
If you are comparing security monitoring options, the SOC vs MDR question usually arrives with three more acronyms: EDR, XDR and SIEM. Vendors use these terms loosely, and proposals that look alike can cover very different things. One quote buys software. Another buys people who watch that software at 3 a.m. and are allowed to act.
This guide explains each term in plain English: what it detects, who watches the alerts, whether coverage is 24/7, what response actions are included and how long logs are kept. If you already know you want monitored detection and response, see our threat mitigation and 24/7 SOC monitoring page.
The short version: EDR, XDR and SIEM are tools. A SOC is a team and a process. MDR is a service that rents you part of that team.
Key takeaways
- EDR, XDR and SIEM are technologies. A SOC is people plus process. MDR is a managed service that supplies analysts.
- The key question in any SOC vs MDR comparison is who acts on an alert at night, and what they are pre-authorized to do.
- EDR sees endpoints, not firewall, VPN, identity or cloud audit logs.
- 2024 joint guidance from CISA, the FBI, NSA and partners says default log retention is often too short, since some incidents take up to 18 months to discover.
- Small firms usually get the best value from managed EDR or MDR with 24/7 response. Regulated and larger firms usually also need centralized logging.
Where this guidance comes from. We used NIST SP 800-61r3 (April 2025), the NIST CSRC glossary, OMB memoranda M-21-31 and M-22-01, the joint “Best Practices for Event Logging and Threat Detection” guidance (August 22, 2024) from ASD’s ACSC, CISA, the FBI, NSA and partners, CISA’s performance goals, UK NCSC SOC guidance, and the FTC Safeguards and HIPAA Security Rules in the eCFR, plus our veteran-led team’s experience onboarding monitoring clients and responding to incidents. This is general information, not legal advice; confirm compliance specifics with counsel or your assessor.
What is a SIEM?
NIST’s glossary, citing SP 800-128, defines a SIEM tool as an “application that provides the ability to gather security data from information system components and present that data as actionable information via a single interface.” It ingests logs from firewalls, VPNs, identity providers, servers, email and cloud services, then applies correlation rules to raise alerts.
NIST SP 800-61r3 recommends tools such as SIEM and SOAR to continuously monitor log events and correlate data from multiple sources. That makes a SIEM the central record for investigations and compliance evidence. But a SIEM does nothing alone: it needs connected sources, tuned rules and someone reviewing alerts. For very small Windows environments, CISA offers Logging Made Easy, a no-cost centralized log management tool for organizations with limited resources.
What is EDR, and how does XDR extend it?
OMB memorandum M-22-01 (October 2021) says EDR “combines real-time continuous monitoring and collection of endpoint data (for example, networked computing devices such as workstations, mobile phones, servers) with rules-based automated response and analysis capabilities.” Unlike traditional antivirus, EDR watches behavior, such as a document launching PowerShell, not just known malware files.
EDR’s strength is response: it can isolate a laptop, kill a process or quarantine a file in seconds. Its limit is scope. It does not see your firewall, Microsoft 365 sign-ins or cloud console, so an attacker using stolen credentials can look like a normal employee.
XDR combines endpoint data with identity, email, cloud and sometimes network signals. The 2024 joint logging guidance lists SIEM and XDR together as the analytic tools that should receive logs from a centralized logging facility. They overlap, and many organizations use both.
What is a SOC?
The UK NCSC’s SOC guidance (May 2022) notes that most SOCs “are responsible for detecting and responding to cyber attacks,” limiting damage from attacks that get past preventive controls. A SOC is defined by people and process: analysts who triage alerts, written playbooks, an escalation matrix with named contacts and the authority to contain threats.
A SOC can use SIEM, EDR, XDR or all three, and it can be in-house, outsourced or hybrid. NIST SP 800-61r3 gives “outsourcing a security operations center [SOC] to a managed security services provider [MSSP]” as a normal staffing option. Covering every hour of every week in-house takes several trained analysts, which is why most small and mid-sized firms buy SOC coverage as a service.
What is MDR?
MDR is a service category, not a standard, so definitions vary. Generally, an MDR provider deploys or manages a detection tool (most often EDR or XDR), watches alerts around the clock, investigates them and takes some response actions for you.
The details differ. Some MDR covers only endpoints; some includes identity and cloud. Some isolates devices on its own; some only sends a notification. NIST SP 800-61r3 calls outsourced detection and response a shared responsibility model whose duties should be “clearly defined in a contract,” including the provider’s authority to act.
SOC vs MDR: the difference that matters most
In most proposals, the real SOC vs MDR difference is scope. MDR typically centers on one detection platform. A managed SOC typically watches a wider set of sources, such as identity, email, firewall, VPN, cloud audit logs and the SIEM, and ties detection to your incident response plan.
The second difference is who acts. Ask what happens at 3 a.m. on a Sunday when a real alert fires. A service that emails you and stops is monitoring. A service that confirms the threat, isolates the endpoint or disables the account under a pre-approved playbook, then notifies you, is detection and response.
The third difference is evidence. A SOC built on centralized logs can answer “what else did the attacker touch?” weeks later. Endpoint-only services may lack the sign-in or firewall records an insurer or attorney will ask for.
Not sure which model fits? You can request a SOC or MDR assessment online and we will review your tools, log sources and coverage hours, or book a consultation online to talk it through first.
Comparison table: SOC vs MDR vs EDR vs XDR vs SIEM
| Question | SOC | MDR | EDR | XDR | SIEM |
|---|---|---|---|---|---|
| What it is | Team, process and playbooks | Managed service (outside analysts) | Agent on endpoints | Detection across several sources | Log collection and correlation platform |
| What it detects | Whatever its tools and logs cover | Mostly the provider platform’s scope | Malicious behavior on computers and servers | Endpoint, identity, email, cloud, some network | Anything that sends it logs, per your rules |
| Who watches alerts | SOC analysts, in-house or outsourced | Provider’s analysts | No one unless assigned | No one unless assigned | No one unless assigned |
| 24/7 coverage | Only if staffed or contracted | Usually, confirm in writing | Tool yes, people maybe | Tool yes, people maybe | Tool yes, people maybe |
| Response actions | Pre-approved containment and escalation | From notify-only to isolate and disable | Isolate host, kill process, quarantine | Cross-source actions | Alerts and search; response needs SOAR or a person |
| Log retention | Set by policy and platforms | Often platform default, confirm | Vendor default | Varies by vendor tier | Set by you and budget |
The row that surprises most buyers is “who watches alerts.” Tools generate alerts around the clock, but software alone does not investigate or decide.
How long should security logs be kept?
The joint “Best Practices for Event Logging and Threat Detection” guidance (August 2024) says default retention periods are often insufficient. It notes it can take up to 18 months to discover an incident, and some malware sits on a network for 70 to 200 days before causing visible harm. It recommends hot and cold storage tiers so recent logs stay quick to search.
For a benchmark, OMB M-21-31 (August 2021) requires federal agencies to keep many log categories 12 months in active storage and 18 months in cold storage, as minimums. It also defines four event logging tiers:
- EL0, Not Effective: highest-criticality requirements not met or only partly met.
- EL1, Basic: only highest-criticality requirements met.
- EL2, Intermediate: highest and intermediate requirements met.
- EL3, Advanced: all criticality levels met.
M-21-31 binds federal agencies, not private businesses, but it is a useful yardstick when a provider quotes 30 or 90 days. If your insurer, a contract or a regulator sets a period, that period controls. As of October 2026, check each requirement against its current text.
How SOC, MDR, EDR, XDR and SIEM fit together
These are layers, not rivals. The 2024 joint guidance describes the flow:
- Collect. EDR on endpoints plus logs from identity, email, firewalls, VPN and cloud. The guidance’s enterprise priority list starts with critical systems, internet-facing services, identity servers and edge devices.
- Centralize. Send logs to a protected central store or SIEM. CISA’s performance goals call for central log storage that only authorized users can access or modify.
- Detect. EDR, XDR and SIEM rules flag suspicious behavior.
- Triage. SOC or MDR analysts confirm what is real.
- Respond. Pre-approved containment, then escalation to your team and, for serious events, cyber incident response.
A strong EDR with no one watching at night is a gap. A SIEM with no tuned rules is an expensive archive.
How to choose: SOC vs MDR by company size and compliance needs
Under about 50 employees
Start with EDR on every laptop and server, managed by someone who will respond, plus monitoring of email and Microsoft 365 or Google Workspace sign-ins. At this size the SOC vs MDR decision usually favors managed EDR or MDR with 24/7 response. Our guide to managed IT for small business security explains why IT management and security are hard to separate at this size.
About 50 to 500 employees
These firms usually have more identity, cloud and network sources than endpoint-only MDR covers. A managed SOC combining EDR with centralized logging is often the better fit, and retention, playbooks and monthly reporting start to matter for insurers and auditors. See our managed security services (MSSP) guide for evaluating the wider relationship.
Regulated industries and larger organizations
Compliance often decides the question. The FTC Safeguards Rule (16 CFR 314.4) requires covered financial institutions to “monitor and log the activity of authorized users.” The HIPAA Security Rule (45 CFR 164.312(b)) requires mechanisms that “record and examine activity” in systems holding electronic protected health information. Both point toward centralized logging and regular review, usually a SIEM or managed log platform plus a SOC. Government contractors and payment card environments carry their own rules, so confirm specifics with counsel or your assessor before signing.
Questions to ask a SOC or MDR provider
- Who looks at an alert at 3 a.m. on a Sunday, and how fast?
- What containment actions are you pre-authorized to take, and how is that approved in writing?
- Which log sources are in scope, and which are excluded?
- How long do you retain our logs, and can we export them if we leave?
- Who owns the data, detection rules and licenses when the contract ends?
- Is incident response and forensics included, on retainer or billed separately?
- What do monthly reports show?
For the response side, compare incident response retainers vs on-demand help. For a quick read on exposure, try our free cyber risk check.
What drives the cost of SOC and MDR services
Prices vary widely, so compare SOC vs MDR proposals on cost drivers rather than a headline number: endpoints and user identities, log sources and volume, retention length, business-hours versus 24/7 coverage, and included response actions. Onboarding, full incident response and forensics are often quoted separately. Watch for low quotes that cover a tool license but not people.
How Honeybadger delivers SOC monitoring and managed detection
Honeybadger Solutions is a veteran-owned, veteran-led firm based in Casa Grande, Arizona, delivering cybersecurity services nationwide. Our Threat Mitigation and SOC service combines system, device and credential hardening with WhiteBox network monitoring watched by our Security Operations Center 24/7/365. Analysts detect, triage and escalate suspicious activity and take containment steps you pre-authorize in writing, such as isolating an endpoint, disabling an account or blocking a destination.
Monitoring covers identity, endpoints, email, cloud and SaaS, network and edge devices, and operational technology where present. Onboarding includes a baseline period, tuning, written playbooks, an escalation matrix and a tabletop exercise, then monthly reporting. Endpoint coverage comes through endpoint management and managed EDR, with managed EDR alerts routed to a monitored queue. Our managed cyber security (MSSP) team adds penetration testing, vulnerability management and compliance support, and our incident response team handles containment, recovery and court-ready documentation when an alert becomes an incident.
The easiest next step is to submit a service request online with your headcount, current tools and compliance needs, and we will recommend a SOC, MDR or hybrid model. Prefer to talk first? Book a consultation online.
Why the online intake is faster than a phone call: it takes about two minutes, and your answers are routed straight to the specialist team that handles your kind of matter, whether that is cyber and forensics, investigations or field security. That team sees the full picture before it replies, so you skip phone tag and get a real answer and next steps sooner. If it cannot wait for business hours, use the urgent intake form, which is read seven days a week.
Frequently asked questions
Is MDR the same as a SOC?
No. A SOC is the team and process that monitors, investigates and responds to security events. MDR is a service in which an outside provider supplies analysts, usually around an endpoint or extended detection tool. Many MDR services run from a SOC, but a SOC often watches identity, network and cloud logs that narrow MDR does not.
Do I need a SIEM if I already have EDR?
Not always. EDR covers computers and servers but does not see firewall, VPN, identity, email or cloud audit logs on its own. If you need those logs for detection, investigations or compliance, you need a central log platform, usually a SIEM or a managed log service.
What is the difference between EDR and XDR?
EDR watches and responds on endpoints such as laptops and servers. XDR extends detection to identity, email, cloud and network sources so related events can be investigated together.
How long should a small business keep security logs?
There is no single number. The August 2024 joint logging guidance says default retention is often too short and notes some incidents take up to 18 months to discover. OMB M-21-31 sets 12 months active plus 18 months cold storage for many federal log types, a useful benchmark. Any period set by a regulator, contract or insurer controls.
Does a SOC or MDR provider stop every attack?
No provider can promise that. Good monitoring shortens how long an attacker goes unnoticed and starts containment quickly. Judge providers on written detection and response commitments, not prevention claims.
Can a small company get 24/7 monitoring without hiring a night shift?
Yes. Most small and mid-sized businesses buy 24/7 coverage as a managed service. NIST SP 800-61r3 treats outsourcing a SOC to a managed security services provider as normal, provided duties and the provider’s authority to act are written into the contract.
Sources and further reading
- NIST CSRC Glossary: SIEM Tool — SIEM definition (NIST SP 800-128).
- NIST SP 800-61r3 (April 2025) — outsourced SOC roles, shared responsibility, SIEM and SOAR.
- CISA: Best Practices for Event Logging and Threat Detection (2024) — joint logging guidance overview.
- Event logging and threat detection guidance, full PDF (August 22, 2024) — retention, dwell time, log priorities, SIEM and XDR.
- OMB M-21-31 (August 2021) — EL0 to EL3 tiers and federal log retention.
- OMB M-22-01 (October 2021) — federal description of EDR.
- UK NCSC: Building a Security Operations Centre — what a SOC does.
- CISA Cybersecurity Performance Goals — log collection and secure log storage.
- CISA Logging Made Easy — no-cost log management option.
- 16 CFR 314.4, FTC Safeguards Rule — monitoring and logging user activity.
- 45 CFR 164.312, HIPAA technical safeguards — audit controls.
Written and reviewed by the Honeybadger Solutions security and investigations team, a veteran-led Arizona firm (Arizona DPS private investigation agency license No. 1759795). Facts checked against the cited sources on October 2, 2026. This article is general information, not legal advice.
Browse by topic
Security guard services · Private investigations · Cybersecurity · Digital forensics · Financial fraud investigation · Executive protection · All articles