QuietHours by securITDiscuss your scope

Operations

Managed SOC, in-house SOC, or MDR: an honest comparison

The decision is usually framed as build versus buy. That framing hides the variable that determines success: who is accountable for the decision to act at three in the morning, and whether they have the authority to make it.

Minimalist node graph representing distributed monitoring

Round-the-clock monitoring is now a practical obligation for a large share of European organisations, partly through NIS2 and DORA and partly because incidents do not respect business hours. The question is not whether to have it. It is which delivery model you can actually sustain.

What 24/7 in-house really costs

Continuous coverage requires enough analysts to staff a rota without burning people out. Accounting for leave, sickness, training and turnover, that means roughly eight to twelve analysts across tiers, plus at least one detection engineer and someone owning the platform. This is the number that surprises people: it is not a team of three with an on-call phone.

Cost componentIn-house 24/7Managed SOCMDR
Analyst staffing8–12 FTE plus engineeringIncludedIncluded
Platform and licensingYours, and you negotiate itOften provider's, sometimes yoursUsually provider's stack
Log ingestion costDirect and highly variablePassed through or bundledUsually bundled, with limits
Detection engineeringYoursShared, varies by contractProvider's, largely opaque
Response authorityYours entirelyYours; provider escalatesProvider can act, within limits
Time to operational9–18 months realistically4–10 weeks1–4 weeks
Context about your businessExcellentBuilt over timeLimited by design
Key-person riskHighLowLow

Where each model actually fails

In-house

  • Attrition. Tier-1 analysis is repetitive work, and the market for experienced analysts is competitive. Losing two people can end continuous coverage overnight.
  • Detection decay. Rules are written, environments change, log sources quietly stop, and nobody notices because absence of alerts looks like success.
  • Night-shift quality. The 03:00 analyst is usually the least experienced person on the team, facing the alerts most likely to matter.

Managed SOC

  • Context gap. The provider does not know that the finance system always runs a bulk export on the last Friday of the month, so it is either escalated every month or tuned out permanently.
  • Escalation-only scope. Many contracts stop at notification. If nobody on your side answers at 03:00, the escalation achieved nothing.
  • Alert-volume incentives. If the contract measures alerts handled, you will receive alerts. Measure investigations closed and escalations that were correct instead.

MDR

  • Coverage limited to the provider's stack. Excellent on endpoint, frequently weaker on identity, SaaS, cloud control planes and bespoke applications — which is where a lot of modern attack activity now lives.
  • Opaque detection logic. You often cannot see or influence the rules, which makes it hard to evidence coverage to an auditor.
  • Containment authority. Automatic isolation is powerful and occasionally isolates something business-critical. Agree the boundaries in writing before go-live.

The hybrid that most mid-sized organisations end up with

The arrangement that works most often is not on this list as a pure option: an internal security lead who owns detection strategy, business context and response authority, plus an external provider supplying continuous coverage and tier-1 triage.

One internal person makes the external service dramatically more effective, because someone on your side can answer 'is this normal?' in minutes, can approve containment, and can push back when escalation quality drops. Providers deliver noticeably better outcomes to customers who have this role filled, and it is a single salary rather than twelve.

Questions to ask any provider before signing

  1. What exactly happens at 03:00 when a genuine critical alert fires? Walk me through the last real one, redacted.
  2. Can you contain — isolate a host, disable an account — or only notify? If containment, under what authority and with what limits?
  3. Which log sources are in scope, and specifically: is my identity provider included? Are my SaaS audit logs included?
  4. How do I see your detection coverage? Can I map it to a framework such as MITRE ATT&CK, and can I request new detections?
  5. What is the contractual time to acknowledge and time to escalate, and what happens when you miss it?
  6. How do you monitor for a log source going silent? This is the most common invisible failure.
  7. Who owns the data if I leave, and in what format do I get it?
  8. Will you support an adversary simulation exercise, and will you accept being measured on what you detected?

That last question is the most revealing. A provider willing to be measured by an independent red team is confident in their coverage. A provider who resists it is telling you something important.

Choosing

Your situationModel that usually fits
Under 500 staff, no dedicated security teamMDR, plus a named internal owner even if part-time
500–2,000 staff, one to three security peopleManaged SOC with an internal detection owner
Regulated, needs auditable detection logicManaged SOC on your own platform, or hybrid
Over 3,000 staff with mature security functionIn-house core with external overflow and out-of-hours
Highly bespoke or OT-heavy estateIn-house or hybrid — external context gap is too costly

Frequently asked questions

How many analysts does a 24/7 SOC need?

Realistically eight to twelve analysts across tiers to sustain continuous coverage once leave, sickness, training and turnover are accounted for, plus detection engineering and platform ownership. Teams smaller than that are usually running business-hours monitoring with an on-call rota, which is a valid model but should be described accurately.

What is the difference between a managed SOC and MDR?

A managed SOC generally monitors the log sources you choose, often on a platform you own, and escalates to you for response. MDR is a more packaged service built around the provider's own detection stack, usually endpoint-centric, and typically includes some containment authority. MDR is faster to deploy; a managed SOC gives broader source coverage and more visible detection logic.

Can a small company meet 24/7 monitoring expectations?

Yes, through MDR or a managed SOC combined with a named internal owner who can answer context questions and authorise containment. The internal owner is what makes the external service effective, and it is one role rather than a full team.

Talk to the team

Need this tested rather than described?

QuietHours is a European cybersecurity practice operated by the securIT team. Send us the system, service, or control you are concerned about and we will help turn it into a workable scope.

Discuss your scope

Related reading