We're a 20-person B2B logistics software company based in Delaware. We host client enterprise operational data in cloud servers, and our entire team works remotely on company laptops. A major enterprise client recently sent us a vendor security audit asking about our 24/7 security monitoring and incident response processes.
So we started looking to outsource this and came across two different models. One security vendor offered managed SOC for 3,200 dollars a month, saying they'd ingest all logs and monitor everything centrally around the clock. Another vendor quoted us 1,100 dollars a month for MDR, deploying agents to our endpoints and cloud servers.
The cost difference is almost 3x. For a company our size, what's the actual difference between a managed SOC and MDR? Do we really need both or can we just go with MDR, tick the audit boxes and be fine?