Every business that gets serious about cyber security eventually asks the same question: do we build our own security operations capability, or buy it as a service?
It’s rarely a question of whether round-the-clock monitoring is needed. Attackers work nights, weekends and bank holidays, and many successful breaches begin outside business hours precisely because nobody is watching. The real question is what genuine 24/7 coverage costs, and which route gets you there without breaking the budget.
A note on why we’re writing this now: we’ve just launched the Atlas Cloud SOC, a UK-based managed security operations centre. This piece sets out the maths and the trade-offs we walk prospective clients through, whichever route they choose.
What does a SOC actually do?
A security operations centre (SOC) is the team, tooling and processes responsible for monitoring your IT environment continuously, detecting threats and responding to incidents. Day to day, that means watching every user, device, application and server; correlating signals across your environment to spot attacks that individual tools miss; investigating alerts to separate genuine threats from noise; containing confirmed threats by isolating devices and restricting accounts; and reporting on what happened and what to fix.
The distinction that matters: security tools generate alerts. A SOC decides what those alerts mean and acts on them. Without that layer, alerts pile up unread, and a typical business tool stack generates thousands per week.
What building an in-house SOC really costs
The headline figure gets quoted a lot, so here’s where it comes from. A credible in-house SOC needs, at minimum:
Analysts on a 24/7 rota
Genuine round-the-clock coverage needs 4–5 analysts once you account for shifts, holidays and sickness. At UK security salaries, £250k–£350k a year before you’ve hired a lead.
SIEM and tooling
Licensing, log ingestion and storage costs scale with your estate. £30k–£100k+ annually for a mid-sized environment.
Training and retention
SOC analyst turnover is notoriously high, and certifications need constant renewal. Budget for recruitment fees on repeat.
Management overhead
Someone senior has to own playbooks, escalation, tuning and reporting. That’s a role, not a side task.
Realistically, a UK mid-market business is looking at £400,000+ per year to run this credibly in-house. Below that spend, what you usually get is a SOC in name only: one or two analysts covering office hours, with alerts going unwatched at exactly the times attackers prefer.
What a managed SOC includes
A managed (or outsourced) SOC gives you the same capability as a shared service. You’re not hiring the rota; you’re renting your share of one that already exists, along with the tooling, playbooks and accumulated experience of analysts who see attacks across many environments rather than just yours.
Ours, for reference, includes 24/7 UK analyst-overseen monitoring, automated triage and enrichment, analyst-led investigation, automated containment, proactive threat hunting, dark web monitoring and monthly reporting, from £15 per user per month. Comparable services price similarly: per-user or per-device subscription, a fraction of the in-house figure.
The trade-off is honesty about what “managed” means. You’re sharing analyst attention with other clients, which is exactly why SLAs matter (more below).
When in-house still makes sense
A managed SOC isn’t the right answer for everyone, and providers who claim otherwise are selling, not advising. Building in-house is worth considering if you’re a large enterprise with a security team of ten or more already in place; if regulation genuinely requires fully segregated operations (rarer than assumed — most UK regulators care about outcomes and data residency, not org charts); or if security operations is your product.
For everyone else, the economics point one way. The mid-market firms we work with in legal and recruitment simply cannot justify £400k a year, and shouldn’t have to accept office-hours-only monitoring as the alternative.
How to evaluate a managed SOC provider
Whoever you talk to, ask these:
1. Where are the analysts, and where does the data live?
UK-based operations and UK data residency matter for GDPR, and for sector obligations under the FCA and SRA.
2. What are the response SLAs, and are they guaranteed or aspirational?
Ask for the contracted numbers and typical real-world times. Ours: 20 minutes guaranteed for critical incidents; 5–10 minutes in practice.
3. Does it build on tooling you already own?
If you’re a Microsoft house, a SOC built on Sentinel and Defender extends your existing investment rather than duplicating it.
4. Is it aligned with recognised frameworks?
NCSC guidance, NIST response playbooks, MITRE ATT&CK mapping. These signal maturity, not marketing.
5. Can you see what they’re doing?
A live portal beats a monthly PDF. If you can’t watch incidents and analyst activity in real time, you’re buying trust blind.
If you’re not sure where your current gaps are, our Cyber Security MOT maps them before you commit to any monitoring service, and Cyber Essentials certification covers the baseline controls a SOC builds on.
Frequently asked questions
What is a SOC in cyber security?
A security operations centre is a dedicated team and set of processes that monitors an organisation’s IT environment around the clock, detects threats and responds to incidents.
How much does a SOC cost in the UK?
Building in-house typically costs £400,000+ per year for genuine 24/7 coverage. A managed SOC delivers the same capability on subscription; ours starts from £15 per user per month, scoped to your environment.
What’s the difference between a managed SOC and an outsourced SOC?
Largely terminology. Both mean a third party runs your security operations. “Co-managed” is the variant where the provider works alongside your internal IT or security team, which is how we operate.
Is a managed SOC suitable for regulated industries?
Yes, provided data residency and reporting obligations are met. Our SOC keeps all data processing and storage in the UK and supports FCA, SRA and legal sector reporting requirements.
Do we need to replace existing security tools?
Usually not. A well-designed managed SOC builds on what you have. Ours runs on Microsoft Sentinel and Defender, so existing Microsoft licensing does more work rather than being replaced.
See what 24/7 coverage would look like for your business
Book a 30-minute discovery call with our UK team. We’ll map your environment, show you the SOC portal live, and give you a scoped proposal with no obligation. And if in-house genuinely makes more sense for you, we’ll say so.
Book a discovery call Explore the Atlas Cloud SOC