vCISO, MSP, MDR — who owns what.
Three roles that are constantly confused, on one screen: what each is accountable for, what it owns, what it does not own, who buys it, and how it fails. Buy the wrong one and a critical responsibility ends up owned by nobody.
Three roles, one responsibility map.
Read down each column to understand a role; read across each row to see where responsibility hands off. A mature program usually needs more than one — the failure mode is assuming one covers another's job.
| Dimension | vCISO security leadership & program |
MSP IT operations |
MDR detection & response operations |
|---|---|---|---|
| Accountability | Accountable for the security program and risk decisions, reporting to leadership and the board. | Accountable for IT systems working — uptime, support, and day-to-day administration. | Accountable for detecting and responding to threats within a contracted scope and service level. |
| Scope | Strategy, risk, policy, roadmap, budget guidance, and provider oversight. | Endpoints, network, identity administration, patching, and backup operation. | Around-the-clock (24/7) monitoring, alert triage, and contracted containment. |
| What they own | The risk register, the security roadmap, policy, board reporting, and vendor/provider selection. | IT operations and the health of the systems they manage. | Detection tooling operation, triage, and the response actions their contract covers. |
| What they do NOT own | Day-to-day IT operations, live monitoring, and detection — those are operational roles. | Security strategy, risk acceptance, and detection/response accountability. | Your security strategy, risk decisions, or the controls outside the monitored scope. |
| Typical buyer | CEO/CFO or the board at a firm too small for a full-time CISO. | Owner or operations lead who needs IT run reliably. | CISO or IT leader who needs eyes on the environment after hours. |
| How they fail | Advice without execution capacity, or leadership with no operational partners to carry it out. | Treated as the security team when their remit is IT operations, leaving detection and strategy unowned. | Alerts with no one accountable to act on findings, or a monitored scope narrower than the business assumes. |
Want the responsibilities split into a full RACI, including who performs live digital forensics and who accepts residual risk? Read the deep dive.
Get the leadership layer, keep your operators.
A free 30-minute Cyber Risk Check scopes fractional security leadership (vCISO) for your program — and helps you select the MSP and MDR partners you contract directly.
What this is and is not. A point-in-time, factual role comparison. It is not a DSE assessment, an audit, a procurement recommendation, or legal advice, and it names no provider. DSE provides fractional security leadership (vCISO); we are not an MSP and do not operate MDR, and where you need those we help you scope and select a provider you contract directly. See the deep dive for the full RACI.
Primary source, verified.