MSSP or In-House SOC?

Every security operations decision that reaches a board eventually gets compressed into two columns. On one side sits a contract with a managed security service provider (MSSP): a monthly fee and a promise of coverage that never sleeps. On the other sits a business case for an internal security operations center, with headcount, tooling, and the appeal of keeping the whole function under one roof. The pitch tends to arrive framed the same way. Which option costs less, and which delivers more capability.

That framing is comfortable because it converts a hard question into an arithmetic one. It is also why so many of these decisions age badly.

Why cost and capability are the wrong axis

The vendor case for buying is a spreadsheet. A mature detection capability, staffed and watching at three in the morning, for less than the fully loaded cost of building the same thing internally. The case for building is about control and context: a team that knows your systems, your people, and the difference between a genuine anomaly and an ordinary Tuesday.

Both arguments are real. Neither is the decision. Gartner's 2025 Market Guide describes MSSP as a turnkey, human-led service delivering threat detection, investigation, and response around the clock, and an earlier piece in this series set out what each detection category actually watches. The category question, endpoint against extended against managed, is settled elsewhere. What a board approves when it signs either option is not a capability. It is a division of labor. And labor is the one part of this decision that can be moved.

‍ ‍

The work is transferable. The accountability is not.

A company can hand the monitoring, the triage, and the first response to a provider. It cannot hand over the consequence. When customer data leaves the building, the regulator writes to the board, not to the vendor. The breach notification carries the company's name. The reporting duties, whether to the SEC or to a sector regulator, attach to the organization and its officers, not to a monitoring contractor. The shareholders, the insurer, and the press all address the entity that owned the data, whatever contract sat behind the screen.

This is the variable the two-column framing omits. The board owns the outcome at three in the morning regardless of who is awake and watching. So the useful question is not which model is cheaper or more capable. It is which failures the organization can afford to own around the clock, and whether it can realistically staff itself to be awake for them.

‍ ‍

What an in-house SOC actually costs to staff

Start with the number that vendors and consultancies both tend to soften. The 2025 SANS SOC Survey, which asks practitioners how they build and run security operations, found that the most common answer to how many people it takes to run a SOC is ten full-time equivalents, covering monitoring, incident response, threat intelligence, and engineering. That is the team, not the tooling.

The arithmetic of coverage forces the number up before skill even enters the conversation. A single monitoring seat, filled every hour of every day, already takes more than four people once weekends, leave, illness, and training are accounted for. Ten is what it takes to cover the seats a real SOC runs and still do more than stare at a queue.

‍ ‍

A credible in-house SOC runs on roughly ten full-time people. At the US median wage for a security analyst, that is about 1.25 million dollars in salaries before a single tool is licensed.

‍ ‍

The US Bureau of Labor Statistics puts the median annual wage for information security analysts at 124,910 dollars as of May 2024. Ten of them approach 1.25 million dollars a year in base pay alone, before benefits, before a SIEM license, before the management layer that keeps a rotation staffed across nights, weekends, and holidays.

The harder problem is not the money. ISC2's 2025 workforce study found that a third of organizations say they lack the resources to staff their security teams adequately, and roughly three in ten cannot afford the skills they actually need. The same body stopped publishing its long-quoted global workforce-gap figure this year, having concluded that the need for critical skills now outweighs the need for raw headcount. The shortage that remains is concrete: even funded teams struggle to hold people. SANS found that 62 percent of practitioners say their own organization is not doing enough to retain them.

A round-the-clock in-house SOC is therefore not a purchase. It is a standing commitment to hire, train, and hold a specialized team through turnover, in a market that makes all three difficult.

‍ ‍

Where managed detection stops, and we will say so

We sell MSSP, which is exactly why the next point carries weight. Managed detection earns its fee on speed. CrowdStrike's 2026 Global Threat Report found that the average breakout time, the interval between an attacker's initial break-in and their first move deeper into the network, fell to 29 minutes in 2025, down from 48 minutes a year earlier.

‍ ‍

When the average intrusion moves laterally within half an hour of breaking in, coverage that only watches during office hours is not coverage. It is a gap with a service badge.

‍ ‍

A provider that is already staffed, already tuned, and already awake closes that half-hour window in a way most companies cannot replicate on their own payroll. That is the honest case for buying.

Here is the honest limit. MSSP does not own your environment, your business decisions, or your reporting clock. A provider can detect an intrusion and recommend or execute containment. It cannot decide whether to pull a revenue-generating system offline, whether to pay or refuse an extortion demand, or when a disclosure obligation to a US regulator has been triggered. It does not patch your systems, govern your identities, or carry your legal exposure. When the alert fires, someone inside the company still authorizes the response, owns the root-cause fix, and answers for the outcome. MSSP makes an organization faster. It does not make it absolved.

‍ ‍

When building in-house is the right answer

An honest operator names the cases where its own product is not the answer. Some environments should keep detection and response internal. Organizations with deep, idiosyncratic systems, where context cannot be transferred to an outsider quickly enough to matter. Sectors with data-residency or sovereignty constraints that make third-party monitoring a compliance problem rather than a solution. Firms at a scale where the economics finally favor a full internal team. The SANS data reflects this pattern: companies tend to keep monitoring, incident response, and compliance internal precisely because those functions demand intimate knowledge of the business and close coordination with legal and executive stakeholders.

For those organizations, an internal SOC is not the expensive option. It is the correct one, and a provider that pretends otherwise is selling.

‍ ‍

The question a board should actually ask

Most organizations land somewhere in between, and that is a defensible place to be. What matters is how they get there. A decision made on cost and capability produces a contract. A decision made on accountability produces a posture: a clear-eyed map of which failures the company will own directly, which it will share, and which it is paying a provider to catch first.

The arithmetic still matters. It simply belongs after the harder question, not in front of it. Whoever is watching the screen at three in the morning, the accountability stays in the building. The board's task is to decide, deliberately rather than by default, how much of the work to keep within reach of the people who will answer for it.


Sources

  1. Gartner, Market Guide for Managed Detection and Response (Pete Shoard, Andrew Davies, Angel Berrios, 1 October 2025). https://www.gartner.com/en/documents/7010398

  2. ISC2, 2025 ISC2 Cybersecurity Workforce Study. https://www.isc2.org/Insights/2025/12/2025-ISC2-Cybersecurity-Workforce-Study

  3. SANS Institute, SANS 2025 SOC Survey (Christopher Crowley, July 2025). https://www.sans.org/white-papers/sans-2025-soc-survey

  4. U.S. Bureau of Labor Statistics, Occupational Outlook Handbook: Information Security Analysts. https://www.bls.gov/ooh/computer-and-information-technology/information-security-analysts.htm

  5. CrowdStrike, 2026 Global Threat Report. https://www.crowdstrike.com/en-us/global-threat-report/


Disclaimer

This article is provided for general informational and educational purposes only. It does not constitute legal, regulatory, financial, or professional security advice, and it should not be relied upon as a substitute for tailored guidance from a qualified adviser who understands your specific environment and obligations. Cost figures, salary benchmarks, and threat-intelligence findings are drawn from the named third-party sources and reflect the periods those sources cover; they are illustrative and will vary by organization, region, and time. Regulatory requirements and reporting obligations change and differ by jurisdiction and sector, so confirm current duties against the relevant primary sources before acting. AKATI Sekurity makes no warranty as to the accuracy or completeness of third-party data cited here.


MSSP or In-House SOC FAQ | AKATI Sekurity

Frequently Asked

MSSP or In-House SOC

The buy-versus-build decision, answered from the seat that runs both.

An in-house SOC is an operating model in which a company builds, staffs, and runs its own security operations team. An MSSP (managed security service provider) is an external firm that runs those functions on the company's behalf, commonly delivering 24/7 threat detection, investigation, and response. The distinction is who does the work, not what the tools can see. Both models can deliver equivalent detection; they differ in staffing, cost structure, and how much day-to-day operation the organization retains.
For most organizations, an MSSP is less expensive than a fully staffed 24/7 in-house SOC, because a provider spreads the cost of analysts, tooling, and round-the-clock coverage across many clients. A credible internal SOC commonly requires about ten full-time staff plus tooling, licensing, and management overhead. But cost is only part of the decision: an MSSP shifts the work to a provider while the accountability for the outcome stays with the company.
Salaries are the largest and most predictable line. The 2025 SANS SOC Survey found that the most common staffing level for a functioning SOC is ten full-time equivalents. At the US median wage for information security analysts, about 124,910 dollars in May 2024 per the Bureau of Labor Statistics, that is roughly 1.25 million dollars a year in base pay alone, before benefits, SIEM licensing, facilities, training, and the management layer needed to sustain a 24/7 rotation.
No. A company can outsource the work of detection and response to an MSSP, but not the accountability for the outcome. An MSSP can detect an intrusion and help contain it, but the organization still decides whether to take systems offline, whether to pay or refuse an extortion demand, and when a regulatory disclosure obligation is triggered. Regulators, customers, insurers, and shareholders hold the company that owned the data responsible, regardless of who was monitoring the systems.
An in-house SOC is often the better choice for organizations with highly idiosyncratic environments where internal context is hard to transfer, for sectors with data-residency or sovereignty constraints that make third-party monitoring a compliance risk, and for firms large enough that the economics favor a dedicated team. Functions that depend on deep business knowledge and close coordination with legal and executive stakeholders, such as incident response and compliance, are also commonly kept internal.
Next
Next

Internal Scans, ASV Scans, Pen Tests