A managed security services provider (MSSP) runs your security program for you: it deploys and configures the controls, monitors them around the clock, responds when something fires, and produces the evidence you hand to an auditor, an insurer, or a client’s security questionnaire. The difference from a managed service provider (MSP) is scope. An MSP keeps your technology working. An MSSP is accountable for keeping it defended.
Be Structured is both, which is why most of our Los Angeles clients buy one relationship instead of two.
Los Angeles based since 2007 · Channel Futures MSP 501 ranked · CA License #1140088
What does an MSSP actually do?
Four functions, in this order:
Implement. Put the controls in place and configure them properly. Most environments we inherit have licensed capability nobody turned on.
Monitor. Watch the output continuously, including nights and weekends. Anomalies generate a prioritized ticket within 60 seconds of detection.
Respond. Act on the alerts that are real, with containment authority agreed in writing in advance so nobody is waiting on a decision at 2 a.m.
Evidence. Produce the logs, reports and documentation that prove the first three happened.
Our MSSP work covers the implementation, configuration and supervision of the following, on top of our all-inclusive managed services:
- Advanced firewalls with hardening services
- Security Information and Event Management (SIEM) systems
- Active Directory monitoring
- 24/7 Security Operations Center (SOC)
- Anti-spam with Data Loss Prevention (DLP)
- Intrusion prevention systems (IPS)
- Mobile device management (MDM)
- Web content filtering
- Identity and access management (IAM)
- Multi-factor authentication
- Windows device hardening services
- Information security policy and implementation services
- Internal and external penetration testing and remediation
Alongside those controls, the ongoing service covers management of all security systems, log monitoring, device management, solution research and implementation, audits and reports, consultancy, security updates, and protection for remote workers.
We also run controls most providers leave out: penetration testing services, advanced endpoint protection, privileged access management, endpoint detection and response, and zero trust network architecture.
MSP vs. MSSP: what actually changes
The clue is the extra S. An MSP includes security as part of a general package. An MSSP is organized around it: an MSP typically runs a network operations center to keep systems available, while an MSSP runs a security operations center to keep them defended. Different queue, different skill set, different definition of a good day.
| MSP | MSSP | |
| Primary goal | Keep technology working | Keep technology defended |
| Core function | Network operations center | Security operations center |
| Typical alert | A server is down | An account signed in from two countries in an hour |
| Deliverable to a third party | Uptime reporting | Compliance and incident evidence |
| Who asks for it | Your staff | Your insurer, your auditor, your clients |
Be Structured is both an MSP and an MSSP. If you need both, everything stays under one roof and there is no argument about whose ticket it is.
Who needs an MSSP, and who is better served by an MSP alone?
You need the MSSP layer if you hold regulated data (healthcare, financial services, legal, taxpayer records), if clients or prime contractors send you security questionnaires, if you are renewing cyber insurance and the application asks about 24/7 monitoring and incident response, or if you have already had an incident and need to demonstrate that something changed.
Managed IT alone is enough if you are a small team on cloud-only tools with no servers, no regulated data, and no third party auditing you. Buy multi-factor authentication, managed endpoint protection and tested backups, and revisit when one of those conditions changes.
We would rather tell you that at the scoping call than sell you a security program you do not need yet.
What does an MSSP cost compared with hiring security staff?
Be Structured prices managed security per device, commonly $50 per device per month for the full stack: EDR with 24/7 SOC monitoring, multi-factor authentication, Windows Defender hardening and LAPS, spam and outbound email filtering, SPF, DKIM and DMARC management, dark web monitoring, quarterly internal and external vulnerability scanning, and Microsoft 365 backup with disaster recovery. Managed IT sits underneath at $125 to $300 per user per month depending on headcount and coverage depth. Project work outside the recurring scope is quoted in advance. The full breakdown is on our managed IT services cost page.
The hiring comparison is not one salary against one subscription. Round-the-clock coverage is 168 hours a week, which is 4.2 full-time people before anyone takes a vacation day, and security specialists in Los Angeles do not come at general IT rates. Below a few hundred employees the arithmetic rarely favors building it.
The subscription model also scales in both directions. Because it follows a per user and per device model, adding seasonal staff or pulling back after a project is a line change, not a hiring decision.
What changes on day one?
- Assessment. We count users, devices and servers, review your Microsoft 365 tenant and current security posture, and give you a written scope and a fixed monthly price before you commit.
- Deployment. Agents and monitoring go on every endpoint and server, usually inside one business day, with no disruption to your team.
- Escalation agreement. We agree in writing who we call at 2 a.m., and what we are pre-authorized to do without asking: isolate a host, disable an account, block an address.
- The first report. Within the first month you get a written picture of what is actually happening on your network, which is usually the first time anyone has looked.
Response commitments are in the service level agreement, not in the brochure. Ours documents response times by severity and what happens if a breach occurs.
How to evaluate an MSSP
- Ask what they do after hours, specifically. A dashboard is not a SOC. Ask for a target time to first human touch on a critical alert.
- Ask for the containment authority in writing. What can they do without you, at what severity.
- Ask what is included and what is billed separately. Penetration testing, compliance assessments and incident response hours are common carve-outs. Get the list before you compare two quotes.
- Ask for a sample monthly report. If you cannot read it, you will not read it.
- Ask about the compliance role. A good answer sounds like “we help you meet the requirements and document the controls; we are not the certifying body.” An answer that promises certification is a warning.
- Ask what happens on exit. Your log history, your agent licensing, and your documentation should not be hostage to a renewal.
Your Los Angeles MSSP
Be Structured has supported Los Angeles businesses since 2007 from 500 S. Grand Avenue, 22nd Floor, in Downtown LA, alongside the surrounding cities. We tailor security by industry, whether that is healthcare or the extra requirements financial services carry, and our other managed IT services in Los Angeles run from cloud migration to hardware installation under the same agreement. If you are weighing us against another provider, our page on outsourced IT support services lays out what the engagement includes.
➤ Get Your Free IT Assessment: contact Be Structured for a no-cost scoping assessment and a fixed monthly price, or call (323) 331-9452.
