Every MSP in South Africa eventually gets asked to provide 24/7 security monitoring, and most say yes before working out what round-the-clock cover actually costs. A staffed security operations centre needs somewhere between eight and twelve analysts to run three shifts with leave cover. This is the arithmetic behind that decision, what managed XDR replaces, and the specific questions to ask a vendor before you put your own brand on their service.
What is managed XDR?
Managed XDR is extended detection and response delivered as a service, where a vendor’s security operations centre does the monitoring, triage and response rather than your own staff. The detection technology spans endpoints, servers, email, network and cloud identity, and the managed layer is the part that matters commercially: someone else is awake at 03:00.
XDR differs from endpoint detection and response in scope. EDR watches endpoints. XDR correlates signals across several layers, so a suspicious login in cloud identity plus an unusual process on a laptop becomes one incident rather than two unrelated alerts nobody connects.
For an MSP the distinction that counts is not the acronym. It is whether alerts arrive as work you must do or as incidents somebody has already investigated.
What does running your own SOC cost?
Continuous cover needs three shifts, seven days a week, plus leave and attrition headroom. In practice that means a minimum of eight analysts and realistically closer to twelve before the rota stops breaking every time someone takes a week off.
South African security analyst salaries make that a seven-figure annual commitment before tooling, and the tooling is not cheap either. A SIEM, log storage, threat intelligence feeds and the integration work to make them talk to each other.
Then there is the part nobody budgets: analyst churn. Security analysts are scarce and mobile, and an MSP that trains them competes with banks for retention. A SOC that loses two of its eight analysts is no longer a 24/7 SOC, but the client contract still says it is.
The honest answer for most South African MSPs is that building is the wrong call unless security monitoring is the core business rather than an attachment to it. Buying capacity and reselling it is how the numbers work at the scale most local partners operate at.
What should you ask a managed XDR vendor?
Ask for the response SLA in writing, by severity, and ask what “response” means. There is a large difference between a vendor that emails you an alert and one that isolates the device itself.
Barracuda publishes theirs: high-risk incidents responded to within 20 minutes, medium within one hour, low within eight hours, with SLA compliance stated at over 96%. Their SOC runs follow-the-sun across US, EMEA and APAC operations, correlating against 11 billion indicators of compromise, and response actions include isolating devices, suspending accounts and terminating processes.
SonicWall publishes a different kind of number for SonicSentry MXDR: an average SOC response time of four minutes, rather than a target by severity. The service is sold in parts, with SonicSentry MDR for Endpoint, MDR for Cloud and MDR for Network available individually or together, billed monthly with no contracts and no minimums.
Notice that the two figures do not measure the same thing. An average tells you what usually happens, and a severity SLA tells you what the vendor commits to when it does not. Ask each vendor for the number the other one publishes.
That last list is the one to interrogate. A SOC that can only notify is a paging service. A SOC that can act has to be trusted with privileged access to your clients’ environments, which is a conversation you need to have with the client before the incident, not during it.
Ask three more things. What happens to the data, and where is it stored. Whether you can white-label the service or whether the client sees the vendor’s brand. And what the escalation path looks like at 02:00 on a Sunday in South African time, given the vendor’s nearest operations centre is probably in EMEA.
If you want that comparison done against your own client mix, you can speak to our team about partner enablement before you commit to a platform.
Why are South African MSPs being asked for this now?
Client boards started asking after the sustained run of South African breaches made data compromise a business-risk agenda item rather than an IT one. POPIA’s section 22 breach notification duty turned a technical incident into a regulatory one, and a business that must notify the Information Regulator wants evidence it was monitoring in the first place.
The threat data supports the demand. SonicWall’s 2026 Cyber Protect Report found that 88% of breaches at small and medium businesses involved ransomware in 2025, with average breach detection running at 181 days and average SMB breach cost at $4.91 million. High and medium severity attacks rose 20.8% to 13.15 billion hits.
Detection time is the number that sells monitoring. A business that finds out six months late has already lost the data, and no backup strategy recovers a reputation.
WORKING OUT WHETHER TO BUILD OR BUY?
We help South African partners size managed detection against their real client base and margin targets.
Start my partner enquiry
How does managed XDR fit an existing MSP stack?
Managed XDR sits above the tools you already sell rather than replacing them. Email security, firewalls and backup stay where they are, and XDR consumes their telemetry.
That ordering matters for margin. An MSP selling managed detection on top of an existing security stack is adding a recurring line to an existing account, which is far cheaper than winning a new one. It also makes the existing products stickier, because the monitoring only works while the client keeps the underlying tools.
Both vendors Loophold distributes offer the service, and the choice usually follows the stack you already sell. Barracuda Managed XDR sits alongside Barracuda RMM for remote monitoring and management, and our Barracuda MSP programme page sets out what is available to South African partners.
SonicWall’s SonicSentry MXDR is the one to evaluate first if your clients already sit behind SonicWall firewalls, because it adds the SOC from the vendor whose network kit you already manage. Our SonicWall MSSP programme page covers the partner side.
Worth being clear about one thing. Adding a SOC does not reduce your obligations to the client, it formalises them. The contract needs to say what the SOC does, what you do, and what the client must do, because the gap between those three is where every post-incident argument happens.
What does this mean for a partner deciding this quarter?
Start by pricing the service you would have to deliver if the client said yes tomorrow. Most MSPs discover the monthly fee they had in mind does not cover a single analyst, let alone a rota.
Then decide whether security monitoring is a product you sell or a business you are in. Those are different companies with different economics, and the second one takes years to build. Most South African partners are better served buying the capability, wrapping it in their own service and support, and competing on the relationship rather than the SOC.
READY TO ADD MANAGED DETECTION TO YOUR PRACTICE?
Loophold distributes Barracuda and SonicWall to South African MSPs, with the enablement and training behind it.
Become a Loophold partner




