Explainer · 7 min read

SIEM, SOC, EDR, XDR and MDR: what the acronyms actually mean

The security market uses five overlapping terms for related things. Here is what each one is, how they differ, and which questions to ask a vendor using them.

Why the terms are confusing

These acronyms describe overlapping things, and vendors apply them loosely because each has been fashionable in turn. The useful distinction is not between the labels but between three separate questions: what collects the data, what analyses it, and who acts on the result.

SIEM - Security Information and Event Management

A SIEM is the place security data lands. It collects logs from across your estate, normalises them into a consistent format, retains them, and runs correlation rules to identify suspicious patterns.

A SIEM is a platform, not an outcome. On its own it produces alerts. Whether those alerts are useful depends entirely on the detection content written for it and whether anyone investigates what it raises. A SIEM nobody tunes and nobody watches is an expensive log archive.

EDR - Endpoint Detection and Response

EDR is agent-based monitoring on servers and workstations. Where antivirus asks whether a file matches something known to be bad, EDR records behaviour: which process spawned which, under what account, with what command line, connecting where.

This matters because modern intrusions frequently use tooling that is already installed and already signed. Nothing malicious is written to disk, so signature matching sees nothing, while the behaviour is plainly unusual.

XDR - Extended Detection and Response

XDR extends the same idea beyond the endpoint, correlating endpoint telemetry with network, identity, email and cloud signals so that related events are assessed as one sequence rather than separately.

In practice the boundary between a modern SIEM and an XDR platform is largely a marketing distinction. Ask what data sources are actually correlated and how, rather than which label the product carries.

SOC and MDR - the human layer

A SOC is the function that operates all of the above: the people, the process and the shifts. MDR - Managed Detection and Response - is that function bought as a service, usually with the provider supplying the technology as well.

The distinction that matters commercially is between a service that alerts you and a service that investigates before alerting you. Both are sometimes called MDR. The first forwards events and leaves the judgement with you; the second does the judgement and escalates conclusions. The price difference reflects a genuine difference in work.

The questions worth asking any vendor

Regardless of which acronym a vendor leads with, these questions separate substance from packaging.

  • Which data sources do you actually collect from my environment, and which do you not?
  • Do your analysts investigate before contacting me, or do you forward alerts?
  • Who writes the detection rules, and how often are they updated for my environment specifically?
  • What happens at 02:00 on a Sunday, concretely?
  • How do you know your own platform is still detecting? What would tell you if a log source stopped?
  • How is my data isolated from your other customers, and how has that isolation been tested?

Get started

Find out what is actually happening on your network

A short conversation is usually enough to establish whether monitoring would tell you something you do not already know. There is no obligation and no sales script.