MSSP or In-House SOC?
Every security operations decision that reaches a board eventually gets compressed into two columns. On one side sits a contract with a managed security service provider (MSSP): a monthly fee and a promise of coverage that never sleeps. On the other sits a business case for an internal security operations center, with headcount, tooling, and the appeal of keeping the whole function under one roof. The pitch tends to arrive framed the same way. Which option costs less, and which delivers more capability.
That framing is comfortable because it converts a hard question into an arithmetic one. It is also why so many of these decisions age badly.
Why cost and capability are the wrong axis
The vendor case for buying is a spreadsheet. A mature detection capability, staffed and watching at three in the morning, for less than the fully loaded cost of building the same thing internally. The case for building is about control and context: a team that knows your systems, your people, and the difference between a genuine anomaly and an ordinary Tuesday.
Both arguments are real. Neither is the decision. Gartner's 2025 Market Guide describes MSSP as a turnkey, human-led service delivering threat detection, investigation, and response around the clock, and an earlier piece in this series set out what each detection category actually watches. The category question, endpoint against extended against managed, is settled elsewhere. What a board approves when it signs either option is not a capability. It is a division of labor. And labor is the one part of this decision that can be moved.
The work is transferable. The accountability is not.
A company can hand the monitoring, the triage, and the first response to a provider. It cannot hand over the consequence. When customer data leaves the building, the regulator writes to the board, not to the vendor. The breach notification carries the company's name. The reporting duties, whether to the SEC or to a sector regulator, attach to the organization and its officers, not to a monitoring contractor. The shareholders, the insurer, and the press all address the entity that owned the data, whatever contract sat behind the screen.
This is the variable the two-column framing omits. The board owns the outcome at three in the morning regardless of who is awake and watching. So the useful question is not which model is cheaper or more capable. It is which failures the organization can afford to own around the clock, and whether it can realistically staff itself to be awake for them.
What an in-house SOC actually costs to staff
Start with the number that vendors and consultancies both tend to soften. The 2025 SANS SOC Survey, which asks practitioners how they build and run security operations, found that the most common answer to how many people it takes to run a SOC is ten full-time equivalents, covering monitoring, incident response, threat intelligence, and engineering. That is the team, not the tooling.
The arithmetic of coverage forces the number up before skill even enters the conversation. A single monitoring seat, filled every hour of every day, already takes more than four people once weekends, leave, illness, and training are accounted for. Ten is what it takes to cover the seats a real SOC runs and still do more than stare at a queue.
A credible in-house SOC runs on roughly ten full-time people. At the US median wage for a security analyst, that is about 1.25 million dollars in salaries before a single tool is licensed.
The US Bureau of Labor Statistics puts the median annual wage for information security analysts at 124,910 dollars as of May 2024. Ten of them approach 1.25 million dollars a year in base pay alone, before benefits, before a SIEM license, before the management layer that keeps a rotation staffed across nights, weekends, and holidays.
The harder problem is not the money. ISC2's 2025 workforce study found that a third of organizations say they lack the resources to staff their security teams adequately, and roughly three in ten cannot afford the skills they actually need. The same body stopped publishing its long-quoted global workforce-gap figure this year, having concluded that the need for critical skills now outweighs the need for raw headcount. The shortage that remains is concrete: even funded teams struggle to hold people. SANS found that 62 percent of practitioners say their own organization is not doing enough to retain them.
A round-the-clock in-house SOC is therefore not a purchase. It is a standing commitment to hire, train, and hold a specialized team through turnover, in a market that makes all three difficult.
Where managed detection stops, and we will say so
We sell MSSP, which is exactly why the next point carries weight. Managed detection earns its fee on speed. CrowdStrike's 2026 Global Threat Report found that the average breakout time, the interval between an attacker's initial break-in and their first move deeper into the network, fell to 29 minutes in 2025, down from 48 minutes a year earlier.
When the average intrusion moves laterally within half an hour of breaking in, coverage that only watches during office hours is not coverage. It is a gap with a service badge.
A provider that is already staffed, already tuned, and already awake closes that half-hour window in a way most companies cannot replicate on their own payroll. That is the honest case for buying.
Here is the honest limit. MSSP does not own your environment, your business decisions, or your reporting clock. A provider can detect an intrusion and recommend or execute containment. It cannot decide whether to pull a revenue-generating system offline, whether to pay or refuse an extortion demand, or when a disclosure obligation to a US regulator has been triggered. It does not patch your systems, govern your identities, or carry your legal exposure. When the alert fires, someone inside the company still authorizes the response, owns the root-cause fix, and answers for the outcome. MSSP makes an organization faster. It does not make it absolved.
When building in-house is the right answer
An honest operator names the cases where its own product is not the answer. Some environments should keep detection and response internal. Organizations with deep, idiosyncratic systems, where context cannot be transferred to an outsider quickly enough to matter. Sectors with data-residency or sovereignty constraints that make third-party monitoring a compliance problem rather than a solution. Firms at a scale where the economics finally favor a full internal team. The SANS data reflects this pattern: companies tend to keep monitoring, incident response, and compliance internal precisely because those functions demand intimate knowledge of the business and close coordination with legal and executive stakeholders.
For those organizations, an internal SOC is not the expensive option. It is the correct one, and a provider that pretends otherwise is selling.
The question a board should actually ask
Most organizations land somewhere in between, and that is a defensible place to be. What matters is how they get there. A decision made on cost and capability produces a contract. A decision made on accountability produces a posture: a clear-eyed map of which failures the company will own directly, which it will share, and which it is paying a provider to catch first.
The arithmetic still matters. It simply belongs after the harder question, not in front of it. Whoever is watching the screen at three in the morning, the accountability stays in the building. The board's task is to decide, deliberately rather than by default, how much of the work to keep within reach of the people who will answer for it.
Sources
Gartner, Market Guide for Managed Detection and Response (Pete Shoard, Andrew Davies, Angel Berrios, 1 October 2025). https://www.gartner.com/en/documents/7010398
ISC2, 2025 ISC2 Cybersecurity Workforce Study. https://www.isc2.org/Insights/2025/12/2025-ISC2-Cybersecurity-Workforce-Study
SANS Institute, SANS 2025 SOC Survey (Christopher Crowley, July 2025). https://www.sans.org/white-papers/sans-2025-soc-survey
U.S. Bureau of Labor Statistics, Occupational Outlook Handbook: Information Security Analysts. https://www.bls.gov/ooh/computer-and-information-technology/information-security-analysts.htm
CrowdStrike, 2026 Global Threat Report. https://www.crowdstrike.com/en-us/global-threat-report/
Disclaimer
This article is provided for general informational and educational purposes only. It does not constitute legal, regulatory, financial, or professional security advice, and it should not be relied upon as a substitute for tailored guidance from a qualified adviser who understands your specific environment and obligations. Cost figures, salary benchmarks, and threat-intelligence findings are drawn from the named third-party sources and reflect the periods those sources cover; they are illustrative and will vary by organization, region, and time. Regulatory requirements and reporting obligations change and differ by jurisdiction and sector, so confirm current duties against the relevant primary sources before acting. AKATI Sekurity makes no warranty as to the accuracy or completeness of third-party data cited here.
Frequently Asked
MSSP or In-House SOC
The buy-versus-build decision, answered from the seat that runs both.