Managed Security Services
MSS

In short
Managed security services means an external provider runs your security day to day – monitoring, detecting, responding – rather than selling you software and leaving. What separates it from antivirus is not the tooling but the commitment: somebody is watching, including at three in the morning, and the contract states how fast they act on what they see.
Why tools on their own fall short
An intrusion almost always leaves traces before it does damage: an account signing in from another country, a service writing data out at night. The tools flag this already – nobody reads it.
That gap is what a managed security service closes. It does not buy better software; it buys the attention that turns an alert into a response.
Four acronyms worth keeping apart
SIEM collects logs and spots patterns across them. EDR sits on the individual device and stops suspicious behaviour there. SOC is the team operating both. MDR is the arrangement where that team is allowed to act, not merely notify.
For a smaller company the last distinction matters most. A service that only notifies has moved the problem into your evening.
What the contract has to state
Three commitments, or it is a subscription without effect. Detection time: how long may something run unnoticed? Response time: within what window does someone act, not just report? Authority to intervene: may the provider lock an account or isolate a device without asking first?
The third one decides hours in a live incident. Leave it open and you have bought a service that watches.
For companies operating in Switzerland
Since 1 April 2025, operators of critical infrastructure have had a duty to report cyberattacks to the Federal Office for Cybersecurity within 24 hours of discovery (Information Security Act, SR 128, Art. 74a ff.). Companies outside that scope are not exempt from reporting altogether: the revised Data Protection Act requires notification to the FDPIC under Art. 24 once a security breach poses a high risk to the people affected.
Both presuppose that an incident is noticed in the first place. A reporting duty without monitoring is a duty you cannot discharge.
How we handle it
ALPENIQ IT starts with what is already there – most companies have licensed more protection than they have switched on. Additional services are the question after that, not before it.
How we work: IT security, managed IT and backup and cloud.
A term in your quote that nobody explained?
In a strategy call we translate the offer in front of you – even when it did not come from us.