In-House SOC vs SOC-as-a-Service: The Real Cost Comparison

Last updated: 08/07/2026
Cybersecurity

An in-house 24/7 SOC costs roughly $1.4 million to $2.1 million a year once you staff 9 to 14 people and license the tooling. SOC-as-a-Service runs $60,000 to $300,000. Coverage hours drive the gap.

Building a 24/7 security operations center in-house costs a mid-market company roughly $1.4 million to $2.1 million a year, because keeping one seat filled around the clock takes 4.2 people before anyone takes vacation. SOC as a service covers the same 8,760 hours for $60,000 to $300,000. The gap is real, but the number that should decide it is cost per covered hour.

The Comparison Almost Everyone Runs Wrong

A year has 8,760 hours in it. That number quietly decides this entire argument, and it almost never makes it into the spreadsheet.

Ask a CFO to evaluate in-house SOC vs SOC-as-a-Service and the conversation becomes a salary comparison inside four minutes. Analyst headcount. SIEM licensing. A line item for training, if someone is being thorough. Then the columns get totaled, the smaller number wins, and everyone moves on to the next agenda item. Decision made. Wrong question, though.

You aren't buying analysts. You're buying hours of the year when a trained human is actually looking at your environment, and the two models divide those hours in ways that a salary column completely hides. Run the comparison on annual totals and you'll pick wrong in a specific, predictable direction. Run it on cost per covered hour and the answer changes shape.

What follows is the full build, priced from parts. Not a vendor range someone asserted.

What Does an In-House SOC Actually Cost Per Year?

A fully staffed in-house 24/7 SOC costs a mid-market company between $1.4 million and $2.1 million annually. That covers 9 to 14 people, security tooling, and the recruiting and certification spend it takes to keep the seats filled.

Payroll is the largest line and the most underestimated. The U.S. Bureau of Labor Statistics puts the median wage for information security analysts at $124,910 as of May 2024, with the occupation projected to grow 29% through 2034. Inside a SOC, that median splits into tiers. Tier 1 triage analysts run $75,000 to $95,000. Tier 2 investigators land between $95,000 and $130,000. Tier 3 and detection engineers clear $130,000 and keep going. A SOC manager sits at $140,000 to $180,000.

Then you load it. Benefits, payroll taxes, equipment, and software seats add 25% to 40% on top of base, which is the multiplier most internal business cases forget entirely, and forgetting it is how a $1.1 million payroll estimate quietly becomes a $1.5 million one somewhere between the board deck and the first quarterly review.

Here's the stack for a 250-user manufacturer running about 300 endpoints.

Annual cost components of an in-house 24/7 security operations center

Tooling is the line that surprises people, because it doesn't behave like the others. Your SIEM platform, the system that collects and correlates logs from across your environment, gets billed on how much data you send it, not how many people you hire. Microsoft Sentinel and Splunk both price on ingestion volume, and both offer commitment tiers that only pay off if you can forecast that volume accurately a year ahead. But forecasting it is the hard part. Double your log sources and the bill moves whether or not anyone is reading the output.

Nothing above is unusual. It's just rarely added up in one place. If you want the plain-language version of what these people and tools do all day, what a SOC actually does covers the ground before the money conversation starts.

Why 24/7 Coverage Takes 9 to 14 People, Not 3

The 8 to 12 analyst figure gets repeated across every cost guide on page one of this search. None of them show the arithmetic behind it, which is a shame, because the arithmetic is the most persuasive thing in the entire business case.

Start here. A week contains 168 hours. A full-time employee works 40 of them. To keep a single chair occupied continuously for one week, you need 168 divided by 40, which is 4.2 people. Not three. Three people working 8-hour shifts cover the clock only if none of them ever sleeps in on a Sunday, gets the flu, or takes a Thursday off in July.

4.2 is the floor. It's also a fantasy floor. Add two weeks of vacation, statutory holidays, sick days, and the training time that keeps a security analyst from going stale, and one continuously staffed seat costs you 5 to 6 people in practice.

Now ask whether one person alone at 3 a.m. is an acceptable design. It isn't. A lone overnight analyst with no one to escalate to is a single point of failure sitting on top of your incident response plan, so real SOCs run two per shift. Two seats at 5 to 6 people each puts the operations layer at 8 to 10 humans before you've hired anyone who builds detections, administers the tools, or manages the team.

Add those three and you land at 9 to 14. That's not padding. That's a functioning operation.

Staffing problems don't end at the offer letter. The 2026 SANS SOC Survey, built on interviews with 444 practitioners and 69 senior security executives, found staffing to be the single top operational challenge reported by SOC teams. It also surfaced something more uncomfortable for anyone about to sign off on a build. When asked whether management pays close attention to SOC hiring and retention, 59% of security leaders said yes. Only 32% of the practitioners doing the work agreed. That 27-point gap has held steady every year the question has been asked.

Executives think staffing is handled. The people on the shift schedule disagree.

What Does SOC-as-a-Service Cost?

SOC-as-a-Service costs $60,000 to $300,000 a year for organizations in the 200 to 2,000 employee range. Providers price three ways, and which one you get changes the math considerably.

SOC-as-a-Service pricing models and typical 2026 ranges

So what moves the number inside any of those models? Five things. How much log data you generate. How many hours a human is genuinely watching versus a dashboard being available. How many attack surfaces the detections actually cover. Whether response means someone calls you or someone isolates the host. And how much compliance reporting is bolted on.

That third one deserves scrutiny during a bake-off. Real scrutiny. Alert forwarding is cheap and gets sold under the same three letters as real detection and response. If a quote comes in at $3 per endpoint, you're buying a mail relay with a dashboard. Nothing more. Ask what the provider does at 2 a.m. when a domain controller, the server that authenticates every login in your company, starts behaving oddly, and whether the answer involves a phone call to you or a containment action taken on your behalf.

Worth naming plainly, because the category labels are a mess. MDR, MSSP, and SIEM aren't interchangeable, and a fair number of companies shopping for a SOC actually need managed detection and response instead. Get the category right before you compare prices, or you'll compare two things that aren't the same product.

The Number That Changes the Comparison: Cost Per Covered Hour

Divide annual cost by hours actually covered and you get cost per covered hour. It's a rough metric. It's also the only one that exposes the trap in the middle option, which is where a lot of companies quietly end up.

Same 250-user manufacturer. Three scenarios.

Cost per covered hour for in-house 24/7, business-hours-only, and outsourced SOC

Those figures are a modeled scenario built from published market ranges, not a quote. Your numbers will move with headcount, log volume, and how much response authority you buy. Run them yourself.

Look at the middle row. Then look again. A three-analyst team working Monday through Friday, 8 a.m. to 6 p.m., costs less in total than the full build. It also costs more per protected hour, roughly 24% more, while leaving 6,160 hours of the year with nobody watching. The tooling bill barely moves either, because your SIEM ingests the same volume overnight whether or not a person is reading it.

Cheapest-looking build, worst value on the board. Most companies do this backward. They hire three analysts, call it a SOC, and never run the division that would have shown them the problem.

Then there's the part that turns a budgeting question into a risk question. According to the Sophos Active Adversary Report 2026, which analyzed 661 incident response and MDR cases across 70 countries between November 2024 and October 2025, 88% of ransomware encryption events were deployed during non-business hours. Data exfiltration ran at 79%. The median time from intrusion to reaching Active Directory, the system that controls who can log into what, was 3.4 hours.

Put the two figures side by side. A business-hours-only team covers about 30% of the calendar. Thirty percent. Attackers detonate in the other 70% roughly nine times out of ten. You're paying a premium per hour to be awake during the window attackers deliberately avoid.

Business-hours coverage against the full 8,760-hour year

That pattern is also getting worse, not better. When FireEye ran the same analysis on 2017 through 2019 incidents, 76% of ransomware was executed after hours. 12 points of drift in 6 years. Attackers noticed the shift schedule.

One honest caveat on that $14 figure, because it's flattering in a way that deserves a footnote. You are not buying a dedicated analyst for $14 an hour. You're buying a share of a rotation amortized across many clients, which is precisely why the number is low and precisely where the tradeoff lives. A shared SOC will not know on day one that your ERP service account legitimately touches 40 servers every night at 11. Onboarding, tuning, and giving the provider real business context is work, and skipping that work is how companies end up 18 months into a contract complaining that the provider still pages them at midnight about the same benign backup job nobody ever bothered to document.

What the Build-Side Spreadsheet Leaves Out

Turnover is the big one. Not tooling. The Tines Voice of the SOC Analyst report found 71% of analysts experiencing burnout, 69% saying their team is understaffed, and 64% considering leaving their role inside a year. Build a 10-person SOC and you should plan on replacing 2 to 3 of them annually. Each replacement carries recruiting fees, a hiring cycle measured in months, and a ramp period where the new analyst doesn't yet know which alerts in your environment are noise.

Budget is the constraint, not talent supply. ISC2's Cybersecurity Workforce Study found budget constraints displacing "lack of qualified talent" as the top cause of security staffing shortages, with 38% of organizations reporting hiring freezes and a third saying flatly they lack the resources to staff their teams properly. The approved headcount and the filled headcount are different numbers.

Detection engineering gets cut first and hurts longest. Every time. It's the least visible role in a SOC, so when a budget tightens it's the seat that doesn't get backfilled. Six months later the alert quality has degraded, the analysts are drowning in false positives that nobody has time to tune out, and nobody can point back to the single budget decision that caused any of it.

And the cost of getting this wrong is climbing. IBM's 2026 Cost of a Data Breach report put the global average at $4.99 million and, more tellingly, found mean time to identify and contain rising to 247 days, reversing five consecutive years of improvement. Breaches that ran past the 200-day mark cost about a third more than the ones closed faster. Detection speed is not a technical metric. It's a line on the income statement.

When Building In-House Is the Right Call

So is the answer always buy? No. Four situations make an internal SOC the correct answer regardless of what the per-hour math says.

  • You hold classified contracts or federal work that requires security-cleared US citizens working on your own infrastructure. The requirement decides it. The spreadsheet doesn't get a vote.
  • Scale. Past roughly 1,000 users the per-endpoint subscription curve starts converging with the fixed cost of a payroll, and somewhere on the far side of that crossover the fixed-cost model stops being the expensive option and starts being the cheap one.
  • You already run 24/7. A manufacturer with three production shifts has night supervision, escalation habits, and a culture that doesn't treat 2 a.m. as unusual. Half the hard part of a SOC is organizational, and you've already paid for it.
  • Your detections have to be custom-built. Odd industrial control protocols, proprietary applications, unusual data flows that no shared detection library will ever cover well.

If you have a full-time CISO, a working detection engineering function, and analysts who already know your environment cold, skip this comparison. You're not the buyer.

Under 20 users, skip it too, though for the opposite reason. Endpoint protection and a disciplined patching cadence will move your risk further than a monitoring contract at that size.

Same logic shows up one layer down, in IT operations rather than security, and the arithmetic rhymes. We published the manufacturing version of it in the same build-vs-buy math on the IT side if you want to see how the pattern repeats.

The Option Most Companies Actually Land On

Neither column, usually. They split the clock.

In a co-managed arrangement your internal team owns business hours, business context, and the final call on incident response. The provider owns nights, weekends, holidays, and Tier 1 triage. You keep the 2 or 3 security people you already have and stop asking them to carry a pager they resent.

Co-managed SOC with an internal team and a provider sharing coverage

This works because the two sides are good at genuinely different things, and the split holds up under pressure in a way that a single overloaded internal team never does when three incidents land in the same week. Your people know that the finance team runs a batch job at midnight on the last business day of the month. A provider knows what the same attack pattern, attackers testing stolen passwords at scale, looked like at 40 other companies last Tuesday. Neither knowledge substitutes for the other, and the arrangement only works when the provider gets real onboarding rather than a firehose of logs and a phone number.

It also solves the coverage-window problem directly, which is the whole point. Your 30% stays staffed by people who understand the business. The other 70%, where 88% of the encryption events land, stops being dark. Structurally it mirrors how the co-managed model works on the IT side, and companies that already run co-managed IT tend to find the security version an easy conversation.

How to Run This Comparison on Your Own Numbers

Five steps. A finance lead can execute all of them in a week.

  1. Count your real hours. Write down the hours your current team is genuinely watching, not the hours they're technically on call. On call at 2 a.m. is not coverage. It's a delayed response with extra steps.
  2. Price the full build honestly. 9 to 14 people, loaded at 1.3x base, plus your actual SIEM ingestion bill at current log volume. Not a vendor's illustrative number. Yours.
  3. Divide both models by hours covered. Put in-house 24/7, in-house business hours, and outsourced in the same table. The middle row is where the surprise usually lives.
  4. Ask every provider one question. What do you do at 2 a.m. when a domain controller starts behaving oddly, and does your answer end with a phone call or a containment action? The gap between those two answers is most of the price difference in the market.
  5. Add the risk number. Multiply your realistic breach exposure against the 247-day detection average, then against what detection inside a week would look like. That delta belongs in the comparison, and it's usually larger than the entire annual difference between the two models.

What This Decision Is Really About

The build-versus-buy question is not a budget question wearing a security costume. It's a coverage question. In-house at full strength runs $1.4 million to $2.1 million and covers all 8,760 hours. SOC-as-a-Service covers the same hours for $60,000 to $300,000, with the tradeoff being that you're renting a share of a rotation rather than owning a team. The business-hours-only build looks like the reasonable middle and is the worst value of the three, because it costs more per protected hour while leaving the window attackers actually use completely unwatched.

Consilien builds and runs security operations for companies with 20 to 500 users, mostly in manufacturing, distribution, professional services, and real estate management. We're security-first rather than help-desk-first, which means the SOC conversation starts with your risk and coverage gaps rather than a per-endpoint quote. For companies whose real need is detection and response rather than a full operations center, our managed detection and response service covers the same ground at a narrower scope. If you're weighing this decision right now, bring your current log volume and your actual covered hours to the table and speak to a SOC expert about what the gap costs you today.

Run the Coverage Math Before You Run the Budget

The build-versus-buy question is a coverage question wearing a budget costume. A business-hours-only team covers about 30% of the year and costs more per protected hour than either alternative, while 88% of ransomware encryption fires in the window nobody is watching.

Bring your current log volume and your actual covered hours. We will price all three models against your environment, including the option where your team keeps business hours and we take the nights.

What People Actually Ask Before They Decide

Is a SOC-as-a-Service provider going to know our environment well enough to be useful?
Not on day one. Any provider claiming otherwise is selling. The first 30 to 60 days are tuning, where your team explains which oddities are legitimate and the provider suppresses them. Companies that treat onboarding as a checkbox get a noisy service and blame the provider. Companies that assign someone to answer questions during tuning end up with detections better than what they had internally, because the provider is pattern-matching against every other environment they watch.
We already have two IT people. Can they just watch the alerts?
Two people cover about 30% of the year. That's if neither takes vacation. The deeper issue is that alert triage is a specialty, not a spare-time task. Your IT team is measured on uptime and user support. Asking them to also investigate a suspicious PowerShell execution means one of those jobs gets done badly, and it's usually the security one, because nobody files a ticket when a detection gets missed.
Realistically, how fast can outsourced coverage be running?
2 to 4 weeks to live monitoring for a typical mid-market environment, then another month of tuning before alert quality settles. Compare that to 90 to 180 days to recruit, hire, and onboard even a partial internal team, and only if the market cooperates.
Do we lose control of incident response if we outsource?
Depends entirely on what you sign, and this is the clause worth reading twice. Contracts range from notify-only, where the provider calls and waits, through to full containment authority, where they isolate a host at 3 a.m. without asking. Most mid-market companies land in the middle, granting pre-authorized containment for a defined set of scenarios like isolating a single endpoint or disabling a compromised account, and requiring a phone call before anything touches a production server. Write the scenarios down before signing. Deciding what the provider may do unilaterally is much easier on a Tuesday afternoon than during an active incident.
Our SIEM bill is already the biggest line item. Does outsourcing fix that?
Partly. It depends on whose platform the data lands in. Providers who bring their own stack fold ingestion into the subscription, which usually lowers total spend. Providers who monitor your existing SIEM leave that bill exactly where it is. Ask which model you're being quoted before comparing anything.
At what size does building your own start to pencil out?
Somewhere north of 1,000 users. Though user count is a proxy, not the real driver. What actually decides it is whether you have enough log volume and enough custom detection work to keep 9 to 14 specialists productively occupied. A 1,200-user company with a standard Microsoft environment still shouldn't build one. A 600-user defense manufacturer running custom factory-floor control systems, with clearance requirements attached to its contracts, probably should.

Related Articles

Stay ahead with expert tips, industry trends, and actionable strategies.