§ Cybersecurity proof & diagnostic assets·print-friendly · comparison

vCISO, MSP, MDR — who owns what.

Three roles that are constantly confused, on one screen: what each is accountable for, what it owns, what it does not own, who buys it, and how it fails. Buy the wrong one and a critical responsibility ends up owned by nobody.

About this asset

Audience
Owners and executives deciding which security provider they actually need, and how the roles divide responsibility.
Owner service
Fractional CISO & Security Program Leadership
Classification
Classification: Public · Version 1.0 · July 2026
Methodology
A factual role comparison drawn from the governance and oversight outcomes in NIST Cybersecurity Framework 2.0 (NIST CSWP 29, the Govern Function) — leadership and accountability sit above operations. No vendor names and no pricing; the point is the division of responsibility, not a market ranking.
Limitations
Point-in-time, self-diagnostic comparison. It is not a DSE assessment, an audit, a procurement recommendation, or legal advice, and it makes no claim about any specific provider.
Verification
The framework reference was checked against the csrc.nist.gov landing page for NIST CSWP 29. The role definitions are general-industry usage, stated without naming any product or company.
The comparison

Three roles, one responsibility map.

Read down each column to understand a role; read across each row to see where responsibility hands off. A mature program usually needs more than one — the failure mode is assuming one covers another's job.

Dimension vCISO
security leadership & program
MSP
IT operations
MDR
detection & response operations
Accountability Accountable for the security program and risk decisions, reporting to leadership and the board. Accountable for IT systems working — uptime, support, and day-to-day administration. Accountable for detecting and responding to threats within a contracted scope and service level.
Scope Strategy, risk, policy, roadmap, budget guidance, and provider oversight. Endpoints, network, identity administration, patching, and backup operation. Around-the-clock (24/7) monitoring, alert triage, and contracted containment.
What they own The risk register, the security roadmap, policy, board reporting, and vendor/provider selection. IT operations and the health of the systems they manage. Detection tooling operation, triage, and the response actions their contract covers.
What they do NOT own Day-to-day IT operations, live monitoring, and detection — those are operational roles. Security strategy, risk acceptance, and detection/response accountability. Your security strategy, risk decisions, or the controls outside the monitored scope.
Typical buyer CEO/CFO or the board at a firm too small for a full-time CISO. Owner or operations lead who needs IT run reliably. CISO or IT leader who needs eyes on the environment after hours.
How they fail Advice without execution capacity, or leadership with no operational partners to carry it out. Treated as the security team when their remit is IT operations, leaving detection and strategy unowned. Alerts with no one accountable to act on findings, or a monitored scope narrower than the business assumes.

Want the responsibilities split into a full RACI, including who performs live digital forensics and who accepts residual risk? Read the deep dive.

Get the leadership layer, keep your operators.

A free 30-minute Cyber Risk Check scopes fractional security leadership (vCISO) for your program — and helps you select the MSP and MDR partners you contract directly.

What this is and is not. A point-in-time, factual role comparison. It is not a DSE assessment, an audit, a procurement recommendation, or legal advice, and it names no provider. DSE provides fractional security leadership (vCISO); we are not an MSP and do not operate MDR, and where you need those we help you scope and select a provider you contract directly. See the deep dive for the full RACI.

Primary source, verified.