How to Choose Managed Security Services: The Practitioner's Guide
TL;DR: Choose a Managed Security Services Provider (MSSP) by starting with your compliance driver (SOC 2, HIPAA, CMMC), demanding a written incident response SLA with on-site commitments, scoring vendors against a weighted rubric, and auditing the MSSP's own security posture. Total cost of ownership matters more than the monthly fee.
The average mid-market breach now costs $4.88 million according to IBM's 2024 Cost of a Data Breach Report, and Verizon's 2024 DBIR found that 15% of breaches involved a third party, up from 9% the prior year. Your MSSP is part of that supply chain. Pick wrong and you've imported risk, not transferred it.
Here's the framework I use when clients ask me to sanity-check their MSSP shortlist.
Step 1: Nail Down Your Actual Security Requirement Before You Talk to Anyone
Most buyers start by demoing tools. That's backwards. Start with the trigger.
Are you 90 days out from a SOC 2 Type II audit? Renewing cyber insurance and the broker just asked for proof of 24/7 monitoring? Recovering from a ransomware hit? Closing a Fortune 500 deal that requires you to produce a SIG questionnaire response by Friday? Each trigger leads to a different MSSP profile.
Compliance frameworks set the floor:
- HIPAA Security Rule distinguishes between required and addressable safeguards. Your MSSP needs to know the difference and tune SIEM rules around PHI access patterns, not just generic Windows events.
- SOC 2 Type II under the AICPA 2017 Trust Services Criteria needs continuous control evidence collection over a 3-to-12 month observation window. An MSSP that can't produce monthly control attestations is useless here.
- CMMC 2.0 Level 2 maps to 110 practices from NIST SP 800-171 Rev. 2. If you're a defence contractor handling CUI, your MSSP must know your SPRS score and have run a gap assessment against all 110.
No compliance driver? Then map your attack surface first: endpoints, cloud workloads (AWS, M365), identity (Okta, Entra ID), and email. That dictates the tool stack you'll be paying for.
Also document your required response time. A Thursday-night ransomware hit needs an SLA with on-site response. A Monday-morning phishing alert can tolerate a 4-hour remote triage. Don't pay for what you don't need, but don't underwrite what you can't afford to lose.
Step 2: The MSSP Evaluation Scorecard
I give clients a five-category weighted rubric. Copy it, adjust the weights for your situation, and score every vendor on a 1-to-5 scale.
| Category | Weight | What to score |
|---|---|---|
| Incident Response SLA | 25% | Named response time, on-site clause, escalation tree |
| Compliance depth | 25% | Vertical references, framework-specific evidence workflows |
| Tool stack transparency | 20% | Named SIEM, EDR, identity tools with prices |
| SOC staffing model | 20% | 24/7 tiered analysts, analyst-to-client ratio |
| Contract flexibility | 10% | Exit clauses, auto-renewal, tool portability |
IR SLA
"24/7 monitoring" is marketing. An IR SLA is a contractual response time with consequences if missed. Ask: what's the guaranteed time to first analyst engagement on a P1 alert? Is on-site response included or billed separately? What's the credit if you miss the SLA? "Best efforts" isn't an SLA, it's a disclaimer.
Dwell time is where providers genuinely separate. The industry average sits at 204 days according to Mandiant's M-Trends, and shortening it comes from detections written for your environment rather than the ones that shipped with the platform. Ask how a prospective MSSP tunes rules for your stack, and what they report detection time against each month.
Compliance depth
Ask for a customer reference in your specific vertical. Being told you are compliant means very little without the evidence trail sitting behind the statement, and a readiness assessment is usually the moment that difference becomes visible. Generic compliance claims don't survive contact with an auditor.
Tool stack transparency
Any MSSP that won't name their SIEM, EDR, and identity monitoring tools is hiding margin or hiding a Frankenstein. Benchmarks for 2024:
- CrowdStrike Falcon Insight: ~$15/endpoint/month for EDR with managed threat hunting
- SentinelOne Singularity Complete: ~$6 to $10/endpoint/month depending on tier
- Splunk Cloud: ~$150/GB/day ingestion at list, often negotiable
- Microsoft Sentinel: ~$2.46/GB/day plus Log Analytics costs
If a vendor quotes you a flat per-user fee with no tool breakout, you're paying retail plus a markup you can't see. Get the endpoint protection platform selection guide for deeper EDR comparison.
SOC staffing model
Is it a real Security Operations Center with Tier 1 triage, Tier 2 investigation, and Tier 3 threat hunting? Or is it an alerting platform with an on-call rotation? Ask for the analyst-to-client ratio. SANS recommends no more than 50 active client environments per Tier 2 analyst for quality threat detection and response. Some MSSPs run 200-to-1 and call it scale.
Contract flexibility
Watch for 3-year auto-renewing terms with 90-day notice windows, exit fees of 3 to 6 months of contract value, and tool licenses that don't transfer if you leave. These are the contract traps I see most often during second-opinion reviews.
Step 3: Calculate True Total Cost of Ownership
The monthly invoice is the visible iceberg. Build a 3-year TCO model.
Inputs:
- MSSP service fee (per endpoint or per user)
- Tool license pass-throughs (often 30 to 50% of total)
- Onboarding and integration labour (usually $15K to $75K one-time)
- Incident response hours above the monthly cap (commonly $300 to $450/hour)
- Exit costs (data export, tool deprovisioning, knowledge transfer)
Compare against in-house. Per the BLS Occupational Outlook and the Dice 2024 Tech Salary Report, a SOC analyst earns $95,000 to $130,000 base, plus roughly 30% in benefits and burden. 24/7 coverage requires a minimum of 4 to 5 FTEs to handle shifts, vacation, and attrition. Add a SIEM licence, an EDR licence, and a threat intel feed.
For a 150-person company, an equivalent in-house security function runs $800K to $1.2M annually in personnel before tooling. A competent MSSP at that scale typically prices between $8,000 and $25,000 per month. Even the high end is half the in-house cost, and you get vacation coverage. Read the full managed security services vs in-house TCO breakdown for the spreadsheet. For detailed managed IT pricing by contract type, see our managed IT services pricing guide.
Hidden fees to probe: per-device overages above contracted counts, SIEM log ingestion overages (a single chatty firewall can blow your budget), and IR hours billed separately above a monthly cap. Ask for an itemised quote. Refusal is your answer.
Step 4: Audit the MSSP's Own Security Posture
This is the step almost no buyer takes, and it's the one that bites hardest. Verizon's 2024 DBIR put third-party involvement in 15% of breaches. Kaseya VSA (2021) and the SolarWinds Orion supply-chain compromise (2020) both proved that your security vendor is a privileged access point into your environment.
Ask for:
- Their SOC 2 Type II report. If they sell compliance services and don't hold their own SOC 2, walk away. Read about realistic SOC 2 certification cost so you understand what you're asking for.
- A penetration test summary from the last 12 months with remediation status.
- Their privileged access management approach. They should use CyberArk, BeyondTrust, or equivalent with session recording, not shared admin credentials in a password manager.
- Cyber insurance limits. A vendor with $1M in cyber liability covering 500 clients is not adequate if they become your breach vector. Check our cyber insurance requirements for 2026 for context.
- Their own incident history. Search SEC EDGAR if they're public. Check the HHS OCR breach portal if they serve healthcare.
Step 5: Industry-Specific Selection Criteria
Generic "we support all compliance" claims are a red flag. Vertical depth is what you're paying for.
Healthcare: HIPAA Security Rule expertise, PHI-aware SIEM rules, willingness to sign a BAA before any eval data sharing. HHS OCR issued over $4.1M in HIPAA settlements in 2023 across multiple actions, and most involved inadequate audit logging or access controls. If you're in Tennessee, our HIPAA compliance services in Nashville outline what audit-ready looks like.
Financial services: SOC 2 plus NY DFS 23 NYCRR 500 or GLBA Safeguards Rule familiarity. Annual penetration testing evidence is non-negotiable. Charlotte buyers should look at our SOC 2 compliance services in Charlotte as a reference profile.
Manufacturing and defence: CMMC 2.0 roadmap support and NIST SP 800-171 assessment experience. The DoD's CMMC final rule took effect 16 December 2024, with phased contract requirements rolling out through 2028. If your MSSP can't talk SPRS scores, they're not ready.
Retail and e-commerce: PCI-DSS v4.0 scoping, cardholder data environment segmentation, and quarterly ASV scans.
Step 6: Post-Contract KPIs and When to Fire Them
Establish baseline KPIs at contract signing, not six months in when something's already wrong.
- MTTD (Mean Time to Detect): target under 24 hours for critical alerts. IBM's 2024 report put the industry mean at 194 days for breaches involving stolen credentials.
- MTTR (Mean Time to Respond): target under 4 hours for critical incidents.
- False positive rate: target under 15%. Higher than that and your team will start ignoring alerts.
- Patch SLA compliance: percentage of critical CVEs remediated within agreed window.
- Monthly compliance posture score: trended over time.
Require a monthly executive summary in plain language. If they can only send a 40-page log dump, that's a service delivery failure.
Legitimate exit triggers: missed IR SLA two or more times in a quarter, failure to produce audit evidence on deadline, unannounced tool substitution, or their own security incident affecting your environment. Make sure your contract has a "for cause" exit clause tied to specific SLA failures, not just a "for convenience" clause that requires paying out the remaining term.
Documented incident response testing is one of the few things an insurer can price directly, so treat it as a deliverable you expect from a provider rather than a bonus you hope for. That's the kind of outcome you should be measuring against, and it's the standard our cybersecurity services in Tampa practice is built around.
Book the Audit
If you're within 90 days of a SOC 2 or HIPAA audit and don't know where you stand, book a free 30-minute audit with Mike. We'll tell you exactly which MSSP criteria matter for your specific compliance deadline, no pitch deck required.
Frequently Asked Questions
What's the difference between an MSP and an MSSP? An MSP (Managed Service Provider) handles broad IT operations: helpdesk, infrastructure, patching, backups. An MSSP (Managed Security Services Provider) focuses on security operations: SOC monitoring, SIEM tuning, EDR management, incident response, and compliance evidence. Many providers do both. Make sure the security side has its own dedicated team, not a help desk technician moonlighting as an analyst.
How much should managed security services cost for a 100-person company? Expect $6,000 to $18,000 per month for full coverage including EDR, SIEM, 24/7 SOC, vulnerability management, and IR retainer. Variance depends on cloud footprint, compliance scope, and tool selection. Below $5,000/month for a 100-person company usually means alerting only with no real analyst response.
Do I still need cyber insurance if I have an MSSP? Yes. An MSSP reduces likelihood and severity. Cyber insurance covers the financial fallout when controls fail anyway: ransom payments, business interruption, legal defence, regulatory fines. They're complementary. Most underwriters in 2025 require documented MSSP coverage or equivalent in-house SOC as a precondition for issuing a policy.
Can an MSSP replace an internal IT security team? For companies under 250 employees without strict regulatory requirements, often yes. Above that, or in regulated industries, you typically need at least one internal security lead to own vendor management, policy, and risk decisions. The MSSP runs operations. Your internal lead runs governance.
How long does MSSP onboarding take? 30 to 90 days for full integration. Day 30 should have EDR deployed across all endpoints and SIEM ingesting your core log sources. Day 60 should have SOAR playbooks tuned and the IR runbook tested. Day 90 should have a baseline KPI report with real numbers. Anything faster is shortcutting tuning. Anything slower is a project management problem.
Know exactly where your security stands.
Get your free security assessment →Ready to take the next step?
Our team is here to help. No sales pitch, just a conversation.
Get a Free Security Assessment