
Building a SOC: Build, Buy or Co-Manage?
The honest maths of 24x7 staffing, what a SOC really needs beyond a SIEM, and a framework for choosing between in-house, managed and co-managed security operations.
A poorly scoped test produces a clean report and a false sense of security. Here is how to define objectives, assets, approach and rules so the results mean something.

Two penetration tests with the same budget can produce radically different value. One examines the systems attackers would actually target, with enough time and access to go deep. The other skims a list of hosts and reports automated scanner output. The difference is almost always decided before testing starts — in the scope.
A good scope answers one question clearly: what do we need to know? Whether an external attacker can reach customer data, whether a compromised employee laptop can reach the domain controllers, whether a new mobile app can be abused to access other users' accounts. Each needs a different test.
The objective determines everything else: which assets, which approach, how much time and what the report must say.
Ambiguity in the asset list is the most common cause of disputes and disappointing results. Specify:
| Approach | What the tester knows | Best for |
|---|---|---|
| Black box | Nothing beyond the target | Simulating an uninformed external attacker |
| Grey box | Credentials for defined roles and basic documentation | Most application and internal tests — the best balance of realism and depth |
| White box | Architecture, source code and configuration | High-assurance reviews of critical systems |
Black-box testing sounds realistic, but it spends much of a fixed budget on discovery that real attackers would complete over weeks. Grey-box testing lets testers spend their time finding and proving vulnerabilities.
Agree the deliverables before testing begins. A useful report contains:
Day rate is the least useful comparison. Ask each provider for the effort in person-days per asset, the methodology they follow — such as the OWASP Web Security Testing Guide, PTES or NIST SP 800-115 — a sample report, the experience and certifications of the named testers, and whether retesting is included. A cheaper quote that allocates half the effort is not cheaper.

The honest maths of 24x7 staffing, what a SOC really needs beyond a SIEM, and a framework for choosing between in-house, managed and co-managed security operations.

What the 2022 edition actually asks of you, how the certification audit works, and the six decisions that determine whether you certify in five months or fifteen.

Type I versus Type II, how observation periods and sampling work, and the ten control areas where first-time SOC 2 audits most often produce exceptions.
Tell us what you are working on. A senior NAZZTEC consultant will come back within one business day with a practical view.
We respond to every enquiry within one business day.