The three roles get confused because all three are sold as “security,” but they answer different questions. A vCISO answers what should we do and in what order. An MSP answers who runs and patches the estate. An MDR provider answers who is watching at 2am and what happens when something fires. Buying two of the three and assuming the gap is covered is the most common structural mistake we find in growing firms — usually discovered during an incident, or during a customer’s diligence review.
Here is the division of labor, written as a RACI rather than as marketing categories, plus the specific gaps that appear at each seam.
The RACI
| Function | vCISO / security leadership | MSP / managed IT | MDR / managed detection | The organization |
|---|---|---|---|---|
| Risk register ownership | Owns | Contributes | Contributes | Accepts residual risk |
| Security roadmap and sequencing | Owns | Executes assigned items | — | Funds |
| Policy set and exceptions | Owns | Applies technically | — | Approves |
| Endpoint build, patching, estate hygiene | Sets the standard | Owns (operates) | — | Approves change windows |
| Identity administration | Sets the standard | Owns (operates) | — | Approves privileged access |
| Backup operation and restore testing | Sets objectives, reviews evidence | Owns (operates) | — | Owns the RTO/RPO decision |
| 24/7 monitoring, detection, triage | Scopes the requirement | Feeds telemetry | Owns (operates) | Contracts the service |
| Alert response and containment actions | Directs readiness | Executes assigned actions | Executes per its SLA | Executes internal steps |
| Live digital forensics after a breach | Directs the plan | — | Per contract, sometimes | Contracts a DFIR specialist |
| Vendor and provider selection | Owns the process | Advises | Advises | Signs the contract |
| Board and customer reporting | Owns | Supplies data | Supplies data | Presents |
| Regulatory and contractual obligation mapping | Owns the mapping | — | — | Owns the legal determination with counsel |
Two columns in that table are load-bearing and usually left blank in practice: live digital forensics and residual risk acceptance. DFIR is a specialist capability that neither an advisory relationship nor a standard IT contract provides; it needs a named firm and an engagement basis before an incident. Residual risk acceptance is a fiduciary act that stays with the organization’s officers no matter who advises them — a point worth putting in writing in any leadership retainer.
If it helps to mark this division of labor up against your own providers, we keep a printable one-page version in the vCISO vs MSP vs MDR comparison.
Why the seams are where things break
Seam one: MSP and security direction. An MSP is measured on availability and ticket resolution. That is a legitimate and different objective from reducing risk, and it produces predictable friction: MFA that would generate helpdesk volume, privileged access that would slow provisioning, legacy protocol blocks that would break a line-of-business app. None of that is bad faith; it is the incentive structure. A vCISO’s job at this seam is to set the standard and own the exception decision so the MSP is not adjudicating a risk trade-off it was not hired to own.
Seam two: MDR and response authority. An MDR provider detects and, depending on contract, contains. What it usually cannot do is decide whether to take a revenue system offline at 4pm on quarter-end. If nobody has pre-agreed that authority, the alert sits in a queue while someone finds an executive. This is the seam that turns a fifteen-minute detection into a four-hour incident, and it is fixed with a decision-rights table rather than a better tool — see incident response planning without a security team.
Seam three: everyone and evidence. Three providers generate three reports in three formats on three cadences, and none of them is the artifact an insurer, an acquirer, or an enterprise customer asks for. Somebody has to own the consolidated evidence view; the default answer is nobody, until diligence forces the question.
CISA has been explicit that this class of dependency is its own risk category: the Cross-Sector Cybersecurity Performance Goals 2.0 added net-new goals covering cybersecurity oversight, risks associated with managed service providers, the principle of least privilege, and incident communication procedures, and realigned the whole goal set to the NIST CSF 2.0 GOVERN Function. The framework itself puts it in one line — CSF 2.0 subcategory GV.SC-02 requires that cybersecurity roles and responsibilities for suppliers, customers, and partners are established, communicated, and coordinated internally and externally, and GV.SC-08 requires that relevant suppliers and third parties are included in incident planning, response, and recovery activities.
Buying order
For a firm between 50 and 500 people with no internal security function, the sequence that avoids the most rework:
- Direction first, briefly. An assessment plus enough leadership to produce a sequenced roadmap. Without it, the next two purchases are chosen by whoever pitched most recently. A one-page roadmap changes what you buy and what you decline.
- Estate hygiene next. Patching, endpoint standard, identity administration, backup operation. Most of the risk reduction available to a mid-market firm lives here, and it is the cheapest tier. Detection layered over an unmanaged estate produces alert volume, not safety.
- Detection when there is something to detect with, and someone to act. MDR is worth its cost once the estate is managed, logging exists, and response authority is pre-agreed. Bought before those, it is an expensive way to learn that nobody is empowered to act at 2am.
- Leadership cadence to keep it true. The roadmap decays. Something has to own re-prioritization, provider performance review, and the reporting that goes to the board and to customers.
Firms that invert this — MDR first, direction never — end up paying for monitoring of an estate they have not hardened, with alerts routed to people who cannot authorize a response.
What to hold each provider to contractually
- MSP: a named security standard it operates to; a change-approval path for security-relevant settings; evidence outputs on a defined cadence (patch compliance, MFA coverage, backup and restore-test results); an exception log; and clarity that it does not hold the risk-acceptance decision.
- MDR: the detection sources actually in scope; the containment actions it is authorized to take unilaterally versus those requiring approval; escalation contacts and out-of-hours path; reporting format; and the SLA it owns — which is its SLA, not the advisor’s.
- vCISO / security leadership: the artifacts it owns (risk register, roadmap, policy set, board reporting), the meeting cadence, the diligence and questionnaire support included, and an explicit statement that advisory leadership does not assume the client’s statutory officer responsibilities or its risk-acceptance authority.
Where DSE sits, precisely
We are the direction layer. Our fractional CISO and security program leadership engagement owns the roadmap and risk register, runs the governance cadence, produces board reporting, supports diligence and questionnaires, plans budget, oversees remediation, and — importantly here — runs the selection and orchestration of managed providers on a vendor-neutral, documented basis, disclosing any referral relationship.
What we do not do: we do not operate a 24/7 SOC, we do not provide managed detection and response, we do not perform live digital forensics, and we do not inherit or guarantee a provider’s detection SLA. Continuous monitoring is delivered by a provider the client contracts; we scope the requirement, manage the relationship, and translate the output into decisions and reporting. That boundary is deliberate. A firm that both directs the program and claims to operate the monitoring has no independent party left to evaluate the monitoring.
If the immediate question is what to fix rather than who should own it, start with what a cybersecurity risk assessment includes and costs; if it is what your providers should be able to evidence, see the vendor security review checklist for SaaS buyers.
FAQ
What is the difference between a vCISO, an MSP, and an MDR provider?
A vCISO or fractional CISO owns security direction: the risk register, the roadmap, policy, governance cadence, board reporting, and provider selection. An MSP operates the IT estate — endpoint builds, patching, identity administration, and backup operation. An MDR provider operates continuous monitoring, detection, and triage, and executes containment actions within its contracted authority. They are complements, not substitutes.
Can our MSP be our security program?
Rarely, and not by default. An MSP is measured on availability and resolution time, which is a different objective from risk reduction, so security trade-offs that increase support volume tend to lose. An MSP can operate an excellent estate against a standard someone else sets and someone else audits. What it should not also hold is the exception decision, the risk register, or the residual-risk acceptance.
Do we need MDR if we have an MSP?
They cover different functions. An MSP maintains the estate; MDR watches it. Whether MDR is the right next spend depends on whether the estate is managed, whether the necessary logging exists, and whether response authority has been pre-agreed. Detection purchased ahead of those three produces alert volume rather than risk reduction.
Who is accountable when something goes wrong?
The organization. Advisory leadership provides direction and judgment, an MSP operates to a standard, and an MDR provider owns its own detection and response SLA — but statutory officer responsibilities and risk-acceptance decisions remain with the client’s officers. Any leadership retainer should say so in writing, and any monitoring SLA should sit with the party that actually operates the monitoring.
Does DSE run a SOC or provide managed detection?
No. DSE provides security leadership, assessment, and readiness advisory work, and orchestrates managed providers on a vendor-neutral, documented basis with any referral relationship disclosed. Continuous monitoring and detection are delivered by a provider the client contracts; DSE scopes the requirement, manages the relationship, and translates the output for the board. DSE does not perform live digital forensics or commodity penetration testing.
What this guide is / What it is not
What it is: A practitioner RACI for dividing security responsibility across fractional leadership, managed IT, and managed detection, anchored to NIST CSF 2.0 GOVERN subcategories GV.SC-02 and GV.SC-08 (NIST CSWP 29, February 26, 2024) and CISA’s Cross-Sector Cybersecurity Performance Goals 2.0. What it is not: Legal advice, an audit, a certification, or a guarantee of any security, compliance, or insurance outcome. DSE provides advisory security leadership and does not operate a 24/7 SOC or managed detection and response, does not provide live digital forensics, and does not assume any provider’s detection or response SLA. Statutory officer responsibilities and risk-acceptance decisions remain with the client. DSE holds no vendor partner, reseller, or certification status; provider selection is vendor-neutral and any referral relationship is disclosed.
The Bottom Line
Write the RACI before you write the next check. Direction, estate operation, and detection are three jobs, and the failures cluster at the seams between them rather than inside any one of them — an MSP adjudicating a risk trade-off it was not hired to own, an MDR alert waiting on an authority nobody assigned, three reports and no consolidated evidence. Fix the seams by naming an owner for each row, including the two rows most organizations leave blank: who performs live digital forensics, and who accepts residual risk.
Key facts
- NIST Cybersecurity Framework 2.0 subcategory GV.SC-02 requires that cybersecurity roles and responsibilities for suppliers, customers, and partners are established, communicated, and coordinated internally and externally (NIST CSWP 29, February 26, 2024).
- CISA's Cross-Sector Cybersecurity Performance Goals 2.0 realigned the goal set to the NIST CSF 2.0 GOVERN Function and added net-new goals covering cybersecurity oversight, risks associated with managed service providers, the principle of least privilege, and incident communication procedures (CISA, 2026).