SOC as a Service: Build, Buy, or Outsource?

TL;DR

The Real Cost of In-House

True 24/7/365 coverage needs three overlapping shifts, and industry benchmarks put the realistic minimum at 8 to 12 analysts, not the 2 to 3 headcount most mid-market budgets assume:

  • Below 8 analysts, holidays and sickness leave individuals working alone on shift, an operational risk and a burnout problem that feeds the 20%+ annual analyst turnover common across the industry.
  • Fully-loaded, three-shift SOC staffing alone typically runs into seven figures annually before the technology stack (SIEM, EDR/XDR, SOAR, threat intelligence), first-year setup and ongoing training are added.
  • Managed SOC services typically cost 30 to 50% less: most 200 to 2,000-employee organisations pay in the region of $60,000 to $300,000 a year for equivalent coverage.

Worth noting: that gap is why the build-versus-buy conversation so rarely stays theoretical once it reaches a CFO.

What “Outsourced” Actually Means in Practice

Outsourced SOC isn’t one thing, it sits on a spectrum, and providers rarely volunteer where they fall on it until you ask directly:

  • Co-managed vs fully outsourced: do you retain your own SIEM and tooling with the provider’s analysts layered on top, or hand over the full stack?
  • Runbook ownership: who writes and maintains the incident response playbook, and who has authority to act on it without waiting for sign-off?
  • Accountability at 3am: when an alert fires overnight, who is actually paged, and what’s the contractual response time versus the marketing claim?

The takeaway: get these three questions answered in writing before comparing price. A cheaper quote with a vague answer on any of them usually isn’t cheaper.

The Questions that Separate a Real SOC from an Alert-Forwarding Service

Plenty of “SOC” offerings are closer to alert triage than security operations. Ask any provider, including us, these questions:

  • Is coverage genuinely 24/7, or business-hours-plus-on-call dressed up as around-the-clock?
  • What’s the mean time to respond, not just the mean time to detect? Detecting an alert and acting on it are different numbers, and only one of them stops an incident.
  • What’s the analyst-to-client ratio? A provider spread too thin behaves like an alert-forwarding service regardless of what the SLA says.
  • Is threat hunting included, or a separately-priced tier you’ll be offered once you’ve signed?

Bottom line: a SOC that only tells you something happened isn’t doing the job. The value is in the response.

Build, Buy or Hybrid: a Decision Framework

None of these is a universally correct default. Score your organisation against four factors before picking one:

  • Regulatory driver: does a framework you’re already working toward require demonstrable continuous monitoring, not just a policy document?
  • In-house maturity: do you already have security engineering depth, or would a build effort start from close to zero?
  • Budget reality: is the seven-figure in-house cost actually available, or does that number end the conversation before it starts?
  • Headcount risk: can you sustain 8 to 12 specialist hires in a market with persistent analyst shortages and 20%+ annual turnover, or does that risk sit better with a provider?

In practice: most mid-market organisations we talk to land on a hybrid or fully outsourced model, not because build is wrong in principle, but because the headcount risk alone rules it out before cost does.

UK & New Zealand Perspective

Regulatory reporting timelines are pushing continuous monitoring from a nice-to-have to a practical necessity on both sides of the world, even where no framework explicitly mandates a SOC:

  • UK: the Cyber Security and Resilience Bill’s incident reporting requirements are difficult to meet without near-continuous visibility already in place, not built after the fact.
  • NZ: NCSC New Zealand’s Minimum Cyber Security Standards (October 2025) push GCISO-mandated agencies toward monitored, tracked controls on business-critical systems, a direction we’d expect to filter into wider procurement over time.

Our view: neither framework says “buy a SOC.” Both make the absence of one progressively harder to defend.

What We’re Seeing in Practice

Where clients can often struggle:

  • Budgeting for 2 to 3 analysts and assuming that covers 24/7, then discovering the coverage gap during an actual incident, not during procurement.
  • Choosing a provider on price per endpoint without asking the runbook and accountability questions above, then finding out the hard way what “outsourced” meant in that contract.
  • Treating threat hunting as automatically included, then finding it’s a change request away.

Official reference: Cyber Security and Resilience Bill progress (UK Parliament)

Official reference: Minimum Cyber Security Standards (NCSC NZ)

ITogether’s Independent Verdict

There’s no universally right answer between build, buy and hybrid, but there is a universally wrong way to decide: on price per seat alone. The organisations that get this right start with the headcount and accountability questions, then let cost confirm the decision rather than drive it.

👉Working out whether build, buy or hybrid is right for your SOC, or want a straight answer on where a provider’s coverage actually starts and stops, get in touch.

📞 UK +44 (0) 113 341 0123

📞 NZ +64 (0)9 802 2444

📧 hello@itogether.com

FAQs

Is a managed SOC actually cheaper than building one in-house?

Usually, yes. Industry benchmarks put managed SOC services 30 to 50% below the fully-loaded cost of an in-house 24/7 operation, largely because true around-the-clock coverage needs 8 to 12 analysts, not the 2 to 3 most budgets assume.

What’s the difference between mean time to detect and mean time to respond?

Detection is spotting the alert; response is acting on it. A provider with a fast detection time but a slow response time hasn’t actually reduced your risk, ask for both numbers, not just one.

Is co-managed or fully outsourced SOC the right model?

It depends on whether you want to retain your own SIEM and tooling with a provider’s analysts layered on top (co-managed) or hand over the full stack (fully outsourced). Neither is inherently better, the right choice depends on your in-house maturity and how much control you want to retain.

Does outsourcing a SOC always include threat hunting?

Not always, it’s frequently sold as a separate, higher tier. Confirm this explicitly before signing, it’s one of the most common gaps between what buyers assume is included and what actually is.

0 Comments

Submit a Comment