SOC status:Duty analyst on shift

UK Cyber Defence
Guide

What is a managed SOC, and what does SOC as a service cost in the UK?

A managed SOC is a security operations centre you subscribe to rather than build. Here is what you are actually buying, what it costs in the UK compared with building your own, how the market prices it, and how to choose a provider you will not regret a year later.

14 min readRead 6 timesReviewed 13 September 2026

A managed SOC is a security operations centre you subscribe to rather than build: a team of analysts, a detection platform and a response process, watching your systems around the clock for a fee. In the UK the fee ranges from a few thousand pounds a year for a small estate to six figures for a large one, and it is almost always a fraction of what the same coverage costs to build in-house. This guide explains what you are actually buying, what the alternatives cost, how the market prices it, and how to choose a provider without regretting it a year later.

The short answer

If you have between fifty and a few thousand staff, operate in a regulated or high-consequence sector, and do not already employ a security team of eight or more, a managed SOC is the only realistic way to get 24/7 detection and response. Building the equivalent in-house costs from roughly £250,000 a year for a small organisation to over £1 million for a mid-sized one, before anything goes wrong; a managed service typically costs between a fifth and a tenth of that, and is running within weeks rather than a year.

The price you will be quoted depends on the size and shape of the estate — endpoints, identities, cloud tenants, network and log volume — and on how much of the work the provider does for you when something happens. The cheap end of the market monitors and tells you; the expensive end contains, investigates and reports to your board. Knowing which you are buying is most of the skill in buying well.

What a SOC actually does

A security operations centre exists to turn telemetry into decisions. Every laptop, server, identity provider, cloud tenant and firewall you own produces events — logins, processes, network connections, configuration changes — in volumes no human can read. The SOC collects those events, correlates them against known attacker behaviour and against the intelligence it holds, and produces a much smaller stream of things worth a person's attention. An analyst then decides: is this real, what is the attacker trying to do, and what should we switch off first?

That last question is the difference between a SOC and a monitoring service. Detection without response is a smoke alarm with the batteries removed. A SOC worth paying for does four things, in order: it detects (behavioural analytics, engineered detections and threat intelligence applied to your telemetry), it validates (a human confirms the signal and gathers context, so you only hear about what is real), it contains (isolation, credential locking and blocking, either with your approval or under pre-agreed authority), and it reports (what happened, what was done and what to change, in a form your board and your auditors can both use). We describe our own version of this in how SOC365 works, and the longer history and anatomy of the SOC in What is a SOC?.

SOC, MDR, MSSP, SIEM-as-a-service: the vocabulary

The market uses four labels for overlapping things, and vendors are not consistent, so it is worth pinning them down before comparing quotes.

A managed SOC or SOC as a service is the whole operation delivered as a service: platform, analysts, detection engineering, response and reporting. Managed detection and response (MDR) is, in practice, the same promise with more emphasis on the response half; historically MDR providers grew out of endpoint detection tools, so some still see only the endpoint. A managed security service provider (MSSP) is the older category — outsourced management of security tools such as firewalls and SIEM, often with monitoring but usually without investigation or containment. SIEM-as-a-service is the platform alone: your logs, their software, your analysts.

When you read a proposal, ignore the label and ask three questions. Who looks at an alert at 3 a.m., and are they employed by the provider? What can they do about it without waking you? And what do you receive afterwards? Those answers place any provider on the spectrum from "tells you" to "handles it".

In-house, managed or co-managed

Most organisations that build a SOC in-house underestimate the staffing arithmetic. Continuous cover needs at least five analysts to fill one seat around the clock once leave, sickness and training are allowed for, and a single seat is not a SOC: someone has to engineer detections, someone has to run incidents, and someone has to manage the people doing both. Our earlier analysis, Building a SOC in 2025, works through the numbers in detail; the summary is below.

OrganisationTypical in-house teamTechnologyAll-in annual cost (UK)
Small (50–100 staff)2–5 analysts, no 24/7 without outsourcing nightsOpen-source or low-cost tooling, £20k–£50k£250k–£400k
Mid-sized (250–1,000 staff)8–10 analysts plus a responder and a managerCloud SIEM, EDR, some SOAR, £100k–£200k£700k–£1m
Enterprise (1,000+ staff)20–50 across tiers, hunting, intelligence and red teamBest-of-breed platforms, £500k–£1m+£2m–£5m and upwards

Set against those figures, a managed service is not a compromise; it is the same capability bought at the provider's economies of scale. The provider's analysts already exist, its platform is already tuned, and its intelligence is drawn from every estate it watches rather than one. The genuine trade-offs are control and intimacy: an external team has to learn your environment, and you have to trust its judgement about your systems. Both are managed with a named analyst who knows your estate, pre-agreed containment rules and a monthly review where you can see the decisions that were made.

The co-managed model suits organisations that already have one or two security people. The internal team keeps what only it can do — business context, sensitive incidents, relationships with the rest of IT — and the provider supplies the platform, the overnight cover and the detection engineering. It is the arrangement most of our mid-sized clients settle on, and it is usually the cheapest way to get a competent security function that does not burn out.

What SOC as a service costs in the UK

Providers price in one of four ways, and the pricing model tells you something about the service. Per endpoint pricing (a monthly fee per laptop, server or device) is common among MDR providers that grew out of endpoint tooling; it is transparent but tends to leave identity, cloud and network out of scope unless bolted on. Per user pricing suits organisations whose estate is mostly people and Microsoft 365. Per gigabyte pricing follows the SIEM licence underneath and can surprise you when a noisy system doubles your log volume. Flat or tiered pricing, based on the size and complexity of the estate assessed at discovery, is the most predictable. SOC365 is priced per device per month, at a rate that falls as the number of devices rises, which keeps the arithmetic simple and the scope honest: every device you add is watched.

Published UK price points give the shape of the market. Entry-level managed SOC services start at around £15,000 a year for basic coverage of a small estate; several UK providers advertise managed SOC from about £900 a month; MXDR services aimed at Microsoft-centric organisations are quoted at a few pounds per user per month; and enterprise engagements covering thousands of endpoints and multiple cloud tenants run to six figures a year. The spread is wide because the services are not the same. The questions that separate a £15,000 service from a £150,000 one are these:

  • Scope. Endpoints only, or endpoints, identity, cloud, network, OT and applications? The identity layer is where most 2026 intrusions begin, so a service that does not watch Entra ID or Okta is watching the wrong door.
  • Response authority. Will the provider isolate a machine or lock an account at 3 a.m. under rules you have agreed, or send you an email and wait?
  • Detection engineering. Are detections written and tuned for your environment on a schedule, or is the ruleset whatever the platform shipped with?
  • Intelligence. Does the provider hold its own — honeypots, sector reporting, adversary infrastructure tracking — or resell a feed?
  • Reporting and evidence. A monthly service review, an incident report your auditor accepts, ATT&CK coverage you can see, and the records a regulator asks for.
  • Testing. Whether the provider also tests your defences, and whether findings from a penetration test feed straight into detections.
  • Exit. Whether your logs, your detections and your data come with you if you leave.

There are also costs that do not appear on the quote. Onboarding may require agents, log collectors or licence changes; some platforms bill overages on log volume; incident response beyond a defined number of hours may be charged separately or require a retainer. Ask for the total cost of the first year, including onboarding, and for the price of an incident that runs to fifty hours.

For our own service: SOC365 costs between £5 and £12 + VAT per device per month, depending on how many devices we monitor, confirmed after a short discovery so that the price reflects your environment rather than a tier designed for someone else's. For a 200-device organisation that puts a 24/7 managed SOC in the low tens of thousands a year, against the £250,000 to £400,000 the in-house table above suggests. Our Incident Response Retainers are published — from £2,500 a year — because a guaranteed response time should not be something you negotiate on the worst day.

What "good" looks like: the ten questions

Every provider claims 24/7 monitoring, experienced analysts and rapid response. The way to see through the brochure is to ask questions whose answers cannot be improvised. We published the full set in What should a board expect from a modern SOC provider? and turned it into a checklist you can take into a procurement meeting. The ten that matter most:

  1. What is our MITRE ATT&CK detection coverage today, and where are the gaps?
  2. How many threat hunts did you run for clients last quarter, and what did they find?
  3. What are our mean time to detect and mean time to respond, and how are they trending?
  4. Show us a detection you wrote or tuned for an environment like ours.
  5. What containment actions can you take without waiting for our approval?
  6. How do penetration-test findings reach your detection and response posture?
  7. What is your analyst-to-client ratio, and what qualifications do the analysts hold?
  8. How do you evidence our regulatory obligations to an auditor?
  9. If we leave, do we keep our logs, our detections and our data?
  10. What is the single biggest risk you see in our environment today?

A provider who answers the last one with a dashboard rather than a sentence is telling you something.

What onboarding looks like

A credible provider will have a repeatable path from contract to first alert, and it should take weeks rather than quarters. Ours runs in five steps: a discovery workshop to agree scope, crown jewels and the containment rules; telemetry connection — endpoints, identity, cloud, network and any existing tools, in a defined order; a tuning period in which detections are engineered for your environment and the noise is driven down before you are paged for anything; the go-live, with a named duty analyst and your escalation paths tested; and a first monthly review where you see the decisions made, the coverage achieved and the changes proposed. The first four weeks are where most of the value of the first year is created, so ask any provider to describe theirs in the same detail.

Regulation: what the SOC has to prove

Regulated organisations buy a SOC partly for the evidence it produces. The FCA's operational resilience regime expects firms to detect and respond to incidents that threaten important business services and to test that they can; DORA requires an ICT risk management framework, incident classification and reporting, and regular resilience testing for financial entities within its scope; NIS (and NIS2 for organisations with EU operations) puts the same expectations on operators of essential services; Cyber Essentials Plus and ISO 27001 are what counterparties and insurers ask to see. A managed SOC should produce the logs, the response records, the testing evidence and the management reporting these regimes need as a by-product of doing the work, not as a separate paperwork exercise. We set out the detail in How SOC as a service supports FCA, DORA and NIS2 compliance, and the sector pages — financial services, healthcare, legal and the rest — describe what each regulator expects.

Why so many SOC as a service contracts disappoint

Most of the disappointment we hear about from organisations arriving from another provider comes down to five things, none of them exotic. The service was built for a smaller or simpler estate than the one it ended up monitoring, so coverage thinned as the organisation grew, acquired or moved to the cloud. Onboarding took months rather than weeks, because the platform needed heavy customisation or the collectors were an afterthought, and the organisation was exposed for the whole of that period while paying for protection. The provider was built for one country, which shows the moment a subsidiary in another jurisdiction needs the same cover and the same evidence. The service was passive: alerts were generated and forwarded, but nobody investigated, contextualised or contained anything, so the work landed back on an internal team that had bought the service to avoid exactly that. And the contract created lock-in: proprietary platforms, data that could not be exported, detections that belonged to the provider, and a migration that was painful enough to postpone indefinitely.

These are the reasons SOC365 is built the way it is: priced per device so the scope grows with you, connected through standard integrations so that go-live is measured in weeks, run for organisations across the UK and Europe, staffed by analysts who investigate and act rather than forward, and vendor-neutral, so your existing tools stay and your logs and detections leave with you if you ever do. None of that is unique to us. It is simply what you should insist on from anyone.

The mistakes we see most often

The first is buying monitoring and believing it is response: the contract says "24/7 alerting", and at 3 a.m. an email arrives that nobody reads until nine. The second is scoping to the endpoint because that is what the provider's platform does, and discovering after a helpdesk-pretexting attack that nobody was watching the identity provider. The third is accepting alert volume as a measure of value; a SOC that sends you two hundred alerts a month is not working harder than one that sends you three, it is working less. How alert fatigue destroys security teams explains why. The fourth is never testing the service: if you have not simulated an intrusion and watched what the SOC did, you do not know what you have bought.

Frequently asked questions

How quickly should a managed SOC detect and respond? Providers should publish their figures and show you the trend. Ours are a mean time to detect under eight minutes and a mean time to respond under twenty; anything measured in hours is monitoring with a delay.

Do we need our own tools first? No. A good provider brings the platform and works with what you already have — most existing EDR, identity and cloud logs can be ingested — and will tell you honestly where a control is missing rather than sell you a replacement.

Can a managed SOC replace our IT provider? No, and it should not try. Your IT partner keeps things running; the SOC watches for what should not be happening and acts on it. The two work best when the SOC's containment rules are agreed with the IT partner in advance.

What about small organisations? The organisations most often hit by helpdesk pretexting and payment-diversion fraud in 2025 and 2026 were not the largest. A managed SOC sized to the estate — priced on what is monitored, not on enterprise tiers — is the right shape for a firm of thirty as well as three thousand.

How long is the contract? Twelve months is standard and reasonable; the first four weeks of tuning are a genuine investment on both sides. Be wary of three-year lock-ins before the service has been tested, and confirm what happens to your data on exit.

Next steps

If you are choosing a provider, take the checklist into the meetings and score the answers. If you want to see what our own answers look like, SOC365 describes the service, the technology and the retainer pricing, and thirty minutes with an analyst will tell you what we would do in your position — whether or not it involves us.

Share

Written by

PB
Peter Bassill

Founder and Head of Threat Disruption

Founder of UK Cyber Defence. Former Global CISO for a FTSE 100 gaming company and for Microsoft Europe; founded Hedgehog Security in 2009.

WebsiteLinkedIn

Next step

Want this looked at in your own estate?

Thirty minutes with an analyst, not a salesperson. We will tell you whether it matters to you and what to do first.

Related insights

Insights

What Should a Board Expect from a Modern SOC Provider?

Cyber security has moved from the server room to the boardroom. Regulators, insurers, and shareholders now expect boards to demonstrate active oversight of cyber risk — and for most organisations, that means understanding what their Security Operations Centre provider is actually delivering. This article sets out the ten areas every board should scrutinise when evaluating a modern SOC provider, from detection engineering and threat intelligence to transparent reporting, compliance alignment, and measurable outcomes.

Peter Bassill18 min read · 2 reads
Insights

How Alert Fatigue Destroys Security Teams — and How Managed SOC Solves It

The modern SOC is drowning. Industry research consistently reports that organisations receive thousands of security alerts per day, that the majority are false positives, and that analysts are leaving the profession faster than the industry can replace them. Alert fatigue is not a minor inconvenience — it is a structural vulnerability that attackers actively exploit. When every alert looks the same, none of them look important. This article examines the mechanics of alert fatigue, its quantifiable cost to organisations, and the specific practices a well-engineered managed SOC deploys to break the cycle — because the solution is not working harder, but building a fundamentally different operational model.

Peter Bassill18 min read · 4 reads
Insights

How SOC as a Service Supports FCA, DORA and NIS2 Compliance

The regulatory environment for cyber security has undergone a fundamental shift. The FCA's PS21/3 operational resilience framework is now fully enforceable, DORA has been in effect since January 2025, and NIS2 transposition is reshaping obligations across the EU — with the UK's own Cyber Security and Resilience Bill following close behind. For organisations navigating these overlapping requirements, a well-structured SOC as a Service engagement is no longer a convenience. It is a compliance enabler. This article maps the specific requirements of each framework to the capabilities a modern managed SOC should deliver.

Peter Bassill19 min read · 1 read