Short answer: a managed SOC is a security operations centre run by a third party. You subscribe to continuous monitoring, threat detection, investigation and response instead of hiring analysts and staffing shifts yourself. Who needs one: any organisation without 24/7 security coverage, any team where security is somebody's second job, and any business facing regulatory or cyber insurance requirements it cannot meet internally. Organisations with a mature in-house SOC, or a very small estate with no infrastructure, generally do not.
That is the summary. The detail below covers how these services actually work, what separates the models, what should be in scope and what to ask before signing.
What a security operations centre actually does
Before the managed version, the function itself.
A SOC is the team and process responsible for detecting and responding to threats across an organisation's infrastructure. It is not a product you install. It is a capability made of three things: telemetry, analysis and authority to act.
Telemetry flows in from endpoints, servers, cloud workloads, identity providers and applications.
Analysis turns that stream into decisions. Most of it is noise. A small fraction is an attacker, and separating the two is the work.
Authority to act closes the loop. Detecting a compromised host matters only if somebody can isolate it before the attacker moves laterally.
Organisations frequently build the first, partially build the second, and skip the third.
How a managed SOC works in practice
Four stages, running continuously.
Onboarding and baselining. The provider maps your environment, connects data sources and establishes what normal looks like. An alert only means something relative to a baseline.
Continuous monitoring. Telemetry is ingested and correlated around the clock. Correlation is the part that matters. A failed authentication is nothing. A failed authentication followed by a success from a different country, then a new admin account, is a sequence worth waking someone for.
Triage and investigation. Analysts determine whether an alert represents genuine activity, what it touched and how far it reached. This is judgment work, and it is where most in-house efforts collapse under alert volume.
The staffing behind it is tiered. Tier one triages and prioritises alerts. Tier two investigates and remediates what gets escalated. Tier three hunts proactively for threats that have triggered nothing. Around them sit a security architect who designs the detection logic, a compliance function, and a coordinator who is your actual point of contact. Ask who you will be speaking to, because it is rarely the analyst who found the problem.
Containment and response. Isolating hosts, terminating processes, revoking sessions, blocking indicators. Whether the provider does this or hands it back to you is the single most important thing to establish before signing.
What separates the service models
The terminology in this category is genuinely confusing, and vendors do not always help.
Managed SIEM gives you a platform and someone to run it. You still investigate and respond.
SOC-as-a-Service outsources the operations centre broadly, covering monitoring, log management, reporting and compliance alongside detection.
Managed detection and response is narrower and deeper, concentrating on detecting, hunting and responding rather than running a full SOC.
The practical distinction is not scope but authority. Ask whether the provider contains threats or notifies you about them. Services in the first group remove work. Services in the second relocate it.
For teams whose priority is speed of detection and response rather than a complete outsourced operations centre, MDR is frequently the better fit. ESET publishes a mean time to respond of 6 minutes, benchmarked against figures from the Verizon 2025 Data Breach Investigations Report and sample MDR providers, and is named a Market Leader in MDR in the KuppingerCole Leadership Compass 2026
Why 24/7 is the entire argument
This is the part worth dwelling on, because everything else follows from it.
Attacks are timed deliberately. Weekends, holidays and overnight hours are when detection is thinnest and response is slowest, and attackers know the pattern as well as defenders do.
A nine-to-five security function covers about a quarter of the week. An intrusion beginning on Friday evening has roughly sixty hours before anyone examines it properly.
Closing that gap internally means shift coverage. Three shifts, seven days a week, with holiday and sickness cover, requires eight to twelve analysts at minimum. At market rates for people who can genuinely investigate an incident, that is a seven-figure annual commitment before any tooling is purchased.
That arithmetic is the reason this category exists.
What coverage should include
Scope varies more than buyers expect, so establish it explicitly.
Endpoints and servers, the baseline. Cloud workloads and SaaS, increasingly where the real risk sits. Identity, the attack path in most modern intrusions, where credential compromise rarely triggers an endpoint alert. Email, still the dominant initial access vector. Network telemetry where available.
A provider covering endpoints alone is not covering your environment.
Who needs a managed SOC
Specific, because the honest answer is not everyone.
Organisations with no overnight coverage. If nobody is monitoring outside business hours, the gap is structural and no product closes it.
Teams where security is a secondary responsibility. A sysadmin handling security alongside infrastructure will handle it when nothing else is urgent, which is precisely the wrong time.
Organisations facing regulatory or insurance requirements. EDR, XDR and MDR are becoming prerequisites for cyber insurance rather than optional differentiators, and several providers now bundle warranty cover with eligible subscriptions.
Small security teams drowning in alerts. These services are not only for organisations with nothing. They frequently take triage away from a capable team so it can do architecture instead.
Organisations that have had an incident. The clearest predictor of purchase, and the most expensive way to arrive at the decision.
Who probably does not
Mature enterprises with an existing SOC running genuine shift coverage and their own threat intelligence.
Very small operations with a handful of managed laptops, enforced MFA and no on-premises infrastructure. The attack surface may not justify the spend.
Organisations with specialised regulatory constraints requiring security operations to remain physically or legally in-house.
Six questions to ask before signing
What is your mean time to respond, and measured from what? Detection to first action is a different number from detection to full remediation.
Do you contain threats or notify us? Get the authority boundaries written into the contract.
What is in scope? Endpoints only, or cloud, identity and email as well. Misconfiguration and lack of visibility are among the most common cloud security risks, and neither produces an endpoint alert, so a device-only service leaves the newer exposure uncovered.
Who investigates? A named team familiar with your environment, or whoever picks up the queue.
What happens during a real incident? Escalation path, forensic support, and whether incident response is included or billed separately.
How is onboarding handled? The better providers assess your environment and build a profile rather than applying a template.
Common questions
How much does a managed SOC cost? Pricing is typically per endpoint or per user, monthly. The useful comparison is against the eight to twelve analysts an equivalent in-house function requires, not against a software licence.
Is MDR the same as a managed SOC? No. MDR concentrates on detecting, hunting and responding to threats. A managed SOC covers a broader operational scope including log management, reporting and compliance. MDR is deeper and narrower.
Do small businesses need one? If you have servers, cloud workloads or regulated data and nobody monitoring outside business hours, yes. If your estate is a handful of laptops with enforced MFA and no infrastructure, probably not.
How long does onboarding take? Days to weeks for MDR, weeks for a broader managed SOC. Building the equivalent internally takes six to eighteen months.
Does it replace our IT team? No. It removes alert triage and incident response, which frees internal staff for architecture and engineering rather than replacing them.
What happens to our data if we leave? Ask before signing. Historical telemetry and custom detection logic are the two things providers are least consistent about returning.
The realistic summary
A managed SOC solves a staffing problem before it solves a security problem. The security improvement follows from having competent people watching continuously, which is something most organisations cannot fund directly.
The decision turns on two things. Whether your current coverage has gaps you can name, and whether closing them internally costs more than buying the capability.
For most organisations below enterprise scale, that comparison is not close. The value is in the hours nobody is currently watching, and those hours are exactly when attacks are timed to land.


