MDR procurement glossary.
Single source of truth for the acronyms that appear on MDR quotes. Definitions match the procurement vocabulary, not the marketing vocabulary.
MDR = outsourced 24x7 monitoring with validated alerts. MSSP = the legacy alert-forwarding category MDR replaced. SOCaaS = synonym for fully-outsourced MDR. XDR = the detection platform; not a service. SOAR = the automation layer. SIEM = the log platform. EDR = the endpoint agent.
- MDR
- Managed Detection and Response. Outsourced 24x7 security monitoring with analyst-validated alerts and (at higher tiers) active response on the customer's environment.
- MSSP
- Managed Security Service Provider. Legacy category that predates MDR; most MSSPs delivered alert forwarding rather than validated response. The MDR category emerged to mark the difference.
- SOCaaS
- SOC as a Service. Synonym for fully-outsourced MDR; emphasises the SOC-function-replacement framing over the detect-and-respond framing.
- XDR
- Extended Detection and Response. Platform category that bundles EDR with cloud, identity, network, and email signal sources into one detection layer.
- SOAR
- Security Orchestration, Automation and Response. The playbook-and-automation layer that converts an alert into a series of actions; sits between SIEM and the response tools.
- TIP
- Threat Intelligence Platform. Aggregates indicators of compromise and threat actor profiles; feeds detection content into SIEM and EDR.
- SIEM
- Security Information and Event Management. The log-collection and detection-rule platform that MDR vendors monitor on the customer's behalf; in BYO-SIEM the customer owns the licence.
- EDR
- Endpoint Detection and Response. The agent on the device that produces the telemetry MDR analysts triage.
- CST
- Concierge Security Team. Arctic Wolf's marketing term for the named-analyst delivery model. Other vendors use 'pod' or 'dedicated team' for similar constructs.
- Pod
- A named, persistent group of analysts assigned to a single customer or small set of customers. The opposite of the random-analyst MDR delivery shape.
- Log source
- A device, application, cloud account, or SaaS that produces logs the SOC monitors. Per-log-source pricing meters on this unit.
- EPS
- Events Per Second. The unit a SIEM (and some MDR contracts) uses to size ingest capacity; converts roughly to GB/day depending on event size.
- MTTD
- Mean Time To Detect. The SLA target for how quickly the SOC identifies a suspicious event after it occurs.
- MTTA
- Mean Time To Acknowledge. The SLA target for how quickly an analyst opens an alert after the SIEM creates it.
- MTTR
- Mean Time To Respond (or Resolve). The SLA target for how quickly the SOC contains or resolves a confirmed incident.
- BYO-SIEM
- Bring Your Own SIEM. MDR delivery where the vendor monitors the customer's existing SIEM rather than ingesting into the vendor's proprietary data lake.
- Active response
- Authority delegated to the vendor to take action on the customer's environment without per-incident approval (isolation, account disable, malicious process termination).
- Breach warranty
- A vendor commitment to pay out a capped sum if a breach occurs while the customer is fully covered by the vendor's product. Examples: Sophos ($1M), CrowdStrike Falcon Complete ($1M).