated playbooks that speed up and standardize parts of incident response

The single most important relationship in that table is between EDR, MDR, and the SOC, because it is where buyers most often think they have bought protection when they have only bought a tool. We unpack it in detail below.

Defense in depth

The layers a modern stack has to cover

No single product is “security.” Real protection is layered, so that if one control fails another still stands. A complete MSP security stack covers six layers — use these as the headings you check a proposal against.

1

Identity

MFA on every account, conditional access, and tight control of admin privileges. Identity is the most attacked layer, so it is the most important to lock down.

2

Endpoint

EDR on every laptop and server, plus patching and device hardening. This is where most attacks try to land and execute.

3

Email & web

Advanced email security beyond a basic spam filter — phishing, impersonation, and link protection — because email is the number-one entry point.

4

Network

Firewall management, segmentation, and modern remote access (ZTNA) rather than a flat network anyone inside can move across freely.

5

Detection & response

The monitoring layer — MDR, a SIEM, and a SOC — that turns alerts into action around the clock. This is the layer most often missing.

6

Recovery & people

Tested, isolated backups and a written incident-response plan, plus security awareness training — because your staff are both the top target and the last line.

The dividing line

Table stakes vs premium add-on

Not everything can or should be in a base plan — but some things are non-negotiable, and an MSP that treats them as upsells is shifting risk onto you. Here is where each capability typically sits in 2026, and what an honest provider includes by default.

CapabilityWhere it usually sitsWhat it delivers
Managed patching & updatesTable stakesBaseline hygiene; closing known vulnerabilities
MFA enforcementTable stakesBlocks most account takeover; treating it as an add-on is a red flag
EDR on endpointsTable stakes in 2026Now expected and required by most cyber insurers
Email security (basic)Table stakesSpam and basic phishing filtering on every mailbox
Tested backup & recoveryTable stakesIsolated backups you can actually restore from
Advanced email / phishing defenseStandard add-onImpersonation, link rewriting, and attachment sandboxing
Security awareness trainingStandard add-onPhishing simulations and recurring staff training
24/7 MDR + SOCPremium add-onA human team operating detection and response around the clock
SIEM & log retentionPremium add-onCentralized logging and correlation; often required for compliance
vCISO / security strategyPremium add-onRoadmap, policy, and risk ownership at a leadership level

The honest summary: patching, MFA, EDR, basic email security, and tested backups should be in any credible 2026 plan. The advanced detection-and-response layer — MDR, SIEM, and a SOC — is a legitimate premium because it requires a staffed team, but it is also the layer that most determines whether an attack becomes an incident or a catastrophe. Pay for it deliberately; do not assume it is already there.

The crucial distinction

EDR vs MDR vs SOC: tool, service, and team

This is the distinction that costs businesses the most when they get it wrong. The three sound interchangeable in a sales conversation, but they are not — one is a tool, one is a service, and one is the team behind it. Buying the tool without the team is the most common and most dangerous security gap.

LayerWhat it isTool or serviceWithout it…
EDRSoftware that detects and contains threats on endpointsA toolAlerts may fire with no one assigned to act on them
MDRA managed team operating that EDR for you, 24/7A serviceYou own detection tooling but have no responder behind it
SIEMCentralized log collection and correlationA platformNo audit trail and blindness to attacks that cross systems
SOCThe staffed 24/7 team watching it allA team / serviceDetection happens, but no human triages or responds in time

The way to remember it: EDR is a smoke detector, MDR is the monitoring service that calls the fire department, and the SOC is the firefighters. A smoke detector nobody is listening to does not save the building. If your MSP sells you EDR but no managed response, you have detection without anyone watching — which is exactly the gap attackers exploit at nights and weekends, when in-house teams are offline.

The question that cuts through it

Ask one thing: “When EDR raises an alert at 2 a.m. on a Saturday, who sees it, and what do they do?” If the answer is “we review it the next business day,” you have EDR without MDR — a tool without a team. That gap is where ransomware does its work.

Evaluate it

How to read an MSP’s security stack

You do not need to be a security engineer to evaluate a proposal. You need to map what is offered onto the layers above and find the holes. Work through a security stack in this order.

  • Get the stack in writing. Ask for the security inclusions itemized by layer — identity, endpoint, email, network, detection/response, recovery. A provider that cannot or will not produce this is the first red flag.
  • Check identity first. Confirm MFA is enforced on every account and admin access is controlled. If MFA is optional or an add-on, stop — nothing else matters as much.
  • Separate tools from services. For each detection capability, ask whether a human operates it 24/7. EDR without MDR, or a SIEM with no SOC, is a tool with no team.
  • Find the monitoring gap. Establish who watches alerts outside business hours and how fast they respond. Most breaches exploit nights, weekends, and holidays.
  • Confirm recovery is tested. Backups only count if restores are tested and the backups are isolated from the network that ransomware would encrypt.
  • Match it to your risk. A compliance-bound or high-value target needs the full detection-and-response layer; a low-risk shop may reasonably defer some premium pieces — but should do so knowingly.

Spot it early

The gaps that cause breaches

When an SMB is breached through its MSP-managed environment, the cause is rarely exotic. It is almost always one of a short list of missing or half-implemented basics. These are the gaps to hunt for before an attacker finds them.

The most common hole is detection without response — EDR deployed but no MDR or SOC behind it, so an alert at 2 a.m. waits until Monday. Close behind is incomplete MFA, where multi-factor is enabled for some users or some apps but not enforced everywhere, leaving a side door open. Then comes email security that stops at spam filtering, missing the targeted phishing and impersonation that actually breach businesses.

The rest of the list is just as mundane and just as dangerous: no log retention or SIEM, so an intrusion cannot be detected across systems or investigated afterward; backups that are never test-restored or are reachable from the production network, making them useless against ransomware; no written incident-response plan, so the first hour of a breach is improvised; and no security awareness training, leaving staff as an unguarded entry point. Run your provider’s stack against this list and the gaps usually surface quickly.

Why gaps hide

These holes persist because everything looks fine until it is not. Systems run, tickets close, and the missing detection-and-response layer is invisible right up until the night an attacker walks through it. The only way to find the gap in advance is to audit the stack deliberately — which is the entire point of the questions below.

The investment

What managed security costs

Security depth is the biggest variable in an MSP bill, because the detection-and-response layer requires a staffed team. These are typical 2026 ranges for the security pieces that usually sit on top of, or inside the upper tiers of, a managed IT plan — ranges, not quotes.

Security serviceTypical 2026 rangeNotes
Managed security / MDR + SOC$10–$60 / user / mo24/7 detection and response; the core security upsell
Security awareness training$2–$10 / user / moPhishing simulations plus recurring staff training
vCISO / security advisory$1,500–$5,000 / moStrategy, policy, and risk ownership; sometimes bundled
Compliance-focused managed IT$250–$300 / user / moWhen deep security combines with regulatory documentation
Standard fully managed IT$75–$200 / user / moBaseline plan; how much security is built in varies by tier

The practical takeaway is that adding a real MDR and SOC layer typically costs $10 to $60 per user per month on top of a base plan — a meaningful but rarely decisive amount against the cost of a single ransomware event. The mistake is not paying for security; it is assuming the base plan already includes the response layer when it does not. For how the full set of MSP pricing models fit together, see our MSP pricing guide.

Before you sign

Questions to ask your MSP

Bring these to any current or prospective provider. The answers, more than any brochure, tell you whether your security is real or just looks the part.

  • Is MFA enforced on every account, including admins? The answer should be an unqualified yes, with no exceptions and no extra charge.
  • When EDR alerts at 2 a.m., who responds and how fast? This separates real managed response (MDR + SOC) from detection tooling no one is watching.
  • Is the SOC staffed 24/7, and is it yours or a third party’s? Either can be fine, but you should know who is actually watching and when.
  • How long are logs retained, and can you investigate after the fact? No retention means no forensics and a likely compliance gap.
  • Are backups isolated and test-restored, and how often? Untested or network-reachable backups fail exactly when you need them.
  • Is there a written incident-response plan, and have you exercised it? The first hour of a breach should follow a plan, not improvisation.
  • What is included versus billed separately? Get the line between table stakes and add-on in writing, so there are no assumptions.

For the broader vendor-evaluation process — references, track record, and overall fit beyond the security stack — pair these with our guide on how to choose an MSP and the six-factor Trust Score methodology behind every provider we rank.

Watch out

Security red flags

A few answers should stop a deal, or at least prompt hard questions. Each of these patterns signals a security posture thinner than it appears.

  • “Antivirus” sold as security. Traditional antivirus is not EDR and is not detection-and-response. A provider conflating the two is behind the times.
  • MFA treated as an upgrade. If multi-factor authentication is optional or costs extra, the provider does not take the most basic control seriously.
  • EDR with no managed response. Detection tooling with no 24/7 SOC behind it is a smoke detector no one is listening to.
  • No log retention or SIEM. Without retained logs you cannot detect cross-system attacks or investigate a breach — and you likely fail compliance.
  • Won’t share the stack in writing. A provider that cannot itemize its security inclusions by layer either does not know or does not want you to.
  • No incident-response plan. If there is no written plan for the first hours of a breach, the response will be improvised when it matters most.

Questions

MSP cybersecurity FAQs

At a minimum, a credible 2026 managed IT plan should include enforced multi-factor authentication (MFA), endpoint detection and response (EDR) on every device, basic email security, managed patching, and tested, isolated backups. These are table stakes, and cyber-insurance underwriters increasingly require several of them.

The deeper detection-and-response layer — 24/7 MDR, a SIEM, and a staffed SOC — is a legitimate premium add-on rather than a baseline inclusion, but it is also the layer that most determines whether an attack becomes a minor event or a major breach. Confirm exactly what is included before assuming you are protected.

EDR (endpoint detection and response) is a tool that detects and contains threats on laptops and servers. MDR (managed detection and response) is that tool plus a human team operating it 24/7, so alerts actually get investigated and acted on. A SOC (security operations center) is the staffed, round-the-clock team itself.

The simplest analogy: EDR is a smoke detector, MDR is the monitoring service that calls for help, and the SOC is the firefighters. Buying EDR without MDR leaves you with a smoke detector nobody is listening to — which is the most common and most dangerous security gap.

Traditional antivirus is no longer enough on its own. It matches known threats but misses the fileless, identity-based, and novel attacks that dominate in 2026. EDR adds behavioral detection and the ability to contain a threat and investigate it, which is why insurers now expect it.

EDR still needs someone watching it, though. MDR adds the 24/7 human team that turns an alert into a response. For most businesses, the realistic target is EDR as a baseline with MDR for round-the-clock coverage, not antivirus alone.

MDR, or managed detection and response, is a service in which a provider’s security team operates your detection tooling around the clock — monitoring alerts, investigating them, and responding to contain threats, typically through a 24/7 SOC. It is the difference between owning detection software and having someone actually watch it.

Most businesses do need it, because the alternative is detection that goes unwatched outside business hours, which is exactly when many attacks unfold. If your team cannot credibly monitor and respond 24/7 in-house, MDR is usually the highest-value security layer you can add. It typically costs $10 to $60 per user per month.

A managed security layer with MDR and a 24/7 SOC typically runs $10 to $60 per user per month on top of a base managed IT plan. Security awareness training adds roughly $2 to $10 per user per month, and a vCISO or security advisory layer about $1,500 to $5,000 per month.

For context, standard fully managed IT runs $75 to $200 per user per month, and compliance-focused plans reach $250 to $300. The added cost of real detection and response is modest against the cost of a single ransomware event. See the MSP pricing guide for the full breakdown.

Ask your provider for its security inclusions itemized by layer — identity, endpoint, email, network, detection and response, and recovery — then look for holes. Confirm MFA is enforced everywhere, that a human responds to EDR alerts 24/7, that logs are retained, and that backups are isolated and test-restored.

The sharpest single test is to ask who responds when EDR alerts at 2 a.m. on a weekend. If the answer is “the next business day,” you have detection without response — the gap most breaches exploit. A provider that cannot give clear answers, or will not put the stack in writing, is itself a warning sign.

Managed IT keeps your technology running — support, patching, backups, and administration. Managed security is the separate layer focused on protecting that environment from attack: detection, monitoring, and response through tools like EDR and services like MDR and a SOC.

The two often come from the same provider, but they are not automatically bundled. A plan can keep your systems healthy while leaving the security-operations layer thin or absent, which is why you should always ask what security is included rather than assuming managed IT covers it.

The common warning signs are EDR with no managed 24/7 response behind it, MFA that is enabled for some users but not enforced everywhere, email security that stops at spam filtering, no log retention or SIEM, backups that are never test-restored, and no written incident-response plan. Selling traditional antivirus as if it were modern security is another.

These gaps are dangerous precisely because everything looks fine until an incident exposes them. Auditing the stack deliberately against the layers and questions in this guide is the only reliable way to find them in advance — and for regulated businesses, our compliance guide shows how the same controls map to audit requirements.

Find a security-serious MSP

Compare providers on what protects you.

Browse independently scored MSPs across dozens of US cities and 20 industry verticals, including providers with real detection-and-response depth. Every provider is measured against the same six-factor Trust Score — no paid placements.