Back to Blog
SOC vs EDR vs MDR: Choosing Cybersecurity Services in Nairobi
Cybersecurity

SOC vs EDR vs MDR: Choosing Cybersecurity Services in Nairobi

October 11, 2026GashoTech Team

SOC vs EDR vs MDR: Choosing Cybersecurity Services in Nairobi



Somewhere between a vendor pitch in Westlands and a procurement meeting in Upper Hill, a Kenyan company trying to tighten its security posture gets handed three acronyms at once: SOC, EDR, MDR. They show up in the same proposals and get used as though they mean the same thing. They do not, and the differences decide who is watching your systems at 2am and what they can actually do about it.

This piece explains what each one is, how the three fit together, what suits a growing SME versus a bank or a telco, and what to ask any provider before the contract is signed.

The three, explained



A Security Operations Center (SOC) is a function, not a product. It is a team of analysts working with tooling (log collection, alerting, correlation, case management) whose job is to watch an environment continuously, decide which alerts are real, and escalate what matters. A SOC can be built in-house, rented from a provider, or split between the two. Plenty of companies run a small internal team and lean on an external one overnight. That is still a SOC, as long as someone is clearly watching.

Endpoint Detection and Response (EDR) is software installed on devices: laptops, servers, workstations. Traditional antivirus matches files against known signatures. EDR watches behaviour. A process that suddenly encrypts hundreds of files, an office macro that spawns a command shell, a login from Nairobi followed minutes later by another from a different continent. When it spots something, it can isolate the device, kill the process, and leave behind a record an analyst can read afterwards. EDR protects the endpoint. On its own it tells no one what happened across the rest of your estate.

Managed Detection and Response (MDR) is a service. Someone else runs the monitoring, triages the alerts, and, the part the name insists on, responds. Response means defined actions: isolating a compromised laptop, disabling an account, rolling back a change, then calling your team with a timeline and a recommendation. MDR usually bundles EDR tooling, log analysis and a SOC team into one subscription.

The overlap is what causes the confusion. EDR is a tool. A SOC is a team and a way of working. MDR is a service that typically makes use of both.

How the three fit together



They layer on top of one another. EDR gives you visibility and control at the device level and produces the raw evidence: which process did what, when, and from where. The SOC layer reads that evidence alongside firewall logs, identity events, email security alerts and cloud activity, and works out whether the pattern across them means something. MDR is the arrangement that puts all of it into someone else's hands with a contract attached.

An organisation can run EDR with no SOC. Plenty do, and the familiar result is alerts that arrive by email and sit unread until Monday morning. A SOC without EDR is half-blind, because the analysts lack detailed endpoint telemetry to work from. The layers need each other.

When they work, an incident unfolds like this. EDR flags suspicious behaviour on a finance laptop at 1:40am. The SOC correlates it with a mailbox rule created an hour earlier. The response team isolates the machine, disables the account, and sends a written summary before the workday starts. That sequence, happening without your staff in the room, is what a managed service is really selling.

What 24/7 monitoring actually includes



The phrase appears on nearly every proposal, so definitions matter. Around-the-clock coverage should mean analysts on shift at all hours, not a server that is always on. It should mean defined triage: every alert gets a decision, false positives get tuned out over time, and anything genuinely suspicious reaches a human within minutes. It should mean a documented escalation path naming the people at your company who get called, and a channel that works at night. A phone call, not a ticket queue.

It should also mean retention. Alerts, timelines and analyst notes kept for a defined period, because those records are what you show an auditor, an insurer or a regulator after an event. Ask what the retention window is and what format the evidence arrives in.

What fits which business size



For a small or mid-sized Kenyan company, a firm of 30 to 200 people with a lean IT team, building a SOC in-house rarely makes sense. The cost shape does not work: analysts are salaried, shifts need several of them, and the tooling is priced for larger estates. For most SMEs the sensible combination is EDR on every device plus an MDR contract. You get the tooling and the coverage without hiring a night shift.

Larger organisations — banks, insurers, telcos, public institutions — usually need an internal security function regardless, because accountability has to sit inside the organisation. The question for them is different: which shifts to keep in-house and which to extend to a managed provider, overnight or for surge capacity. A hybrid SOC, internal analysts by day and a partner covering nights and weekends, is a common shape here.

Regulated sectors carry a further constraint. Where the Central Bank of Kenya or a sector regulator expects a particular level of assurance, ownership of the security function cannot simply be outsourced. The work can be. The responsibility cannot.

How to evaluate a Nairobi provider



Local presence matters for practical reasons. When an incident is live, you want someone who can reach your office, who understands the connectivity and power realities your sites run on, and who can sit across the table when the board asks what happened. GashoTech is one Nairobi-based provider offering cybersecurity services alongside broader ICT services, and on-the-ground availability is worth weighing against any proposal, local or international.

Before you sign, get answers in writing.

Who triages the alerts? An in-country team, an offshore follow-the-sun arrangement, or a partner you have never met. All are workable. None should be a surprise after the contract is signed.

What are the response times, and what do they apply to? A response-time commitment means little unless the contract defines severity levels and what happens when a threshold is missed.

What does response authorise? Some contracts let the provider isolate a device immediately. Others require your approval first, which costs time at exactly the moment time matters most. Decide which one you want.

What evidence will we receive? Ask for a sample incident report. The quality of that document is a fair guide to the quality of the service.

What happens if we leave? Data export, log handover, and how quickly the tooling comes off your devices. Better to ask before signing than during offboarding.

The compliance angle



The Kenya Data Protection Act, 2019 makes security controls a legal expectation. It requires appropriate technical and organisational measures for personal data, and it obliges organisations to notify the Office of the Data Protection Commissioner within 72 hours of becoming aware of a breach that poses a real risk to people. Notification requires knowledge, and knowledge requires monitoring.

That is the practical link between these services and compliance. EDR telemetry and SOC timelines are what let you establish what happened, which records were touched, and when. Those are the three questions every breach assessment starts with. When you speak to a provider, ask what their reporting gives you to support an ODPC notification, and whether their retention windows match the periods your own data protection documentation promises. A provider who answers that clearly has done this before.

Questions buyers ask



Can we start with EDR and add MDR later?



Yes, and many companies do exactly that. Deploying EDR first builds the device visibility an MDR provider will need anyway and shortens onboarding later. Check that whichever EDR you choose integrates with the MDR services you might want, since tooling lock-in is real.

Is an in-house SOC ever the right call for a Kenyan company?



For organisations large enough to keep analysts busy across several shifts and willing to pay to retain them, yes. The deciding factors are estate size, regulatory expectation, and how central security is to the business itself.

What does 24/7 coverage cost?



Providers price it either per endpoint per month or as a managed retainer covering the whole service. Per-endpoint pricing scales with your device count and is easier for a smaller firm to model. Retainers bundle tooling, people and response into one number on one invoice. Either way, ask what is excluded. On-site response, forensic investigation after an incident and formal compliance reporting are the usual extras.

What should we have ready before onboarding?



An asset inventory, a list of critical systems, current admin accounts, and named escalation contacts. Providers onboard faster and tune alerts better when they know what matters to you. That first-month clean-up, removing stale devices and closing old accounts, carries a good deal of the value.

Want to learn more?

Contact GashoTech for personalized consultations on AI, automation, and cybersecurity solutions.

Get in Touch