Skip to content
Zyberum Cyber Security Firm
Menu
ComparisonsDetection and response

Managed SOC vs In-House SOC: Buy 24/7 Detection or Build It Yourself?

A managed SOC gives you 24/7 detection and response for a monthly fee. An in-house SOC gives control and context at the price of a team. Who should pick which, honestly.

Updated This page as Markdown

In short

A managed SOC is a provider's analysts and tooling watching your systems around the clock for a monthly fee, usually per device or user. An in-house SOC is your own team, SIEM and on-call rota: full control and deep knowledge of your environment, but real 24/7 needs eight to twelve analysts and typically a seven-figure yearly budget. Companies below a few thousand employees rarely get an in-house SOC to work; very large organisations and those with their own OT or product telemetry often should build one. Zyberum sells a managed SOC, Zyberdome, so read the in-house arguments here as the ones we would make against ourselves.

What is the difference?

A security operations centre is the function that watches your systems for signs of an attack and acts when one is found: collecting logs and telemetry, correlating them, triaging alerts, investigating, containing and reporting. A managed SOC is that function bought as a service: the provider’s analysts, platform and detection content, watching your estate from their site, with a contract that says what they watch, how fast they react and what they are allowed to do on your systems. An in-house SOC is the same function built with your own people, your own SIEM or EDR platform and your own processes.

What changes is not what the SOC does but who knows what. The provider knows attacker tradecraft across many customers and sees a new campaign in one place before it reaches you. Your own team knows that the login from Poland at 3 a.m. is the CFO on a business trip, which server runs the production line and whom to call. A good managed SOC closes that context gap with onboarding, runbooks and a named contact on your side; a good in-house SOC closes the tradecraft gap with threat intelligence feeds and training. Neither is free.

Side by side

Managed SOCIn-house SOC
What it covers24/7 monitoring of the agreed log sources and endpoints, triage, investigation, alerting and usually first containment steps; detection content maintained by the providerWhatever you build: monitoring, detection engineering tailored to your environment, response with full access, forensics, threat hunting, integration with OT and product telemetry
What it missesBusiness context unless you provide it; systems that are not onboarded; deep response on systems the provider has no access to; your internal politicsCross-customer visibility of new campaigns; nights and weekends if understaffed; everything while the team is hiring or on holiday
Who does itThe provider’s analysts in shifts, with a contact person at your side who takes decisionsYour analysts, a SOC lead, a detection engineer and a platform owner; eight to twelve people for real 24/7
Time to set upWeeks: agent rollout, log forwarding, runbooks, escalation listTwelve to twenty-four months: hiring, platform selection, log onboarding, detection content, processes
Typical costPer device, user or data volume; a few thousand to around twenty thousand euros a month for a mid-sized company; typical ranges for Germany and the EU, not an offerSalaries for eight to twelve specialists, SIEM or EDR licences, infrastructure and training: typically one to three million euros a year for a small 24/7 SOC
Coverage24/7 by contract from day one24/7 only with full staffing; otherwise business hours plus on-call
Required byNobody by name; NIS2 Art. 21 and 23 and KRITIS attack-detection duties in practice need continuous monitoring, and a managed service is an accepted way to provide itSame; some regulators and customers require that incident handling and data stay inside the organisation or the country, which favours in-house or an EU-based provider
OutputAlerts with triage, incident reports, monthly reporting, support for the NIS2 24 hour early warning; evidence for auditorsThe same plus your own detection rules, forensic capability and institutional knowledge that stays when the contract would have ended

Choose a managed SOC when

  • You have fewer than a few thousand employees and no 24/7 operations team today. The arithmetic of eight to twelve analysts does not work at that size, and a half-staffed in-house SOC is the worst of both worlds.
  • You need coverage soon, for example because NIS2 reporting duties or a customer requirement apply this year. A provider is live in weeks.
  • Your IT team is small and already busy keeping things running. Adding alert triage at night to the same people means alerts get ignored.
  • You want predictable costs per device or user and the option to stop.

Choose an in-house SOC when

  • You are large enough: several thousand employees, many sites, your own data centres, and a security budget in the millions. Then the fixed cost of a team is spread far enough and the context advantage pays off.
  • Your detection needs are specific: OT and plant protocols, telemetry from your own products in the field, bespoke applications. Providers detect generic attacker behaviour well; your own engineers write the rules for your production line.
  • Regulation, customers or your own policy require that incident data and response stay inside the organisation, or that analysts hold specific clearances.
  • You want detection engineering and incident response as a competence of your company, not a line in a contract, and you can hire and keep the people.

In these cases the in-house SOC is the better choice despite the cost, and a provider who tells you otherwise is selling.

Both together

The common pattern in larger organisations is a hybrid: a managed SOC provides 24/7 first-line monitoring and triage, and a small in-house team of two to four people owns detection priorities, handles escalations with full context, runs the incident process and talks to management and authorities. That gets you round-the-clock coverage without ten hires, and it keeps the knowledge and the decisions in the company. The split works only if the in-house people have time for it and the provider accepts a customer who asks questions.

Zyberum operates Zyberdome, a managed SOC with a fixed monthly price per device, so we are not neutral in this comparison; that is why the in-house arguments above are spelled out. If you are large, regulated or OT-heavy enough that an in-house or hybrid SOC is the right answer, we say so and help you design the detection and the incident process instead. If you are a small or mid-sized company that needs 24/7 detection this year, that is what Zyberdome is for.

FAQ

Frequently asked questions

Does NIS2 require a SOC?

Not by that name. Art. 21(2)(b) of Directive (EU) 2022/2555 requires incident handling as a risk-management measure, and Art. 23 requires an early warning within 24 hours of becoming aware of a significant incident. Neither works without someone watching logs and alerts, including at night and on weekends. Whether that someone is your employee or a provider is your choice; the obligation and the liability stay with you.

How many people does an in-house 24/7 SOC need?

For a single analyst seat staffed around the clock you need about five full-time people once shifts, holidays, sickness and training are counted. A functioning SOC needs at least two seats plus a lead, a detection engineer and someone who maintains the platform, so eight to twelve people is the realistic minimum. Many in-house SOCs that look cheaper on paper run on one or two people and are effectively a business-hours service with an alert e-mail at night.

What does a managed SOC cost?

Providers price per device, per user or per data volume. For a mid-sized company the typical range in Germany and the EU is a few thousand to around twenty thousand euros a month depending on the number of systems, the log sources and whether response is included; this is a market range, not an offer. Zyberdome has a fixed monthly price per device, published on its page. In both cases the yearly cost is well below the salary of two analysts.

Sources

Related pages

Get started

Not sure which test you need?

Describe your product or environment in a 15-minute call. You get a clear recommendation and, if you want one, a fixed-price offer.

  • A recommendation, not a sales pitch
  • Scope and effort estimate on the spot
  • Free and without obligation
Tom Zaubermann

Your call is withTom ZaubermannFounder & CEO, Zyberum

Call us: +49 176 439 17074info@zyberum.com

Or send us a message

We reply within one business day.

Call usGet a recommendation

Pick a time that suits you

Open in a new tab