



The build-versus-buy question for a SOC (security operations centre) usually gets answered with adjectives — control, expertise, focus. It deserves arithmetic instead, because the economics of security monitoring are dominated by one stubborn number: what it takes to keep even a single analyst chair staffed around the clock. This page works that number out for India, in rupees, and then looks at what outsourcing actually changes — including the parts where the in-house answer genuinely wins.
A week contains 168 hours. An analyst, after Indian statutory leave, training and normal absence, reliably covers about 40 of them. Divide, and one continuously staffed seat needs 4.2 people before anything goes wrong — and something always goes wrong, because security analysts are among the most poached professionals in the Indian job market. Plan for attrition and you are at five to six people to keep one chair warm. Not for a team. For a chair.
And the grid above is only the first chair. Escalation needs a second and third tier — the senior people who handle what the shift analyst cannot — plus someone running the function. This is why most in-house SOCs in India are honestly described as 8×5 teams with an on-call rota, and why the incidents that matter have a habit of starting at 2 a.m. on a long weekend.
Put rupees against the arithmetic. Five to six shift analysts, two or three senior analysts and engineers, and a lead — ten or so security salaries in a market where that talent is scarce, mobile and expensive to replace. On top of people: a SIEM licensed on log ingest, threat intelligence feeds, endpoint tooling, the infrastructure under all of it, and the recruitment cycle you rerun every time an analyst is poached — in India’s security job market, an annual event, and every departure takes months of your environment’s context with it. Stacked honestly, the figure we and most of the market cite for a credible 24×7 in-house build runs to ₹2–5 crore a year before the first incident is detected.
The bill also arrives before the capability does. A SOC is not operational on the day the SIEM licence activates: log sources take months to onboard cleanly, detections need tuning against your environment’s normal, and analysts need time to learn what your business looks like when nothing is wrong before they can recognise it going wrong. A realistic path from purchase order to a SOC you would trust with a 2 a.m. decision is 18–24 months — during which the full run-rate is already being paid. Organisations that build anyway and staff 8×5 have not beaten the arithmetic; they have bought the gap and renamed it.
An outsourced SOC spreads exactly those fixed costs across many clients. The rota is the provider’s problem — ours is described openly on the team page — the SIEM is already licensed and tuned, attrition is absorbed by a bench rather than by your coverage, and entry pricing starts around ₹50,000 a month for a small estate, scaling with log volume and scope rather than with headcount. What actually drives the monthly fee — analyst coverage, ingest, tuning, response commitments, compliance reporting — is broken down in SOC as a service pricing in India, and the service itself on the SOC as a Service page.
Outsourcing has real costs that do not appear on invoices. An external analyst does not know that the finance server always spikes on month-end, that the plant network is fragile during changeovers, or which alerts your business genuinely fears — that context has to be deliberately transferred and maintained, and providers who skip that onboarding deliver noise with a service-level agreement attached. Response authority needs careful drawing: what may the provider do at 3 a.m. without asking? And a provider serves many clients; your in-house team serves one. These are manageable costs, but a provider who pretends they do not exist is selling something.
There is also a category of organisation for which in-house remains the right answer despite the arithmetic: those with the scale for monitoring to be a genuine internal craft, data-sovereignty constraints that rule out external operations entirely, or a security function that is itself a product of the business. If that is you, the honest use of this page is as a budgeting floor — the arithmetic still applies, it is simply worth paying.
The binary is false anyway. The arrangement a growing share of Indian enterprises lands on is co-managed: your team keeps the daytime shift, the business context and the response authority, and buys the nights, weekends, escalation depth and platform from a provider. You keep the parts of in-house that were genuinely valuable and stop paying for the arithmetic that was not. The delivery models — fully managed, co-managed, hybrid — are laid out on our managed SOC services page.
For regulated Indian organisations the coverage question is not entirely optional. CERT-In directions require incident reporting within six hours and ICT logs retained for 180 days; the DPDP Act 2023 carries penalties up to ₹250 crore; and the RBI and SEBI add sector frameworks on top for banks, NBFCs and market intermediaries — frameworks that typically expect periodic VAPT by CERT-In-empanelled auditors. A six-hour reporting clock is unforgiving to a team that goes home at six, which is why compliance-driven buyers tend to arrive at the outsourced or co-managed model first — the evidence trail, retention and reporting cadence are part of the service rather than another internal project.
Build in-house when you have the scale to keep ten security professionals challenged, a hiring engine that can survive attrition, regulatory or data-sovereignty reasons to keep operations entirely internal, and the patience for an 18–24 month path to maturity. Outsource when you need 24×7 now, when the arithmetic above exceeds your security budget, or when monitoring is essential to you but never going to be your craft. Co-manage when you have a good small team that cannot cover nights, or an existing SIEM investment worth keeping. And whichever way you lean, cost both options at the same coverage standard — an 8×5 in-house plan compared against a 24×7 service is not a comparison, it is a category error.
We have run security operations from Delhi since 2002, with CISSP, CISM, CEH and Fortinet NSE certified engineers staffing a genuine 24×7 rota, serving clients across banking, NBFC, government, manufacturing, IT services and healthcare. We sell the fully managed and co-managed models both — and the assessment of which one your estate actually needs is a conversation we are happy to have argue us out of a sale. Start from managed security services or talk to us directly.