In-house SOC versus managed detection: the honest comparison
For most organisations a fully staffed round-the-clock in-house team is not a budget question, it is a scheduling impossibility. Covering one seat continuously takes roughly five people once leave, sickness, training and turnover are accounted for, before you add a lead, an engineer to maintain the detections, and cover for the second seat you will need when two things happen at once. Recognising that early turns this into a design question about which parts to keep, which is a far more productive conversation.
When is an in-house SOC the wrong answer?
When you cannot staff the rota without relying on the same few people permanently. A continuously covered seat needs about five full-time staff on straightforward arithmetic: a week has one hundred and sixty-eight hours, a person works around forty, and the remainder of the gap is closed by holiday, illness, training and the vacancy that exists while you replace whoever left. Attempting it with three people produces a rota that works until the first resignation.
It is also wrong when the volume of genuine work will not sustain skilled staff. Night shifts in a quiet estate are professionally corrosive, and the people you hire for them leave for somewhere with more to do, which means you carry recruitment cost continuously. This is the reason many organisations that built a full team have since moved the overnight hours to a provider while keeping the daytime capability.
The case for building is different from the case usually made. It is strong where the estate is unusual enough that detection quality depends on knowing the applications, where regulatory or contractual constraints limit who may see the data, or where the same team also does engineering work that a provider would not do. It is weak when the driver is a preference for control, because control without staffing produces coverage on paper only.
What does the staffing arithmetic look like in full?
Take the five-per-seat figure and count what else is required for the function to work rather than merely to be occupied. Someone has to own detection engineering, meaning writing and maintaining rules, because otherwise the tooling degrades quietly. Someone has to run the platform, its ingestion and its costs. Someone has to lead, handle escalations and represent the function to the business. None of those are shift roles and all are unavoidable.
Then add the parts people forget when comparing to a quotation: tooling licences, log ingestion, the training budget that keeps analysts current, out-of-hours allowances, recruitment cost at the turnover rate this discipline actually sustains, and the productivity loss of the first several months while new staff learn an estate they have never seen. A build proposal that omits these will look competitive against a managed service and will not be.
Set against that, a provider is spreading the same rota across many customers, which is the entire economic argument for the model and it is a sound one. What they cannot spread is knowledge of your business, which is why the hybrid arrangement, in-house judgement with outsourced hours, is where most organisations of moderate size settle after trying one of the extremes.
Which model fits which situation?
The realistic options are not build or buy, they are five arrangements with different failure modes. Most organisations move along this list over time rather than choosing once.
| Model | Works when | Real cost drivers | What stays yours regardless |
|---|---|---|---|
| In-house, continuous cover | Large estate, unusual architecture, restrictions on who may see the data | Roughly five staff per seat, plus lead, engineer and platform owner | Everything, including the recruitment problem |
| In-house working hours, provider overnight and weekends | You have daytime capability and cannot sustain night shifts | Handover quality, duplicated tooling, the overnight contract's scope | The decision to contain, and every escalation that arrives at 3am |
| Full managed detection | No security staff, or a single generalist who cannot be on call alone | Endpoint or user counts, log volume caps, overage, incident hours | Asset knowledge, authorisation to act, all reporting duties |
| Managed monitoring with in-house detection engineering | Distinctive applications where vendor rules cannot see the real risks | One or two engineering salaries on top of the service fee | Rule quality, and therefore most of the detection outcome |
| Alert forwarding from a traditional managed provider | Rarely a good outcome, and common as an inherited arrangement | Cheap fee, expensive triage work handed back to you | Triage, investigation, containment and the false sense of cover |
What does managed detection pricing hide?
Four things, consistently. Log volume, where the headline is priced per endpoint or per user but ingestion above an allowance is billed separately, and cloud and identity sources are exactly what push you over it. Incident hours, where triage is included but the forensic investigation that follows a confirmed compromise is sold as a retainer or at day rates, generally agreed under time pressure. Response scope, where containment is limited to endpoints and excludes identity and cloud actions. And exit, where your historical data and the detection logic may not be portable.
Onboarding is the fifth and it is a genuine cost rather than a hidden fee. Getting sources connected, tuning the initial noise and agreeing escalation paths takes weeks of your people's time, and a service that appears live in a fortnight is usually one that is monitoring endpoints only. Plan for the identity, cloud and email sources to take longer than the endpoint agent, because they always do.
The comparison that keeps quotations honest is a fixed scenario list. Give every provider the same six plausible incidents and ask them to state, per scenario, what they would detect, what they would do without asking, what they would escalate, and what falls outside the contract. Differences in price become interpretable once differences in scope are on one page.
What can you never outsource?
The authority to accept business impact. When a provider recommends isolating a host that turns out to be a production database, someone in your organisation has to decide, and if that person is not identified and reachable then the response stalls regardless of how good the detection was. Pre-authorising specific containment actions against specific asset classes is the single most valuable preparation available in this arrangement, and it must be agreed in advance rather than negotiated at 3am.
Asset knowledge is the second. No provider knows which server is load-bearing for month-end, which service account is used by a system nobody has authority to restart, or which supplier connection cannot be blocked without breaching a contract. Providers will ask for this and the answer is usually a spreadsheet that is out of date, which is why their triage looks slower than promised.
Regulatory and contractual notification remains yours in every jurisdiction and under every contract worth signing. A provider can supply the technical facts that inform a notification decision; the obligation, the timing and the wording sit with you, and where personal data or a regulated sector is involved that is a matter for counsel rather than for the security team.
How do you compare two options honestly?
Build the in-house option with the full arithmetic, including the fifth analyst you would rather not need, the engineering time, the tooling and the recruitment cost at a turnover rate you can defend. Compare that against the managed quotation plus the internal time the managed model still requires, which is never zero and is usually a substantial part of one person.
Then compare on the same scenario list rather than on capability claims. For each of your six plausible incidents, write who detects it, who decides, who acts and how long each handover takes, under both models. The model that produces fewer handovers at 3am is generally the better answer even at a higher price, because handovers are where response time is actually lost.
The test worth running this week costs nothing: telephone your own out-of-hours escalation path as if you were an analyst with a confirmed compromise, and time how long it takes to reach a person who can authorise disconnecting something. Whatever the answer is, it applies equally to both models, and it is often the finding that reorders the whole comparison.
Common questions
- How many people does a 24/7 security operations centre need?
- About five full-time staff per continuously covered seat, on simple arithmetic: a week contains one hundred and sixty-eight hours, one person covers roughly forty, and holiday, sickness, training and open vacancies close the rest of the gap. That is before a shift lead, a detection engineer and a platform owner, none of which are shift roles. Attempting continuous cover with three people produces a rota that fails at the first resignation.
- Is managed detection cheaper than building a SOC?
- Usually, for small and mid-sized organisations, because the provider spreads one rota across many customers. The comparison is only fair when the in-house figure includes all of it: five staff per seat, a detection engineer, a platform owner, tooling and ingestion, training, out-of-hours allowances, recruitment at realistic turnover, and reduced output while new analysts learn the estate. It is also fair only when the managed figure includes the internal time that model still requires.
- What do managed detection contracts commonly exclude?
- Four things recur. Log ingestion above an allowance, which cloud and identity sources exceed quickly. Forensic investigation after a confirmed compromise, sold separately as a retainer or day rates and usually agreed under pressure. Response actions outside endpoints, so identity and cloud containment stay with you. And portability at exit, covering both your historical data and the detection logic. Ask for each in writing before signing.
- What cannot be outsourced to a detection provider?
- The authority to accept business impact, knowledge of your own assets, and your reporting obligations. When a provider recommends isolating a host that turns out to be a production database, someone in your organisation must decide, so pre-authorising specific containment actions against specific asset classes in advance is the highest-value preparation available. Regulatory and contractual notification stays with you in every jurisdiction and is a question for counsel.
- What is the best model for a mid-sized company?
- Commonly a hybrid: in-house capability during working hours, a provider covering nights and weekends, and someone internal owning detection quality. It keeps the judgement and asset knowledge that a provider cannot have, avoids the night shifts that drive attrition, and concentrates internal effort on rules for the applications a vendor could never anticipate. The weak point is handover quality, which is worth testing rather than assuming.
- How do you compare detection providers fairly?
- Give every provider the same list of six plausible incidents for your architecture and ask each to state, per scenario, what they would detect, what they would do without asking permission, what they would escalate, and what sits outside the contract. Then map the handovers between their people and yours at 3am. Fewer handovers usually beats a lower price, because handovers are where response time is actually lost.