Three acronyms dominate the search results when a New York business goes looking for IT and security help: MSP, MSSP, and MDR. Vendors often blur them, because the blur sells. But they name three different purchases, with different deliverables, different staffing behind them, and different failure modes when you buy the wrong one. This guide separates them plainly, then covers the part national explainers skip: how New York’s compliance environment changes the answer. For what a combined security scope looks like in practice, see our managed cybersecurity services.
The three terms, defined properly
MSP: managed service provider
An MSP runs IT operations. Help desk, endpoint and server management, patching, Microsoft 365 administration, backups, vendor management, onboarding and offboarding — the work that keeps a business computing. A good MSP is measured on whether systems stay up and requests get resolved. Most MSPs include baseline security: antivirus, a firewall, spam filtering, patch schedules. That is hygiene, and it matters, but it is a different job from watching for an active intrusion and responding to it.
MSSP: managed security service provider
An MSSP runs security operations. It collects telemetry from your endpoints, identities, email, and network; watches it for signs of compromise; manages vulnerabilities; and produces the reporting your auditor, insurer, or client questionnaire asks for. An MSSP generally does not reset passwords, fix printers, or manage your file server — it assumes someone else runs IT. That assumption is where many buyers get hurt, because security findings without an operations team to remediate them are just a well-documented backlog.
MDR: managed detection and response
MDR is not a third kind of company — it is a specific service, usually sold by MSSPs and security vendors. Managed detection and response means telemetry from endpoints and identities is monitored continuously, alerts are triaged by people rather than left in a queue, and the provider takes containment action when something is real: isolating a machine, disabling an account, blocking a sender. If MSSP is the category, MDR is the flagship product inside it.
Side by side
| MSP | MSSP | MDR | |
|---|---|---|---|
| Core job | Run IT operations | Run security operations | Detect and contain active threats |
| Typical deliverables | Help desk, patching, backups, user management | Monitoring, vulnerability management, compliance reporting | Alert triage, containment, incident reports |
| Measured on | Uptime and response to requests | Coverage and quality of evidence | Time to detect and contain |
| Will not do | Hunt intrusions in your logs | Fix the printer | Patch systems or run backups |
Where buyers get burned
The categories blur at the edges — most MSPs now resell some security tooling, and some MSSPs will manage a firewall — but the failure modes are predictable:
- Buying an MSP and assuming detection is included. Antivirus and patching are prevention. If nobody is reading endpoint and identity telemetry, an intrusion is typically discovered by its consequences — an encrypted file server, or a client asking about a strange invoice email — rather than by a console.
- Buying an MSSP with nobody to remediate. Vulnerability reports and hardening recommendations pile up unless an operations team owns the fixes. Two vendors pointing at each other is the standard version of this failure.
- Buying MDR alone on a neglected network. Containment works, but the same weak credentials and unpatched systems keep producing incidents. Detection is not a substitute for hygiene.
What New York adds to the question
For many Tri-State firms, the MSP-versus-MSSP question is settled by obligations rather than preference. Three are worth naming.
NYDFS 23 NYCRR 500. If your firm is licensed under New York’s Banking, Insurance, or Financial Services Law, Part 500 applies regardless of your size. Its amended requirements phased in between December 2023 and November 1, 2025 — the final tranche made multi-factor authentication mandatory for all users and removed the small-business MFA exemption — and a certification of compliance is due to DFS by April 15 each year. Monitoring, incident response, and an accountable security function are program requirements, not options. Our NYDFS Part 500 page covers the full requirement set.
The SHIELD Act and sector rules. New York’s SHIELD Act requires reasonable data-security safeguards from essentially any business holding New York residents’ private information. On top of that, HIPAA attaches program requirements to healthcare practices, and the FTC Safeguards Rule does the same for CPA and tax firms of any size — nine required elements, including monitoring and testing.
Cyber insurance. Carriers increasingly condition coverage on enforced MFA and on endpoint detection and response; underwriting surveys published in 2025 report that the large majority of carriers now require EDR or MDR. Your renewal application is, in practice, a security-operations audit.
So which do you need?
- Under roughly 50 seats, no internal IT, light regulatory exposure: a competent MSP with an honest security baseline, adding MDR as budget allows — insurers are pushing it downmarket quickly.
- A regulated SMB — an RIA, a CPA firm, a medical or dental practice: both disciplines from day one. The regimes above assume monitoring, response, and evidence, and a help desk alone cannot produce them.
- 50 to 500 seats with an internal IT team: keep operations in-house and buy security operations — MDR, vulnerability management, reporting — as a co-managed layer. This is the most common mid-market pattern for a reason.
- Already have an MSP you like: keep them, add detection and response, and put in writing who acts on findings. Split accountability is workable only when it is explicit.
The question that matters more than the acronym
Whoever detects a problem must be able to act on it, and whoever acts must be accountable for the outcome. Most real-world incident damage accrues in the gap between a security vendor that noticed and an IT vendor that was not told, not authorized, or not awake. That is the argument for buying managed IT and security operations from one accountable team — which is how Stedholm is built, so weigh our view accordingly. If you split the roles instead, split them on paper: who monitors, who remediates, who calls the insurer, and who owns the timeline.
If you are not sure which of the three you are paying for today, that is a solvable question. A scoped IT and security assessment reads your current coverage against your obligations and hands you the findings either way.