This distinction matters more than it sounds. A vendor relationship is transactional - scoped deliverables, defined timelines, clean exit. An operator relationship is outcome-driven. We measure success by what actually changed: mean time to detect, compliance coverage percentage, incidents prevented, attack surface reduced. If the security posture didn't measurably improve, we didn't deliver - regardless of what the statement of work says.
Operating means we have skin in the game. When we design a monitoring architecture, we're the ones who have to live with the alert noise. When we write an incident response plan, we're the ones who have to execute it at 2 a.m. When we recommend a tool, we're the ones who have to integrate it, tune it, and prove it works in your specific environment.