For a business with 20–200 staff, the buying decision often starts with a practical concern: you have security tools, but you are not sure who would act if something serious happened tonight.
This guide explains how to compare managed security services in Australia and what to ask before signing. If you are ready to discuss delivery, explore Stanfield IT’s cyber security services.
What does a managed security service provider do?
An MSSP takes responsibility for specified security operations under a service agreement. Depending on the engagement, that might include managing endpoint protection, reviewing identity alerts, monitoring firewalls, investigating suspicious activity or coordinating incident containment.
The important word is specified. One provider may monitor devices and send alerts to your IT team. Another may investigate those alerts and isolate an affected device under agreed authority. A third may also undertake remediation and recovery. Those are materially different services.
Start with three questions: What can the provider see? What will it do? Who owns the next action? A clear answer should identify both the provider’s work and your business’s remaining responsibilities.
MSSP vs MSP vs MDR: which service do you need?
These terms describe different areas of focus, with considerable overlap. A managed IT provider can also deliver security services, and an MSSP may include managed detection and response. Compare the actual proposal.
| Service | Typical focus | Check before buying |
|---|---|---|
| MSP: managed service provider | Day-to-day IT support, device management, maintenance and cloud administration. | Which security activities are included, and who investigates security alerts? |
| MSSP: managed security service provider | Ongoing operation of agreed security controls and monitoring services. | Does the provider notify you, contain threats, remediate systems, or provide a combination? |
| MDR: managed detection and response | Technology and analyst expertise used to detect, investigate and respond to threats. | Which devices and cloud services are covered, during what hours, and with what response authority? |
| Managed SOC: security operations centre service | A service delivered through a security operations function; its tools, staffing and response scope vary. | Who staffs the service, which partners are involved, and who acts after escalation? |
Cisco’s MDR explanation describes the combination of security expertise, detection and response capabilities. Microsoft describes a SOC as a security operations function combining people, processes and technology. Having access to a SOC does not, by itself, explain the customer’s purchased service.
If your internal IT team can maintain systems but struggles to investigate alerts, a scoped managed detection and response service may address that gap. If patching, access management and day-to-day support also lack ownership, consider how security will work alongside managed IT services.
What should managed security services cover?
Build the scope around your business systems and the risks you need to manage. Ask each provider to mark every area as included, optional, excluded or retained by your team.
- Devices and servers: supported operating systems, remote staff, unmanaged devices and the process for spotting failed or missing protection.
- Identity and cloud services: Microsoft 365 or Google Workspace accounts, administrator roles, suspicious sign-ins and the specific logs available for investigation.
- Networks: the firewalls, remote-access services and other network sources being monitored.
- Investigation and response: analyst triage, escalation, authorised containment and the handover into recovery.
- Ongoing improvement: agreed vulnerability reviews, configuration changes, reporting and follow-up actions.
Then check the boundaries. Penetration testing, security awareness training, backup recovery, forensic investigations and major remediation projects may require separate services. A vulnerability report also needs an owner who will resolve the findings.
Microsoft’s shared responsibility guidance explains that customer responsibilities remain when using cloud services, including responsibilities for data and identities. Ask the MSSP to identify which of those customer-side tasks it will undertake.
What does 24/7 security coverage actually mean?
Separate four capabilities: continuous data collection, automated protective actions, human investigation and authority to respond. Ask which operate around the clock in the proposed plan.
For example, software may automatically block suspicious activity while a human reviews other alerts during business hours. Another service may have analysts investigating all night but still require your approval before disabling an account. The distinction matters when the decision-maker is unavailable.
Request written definitions for:
- Critical incident criteria and the point at which each service clock starts.
- Human investigation, customer notification and escalation targets.
- Actions pre-authorised after hours and their operational limits.
- The fallback contact and process when nobody answers.
- Activities charged separately, including recovery or onsite attendance.
A response commitment should explain the action it measures. Our guide to IT support response times and SLAs explains the distinction between acknowledgement, technical response and restoring service.
Who acts when a security incident occurs?
Before signing, walk through a scenario: a suspicious administrator sign-in occurs after hours, followed by unusual access to business files. Ask the provider to explain what happens next, including which actions require permission.
The following is a planning example to adapt with your provider, rather than a description of any particular service plan.
| Action | Responsibility to agree |
|---|---|
| Investigate the alert | The security provider identifies the available evidence and records its assessment. |
| Contain the threat | The authorised responder acts within written limits, or escalates to the named decision-maker. |
| Restore affected services | Your internal IT team, MSP or separately engaged recovery specialist owns the agreed recovery work. |
| Make business decisions | Business leadership owns operational decisions and coordinates legal, insurer and communication advice as needed. |
| Close out the incident | Named owners document the actions, validate recovery and track improvements. |
Ask to see an anonymised incident report. It should make the investigation, actions, remaining risks and next steps understandable without requiring you to interpret a dashboard full of alerts.
How much does a managed security service provider cost?
The price depends on the environment and the work included. A per-device monitoring fee, a broader managed security service and a bundled IT agreement cover different responsibilities.
Ask for a first-year total that separates the following:
- Recurring service fees: the charging unit, minimum commitment and treatment of additional users, devices, servers or sites.
- Product licences and data costs: required security licences, log ingestion, storage and retention.
- Onboarding: discovery, configuration, deployment and transition from existing tools.
- Remediation: fixing existing weaknesses, unsupported systems or configuration problems.
- Incident support and exit: response inclusions, recovery charges, notice periods and handover costs.
Bundled IT and security pricing example
At the time of review, Stanfield IT’s published pricing lists One Complete at A$179 per person per month, excluding GST. This is an indicative bundled plan covering managed IT and security alongside other services, not a standalone MSSP market benchmark. A minimum monthly service level of A$1,190 applies; licences and other environment-specific items may be additional, with final scope confirmed in the proposal.
For 50 people, that published base rate calculates to A$8,950 a month before GST and additional items. The useful comparison is the full scope and total cost of the proposed arrangement, including any work your team must still do.
Eight questions to ask before choosing an MSSP
Send the same questions to each shortlisted provider. Request written answers and supporting examples so you can compare proposals consistently.
1. What will you monitor, and how will you verify coverage?
Request an asset and log-source list, plus the process for identifying devices or connectors that stop reporting. Monitoring only the systems successfully enrolled leaves a gap if nobody reconciles the list.
2. Who provides the security service?
Ask which work is performed directly and which uses partners. Confirm analyst locations, escalation ownership and the service delivered during Australian nights, weekends and public holidays.
3. What can you do without waiting for approval?
Request the containment permissions, exceptions and fallback contacts. An answer such as “we notify your IT team” leaves your team responsible for the next action.
4. How is your own access secured?
Ask about named administrative accounts, multi-factor authentication, least privilege, access reviews and activity records. The ACSC’s guidance on engaging an MSP highlights the need to assess provider security and document responsibilities. Agree a named contact and notification process if an incident in the provider’s own systems could affect your business.
5. Where will our information be stored and accessed?
Confirm the location of security logs and backups, analyst access, subcontractors, retention and deletion arrangements. An Australian office address does not answer all those questions.
6. How will you demonstrate useful work?
Request a sample management report showing coverage gaps, significant incidents, overdue actions and service performance. Each important finding should have an owner and a next step.
7. What happens during onboarding?
Ask how the provider validates licences, deploys tools, tests alerts, agrees response permissions and handles existing protection. Include a sign-off point for confirming the service is operational.
8. What happens if we leave?
Confirm notice periods, access removal, configuration and log exports, documentation, product ownership and transition charges. The exit process should be understandable before the contract begins.
Does an MSSP make your business compliant?
A provider can support your security obligations through agreed controls, records, assessments and remediation. Buying a service does not establish that every requirement applying to your organisation has been met.
The Essential Eight maturity model describes mitigation strategies and maturity requirements. It is not a threat-detection framework. Ask which controls are being implemented, how they will be assessed and what evidence will demonstrate the result.
For help assessing and improving your controls, see our Essential Eight assessment and implementation services.
If you need ISO 27001 readiness or help responding to customer security requirements, define those deliverables separately. Monitoring reports alone do not demonstrate the operation of an entire information security management system.
How should you transition to a new security provider?
A sensible handover maintains protection while responsibilities change. Agree these milestones with the incoming provider and whoever currently manages your systems:
- Document the starting point. Confirm assets, licences, administrators, current tools, important systems and outstanding risks.
- Agree the operating model. Finalise coverage, contacts, response authority, exclusions and business approval requirements.
- Deploy and validate. Test that the agreed devices and log sources report correctly and that alert escalation reaches the right people.
- Complete the handover. Coordinate tool changes, remove superseded access when appropriate and record acceptance of the new service.
- Review early findings. Prioritise gaps, assign remediation owners and confirm the reporting schedule.
For a wider change of IT partner, use our guide to switching IT providers alongside the security handover plan.
Discuss managed security with Stanfield IT
Stanfield IT helps Sydney businesses connect cyber security with the IT systems and people who need to act on it. Whether you have an internal IT team or need broader managed support, start by identifying the responsibilities and coverage your business needs.
Bring your current proposal, service agreement or list of concerns. We can discuss the gaps and suitable next steps through our cyber security services. Monitoring hours, response authority and remediation inclusions should be confirmed in the agreed scope.
Request a Free Assessment to discuss your current security arrangement.
Managed security service provider FAQs
What is the difference between an MSP and an MSSP?
An MSP usually focuses on running and supporting IT. An MSSP focuses on agreed security operations. The services can overlap, so compare the written responsibilities, coverage and response commitments.
Are all managed security services available 24/7?
No. Confirm the hours for data collection, automated protection, human investigation and response separately. Also ask what happens when your nominated contact cannot be reached.
Can we keep our current IT provider and add an MSSP?
Yes, where the parties agree how access, alerts, containment and recovery will work. Document the handover between them so an incident does not stall while each waits for the other.
Is MDR the same as antivirus or endpoint protection?
No. MDR is a managed service focused on detecting, investigating and responding to threats. Endpoint protection may be part of its technology. Confirm the analyst involvement, systems covered and response actions in the agreement.
Does an MSSP replace an internal IT team?
Not necessarily. It can supply security expertise while your team retains IT operations. If you also need user support, patching or cloud administration, confirm which provider or team will own that work.
What should we ask for in an MSSP proposal?
Request the scope, coverage hours, response responsibilities, full pricing, onboarding plan, sample report and exit terms. Ask the provider to show how it would handle a realistic incident affecting your business.