Managed SOC vs In-House SOC: Buy 24/7 Detection or Build It Yourself?
A managed SOC gives you 24/7 detection and response for a monthly fee. An in-house SOC gives control and context at the price of a team. Who should pick which, honestly.
Updated This page as Markdown
In short
A managed SOC is a provider's analysts and tooling watching your systems around the clock for a monthly fee, usually per device or user. An in-house SOC is your own team, SIEM and on-call rota: full control and deep knowledge of your environment, but real 24/7 needs eight to twelve analysts and typically a seven-figure yearly budget. Companies below a few thousand employees rarely get an in-house SOC to work; very large organisations and those with their own OT or product telemetry often should build one. Zyberum sells a managed SOC, Zyberdome, so read the in-house arguments here as the ones we would make against ourselves.
What is the difference?
A security operations centre is the function that watches your systems for signs of an attack and acts when one is found: collecting logs and telemetry, correlating them, triaging alerts, investigating, containing and reporting. A managed SOC is that function bought as a service: the provider’s analysts, platform and detection content, watching your estate from their site, with a contract that says what they watch, how fast they react and what they are allowed to do on your systems. An in-house SOC is the same function built with your own people, your own SIEM or EDR platform and your own processes.
What changes is not what the SOC does but who knows what. The provider knows attacker tradecraft across many customers and sees a new campaign in one place before it reaches you. Your own team knows that the login from Poland at 3 a.m. is the CFO on a business trip, which server runs the production line and whom to call. A good managed SOC closes that context gap with onboarding, runbooks and a named contact on your side; a good in-house SOC closes the tradecraft gap with threat intelligence feeds and training. Neither is free.
Side by side
| Managed SOC | In-house SOC | |
|---|---|---|
| What it covers | 24/7 monitoring of the agreed log sources and endpoints, triage, investigation, alerting and usually first containment steps; detection content maintained by the provider | Whatever you build: monitoring, detection engineering tailored to your environment, response with full access, forensics, threat hunting, integration with OT and product telemetry |
| What it misses | Business context unless you provide it; systems that are not onboarded; deep response on systems the provider has no access to; your internal politics | Cross-customer visibility of new campaigns; nights and weekends if understaffed; everything while the team is hiring or on holiday |
| Who does it | The provider’s analysts in shifts, with a contact person at your side who takes decisions | Your analysts, a SOC lead, a detection engineer and a platform owner; eight to twelve people for real 24/7 |
| Time to set up | Weeks: agent rollout, log forwarding, runbooks, escalation list | Twelve to twenty-four months: hiring, platform selection, log onboarding, detection content, processes |
| Typical cost | Per device, user or data volume; a few thousand to around twenty thousand euros a month for a mid-sized company; typical ranges for Germany and the EU, not an offer | Salaries for eight to twelve specialists, SIEM or EDR licences, infrastructure and training: typically one to three million euros a year for a small 24/7 SOC |
| Coverage | 24/7 by contract from day one | 24/7 only with full staffing; otherwise business hours plus on-call |
| Required by | Nobody by name; NIS2 Art. 21 and 23 and KRITIS attack-detection duties in practice need continuous monitoring, and a managed service is an accepted way to provide it | Same; some regulators and customers require that incident handling and data stay inside the organisation or the country, which favours in-house or an EU-based provider |
| Output | Alerts with triage, incident reports, monthly reporting, support for the NIS2 24 hour early warning; evidence for auditors | The same plus your own detection rules, forensic capability and institutional knowledge that stays when the contract would have ended |
Choose a managed SOC when
- You have fewer than a few thousand employees and no 24/7 operations team today. The arithmetic of eight to twelve analysts does not work at that size, and a half-staffed in-house SOC is the worst of both worlds.
- You need coverage soon, for example because NIS2 reporting duties or a customer requirement apply this year. A provider is live in weeks.
- Your IT team is small and already busy keeping things running. Adding alert triage at night to the same people means alerts get ignored.
- You want predictable costs per device or user and the option to stop.
Choose an in-house SOC when
- You are large enough: several thousand employees, many sites, your own data centres, and a security budget in the millions. Then the fixed cost of a team is spread far enough and the context advantage pays off.
- Your detection needs are specific: OT and plant protocols, telemetry from your own products in the field, bespoke applications. Providers detect generic attacker behaviour well; your own engineers write the rules for your production line.
- Regulation, customers or your own policy require that incident data and response stay inside the organisation, or that analysts hold specific clearances.
- You want detection engineering and incident response as a competence of your company, not a line in a contract, and you can hire and keep the people.
In these cases the in-house SOC is the better choice despite the cost, and a provider who tells you otherwise is selling.
Both together
The common pattern in larger organisations is a hybrid: a managed SOC provides 24/7 first-line monitoring and triage, and a small in-house team of two to four people owns detection priorities, handles escalations with full context, runs the incident process and talks to management and authorities. That gets you round-the-clock coverage without ten hires, and it keeps the knowledge and the decisions in the company. The split works only if the in-house people have time for it and the provider accepts a customer who asks questions.
Zyberum operates Zyberdome, a managed SOC with a fixed monthly price per device, so we are not neutral in this comparison; that is why the in-house arguments above are spelled out. If you are large, regulated or OT-heavy enough that an in-house or hybrid SOC is the right answer, we say so and help you design the detection and the incident process instead. If you are a small or mid-sized company that needs 24/7 detection this year, that is what Zyberdome is for.
FAQ
Frequently asked questions
Does NIS2 require a SOC?
Not by that name. Art. 21(2)(b) of Directive (EU) 2022/2555 requires incident handling as a risk-management measure, and Art. 23 requires an early warning within 24 hours of becoming aware of a significant incident. Neither works without someone watching logs and alerts, including at night and on weekends. Whether that someone is your employee or a provider is your choice; the obligation and the liability stay with you.
How many people does an in-house 24/7 SOC need?
For a single analyst seat staffed around the clock you need about five full-time people once shifts, holidays, sickness and training are counted. A functioning SOC needs at least two seats plus a lead, a detection engineer and someone who maintains the platform, so eight to twelve people is the realistic minimum. Many in-house SOCs that look cheaper on paper run on one or two people and are effectively a business-hours service with an alert e-mail at night.
What does a managed SOC cost?
Providers price per device, per user or per data volume. For a mid-sized company the typical range in Germany and the EU is a few thousand to around twenty thousand euros a month depending on the number of systems, the log sources and whether response is included; this is a market range, not an offer. Zyberdome has a fixed monthly price per device, published on its page. In both cases the yearly cost is well below the salary of two analysts.
Sources
- Directive (EU) 2022/2555 (NIS2), Art. 21(2)(b) incident handling and Art. 23 reporting obligations
- NIST SP 800-61 Rev. 3: Incident Response Recommendations and Considerations for Cybersecurity Risk Management
- ISO/IEC 27001:2022, Annex A controls 5.24 to 5.28 (incident management) and 8.16 (monitoring activities)
- BSI: Systeme zur Angriffserkennung, Orientierungshilfe (German)
Related pages
- GlossarySOC (Security Operations Center)A SOC monitors systems around the clock, detects attacks and coordinates the response. What it consists of, what NIS2 expects, and when a managed SOC is better.
- GlossaryIncident ResponseIncident response is the organised handling of a security incident from detection to recovery. The NIST phases, the NIS2 and CRA deadlines, and what to prepare up front.
- GlossaryNIS2NIS2 (Directive (EU) 2022/2555) sets cybersecurity duties for essential and important entities in 18 sectors. Scope, ten measures, reporting deadlines, German law.
- InsightsThe Ten NIS2 Measures of Article 21(2), ExplainedNIS2 Article 21(2) lists ten risk management measures every affected entity must implement. What each one means, how they map to German law, and where to start.
- For your industryCybersecurity for CISOs and IT Managers: NIS2 Duties, Pentests and DetectionWhat CISOs and IT managers in mid-sized companies need: NIS2 and BSIG duties, management liability, internal attack surface, typical findings and a first-year plan.
- ServicesEnterprise-grade protection. SMB-friendly price.24/7 managed security for SMBs: SentinelOne endpoint protection, SOC analysts, incident response and reports at a fixed monthly price per device.
- ServicesNIS2 without the paper mountain.NIS2 applies in Germany since December 2025. Find out if you are affected and implement risk management, incident reporting and testing with hands-on experts.
