Every organisation that reaches a certain size asks the same question: do we build our own security operations centre, or do we pay somebody else to run one? The answer is usually decided on instinct and a vendor quote. It deserves better arithmetic than that.
The staffing maths nobody runs first
A genuine 24/7 operation is not three people taking turns. To cover 168 hours a week with one analyst always on duty, allowing for leave, sickness, training and attrition, you need a minimum of five to six analysts. To have two sets of eyes during business hours — which you want, because a single junior analyst at 2am is a single point of failure — you are at eight.
Add a SOC manager, a detection engineer to write and tune the rules, and someone who can do incident response properly when triage escalates. You are now at eleven people before a single tool is licensed.
The retention problem
Security analysts are scarce across the region, and the ones you train become more marketable the moment they are good. Budget for the fact that a proportion of your team will leave each year, and that replacing an analyst takes months of recruitment plus months of ramp-up before they are genuinely useful at 3am.
What else a SOC needs
- A SIEM or detection platform, licensed by data volume — which grows faster than you plan for.
- Log storage retained long enough to be useful during an investigation, which is considerably longer than most teams initially budget.
- Threat intelligence, without which your detections only catch what you have already seen.
- A ticketing and case management system that preserves investigation history.
- Playbooks, written and rehearsed, because improvising at 3am produces bad decisions.
Where building genuinely wins
In-house makes sense when any of the following are true:
- Your environment is unusual enough that generic detection misses what matters — industrial control systems, bespoke platforms, unusual regulatory constraints.
- Data residency rules prevent telemetry leaving your premises, and no provider can meet them.
- You are large enough that eleven security staff is a rounding error rather than a line item that gets questioned every budget cycle.
- Security is a product differentiator you sell on, not an overhead you absorb.
Where managed detection wins
For most organisations below a few thousand employees, managed detection delivers the outcome at a fraction of the cost, and — more importantly — it delivers it now rather than eighteen months from now when the team is finally hired and trained.
The honest caveat: a managed provider does not know your business. They will tell you a finance workstation is talking to an unusual host; they cannot tell you whether that is a breach or the quarterly reconciliation process. The hybrid most of our clients land on is a managed provider doing 24/7 detection and triage, with one or two internal people who own the relationship, provide business context, and drive remediation.
The question to actually ask
Not "can we afford a SOC?" but "what are we trying to be able to do at 3am on a Sunday?" If the answer is detect an intrusion and contain it within the hour, work backwards from that. Most organisations discover the honest answer is that they cannot currently do it at 3pm on a Tuesday either.
