If you’ve sat through a security sales pitch lately, you’ve probably been hit with a wall of acronyms. EDR. MDR. SOC. SIEM. They get used almost interchangeably, often by people who are hoping you won’t ask what the difference is. Then a quote shows up with a few of them as line items, and you’re left wondering whether you’re buying four things, one thing four times, or something in between.
We get this question constantly, and it’s a fair one. So let’s take the jargon apart in plain English, and then talk about which of these a real small or mid-sized business actually needs.
EDR: the guard on each computer
EDR stands for Endpoint Detection and Response. An endpoint is just any device your people work on, a laptop, a desktop, a server.
Think of EDR as a smart security guard posted on each machine. Old-style antivirus worked from a list of known criminals: if a file matched a known piece of malware, it got blocked, and anything new walked right through. EDR watches behavior instead. If a Word document suddenly tries to launch a scripting tool, or a process starts encrypting hundreds of files in a row, EDR recognizes that pattern as dangerous, stops it, and can isolate the device so the problem does not spread. The federal Cybersecurity and Infrastructure Security Agency points to this kind of behavior-based endpoint protection as a baseline for modern defense.
EDR is a tool. It is software running on a device. That distinction matters for the next acronym.
SOC: the humans watching everything
A SOC, or Security Operations Center, is not a tool at all. It is a team of people. A SOC is a group of security analysts who watch your environment around the clock, look at the alerts your tools are generating, decide which ones are real, and respond when something is wrong.
This is the layer that turns alerts into action. EDR on its own can flag something suspicious at 2 a.m. on a Saturday, but if nobody is awake to see it, the alert just sits there. Attackers know this, which is why they favor nights, weekends, and holidays. A SOC closes that window. When the right team is watching, a four-hour incident becomes a four-minute one.
This is also where we have to be honest about a thing the industry would rather you not examine too closely. “24/7 SOC” on a quote can mean a local team that knows your business, or it can mean alerts forwarded to an anonymous, unaccountable desk that has never spoken to you. If you want to know how to tell the difference, we wrote a whole piece on how to tell a real SOC from a relabeled offshore queue. At Vicinity, the people watching your environment are part of our own accountable, US-based team, backed by local technicians here in Alaska and Hawaii, because we believe humans should be enhanced by technology, not handed off to an offshore desk that has never spoken to you and doesn’t own the outcome.
SIEM: the central logbook
SIEM stands for Security Information and Event Management. If EDR is the guard on each computer, the SIEM is the central command room where every guard’s report lands.
Your firewall, your servers, your cloud services like Microsoft 365, your endpoints, all of them constantly generate logs of who did what and when. A SIEM collects those logs in one place, correlates them, and raises a flag when the pattern across systems looks like an attack. A single failed login is nothing. A single failed login on the firewall, followed by a successful login from an unusual country, followed by a mailbox rule that forwards all email somewhere strange, that is a story, and the SIEM is what stitches those events into one.
A SIEM by itself is just a very expensive logbook. It needs people, the SOC, to read it and act. The two work together.
MDR: the whole thing as a service
MDR stands for Managed Detection and Response, and this is the one that ties the rest together. MDR is not a separate gadget. It is the service that combines the tools and the people into one outcome you can actually buy.
A good MDR offering typically gives you EDR on your devices, a SIEM collecting and correlating your logs, and a SOC of human analysts watching and responding, all delivered and managed for you. You are not buying four products and hoping they talk to each other. You are buying a result: someone is watching, and someone will act.
Here is the simplest way to hold the four in your head:
- EDR is a tool on each device.
- SIEM is a tool that centralizes all the logs.
- SOC is the team of humans watching.
- MDR is the service that wraps the tools and the team into one thing.
What a small business actually needs
You don’t need to assemble these yourself like a hobby project, and you should be cautious of any provider who hands you a stack of disconnected tools and calls it security. For most small and mid-sized businesses, the practical answer is a managed service where the tooling and the human monitoring come together, with people you can actually reach.
That’s the heart of how we think about layered protection in our People+ Framework: tools and trained people working together so that when one layer is bypassed, the next one catches the problem. You can see how it fits into our full approach to cybersecurity for small business.
Where to start
If a quote you’re holding lists some of these acronyms and you’re not sure whether you’re getting the full picture or paying for overlap, bring it to us. We’re happy to translate it, point out what’s missing, and tell you honestly whether you need everything on the page. Book a short call and we’ll walk through it with you, no sales theater.