Skip to main content

MSSP (Managed Security Service Provider)

Overview​

An MSSP delivers outsourced security operations, often 24/7 monitoring, log aggregation, alerting, vulnerability scanning, and sometimes incident response, so organizations without large in-house SOCs still get continuous coverage.

Key concepts​

  • SOC-as-a-service: Analysts triage alerts from customer telemetry.
  • SIEM / EDR: Tooling for correlation and endpoint visibility.
  • SLAs: Response times for severity tiers and reporting cadence.
  • Shared responsibility: Customer must send the right logs and fix owned assets.
  • Playbooks: Runbooks for phishing, malware, account takeover, etc.

Alert triage sequence​

Sample: handoff fields for an incident ticket​

FieldExample
Detection time2026-04-14T09:12Z
Affected hostapp-03.prod
MITRE techniqueT1190: Exploit public-facing app
ContainmentWAF rule + isolate host
StatusContained: root cause TBD

References​