24/7 Managed SOC and MDR Services in Canada | North Star
HomeCybersecurityMDR and Managed SOC

MDR and managed SOC for Canadian businesses

MDR stands for managed detection and response: a service where someone else's security analysts watch your systems around the clock and act when something is wrong, rather than sending you an alert and wishing you luck. A managed SOC is the team doing that watching. This page explains what the acronyms actually mean, how MDR differs from the EDR and SIEM you may already own, the arithmetic of buying it versus building it, and what North Star charges: $1,500 to $5,000 per month for a BC, Alberta or Yukon SMB.

The short answer

What is MDR, and what is a managed SOC?

MDR is an outcome: detection and response, delivered as a service, with humans in the loop. A SOC, or security operations centre, is the staffed function that produces that outcome. When a provider sells you MDR, what you are buying is access to their managed SOC, plus the tooling it runs on and a contractual commitment about what happens when something fires at three in the morning.

The four acronyms that get sold interchangeably, and what each one actually is.
 What it isWho acts on itWhat it misses on its own
EDRSoftware on each laptop and server that spots malicious behaviourNobody, unless someone is watching the consoleAnything that does not touch an endpoint: cloud logins, email rules, a firewall change
SIEMA place logs are collected and correlatedNobody. A SIEM produces alerts, not decisionsEverything, without analysts. An unwatched SIEM is an expensive disk
XDREDR extended across cloud, identity and email, correlated in one placeStill nobody, unless staffedThe staffing. XDR is better telemetry, not a service
MDRThe above, plus analysts who triage and respond on your behalfThe provider's SOC, to an agreed mandateNothing structural. The question becomes how good the SOC is

The practical point: buying more tooling does not close the gap that matters. Most Canadian SMBs that get breached had security software installed and nobody reading what it said. The gap is attention at 2am, not licences.

Cost

What does MDR cost, and what does building it yourself cost?

North Star's managed SOC runs $1,500 to $5,000 per month for an SMB in BC, Alberta or Yukon, scaling with users, endpoints and the volume of log data ingested. The reason that range beats an in-house alternative is not tooling. It is that 24 by 7 coverage is a staffing problem before it is a technology problem.

The arithmetic

Round-the-clock needs more than three people.

168 hours a week, allowing for holidays, illness and turnover, is conventionally five to six full-time analysts. At Canadian security salaries that is a payroll line most businesses under 500 staff will never justify for one function.

The arithmetic

One analyst is worse than none, almost.

A single security hire gives you weekday daytime coverage and a single point of failure, and attackers deploy ransomware overnight and on long weekends precisely because that is when nobody is looking.

The arithmetic

Shared analysts see more.

A SOC watching many environments recognises a campaign on its third appearance. An in-house team sees each attack once, for the first time, at the worst moment. That pattern exposure is the part you genuinely cannot buy alone.

Where in-house does make sense: a regulated organisation with data-residency constraints that forbid a third party holding logs, or one large enough that a security team has more than one job. Below that, MDR is not a compromise, it is the better answer.

What actually happens

What a managed SOC does with an alert

The value is in what happens between an alert firing and someone deciding it is nothing, because roughly ninety-something percent of alerts are nothing and the cost of treating them all seriously is what defeats in-house teams.

1

Collect, from more than endpoints.

Endpoint telemetry, Microsoft 365 and Entra ID sign-ins, firewall and VPN logs, and cloud audit trails. Identity is where most SMB compromises now begin, and it never appears on an endpoint console.

2

Triage, so you never see the noise.

An analyst decides whether an alert is benign, suspicious or real, using context an automated rule does not have: that this user does travel, that this script is your own, that this login at 4am is a scheduled job.

3

Respond within an agreed mandate.

Isolate the machine, disable the account, block the address, kill the session. Agree in advance what the SOC may do without asking, because a call for permission at 3am is a delay measured in encrypted files.

4

Hunt, and report so it is auditable.

Proactive threat hunting for what the rules missed, plus monthly reporting written for an insurer or an auditor rather than for another engineer.

Two numbers to ask any MDR provider for: mean time to detect and mean time to respond, and whether those are measured to the first automated alert or to a human decision. Providers quote them very differently, and the difference is where the marketing lives.

Questions to ask

How to tell real MDR from an alert forwarder

The commonest disappointment in this market is paying MDR prices for a service that emails you a notification and considers its job done. Five questions separate them.

Ask

Will you act, or notify?

Get the response mandate in writing: what the SOC will do unilaterally, at what hour, and how fast. If everything requires your approval first, you have bought monitoring rather than response.

Ask

Are the analysts people or a rule set?

Ask how many analysts are on shift overnight in the timezone that covers you. Automated response is genuinely useful and it is not the same as a human deciding, and only one of those two is what MDR means.

Ask

Where do the logs live?

Data residency matters for Canadian organisations with privacy obligations or public-sector customers. Ask which country the log data is stored in and for how long. See data residency in Canada.

Ask

What is out of scope?

Most MDR covers detection and containment, not remediation, forensics or rebuilding. Know which side of the line recovery sits on before an incident, not during one.

Ask

Can we leave?

Notice period, and whether you keep your historical log data on the way out. Security telemetry you cannot export is a switching cost dressed up as a feature.

North Star's SOC runs on Huntress and SentinelOne rather than a platform we built ourselves, and we say which because a provider unwilling to name its stack is usually reselling something it would rather you did not price independently.

Why now

What is pushing Canadian SMBs to buy MDR

Trigger

Cyber insurance renewals.

Applications increasingly ask about 24 by 7 monitoring alongside MFA and tested backups. Answering accurately matters more than answering well, because a misrepresented control is a reason for a declined claim. See cyber insurance requirements.

Trigger

A customer security questionnaire.

Enterprise and public-sector procurement asks whether security events are monitored continuously. A managed SOC with monthly reporting is the straightforward way to answer yes and show it.

Trigger

An incident, theirs or a peer's.

Most enquiries arrive the week after something happened to someone nearby. If that is you, start with incident response; MDR is what stops the second one.

Trigger

Nobody is reading the console.

The commonest honest reason. EDR was bought, it works, and no human has opened it in four months. Getting someone to watch what you already own is cheaper than another tool.

Honest limits

What MDR will not do

Not covered

It does not prevent the phishing email.

MDR catches what happens after someone clicks. Reducing the clicking is awareness training and email filtering, and it is a separate line item.

Not covered

It does not replace backups.

Detection shortens an incident. Recovery still depends on a restore that has been tested. See backup and disaster recovery.

Not covered

It does not fix the basics for you.

MFA gaps, local admin rights and unpatched servers are still yours to close. A SOC watching a badly configured environment spends its time on incidents that should not have been possible.

If you are not sure which of those applies to you, the free assessment scores seven domains against CIS Controls v8 and comes back in a business day. It touches no systems and needs no credentials, and it will tell you whether MDR is your next spend or your third.

Find out whether MDR is your next spend

Tell us what security tooling you already own and who is watching it. If the answer is that you own enough and nobody is reading it, that is a short and useful conversation.

Start the free assessment Back to Cybersecurity

Frequently asked questions

What does MDR stand for?

MDR stands for managed detection and response. It is a service in which a provider's security analysts monitor your systems around the clock, decide whether alerts are real, and take containment action on your behalf rather than forwarding a notification for you to deal with. The team doing that work is a security operations centre, or SOC, so managed SOC and MDR describe the same arrangement from two angles: MDR is the outcome you buy, and the managed SOC is the function that delivers it.

What is the difference between MDR and EDR?

EDR is software. It sits on laptops and servers and spots malicious behaviour, and it acts on nothing unless a human is watching its console. MDR is a service that includes tooling like EDR plus the analysts who triage and respond. The practical difference is who acts at 2am. Most Canadian SMBs that get breached already had endpoint software installed and nobody reading what it reported, so the gap MDR closes is attention rather than licences.

How is MDR different from a SIEM or XDR?

A SIEM collects and correlates logs and produces alerts; it makes no decisions, so an unwatched SIEM is an expensive disk. XDR extends endpoint detection across cloud, identity and email and correlates it in one place, which is better telemetry rather than a service. Neither includes staffing. MDR is the layer that adds analysts with a mandate to act, which is why buying more tooling does not close the gap that actually matters.

How much does a managed SOC cost for a Canadian SMB?

North Star's managed SOC runs $1,500 to $5,000 per month for an SMB in BC, Alberta or Yukon, scaling with users, endpoints and the volume of log data ingested. The comparison worth making is not against another product but against staffing it yourself: genuine 24 by 7 coverage allowing for holidays, illness and turnover conventionally needs five to six full-time analysts, which at Canadian security salaries is a payroll line most businesses under 500 staff will never justify for one function.

Can we just hire a security person instead?

One hire gives you weekday daytime coverage and a single point of failure, and attackers deploy ransomware overnight and on long weekends precisely because that is when nobody is looking. There is also a subtler advantage to a shared SOC: a team watching many environments recognises a campaign on its third appearance, whereas an in-house team meets each attack once, for the first time, at the worst possible moment. In-house genuinely makes sense for regulated organisations whose data-residency rules forbid a third party holding logs, or organisations large enough that a security team has more than one job.

Will the SOC act on its own, or just tell us?

That is the single most important question to ask any MDR provider, and it should be answered in writing before you sign. Get the response mandate documented: what the SOC may do unilaterally, at what hour, and how quickly. Isolating a machine, disabling an account, blocking an address and killing a session are the usual pre-authorised actions. If every action needs your approval first, you have bought monitoring rather than response, and a call asking permission at 3am is a delay measured in encrypted files.

Where is our log data stored?

Worth asking every provider, including us, because it matters for Canadian organisations with privacy obligations or public-sector customers. Ask which country log data is stored in, how long it is retained, and whether you can export your history if you leave. Security telemetry you cannot take with you is a switching cost dressed up as a feature. North Star's SOC runs on Huntress and SentinelOne, and we name the stack because a provider unwilling to do so is usually reselling something it would rather you did not price independently.

Does MDR mean we can stop worrying about backups and training?

No, and treating it that way is the commonest expensive mistake. MDR catches what happens after someone clicks; reducing the clicking is awareness training and email filtering. Detection shortens an incident, but recovery still depends on a restore that has actually been tested. And MFA gaps, local administrator rights and unpatched servers remain yours to close, because a SOC watching a badly configured environment spends its time on incidents that should never have been possible.

What does MDR not include?

Most MDR covers detection and containment rather than remediation, forensics or rebuilding, and you want to know which side of that line recovery sits on before an incident rather than during one. Ask specifically whether post-incident forensics, system rebuilds and insurer or regulator reporting are in scope or quoted separately. North Star handles those under incident response, which is a distinct engagement from the monthly SOC service.