SOC (Security Operations Center)
Last updated
Definition
A Security Operations Center (SOC) is the team and tooling that monitors security telemetry – endpoint, identity, email, network, cloud – around the clock, triages alerts, investigates suspicious activity, and contains confirmed threats. It is defined by continuous human coverage, not by a product: an EDR or SIEM console with nobody watching it at 3 a.m. is not a SOC.
Why it matters to an MSP
The question is never whether clients need SOC coverage – ransomware crews deliberately work nights and weekends because that is when nobody is watching – but whether to build one or buy one. The staffing math settles it for most shops. One seat covered 24/7/365 is 8,760 hours; at roughly 1,800 productive hours per analyst that is about five people per seat before vacation and turnover. A minimum-viable SOC needs two analysts on shift plus a lead and someone tuning detections, which is why in-house builds land at roughly 8–12 analysts and typically $1M+ per year fully loaded – before SIEM licensing and before the year it takes to make the detections useful. Few MSPs under $10M in revenue can justify it.
The buy option is SOC-as-a-service, typically sold as MDR: a vendor's analysts monitor your clients' EDR and identity telemetry and either alert your team or take containment actions under agreed rules. Typical cost is $3–15 per endpoint per month, resold inside your security tier at 2–3x. That gives you 24/7 coverage, a defensible answer on cyber insurance applications, and a named party who was watching when something happened. You still own the response: the on-call path, the client communication plan, and the runbook that says who isolates what. See MSP security operations for how to structure that around an outsourced SOC.