TL;DR
- True 24/7 SOC coverage needs 8 to 12 analysts across shifts, not the 2 to 3 headcount most mid-market budgets assume, pushing fully-loaded in-house cost into seven figures a year. Managed SOC services typically run 30 to 50% less, in the region of $60,000 to $300,000 annually for a 200 to 2,000-employee organisation, industry benchmarks suggest.
- Cheaper isn’t the criterion CISOs actually get judged on. The real differentiators are mean time to respond (not just detect), analyst-to-client ratios, and whether threat hunting is included or bolted on.
- Build, buy and hybrid aren’t equally valid defaults, the right one depends on regulatory driver, in-house maturity, budget and headcount risk, not a gut call.
The Real Cost of In-House
True 24/7/365 coverage needs three overlapping shifts, and industry benchmarks put the realistic minimum at 8 to 12 analysts, not the 2 to 3 headcount most mid-market budgets assume:
- Below 8 analysts, holidays and sickness leave individuals working alone on shift, an operational risk and a burnout problem that feeds the 20%+ annual analyst turnover common across the industry.
- Fully-loaded, three-shift SOC staffing alone typically runs into seven figures annually before the technology stack (SIEM, EDR/XDR, SOAR, threat intelligence), first-year setup and ongoing training are added.
- Managed SOC services typically cost 30 to 50% less: most 200 to 2,000-employee organisations pay in the region of $60,000 to $300,000 a year for equivalent coverage.
Worth noting: that gap is why the build-versus-buy conversation so rarely stays theoretical once it reaches a CFO.
What “Outsourced” Actually Means in Practice
Outsourced SOC isn’t one thing, it sits on a spectrum, and providers rarely volunteer where they fall on it until you ask directly:
- Co-managed vs fully outsourced: do you retain your own SIEM and tooling with the provider’s analysts layered on top, or hand over the full stack?
- Runbook ownership: who writes and maintains the incident response playbook, and who has authority to act on it without waiting for sign-off?
- Accountability at 3am: when an alert fires overnight, who is actually paged, and what’s the contractual response time versus the marketing claim?
The takeaway: get these three questions answered in writing before comparing price. A cheaper quote with a vague answer on any of them usually isn’t cheaper.
The Questions that Separate a Real SOC from an Alert-Forwarding Service
Plenty of “SOC” offerings are closer to alert triage than security operations. Ask any provider, including us, these questions:
- Is coverage genuinely 24/7, or business-hours-plus-on-call dressed up as around-the-clock?
- What’s the mean time to respond, not just the mean time to detect? Detecting an alert and acting on it are different numbers, and only one of them stops an incident.
- What’s the analyst-to-client ratio? A provider spread too thin behaves like an alert-forwarding service regardless of what the SLA says.
- Is threat hunting included, or a separately-priced tier you’ll be offered once you’ve signed?
Bottom line: a SOC that only tells you something happened isn’t doing the job. The value is in the response.
Build, Buy or Hybrid: a Decision Framework
None of these is a universally correct default. Score your organisation against four factors before picking one:
- Regulatory driver: does a framework you’re already working toward require demonstrable continuous monitoring, not just a policy document?
- In-house maturity: do you already have security engineering depth, or would a build effort start from close to zero?
- Budget reality: is the seven-figure in-house cost actually available, or does that number end the conversation before it starts?
- Headcount risk: can you sustain 8 to 12 specialist hires in a market with persistent analyst shortages and 20%+ annual turnover, or does that risk sit better with a provider?
In practice: most mid-market organisations we talk to land on a hybrid or fully outsourced model, not because build is wrong in principle, but because the headcount risk alone rules it out before cost does.
UK & New Zealand Perspective
Regulatory reporting timelines are pushing continuous monitoring from a nice-to-have to a practical necessity on both sides of the world, even where no framework explicitly mandates a SOC:
- UK: the Cyber Security and Resilience Bill’s incident reporting requirements are difficult to meet without near-continuous visibility already in place, not built after the fact.
- NZ: NCSC New Zealand’s Minimum Cyber Security Standards (October 2025) push GCISO-mandated agencies toward monitored, tracked controls on business-critical systems, a direction we’d expect to filter into wider procurement over time.
Our view: neither framework says “buy a SOC.” Both make the absence of one progressively harder to defend.
What We’re Seeing in Practice
Where clients can often struggle:
- Budgeting for 2 to 3 analysts and assuming that covers 24/7, then discovering the coverage gap during an actual incident, not during procurement.
- Choosing a provider on price per endpoint without asking the runbook and accountability questions above, then finding out the hard way what “outsourced” meant in that contract.
- Treating threat hunting as automatically included, then finding it’s a change request away.
Official reference: Cyber Security and Resilience Bill progress (UK Parliament)
Official reference: Minimum Cyber Security Standards (NCSC NZ)
ITogether’s Independent Verdict
There’s no universally right answer between build, buy and hybrid, but there is a universally wrong way to decide: on price per seat alone. The organisations that get this right start with the headcount and accountability questions, then let cost confirm the decision rather than drive it.
👉Working out whether build, buy or hybrid is right for your SOC, or want a straight answer on where a provider’s coverage actually starts and stops, get in touch.
📞 UK +44 (0) 113 341 0123
📞 NZ +64 (0)9 802 2444
📧 hello@itogether.com
FAQs
Is a managed SOC actually cheaper than building one in-house?
Usually, yes. Industry benchmarks put managed SOC services 30 to 50% below the fully-loaded cost of an in-house 24/7 operation, largely because true around-the-clock coverage needs 8 to 12 analysts, not the 2 to 3 most budgets assume.
What’s the difference between mean time to detect and mean time to respond?
Detection is spotting the alert; response is acting on it. A provider with a fast detection time but a slow response time hasn’t actually reduced your risk, ask for both numbers, not just one.
Is co-managed or fully outsourced SOC the right model?
It depends on whether you want to retain your own SIEM and tooling with a provider’s analysts layered on top (co-managed) or hand over the full stack (fully outsourced). Neither is inherently better, the right choice depends on your in-house maturity and how much control you want to retain.
Does outsourcing a SOC always include threat hunting?
Not always, it’s frequently sold as a separate, higher tier. Confirm this explicitly before signing, it’s one of the most common gaps between what buyers assume is included and what actually is.

0 Comments