We are a 12-person fully remote fintech company incorporated in Delaware. To pass an enterprise client's security audit, we are required to have 24/7 threat monitoring and incident response in place. We received quotes from two different security vendors. The first proposed a 'Managed SIEM' service at 1,900 dollars a month. The second offered 'MDR' for 1,300 dollars a month.
We don't have an in-house, full-time security specialist; two of our software engineers manage the infrastructure on a part-time basis. Reading the vendors' marketing decks, both say they catch threats, but we can't quite grasp the practical operational difference between them.
For a small team like ours without dedicated security staff which one makes sense? Does one just generate alerts and pass them to us, while the other takes direct action? We don't want to burn money needlessly.