shipping production AI · since 2026 NAICS 541330 / 541511 / 541512 / 541519  ·  CMMC-aware
Refinery Report / Cybersecurity / post · s-what
CybersecuritySecurity LeadershipFractional CISOVendor Management

vCISO vs MSP vs MDR: Who Owns What

A RACI for the three roles growing firms buy in the wrong order: who sets direction, who runs the estate, who watches the alerts, and where accountability actually sits.

D
By the DSE practice team
Operator-led practice · how we research & review
July 19, 2026
11 min · 2,398 words

By the DSE practice team · published July 19, 2026 · reviewed July 19, 2026

The three roles get confused because all three are sold as “security,” but they answer different questions. A vCISO answers what should we do and in what order. An MSP answers who runs and patches the estate. An MDR provider answers who is watching at 2am and what happens when something fires. Buying two of the three and assuming the gap is covered is the most common structural mistake we find in growing firms — usually discovered during an incident, or during a customer’s diligence review.

Here is the division of labor, written as a RACI rather than as marketing categories, plus the specific gaps that appear at each seam.

The RACI

Function vCISO / security leadership MSP / managed IT MDR / managed detection The organization
Risk register ownership Owns Contributes Contributes Accepts residual risk
Security roadmap and sequencing Owns Executes assigned items Funds
Policy set and exceptions Owns Applies technically Approves
Endpoint build, patching, estate hygiene Sets the standard Owns (operates) Approves change windows
Identity administration Sets the standard Owns (operates) Approves privileged access
Backup operation and restore testing Sets objectives, reviews evidence Owns (operates) Owns the RTO/RPO decision
24/7 monitoring, detection, triage Scopes the requirement Feeds telemetry Owns (operates) Contracts the service
Alert response and containment actions Directs readiness Executes assigned actions Executes per its SLA Executes internal steps
Live digital forensics after a breach Directs the plan Per contract, sometimes Contracts a DFIR specialist
Vendor and provider selection Owns the process Advises Advises Signs the contract
Board and customer reporting Owns Supplies data Supplies data Presents
Regulatory and contractual obligation mapping Owns the mapping Owns the legal determination with counsel

Two columns in that table are load-bearing and usually left blank in practice: live digital forensics and residual risk acceptance. DFIR is a specialist capability that neither an advisory relationship nor a standard IT contract provides; it needs a named firm and an engagement basis before an incident. Residual risk acceptance is a fiduciary act that stays with the organization’s officers no matter who advises them — a point worth putting in writing in any leadership retainer.

If it helps to mark this division of labor up against your own providers, we keep a printable one-page version in the vCISO vs MSP vs MDR comparison.

Why the seams are where things break

Seam one: MSP and security direction. An MSP is measured on availability and ticket resolution. That is a legitimate and different objective from reducing risk, and it produces predictable friction: MFA that would generate helpdesk volume, privileged access that would slow provisioning, legacy protocol blocks that would break a line-of-business app. None of that is bad faith; it is the incentive structure. A vCISO’s job at this seam is to set the standard and own the exception decision so the MSP is not adjudicating a risk trade-off it was not hired to own.

Seam two: MDR and response authority. An MDR provider detects and, depending on contract, contains. What it usually cannot do is decide whether to take a revenue system offline at 4pm on quarter-end. If nobody has pre-agreed that authority, the alert sits in a queue while someone finds an executive. This is the seam that turns a fifteen-minute detection into a four-hour incident, and it is fixed with a decision-rights table rather than a better tool — see incident response planning without a security team.

Seam three: everyone and evidence. Three providers generate three reports in three formats on three cadences, and none of them is the artifact an insurer, an acquirer, or an enterprise customer asks for. Somebody has to own the consolidated evidence view; the default answer is nobody, until diligence forces the question.

CISA has been explicit that this class of dependency is its own risk category: the Cross-Sector Cybersecurity Performance Goals 2.0 added net-new goals covering cybersecurity oversight, risks associated with managed service providers, the principle of least privilege, and incident communication procedures, and realigned the whole goal set to the NIST CSF 2.0 GOVERN Function. The framework itself puts it in one line — CSF 2.0 subcategory GV.SC-02 requires that cybersecurity roles and responsibilities for suppliers, customers, and partners are established, communicated, and coordinated internally and externally, and GV.SC-08 requires that relevant suppliers and third parties are included in incident planning, response, and recovery activities.

Buying order

For a firm between 50 and 500 people with no internal security function, the sequence that avoids the most rework:

  1. Direction first, briefly. An assessment plus enough leadership to produce a sequenced roadmap. Without it, the next two purchases are chosen by whoever pitched most recently. A one-page roadmap changes what you buy and what you decline.
  2. Estate hygiene next. Patching, endpoint standard, identity administration, backup operation. Most of the risk reduction available to a mid-market firm lives here, and it is the cheapest tier. Detection layered over an unmanaged estate produces alert volume, not safety.
  3. Detection when there is something to detect with, and someone to act. MDR is worth its cost once the estate is managed, logging exists, and response authority is pre-agreed. Bought before those, it is an expensive way to learn that nobody is empowered to act at 2am.
  4. Leadership cadence to keep it true. The roadmap decays. Something has to own re-prioritization, provider performance review, and the reporting that goes to the board and to customers.

Firms that invert this — MDR first, direction never — end up paying for monitoring of an estate they have not hardened, with alerts routed to people who cannot authorize a response.

What to hold each provider to contractually

Where DSE sits, precisely

We are the direction layer. Our fractional CISO and security program leadership engagement owns the roadmap and risk register, runs the governance cadence, produces board reporting, supports diligence and questionnaires, plans budget, oversees remediation, and — importantly here — runs the selection and orchestration of managed providers on a vendor-neutral, documented basis, disclosing any referral relationship.

What we do not do: we do not operate a 24/7 SOC, we do not provide managed detection and response, we do not perform live digital forensics, and we do not inherit or guarantee a provider’s detection SLA. Continuous monitoring is delivered by a provider the client contracts; we scope the requirement, manage the relationship, and translate the output into decisions and reporting. That boundary is deliberate. A firm that both directs the program and claims to operate the monitoring has no independent party left to evaluate the monitoring.

If the immediate question is what to fix rather than who should own it, start with what a cybersecurity risk assessment includes and costs; if it is what your providers should be able to evidence, see the vendor security review checklist for SaaS buyers.

FAQ

What is the difference between a vCISO, an MSP, and an MDR provider?

A vCISO or fractional CISO owns security direction: the risk register, the roadmap, policy, governance cadence, board reporting, and provider selection. An MSP operates the IT estate — endpoint builds, patching, identity administration, and backup operation. An MDR provider operates continuous monitoring, detection, and triage, and executes containment actions within its contracted authority. They are complements, not substitutes.

Can our MSP be our security program?

Rarely, and not by default. An MSP is measured on availability and resolution time, which is a different objective from risk reduction, so security trade-offs that increase support volume tend to lose. An MSP can operate an excellent estate against a standard someone else sets and someone else audits. What it should not also hold is the exception decision, the risk register, or the residual-risk acceptance.

Do we need MDR if we have an MSP?

They cover different functions. An MSP maintains the estate; MDR watches it. Whether MDR is the right next spend depends on whether the estate is managed, whether the necessary logging exists, and whether response authority has been pre-agreed. Detection purchased ahead of those three produces alert volume rather than risk reduction.

Who is accountable when something goes wrong?

The organization. Advisory leadership provides direction and judgment, an MSP operates to a standard, and an MDR provider owns its own detection and response SLA — but statutory officer responsibilities and risk-acceptance decisions remain with the client’s officers. Any leadership retainer should say so in writing, and any monitoring SLA should sit with the party that actually operates the monitoring.

Does DSE run a SOC or provide managed detection?

No. DSE provides security leadership, assessment, and readiness advisory work, and orchestrates managed providers on a vendor-neutral, documented basis with any referral relationship disclosed. Continuous monitoring and detection are delivered by a provider the client contracts; DSE scopes the requirement, manages the relationship, and translates the output for the board. DSE does not perform live digital forensics or commodity penetration testing.

What this guide is / What it is not

What it is: A practitioner RACI for dividing security responsibility across fractional leadership, managed IT, and managed detection, anchored to NIST CSF 2.0 GOVERN subcategories GV.SC-02 and GV.SC-08 (NIST CSWP 29, February 26, 2024) and CISA’s Cross-Sector Cybersecurity Performance Goals 2.0. What it is not: Legal advice, an audit, a certification, or a guarantee of any security, compliance, or insurance outcome. DSE provides advisory security leadership and does not operate a 24/7 SOC or managed detection and response, does not provide live digital forensics, and does not assume any provider’s detection or response SLA. Statutory officer responsibilities and risk-acceptance decisions remain with the client. DSE holds no vendor partner, reseller, or certification status; provider selection is vendor-neutral and any referral relationship is disclosed.

The Bottom Line

Write the RACI before you write the next check. Direction, estate operation, and detection are three jobs, and the failures cluster at the seams between them rather than inside any one of them — an MSP adjudicating a risk trade-off it was not hired to own, an MDR alert waiting on an authority nobody assigned, three reports and no consolidated evidence. Fix the seams by naming an owner for each row, including the two rows most organizations leave blank: who performs live digital forensics, and who accepts residual risk.

Next step · find the blank rows

Thirty minutes to find out which rows have no owner.

Bring your provider list and your contracts. We will map who actually owns direction, estate, detection, forensics, and residual risk — and tell you where you are paying twice or not at all.

Key facts

Read next · AI Security & Governance

P
Founder · Principal Engineer
Data & AI engineer · 10+ yrs hands-on

Writes most of the long-form here. Lives in the codebase. Active on GitHub and LinkedIn.

§ Next step

Not sure which of these is you?

Tell us what's broken in a paragraph and a principal reads it directly — or walk the ladder from a low-commitment first engagement up to retained work.

One long-form a week. No marketing.

Subscribe to the Refinery Report. Practitioner deep-dives on AI engineering, security, and the realities of running production systems. Unsubscribe in one click.

~12 issues / quarter