A buyer’s guide · Operating since 2002
A managed SOC places the monitoring, detection, investigation and reporting function with a provider on a subscription. You get analysts across all tiers, the platform, the threat intelligence and a 24/7 roster, and what reaches your desk is an investigated incident rather than a queue of alerts.
This page is written as a buyer’s guide rather than a brochure. It sets the model against MDR, MSSPs and managed SIEM, gives the delivery variants their honest definitions, publishes the price points vendors do disclose, and lists the questions that separate a real operations centre from an alerting service. Where a term is marketing rather than a technical category, we say so.
Definition
What a managed SOC actually is
A security operations centre is the focal point for security operations and network defence — staffed people who monitor, correlate and analyse security-relevant events from across the estate, and detect, analyse and respond to incidents on an ongoing basis. That is close to the standards definition, and the important part of it is that a SOC is people, process and technology together.
A managed SOC is that same function obtained from a third party rather than built. This is explicitly a legitimate way to have the capability: larger organisations tend to run a dedicated SOC, while others obtain the same capability from a provider. Renting it does not make it a lesser thing; it makes the scarce skills affordable, because a forensics specialist cannot be kept busy or interested by one mid-sized estate but can be across thirty.
The scope, when the model is delivered properly, covers network monitoring, log management, threat detection and intelligence, incident investigation and response, reporting, and the risk and compliance evidence that follows from all of it. The provider takes on the people, the processes and the technology needed to deliver those.
The comparison
Managed SOC vs MDR vs MSSP vs managed SIEM vs in-house
These labels overlap and vendors blur them. Here is the distinction we would draw across a table, including the limitation of each — the column most comparison charts leave out.
Scroll the table sideways →
| Model | What you actually buy | Who owns the tooling | Response included? | Typical buyer | The honest limitation |
|---|---|---|---|---|---|
| Managed SOCa.k.a. SOCaaS | The whole operations function: monitoring, log management, detection, investigation, reporting. | Usually the provider | In scope by definition, but the depth is contract-defined. | Organisations that need a SOC and will not build one. | A service wrapper is not a guarantee of depth. Quality is whatever the SLA says it is. |
| MDRManaged Detection & Response | One outcome — detection and response over the telemetry the provider ingests. | Almost always the provider | Yes; it is the defining feature. But it ranges from full remote containment to guided advice. | Teams that already have IT and tooling and want detection fast. | Coverage stops at the sensors the provider ingests. Anything outside that footprint is invisible. |
| MSSPManaged Security Service Provider | A category of provider, not one service. Device management, alerting, sometimes much more. | Often you, with the provider operating it | Traditionally no — the MSSP alerts and you respond. Many now bundle MDR; verify. | Organisations outsourcing the running of security tooling. | Alert forwarding without ownership of the outcome, and possible tooling lock-in. |
| Managed SIEM | Operation and tuning of a SIEM platform, hosted or on your licence. | Frequently you | No. A SIEM records that an event occurred; it does not act. | Teams with a SIEM they cannot staff or tune. | A SIEM is a tool, not a function. Without analysts it produces alerts nobody reads. |
| In-house SOC | Whatever you staff and build, with the deepest business context of any model. | You | Yes, with full authority and no third-party approval. | Organisations able to fund genuine 24/7 coverage. | Cost and staffing. Sustaining three tiers around the clock is the binding constraint. |
| Co-managed SOC | A negotiated split — typically the provider takes after-hours and specialist tiers. | Usually you own the licences and the data | Shared, against a written escalation matrix. | Teams with a day shift and no path to 24/7. | Highest coordination overhead. Gaps open at the handover if the RACI is vague. |
If you read one column, read the response column. The most common disappointment in this market is an organisation that believed it had bought containment and had in fact bought notification. It is a contractual question, answerable in a sentence, and it costs nothing to ask before signing.
Delivery models
Fully managed, co-managed, hybrid and virtual
Four words describing who does what, not four different products. The choice is mostly a question of what your own team already covers well, and whether you need to keep ownership of the log platform.
Fully managed
The provider runs it end to end
Platform, analysts and roster all come from the provider. You receive investigated incidents rather than raw alerts. This is what most buyers mean by managed SOC services.
Co-managed
You keep the platform
You retain the SIEM licence, the log data and the day shift; the provider supplies after-hours cover and the specialist tiers. Often chosen where contractual or regulatory terms require you to own the log platform.
Hybrid
Split by function, not only by clock
Internal staff handle tier-one during business hours while a provider covers nights and weekends, or the split follows systems rather than time. Both Microsoft and Splunk stress the same prerequisite: strict escalation processes, or the handover leaks.
Virtual SOC
No physical operations room
Worth knowing that this term is not consistently defined. Fortinet describes it simply as a SOC that works remotely with no physical facility; Splunk’s definition additionally implies part-time or contracted staff. Ask any provider using the phrase which one they mean.
The platform work underneath these models is covered separately: managed SIEM for collection and correlation, SOAR for the repeatable response steps, MDR, EDR and XDR where endpoint depth is the priority, and NOC services where availability monitoring sits alongside security. If you want the same model described as a subscription rather than a managed service, see SOC as a Service — the two terms describe the same construct.
Money
What managed SOC services cost
Most providers quote rather than publish. These are the vendors who do disclose list pricing — useful as benchmarks even where the service shape differs, provided you watch the unit each one prices on.
| Vendor | Service | Published list price |
|---|---|---|
| Huntress | Managed EDR | $8.99 per endpoint / month |
| Huntress | Managed SIEM | $4.00 per data source / month |
| Blumira | Detect / Respond / Automate | $12 / $16 / $21 per employee / month |
| CrowdStrike | Falcon Go / Pro / Enterprise | $59.99 / $99.99 / $184.99 per device / year |
| Wazuh Cloud | Small / Medium / Large | $571 / $923 / $1,467 per month (to 100 / 250 / 500 agents) |
| UnderDefense | MDR | $10–$30 per asset / month, annual contract |
Published list prices as at July 2026, taken from each vendor’s own pricing page. They are not like-for-like — per endpoint, per employee, per data source and per asset are four different meters — and they are given here as reference points, not as our pricing.
Watch the unit, not the number
Per-endpoint and per-employee pricing tie your security bill to headcount rather than to risk. A twenty per cent increase in staff raises the invoice by twenty per cent whether or not your exposure changed. Per-data-source and per-asset models behave differently again, and volume-metered SIEM sits on top of all of them.
Ask what year two looks like. Threat hunting, extended retention, phishing analysis and vulnerability management are commonly included in a first-year deal and reappear as separate line items at renewal.
The number to compare against
Covering one seat continuously is 8,760 console-hours a year. An analyst on a 45-hour week, after leave, public holidays, sick days and a small training allowance, delivers roughly 1,900 productive hours — so about 4.6 people to keep one chair occupied around the clock, and you would hire five or six to survive a single resignation.
Two concurrent seats, the realistic minimum for genuine triage rather than alarm-watching, lands near ten or eleven people before a single specialist is hired. That arithmetic, rather than any vendor’s discount, is what usually decides build versus buy.
The staffing figures are arithmetic on the assumptions stated above, not a published benchmark — adjust the working week and leave entitlement to your own terms and the conclusion moves very little.
Before you sign
Eight questions for a managed SOC RFP
Useful in a formal RFP and useful on a first call. If a provider answers these crisply, they have run this before; if the answers arrive as adjectives, keep looking.
Which log sources are included, and what does adding one cost?
Get the included list into the contract with a unit price for additions. This is where most disputes begin.
Does the SLA measure time-to-alert or time-to-verified-incident?
An alert in sixty seconds means nothing if a human confirms it four hours later. Insist the clock stops at human verification.
Which containment actions are pre-authorised, and who approves the rest?
Ask for the named list — isolate host, disable account, block hash, kill process — and who may authorise each at 3 a.m. “Response included” is not an answer.
Is 24/7 monitoring the same as 24/7 response?
Monitoring hours, triage SLA and response authority are three separate contract terms that are routinely sold as one.
Are the specialist tiers dedicated, shared or subcontracted?
Ask who employs the analysts. Subcontracting is common and rarely volunteered.
Who owns the log data, and how do you get it back?
Logs held on the provider’s platform are what makes switching expensive. Agree the export format and retention on exit before you sign, not after.
What is actually in the monthly report?
Ask for a redacted sample. An “executive dashboard” is often a pie chart of alert volumes and nothing an auditor can use.
What does year two cost?
Threat hunting, extended retention and vulnerability management are frequently free in year one and line items in year two. Ask for the renewal schedule up front.
Straight answers
What buyers get wrong about outsourced security operations
“24/7 monitoring means 24/7 response”
The single most expensive assumption in this market. Monitoring hours, triage SLA and response authority are three independent contract terms, and they are routinely presented as one. A provider can be watching at 3 a.m. and still be contractually unable to do anything until you answer the phone.
“A managed SIEM is a managed SOC”
A SIEM is a tool; a SOC is a function of people, process and technology. A SIEM determines from recorded log data that an event occurred — it is not real-time monitoring and it is not analysts. Buying the platform without the function is how organisations end up with a compliance artefact generating alerts nobody triages.
Only “SOC” is a standards term
NIST defines a security operations centre. It does not define SOCaaS, virtual SOC, co-managed SOC, hybrid SOC or managed detection and response — none of those phrases appear in NIST SP 800-53 Rev. 5, SP 800-61r3 or SP 800-82r3. They are market vocabulary, not technical categories, which is exactly why you should evaluate the contract rather than the label.
“An MSSP will respond to attacks”
Traditionally it will not. The classic MSSP model forwards credible alerts to your team to investigate and resolve. Many MSSPs now bundle detection and response, which is precisely why this must be verified rather than assumed.
“MDR always includes containment”
Response is the defining feature of MDR, but the word is not standardised: some services perform full remote containment, others provide guided advice only. Reduce it to a written list of actions the provider may take without asking you first.
“Outsourcing the SOC outsources the accountability”
It does not. Most managed SOC services still depend on your staff for remediation, and regulatory duties for your estate do not transfer with a contract. What you are buying is capability and coverage, not indemnity.
“Managed SOC” and “SOC as a Service” are the same thing
No standards body distinguishes them. “Managed SOC” is the older, delivery-neutral term; “SOC as a Service” names the same construct after its subscription consumption model. A vendor claiming an architectural difference between the two is selling positioning.
“XDR or SOAR replaces a SOC”
They are tooling a SOC uses. Orchestration automates the repeatable steps and extended detection widens the telemetry, but neither decides whether unusual behaviour on a finance server at midnight is an incident. That judgement is the function you are buying.
Working with us
Why buy this from P J Networks
We have run network and security operations since 2002, for organisations that built their own SOC and for organisations that decided not to. That is the experience this page is written from.
Our own analysts
Fifty-plus in-house NOC and SOC engineers. Ask us who sits in which tier and we will tell you — the same question we suggest you put to everyone you shortlist.
Multi-vendor by default
Real estates are mixed. We monitor Fortinet, Cisco, Dell, Palo Alto and Sophos alongside cloud and identity telemetry. See our technology partners.
Certified operations
ISO/IEC 27001:2022 certified with our security operations centre inside the certified scope, with the scope statement available on request rather than on assertion.

Questions we get asked
Managed SOC services, answered
What are managed SOC services?
Managed SOC services place your security operations centre — the monitoring, detection, investigation and reporting function — with a third-party provider on a subscription. The provider supplies the analysts across all tiers, the platform, the threat intelligence and the round-the-clock roster, and delivers investigated incidents rather than raw alerts. It covers the same ground an internal SOC would: network monitoring, log management, threat detection, incident investigation and response, reporting, and the evidence that supports an audit.
What does managed SOC mean?
It means the security operations centre function is operated for you rather than by you. The term is used interchangeably with outsourced SOC and SOC as a Service; no standards body draws a distinction between them. What varies between providers is not the label but the contract — which telemetry is ingested, who owns the licences and the data, what the triage SLA measures, and which response actions are pre-authorised.
Is managed SOC the same as SOC as a Service?
Yes, in practice. “Managed SOC” is the older delivery-neutral phrase and “SOC as a Service” names the same construct after its subscription consumption model. Where a real difference exists it is usually about tooling ownership: some managed SOC contracts run on a SIEM you already licensed, while SOCaaS more often bundles the platform. Ask which one you are being quoted rather than relying on the term.
What is the difference between a managed SOC and MDR?
Breadth versus depth. MDR buys one outcome — detection and response across the telemetry that provider ingests, usually anchored on endpoint and identity. A managed SOC is the wider function, adding log management, broad-estate coverage and the reporting and retention that an audit needs. Every competent managed SOC does MDR-shaped work; MDR alone does not carry a SOC’s retention and reporting obligations.
What is the difference between a managed SOC and an MSSP?
It is close to a category error: MSSP describes the kind of company, while a managed SOC is one service such a company may sell. The distinction that matters is behavioural. A traditional MSSP operates your security devices and forwards credible alerts for your team to action; a managed SOC owns triage and investigation and delivers a conclusion. Ask whether you are buying device uptime or threat detection — in many contracts the word “monitoring” means the former.
How much do managed SOC services cost?
Most providers quote rather than publish, and the ones who do publish price on very different units, which makes direct comparison difficult. Published examples include Huntress Managed EDR at $8.99 per endpoint per month, Blumira from $12 to $21 per employee per month, CrowdStrike Falcon from $59.99 to $184.99 per device per year, and UnderDefense MDR at $10 to $30 per asset per month. Watch the unit: per-endpoint pricing means a twenty per cent increase in headcount raises your bill by twenty per cent whether or not your risk changed. Ask what year two costs, because features that are free in year one commonly become line items.
How many analysts does 24/7 coverage actually need?
More than most people expect, and the arithmetic is worth doing before you compare quotes. Covering one seat continuously is 8,760 console-hours a year. A full-time analyst working a 45-hour week, after annual leave, public holidays, sick days and a modest allowance for training, delivers roughly 1,900 productive hours. That is about 4.6 full-time staff to keep a single chair occupied around the clock — so you would hire five or six to survive one resignation. Two concurrent seats, which is the realistic minimum for genuine triage, lands near ten or eleven people before you have hired a single specialist. These figures are arithmetic on stated assumptions rather than a published benchmark, but the shape holds anywhere.
What should a managed SOC SLA contain?
At minimum: what the response clock measures and when it stops, severity definitions with a target for each, the named containment actions the provider may take without asking, who is contactable at 3 a.m. and by what channel, the included log source list with a unit price for additions, log retention duration and location, the contents of the monthly report, and what happens to your data on exit. If time-to-verified-incident is missing, that is the one to insist on — time-to-alert is easy to meet and tells you almost nothing.
What is a co-managed SOC?
A co-managed SOC splits the function between your team and a provider. Most often you keep the platform, the licences and the log data along with the day shift, and the provider adds nights, weekends and the specialist tiers such as forensics and malware analysis. It suits organisations that already own a SIEM and cannot staff it around the clock, or whose contractual terms require them to hold their own log platform. It only works when the escalation matrix is written down before go-live.
Is managed SOC the same as SOC 2 compliance?
No, and the shared acronym causes real confusion. SOC 1 and SOC 2 are System and Organization Controls reports under the AICPA framework — attestation reports produced by a licensed CPA firm about an organisation’s controls. A security operations centre is an operational team that monitors and responds to attacks. They are different deliverables bought by different people. Worth knowing: SOC 2 is an attestation report rather than a certification, and no managed security provider can issue one. Good monitoring does produce evidence that makes such an audit easier to pass.
Can a provider monitor a SIEM we already own?
Yes, and it is a common arrangement, usually sold as co-managed. It is often preferred where you need to retain ownership of the log data, either because switching costs matter to you or because a contract requires it. Expect any competent provider to audit the inherited rule set first — platforms that have run without a dedicated team almost always carry detections nobody has reviewed in a year and log sources that stopped reporting without anyone noticing.
How long does onboarding take?
First log sources typically ingest within days; meaningful detection coverage takes weeks. The constraint is tuning rather than integration: a platform freshly pointed at your network produces a great deal of noise, and the value comes from the baselining that follows. Treat any promise of reliable detection on day one as a description of alerting, not detection.
Next step
Get a scoped quote, with the build-it-yourself number beside it
Send us your log sources and monitored asset count. We will quote a specific monthly figure and set it against what the same coverage would cost to staff internally. If building it yourself is the better answer at your size, we will say so.



