Bangalore · Riyadh · Delaware | hello@nazztec.com
Cybersecurity

Building a SOC: Build, Buy or Co-Manage?

The honest maths of 24x7 staffing, what a SOC really needs beyond a SIEM, and a framework for choosing between in-house, managed and co-managed security operations.

28 August 20268 min readNAZZTEC Editorial Team
Building a SOC: Build, Buy or Co-Manage? — cover illustration

Key takeaways

  • One 24x7 seat requires roughly five to six full-time analysts once leave and training are included.
  • Detection engineering, not the SIEM licence, determines SOC quality.
  • Co-managed models suit organisations that want to keep control and context in-house.
  • Measure outcomes — time to detect and respond, coverage — not alert volumes.

What a SOC actually has to do

A security operations centre is not a room full of screens. It is a capability that continuously collects security telemetry, detects threats, investigates alerts, responds to incidents and improves detection over time. Whether that capability sits in-house, with a provider or somewhere between is a business decision — and it should be made on facts, not assumptions.

The staffing maths of 24x7

A year has 8,760 hours. A full-time analyst, after annual leave, public holidays, training and sickness, is typically available for around 1,600 to 1,800 hours. Covering a single seat around the clock therefore needs five to six analysts — before you add a team lead, a detection engineer, threat hunting or incident response specialists.

Most in-house SOC business cases underestimate this. A realistic minimum for a credible 24x7 in-house SOC is a team of eight to twelve people, plus the cost of recruiting and retaining them in a competitive market.

The three models compared

In-houseManaged (MSSP / MDR)Co-managed
ControlFullShared through contractHigh — you keep ownership of decisions
Time to capability12–24 monthsWeeksWeeks to a few months
Business contextDeepestMust be transferred and maintainedRetained in-house
Cost profileHigh fixed costPredictable subscriptionBlended
Best forLarge, highly regulated organisations with scaleOrganisations without a security teamOrganisations with a small team that need 24x7 depth

What a SOC needs beyond a SIEM

  • Log sources that matter — identity, endpoint, email, cloud control planes and critical applications, not simply every firewall log.
  • Detection engineering — use cases mapped to real threats, typically using the MITRE ATT&CK framework, tuned to your environment and reviewed regularly.
  • Response playbooks — agreed steps and authority for containment, including who may isolate a device or disable an account at 3 a.m.
  • Automation — SOAR or built-in automation to enrich alerts and handle repetitive steps.
  • Threat intelligence — relevant to your sector and region, not a generic feed.
  • Metrics — mean time to detect and respond, detection coverage, false-positive rate and escalations handled.

How to choose

  • If you have no security team and need coverage quickly, a managed service is usually the right first step.
  • If you have a capable small team, co-managed lets them keep context and control while a provider covers nights, weekends and surge.
  • If you have the scale, budget and regulatory drivers to justify it, an in-house SOC gives maximum control — often still supported by a partner for specialist skills.
  • Whatever the model, insist on transparency: access to your own data, clear escalation, and the ability to change provider without losing your detection content.

Questions to ask a provider

  • Which log sources and use cases are included, and how are new ones added?
  • What are the contractual response times by severity?
  • Who is authorised to take containment actions, and how is that recorded?
  • Where is our data stored, and who can access it?
  • Do we own the detection rules and playbooks if we leave?
  • How is performance reported, and how often?

Metrics that prove a SOC is working

Alert counts and dashboards full of green tiles say little about protection. These measures tell leadership whether the investment is working:

  • Mean time to detect (MTTD) — how long threats go unnoticed, measured from first malicious activity to alert.
  • Mean time to respond (MTTR) — from alert to containment, split by severity.
  • Detection coverage — the proportion of relevant attack techniques your use cases can detect, typically mapped to MITRE ATT&CK.
  • True-positive rate — the share of escalated alerts that were genuine, a direct measure of tuning quality.
  • Log source health — critical sources that stopped sending data, and how quickly that was noticed.
  • Improvement actions closed — lessons from incidents and exercises turned into new or better detections.

Report these monthly and review them quarterly with the provider or team. A SOC whose metrics never change is not improving.

Frequently asked questions

How much does a SOC cost?
It varies widely by scope, log volume and coverage. The largest cost in an in-house SOC is people; for managed services it is usually tied to data volume or the number of endpoints and users.
Is a SIEM enough to have a SOC?
No. A SIEM is a tool. A SOC needs people, processes, tuned detections and response authority to turn alerts into outcomes.
Can we start managed and bring the SOC in-house later?
Yes. Many organisations do exactly that. Contract for ownership of your detection content and data so the transition is practical.
Keep reading

More insights

How to Scope a Penetration Test Properly — cover illustration
Cybersecurity

How to Scope a Penetration Test Properly

A poorly scoped test produces a clean report and a false sense of security. Here is how to define objectives, assets, approach and rules so the results mean something.

18 September 20268 min read
ISO 27001 Certification: A Practical Guide for 2026 — cover illustration
Compliance & Regulation

ISO 27001 Certification: A Practical Guide for 2026

What the 2022 edition actually asks of you, how the certification audit works, and the six decisions that determine whether you certify in five months or fifteen.

22 September 20269 min read

Talk to the team behind this briefing

Tell us what you are working on. A senior NAZZTEC consultant will come back within one business day with a practical view.

We respond to every enquiry within one business day.