Jaded Security

TECHNICAL · 2011-09-12What Does MSSP Mean in Cyber Security?

– Boris Sverdlik

I keep seeing acronyms thrown around in security marketing like confetti at a parade. The latest one that seems to confuse everyone: MSSP. So let me break it down.

MSSP: Managed Security Service Provider

An MSSP is a company that provides outsourced monitoring and management of security devices and systems. Think of it as hiring a team of security analysts to watch your network 24/7 so you do not have to build that capability in-house.

What an MSSP typically offers

  • 24/7 security monitoring – A Security Operations Center (SOC) that watches your logs, alerts, and events around the clock
  • Firewall and IDS/IPS management – They configure, monitor, and maintain your security devices
  • Vulnerability scanning – Regular scans of your infrastructure to identify weaknesses
  • Log management and SIEM – Collecting, correlating, and analyzing security logs from across your environment
  • Incident response support – When something bad happens, they help you deal with it
  • Compliance reporting – Generating the reports your auditors want to see

MSSP vs MSP

Do not confuse an MSSP with an MSP (Managed Service Provider). An MSP manages your IT infrastructure – servers, networks, help desk. An MSSP focuses specifically on security. Some companies do both, but the skill sets are very different. Your MSP keeping your Exchange server running is not the same as detecting a sophisticated intrusion.

When does an MSSP make sense?

For small and mid-size organizations that cannot justify the cost of a full in-house security team, an MSSP is often the most practical option. Building a 24/7 SOC requires a minimum of 5-6 analysts plus management, tools, and infrastructure. That is a significant investment. An MSSP spreads that cost across many clients.

Larger organizations may use an MSSP to supplement their internal team or to cover off-hours monitoring.

The catch

Not all MSSPs are created equal. Some are just forwarding vendor alerts with no real analysis. Ask about their analyst-to-client ratio, their mean time to detect and respond, and whether they do actual threat hunting or just react to alerts. A bad MSSP gives you a false sense of security, which is worse than no MSSP at all.

Do your homework before signing a contract.


Jaded Security