MSP Security Operations: Build, Buy, or Partner
Last updated
The decision arrives around 500 endpoints
Below a few hundred endpoints, security operations means an EDR agent and whoever is awake when it fires. Past roughly 500 endpoints that stops working: alert volume outgrows the on-call tech, a compliance-driven client asks who is watching at 3 a.m., and a cyber insurance questionnaire asks for "24/7-monitored EDR" and does not accept "we get push notifications." At that point you are choosing how to source a security operation. The choice is build, buy, or partner, and for almost every MSP under a few thousand endpoints the answer is one of the last two.
Three layers, not three products
- EDR is the sensor. An agent on every endpoint and server that records telemetry, flags suspicious behavior, and can isolate the host. It generates alerts; it does not investigate them.
- A SOC is the people and process. Analysts on shift, a triage workflow, detection content someone maintains, runbooks for what happens when a detection fires, and an escalation path to whoever can act. A sensor without a SOC is a smoke detector in an empty building.
- MDR is the packaged service. Sensor plus SOC sold as one subscription, priced per endpoint, with a defined response – anywhere from "we will call you" to "we will isolate the host and disable the account, then call you."
Buying MDR buys the SOC layer and usually the sensor. Building means hiring the SOC layer and licensing the sensor and a SIEM. The sensor is commoditized; the people are the cost.
The 24/7 staffing math
A year has 8,760 hours. One analyst delivers roughly 1,800 after PTO, sick leave, and training, so covering a single chair around the clock takes about five people. A real SOC needs at least two on shift – one to triage, one to investigate and contain – which means nine or ten analysts. Add a lead who tunes detections and owns the SIEM, and you are at 10–12 people. At typical US loaded costs of $90K–130K each, that is $1M–1.5M per year, plus SIEM licensing and log storage that commonly add $50K–150K.
Spread $1.2M across endpoints at a $10/endpoint/month contribution and you need about 10,000 endpoints just to cover cost. An in-house SOC does not pencil below several thousand endpoints.
Option one: resell white-labeled MDR
You license an MDR platform, deploy its agent through your RMM, and the vendor's SOC watches every tenant. Alerts land in your PSA; the SOC contains autonomously or calls you, depending on the authority you grant. Typical wholesale cost as of 2026 is $3–6 per endpoint per month for managed EDR with a SOC behind it, and $8–15 for active-response MDR that isolates hosts and disables identities on its own. This is the default for MSPs from 200 to a few thousand endpoints, and the security stack article covers how it fits with the rest of the baseline.
Option two: partner with an MSSP
An MSSP is a security-only provider that takes on log ingestion, SIEM, threat hunting, and often compliance reporting. You bring the client relationship and endpoint management; they bring analysts and tooling. Typical cost runs $10–25 per endpoint per month, more with firewall, identity, and cloud logs. It suits MSPs whose regulated clients need SIEM retention and audit evidence that packaged MDR does not produce. The risk is the three-party relationship: when something is missed, each vendor points at the other. Settle that in the contract.
Option three: build
Justified only past several thousand endpoints, with many regulated clients, and when you intend to sell security operations beyond your own base. Even then, most start hybrid: a daytime in-house team, with a partner covering nights and weekends. If you cannot fund eight analysts for two years while the SOC loses money, do not build.
Cost, price, and margin
Price it per endpoint and never pass it through at cost. Typical resale as of 2026 is $8–25 per endpoint per month as a line item, or folded into a security tier of $25–50 per seat. Against $3–5 wholesale, managed EDR with SOC yields 60–75% gross margin on the line; active-response MDR at $10–15 wholesale resold at $20–25 yields 40–50%. Include your own triage labor – commonly 10–20 minutes per escalated alert – in COGS, or the margin is fiction.
What you still own when you buy
Buying a SOC does not outsource responsibility; it outsources the night shift. You still own:
- The triage handoff. The SOC escalates; someone at your shop must acknowledge within the SLA you promised the client, decide whether the detection is real, and act. Define who that is at 2 a.m. on a holiday.
- Client communication. The SOC will never call your client. You explain what happened, what was contained, and what it means.
- Containment authority. You decide, in writing, whether the SOC may isolate hosts and disable accounts without asking. Declining means a 3 a.m. phone call that may go unanswered while ransomware spreads. Pre-authorize isolation and accept the rare false positive.
- Incident response. Detection and containment are the first hour. Eradication, recovery, forensics, legal notification, and the insurance claim are yours to run – see the incident response process. The MDR contract ends at containment; the crisis does not.
How to evaluate a provider
- Detection coverage. Endpoints only, or identity, email, and cloud too? An MDR that cannot see Microsoft 365 sign-ins is watching half the field.
- Response authority. Can they actually isolate and disable, or only notify? Is it configurable per client?
- SLA on time-to-acknowledge. Ask for the contractual number on a critical alert – 15 minutes is typical – and the median actual, not the marketing figure.
- Integration with your RMM and PSA. Alerts must arrive as tickets with the client mapped correctly, and deployment must ride your existing agent push. A portal you have to remember to check is where alerts die.
- Evidence and escalation. Can they produce the reports insurers ask for, and who do you call when their SOC is wrong?
Contract questions
Before signing: what is in scope per endpoint – servers, VMs, mobile? What is the minimum commitment and true-up cadence? Can you add and remove clients monthly, or are you locked to a seat count? Who owns the telemetry, and how long is it retained? Is there a data export on termination? What is their liability cap if they miss a critical detection, and does their errors-and-omissions coverage extend to your clients? Do they hold a SOC 2 Type II report you can show your own clients? Are you permitted to white-label, and does your client contract name them as a subprocessor?
Bottom line
EDR is the sensor, the SOC is the people, MDR is the two packaged together. Below several thousand endpoints the staffing math makes building a SOC a money pit, so buy: white-labeled MDR for most MSPs, an MSSP where clients need SIEM retention and audit evidence. Price it at $8–25 per endpoint, keep 50%+ margin, and remember what remains yours: the handoff, the client call, the containment decision, and everything after the first hour.