Q1. What Is a Managed SOC, and What Are You Really Buying When You Outsource It?
A managed SOC, sold as SOC-as-a-Service or an outsourced SOC, is a third-party team and stack that monitors, detects, investigates, and responds to threats across your environment around the clock. What you buy goes deeper than alerts. You buy institutional memory: the correlation rules, the tuning, and the detection logic built over years. The contract decides whether that memory stays yours.
24/7 Eyes on Your Environment – Without the Headcount
The question nobody answers on the sales call
I have sat through a lot of vendor demos. Most skip the one question that matters. Who watches what your agents are actually doing in your environment, and confirms nothing leaked?
Most teams buy point solutions and never stitch them together. From what surfaces when you actually run these environments, the average company juggles around 76 security tools. That sprawl is the real problem a managed SOC solves.
Monitoring tool, MDR, MSSP, or SOCaaS
These terms get used interchangeably. They are not the same thing, and the difference shows up at 2 a.m.
| Category | What it does | The gap |
|---|---|---|
| Monitoring tool | Sends alerts | No one triages them for you |
| MSSP | Manages devices, forwards alerts | Often stops at “here’s an alert” |
| MDR | Detects and responds with analysts | Logic may live in their box |
| SOCaaS | Full outsourced SOC team and stack | Scope and ownership vary widely |
A useful mental model is the old M&M network: a hard candy shell around a soft center. Once an attacker is past the perimeter, only people watching the inside catch them.
A free win you can run Monday morning
Here is a tactic that costs nothing. As a Google or Microsoft admin, you can pull every app where staff authenticated through OAuth consent. That list is a rich source of vendors and shadow tools you did not know were touching your data.
Run it once. You will find sanctioned-looking apps no one approved. That is your real attack surface, and it is usually wider than the asset inventory says.
What you are really buying

The honest reframe: you are buying continuity of judgment, not a dashboard. Verizon’s 2025 DBIR found ransomware present in 44% of breaches, so the response muscle matters more than the alert feed.
At UnderDefense, we run this as a vendor-agnostic MDR service. We monitor inside your stack and surface the full tool and agent sprawl, rather than forcing your data into a box you cannot leave. Price tracks the business logic you would have to rebuild elsewhere, never a flat device count.
Q2. How Much Does a Managed SOC Cost: Pricing Models, Tiers, and the Fees Nobody Quotes?
Managed SOC pricing in 2026 typically runs $10 to $20 per asset, $8 to $30 per endpoint, or $50 to $200 per user per month. Tiers stretch from roughly $3,000 a month at entry to $40,000 and up at premium, plus onboarding fees. The cost that wrecks budgets is per-GB log ingestion billing, which quietly penalizes the high-fidelity logging that actually catches attackers.
The four pricing models, side by side
Vendors price the same service four different ways. The model you pick changes your bill and your risk.
| Model | Typical range (monthly) | Best fit |
|---|---|---|
| Per asset | $10 to $20 | Mixed device estates |
| Per endpoint | $8 to $30 | Endpoint-heavy orgs |
| Per user | $50 to $200 | People-heavy, few servers |
| Per GB of logs | $200 to $500 per GB | Data-light environments only |
Public starting prices help anchor the math. Microsoft Defender Experts starts near $12 per user a month, CrowdStrike Falcon Complete near $59.99 per device, and Arctic Wolf near $2.99 per user.
Tiers and a worked example
Most providers stack three tiers. A 250-person company is a useful test case.
| Tier | Monthly band | What you get |
|---|---|---|
| Entry | $3,000 to $7,000 | Monitoring, basic triage |
| Mid | $8,000 to $20,000 | 24/7 response, tuning |
| Premium | $25,000 to $40,000+ | Threat hunting, dedicated team |
For that 250-employee org on a mid tier, budget roughly $10,000 to $15,000 a month, plus a one-time onboarding fee of $5,000 to $20,000, plus SLA add-ons. Buyers tell us onboarding is the line item they forget. You can sanity-check these bands against our SOC pricing page.
“Setting everything up took some back and forth to get our tools properly integrated. Not really a complaint since it’s expected, but worth mentioning. You’ll need to dedicate some time upfront.”
Verified User in Marketing and Advertising UnderDefense G2 Verified Review
The per-GB trap
Per-GB ingestion billing punishes good security. The more telemetry you collect, the more you pay, so teams quietly drop logs to save money and go blind in the process. Disk pressure makes it worse: when plain-text logs routinely hit 80% of a volume’s free space, a single event storm can bring a managed SIEM to its knees.
“UnderDefense is surprisingly affordable considering the level of protection we get. Their proactive threat hunting and rapid response have saved us from incidents.”
Verified User in Program Development UnderDefense G2 Verified Review
We price UnderDefense by what you protect, not by surprise log volume, so high-fidelity logging stays an asset rather than a penalty.
Q3. Is It Cheaper to Build an In-House SOC or Outsource It?
Outsourcing a SOC usually costs 60% to 80% less than building and staffing a 24/7 internal team, mostly because experienced analysts are scarce and expensive to keep. The sharper argument is what an outside team catches first. One onboarding surfaced a $300K payroll fraud in the first three months, paying for the contract before the security value even started.
The talent math nobody wins
A 24/7 in-house SOC needs eight to twelve analysts to cover shifts, holidays, and burnout. That is salaries, tooling, and a hiring market where senior analysts churn fast. Most mid-market teams cannot win that bidding war.
The deeper cost is toil. When every change runs through manual labor, you bring a knife to a gunfight against attackers who move in minutes. This is the heart of the outsourced vs in-house SOC decision.
A budget visual that exposes the gap
Here is a tactic I give every CISO prepping a board deck. Map your spend against the NIST CSF risk families on a single page.
That one visual is often uncomfortable. Many teams find near-zero dollars sitting in the proactive column, with everything bunched in reactive cleanup. IBM’s 2025 report put the global average breach cost at $4.44M, with AI-driven detection finally bending the curve down. A clear SOC cost calculator makes that column visible fast.
The ROI that pays for itself
The number that lands in a board meeting is the one nobody budgeted for. On one engagement, we surfaced a $300K fraud during the first three months, entirely by accident, while standing up monitoring.
Across deployments we have seen roughly 830% ROI over three years and around 99% noise reduction, which is proactive capacity without a hiring spree.
“We needed round-the-clock monitoring for compliance reasons, but building our own SOC wasn’t realistic with our budget and the current hiring market. UnderDefense fills that gap without us having to hire a full team.”
Verified User in Marketing and Advertising UnderDefense G2 Verified Review
“UnderDefense is surprisingly affordable considering the level of protection we get. They find problems before they become big.”
Verified User in Program Development UnderDefense G2 Verified Review
Q4. Why Do Vendor Lock-Ins Quietly Reset Your Security Maturity to Zero?
Vendor lock-in in a managed SOC turns on one thing: who owns your detection logic. When the business logic, correlation rules, and automation rules live inside a vendor’s proprietary platform, switching means leaving years of tuning behind and climbing the maturity curve again from zero. Pricing models that bill per GB deepen the trap, because your own log history becomes leverage the vendor holds.
The situation: maturity you cannot see
Security maturity is invisible until you try to move it. Two years of tuned alerts, suppressed false positives, and custom correlations feel like yours. They sit on the books as institutional knowledge.
Then you change providers and discover how little of it travels.
The complication: what does not come with you
When you make a vendor switch, the business logic, the correlation rules, and the automation rules often do not come with. You start the tuning process over, and years of institutional memory vanish because it was locked in a proprietary system. This is one of the biggest reasons businesses switch providers in the first place.
Per-GB billing makes the exit worse. Your historical logs live in their platform, and extracting them turns into a negotiation. The pricing model and the lock-in are the same problem wearing two hats.
Patents make the risk concrete. One filing describes a system that auto-generates and reorders proprietary response playbooks, which means the logic protecting you is owned by the vendor, not by you.
The proof: a Monday-morning scramble
I have watched this happen. A team got word their provider was shutting down the next Monday, which forced their hand into a seven-day migration with no clean export. For urgent exits like that, our incident response team can stand up coverage fast. Cybersecurity has its own Blockbuster stories: vendors that look permanent and are gone in two or three years, taking your maturity down with them.
The resolution: own the logic
The escape hatch is treating detection logic as something you own and can move. That principle, detection-as-code, is where the next section goes deeper.
We built the UnderDefense Agentic AI SOC platform around it. We log into your SIEM and XDR, so the correlation rules and detection logic stay in your environment, and a switch becomes an engineering task rather than a reset to zero. Monitoring-only tools and many traditional MSSPs keep that logic in their box, where it dies on exit.
Q5. What Contract Clauses and SLAs Should You Demand Before Signing?
Before signing, demand clauses that keep your detection logic yours: data and rule portability, penalty-free exit, defined transition assistance, transparent cost terms, and real response-time SLAs. Insist on two separate commitments, a 2-minute Alert-to-Triage and a 15-minute escalation for critical incidents. Then ask the one question that reveals everything: if you terminate, do all correlation rules, integrations, and detection logic remain in your SIEM (your security log platform)?
The eight clauses I would not sign without
A contract is where the sales promises either hold or evaporate. Here is the checklist I walk clients through, with what good looks like for each.
- Response SLAs. Demand a 2-minute Alert-to-Triage and a 15-minute escalation for critical incidents, written separately. A single blended “MTTR” number hides which one is slow. We break this down further in our guide to the SLA in cybersecurity.
- Exit and termination. Penalty-free exit with a notice window measured in 30 days, never 60.
- Data portability. Your logs export at a published rate, in a standard format, on demand.
- Detection-content ownership. Correlation rules and automation logic belong to you on exit.
- Interoperability. The provider works inside your stack, not only their portal.
- Cost transparency. No surprise ingestion or egress line items.
- Escalation path. A named procedure to reach a human for a critical incident.
- Transition assistance. Documented handover support when you leave.
What good looks like, side by side
| Clause | Weak version | What to demand |
|---|---|---|
| Exit | 60-day auto-renew | 30-day penalty-free |
| Data | “Available on request” | Published-rate export |
| Logic | Vendor-owned | Stays in your SIEM |
Map your SLAs to the law
Your response clocks should match the regulators who will judge you after an incident.
- SEC Cyber Disclosure Rule, Item 1.05: material incidents reported on an 8-K within four business days.
- GDPR Article 33: notify the supervisory authority within 72 hours.
- EU NIS2 and ISO/IEC 27001: documented incident handling and timely notification.
Write these windows into the contract. A vendor whose escalation is slower than your legal clock is a liability on paper, which is exactly why disciplined compliance services tie response times to regulatory deadlines.
The Termination Test
Here is the question I have clients ask every candidate. “Will you log into our SIEM and XDR, or do you require us to send data to your platform?” Then: “If we terminate, do all rules and detection logic stay in our SIEM?”
I will admit this gets contested. Some teams want a next-generation SIEM and a provider running it, and that tension is real. UnderDefense passes the Termination Test by design, because our MDR service logs into your stack and leaves the correlation rules and detection logic with you.
“Their adherence to SLAs gives me confidence in our infrastructure’s protection. It lets me focus on strategy, knowing the day-to-day security is managed effectively.”
Oleg K., Director of Information Security UnderDefense G2 Verified Review
“Their expert management of our SIEM has added to the value of our security investments and tools.”
Yaroslava K., IT Project Manager UnderDefense G2 Verified Review
Q6. Why Is “Detection Logic as Code” the Asset You Should Actually Own?
The asset worth owning is your detection logic, written like software: in flexible languages such as Python, version-controlled, unit-tested, and deployed through CI/CD (the automated pipeline that ships code). Treating detection as code sharpens alerts, keeps your rules portable across vendors, and forms the foundation for an AI-driven SOC. Own the code, and no contract can hold your visibility hostage.
The standard read gets this backwards
Most buyers obsess over the platform and ignore the logic running inside it. The platform is rented. The detection logic is the part that should be yours.
Forward-looking teams treat detection rules like software. They write them in flexible languages, version them, test them, and deploy them through CI/CD, which is a core theme in our SOC automation checklist.
Why code beats a black box
When detection lives as code, it becomes portable and auditable. You can read it, test it, and carry it to another environment.
Mapping those rules to MITRE ATT&CK, the public catalog of attacker techniques, makes coverage visible. You see exactly which techniques you detect and which you miss, technique by technique, and pairing that with the right threat detection tools closes the gaps faster.
The foundation for an AI SOC

Detection-as-code is also what makes an AI SOC trustworthy. The AI collects and correlates context at machine speed, and then a human decides.
I think of unsupervised agents like a brilliant teenager: supremely capable, with no fear of consequence. You want that horsepower on context-gathering, with a person owning the call. Across our investigations, this model auto-closes more than 95% of items as false positives, which frees analysts for the real ones. Research backs the design: studies find AI should surface evidence over verdicts, and even strong LLM ensembles still need humans in the loop. We dig into that balance in our take on whether AI kills or saves the SOC.
That is how we run the UnderDefense Agentic AI SOC platform: AI collects context, your team decides, and the logic stays yours.

Q7. How Long Should a Managed SOC Retain Your Data, and Why Does It Matter for Investigations?
Plan for at least 40 days of immediate, online retention on fast storage, roughly six weeks, because that is the natural window where investigations and pattern analysis need rapid access before data moves to slow long-term storage. Shorter windows look cheaper while blinding your forensics. Retention is the difference between reconstructing an attack and guessing at it.
The 40-day rule
Here is the number I give every team. Keep about six weeks of data online, on fast storage, before anything drops to the long-term log store.
That window matches how real investigations work. You rarely chase yesterday’s alert; you chase a pattern that spans weeks, which is why managed SIEM retention sizing matters so much.
Why depth beats a tidy alert feed
Shallow logs miss the attacks that matter. In one case, an attacker abused a mail server component called memcache to craft specific requests and harvest more than ten credential pairs, and the activity stayed invisible to EDR (endpoint detection).
Network depth matters too. I have seen an MTU mismatch (a packet-size setting) leave an ICMP error trail that became the only thread back to the real entry point. Without retained packet and log detail, that trail is gone, and a fast incident response depends on having it.
Tie retention to dwell time
Retention should track how long attackers actually hide. Mandiant’s M-Trends 2026 put global median dwell time at 14 days, pushed up by edge-device persistence. Verizon’s 2025 DBIR found edge-device exploitation up roughly eightfold, with a median 32 days to remediate.
A 30-day retention window cannot reconstruct a 32-day remediation story. At UnderDefense, our SOC service sizes retention to investigation reality, never to whichever tier is cheapest to bill.
Q8. Is Your “Managed” Contract Real Security or Just Compliance Theater?
Many “managed” contracts amount to compliance theater, with vendors using AI to answer security questionnaires while buyers use AI to ask them, and neither process preventing tomorrow’s incident. Real security shows up as caught and contained live threats, measured in response speed and false-positive handling. Demand transparency into how a provider’s AI behaves before you trust the attestation.
When the paperwork stops meaning anything
Automated questionnaire responses, including AI-generated ones, have become mutually assured compliance theater. One side’s AI writes the answers, the other side’s AI reads them, and nobody is safer for it.
The honest test of any control is simple. Does it stop an incident tomorrow? A SOC 2 Type II report or an ISO 27001 certificate describes a process, never a guarantee of detection, a distinction our compliance roadmap spells out in detail.
Transparency beats a clean attestation
I would rather run a model I can watch misbehave than trust one a vendor calls unbiased. A model whose errors I can measure is one I can correct. A model sold as flawless is usually hiding something. We flag this exact pattern in our list of AI SOC red flags.
That matters because attackers move fast. The quickest break-in we have clocked sat around 51 seconds, which is shorter than most questionnaire review cycles.
“We receive alerts, but not necessarily a clear path to resolution. This is not an extension of our security team as was originally sold.”
Sr. Cybersecurity Engineer Arctic Wolf Gartner Verified Review
What to verify instead
Trade the paperwork for proof you can observe. Ask to see live triage, response times, and how false positives get handled.
The metrics that matter are a 2-minute Alert-to-Triage, a 15-minute escalation for critical incidents, and a documented false-positive rate. At UnderDefense, our concierge analysts act on threats rather than forwarding them, which is the proof an attestation cannot give you.
“The biggest win for me was getting actual control over our security alerts. When they escalate something, they include the context we need to understand the issue quickly.”
Verified User in Marketing and Advertising UnderDefense G2 Verified Review
Q9. How Does an AI SOC Change Detection, Response, and the Grunt Work of Triage?
An AI SOC collects and correlates context at machine speed, then hands analysts a decision-ready picture so humans respond rather than wade through raw alerts. Done well, it auto-closes the overwhelming majority of false positives and frees analysts for real investigations. The model that wins keeps a human in the loop, because even strong AI detection still mislabels a meaningful share of events.
The simple version
Think of an AI SOC as two layers working together. The machine gathers and connects evidence fast, and a person makes the call.
An alert by itself is a noise. The AI turns scattered signals into one picture, so the analyst starts with context instead of a raw ping, a shift we explore in our piece on conversational SOCs.
What the proof shows
This split has support in both patents and research. Filings describe systems that run autonomous threat hunting and end-to-end incident investigation. Academic work is clear on the guardrail: AI should surface evidence over verdicts, and even strong LLM ensembles hit only around 82.8% detection accuracy, so people stay essential.
In our own work, this model auto-closes more than 95% of investigations as false positives. That is the grunt work disappearing, with humans aimed at the items that matter, which is the heart of practical AI in cybersecurity.
Why the human still matters
There is a quiet trap here. You can find a strange zen in copying and pasting through triage, but that toil never actually goes away on its own. Automation should erase the repetitive work, and then a person should own the response. Disciplined SOC automation is what makes that division of labor hold.
Being a human is a flex in 2026, especially on the edge cases a model misreads. That is how we run the UnderDefense Agentic AI SOC platform: machine-speed context, concierge response, a 2-minute Alert-to-Triage, and a 15-minute escalation for critical incidents.

Q10. Managed SOC Providers Compared: How Do You Pick a Partner Over a Black Box?
The best managed SOC for you depends on whether you want alerts or someone who acts on them. Monitoring-only tools deliver context-free alerts. Many traditional MSSPs add people while holding your logic hostage. AI-native providers with concierge response collect context at machine speed and respond with you. The decisive test: on exit, does your detection logic walk out the door with you?
The one question that sorts the field
Vendors blur together on feature lists. They separate fast on one question: when you leave, do your rules and detection logic come with you?
I will not pretend device count means nothing, but treating a managed SOC as a commodity priced per device misses the real variable. The cost that bites later is rebuilding business logic you thought you owned, which is why our MDR vendors list weighs ownership heavily.
Providers at a glance
| Provider | Response model | Lock-in risk | Best for |
|---|---|---|---|
| UnderDefense | Concierge response, works in your stack | Low, logic stays in your SIEM | Mid-market wanting ownership |
| Arctic Wolf | Co-managed, vendor-run platform | Higher, changes route through their team | Teams wanting a turnkey portal |
| CrowdStrike Falcon Complete | Vendor-managed on Falcon | Higher, tied to Falcon estate | Endpoint-first orgs |
| Rapid7 | Managed on Insight platform | Moderate to higher | Existing Insight users |
| Secureworks Taegis | Managed XDR | Moderate | Taegis adopters |
| Sophos MDR | Vendor-managed | Moderate | Sophos-stack SMBs |
| Microsoft Defender Experts | Managed on Defender | Higher, Microsoft-bound | Microsoft-heavy estates |
| Huntress | Managed, SMB focus | Lower to moderate | Smaller teams |
What buyers actually report
The structural trade-offs show up in verified reviews. Several point to alerts without a clear path to action.
“Solid detection and response capabilities, but overly relies on the client’s team for remediation, which really hurts the value of the service.”
VP of Technology Arctic Wolf Gartner Verified Review
“Anything you want to look at or changes you need to make in the product must go through their engineering team.”
Matt C., Manager, Cybersecurity Services Arctic Wolf G2 Verified Review
“I really like how UnderDefense’s dashboards are. It guides me on what to do if there’s a problem.”
Alexey S., CEO UnderDefense G2 Verified Review
Best-fit scenarios
- Endpoint-heavy and standardized on one EDR: a vendor-native option fits, if you accept the lock-in.
- Mid-market wanting to keep your maturity portable: pick a provider that works inside your SIEM and leaves the logic with you.
We built our MDR service around that second case, with concierge response, a 2-minute Alert-to-Triage, and a 15-minute critical escalation. If you want a straight answer on fit, that is a conversation worth having.
Q11. How Do You Switch Managed SOC Providers Without Losing Years of Tuning?
Switch without resetting your maturity by treating detection logic, correlation rules, and historical data as your property from day one. Export and version your rules, confirm data portability in writing, run the new provider in parallel before cutover, and keep a documented transition window. When a vendor fails suddenly, that prep is the difference between a seven-day scramble and an orderly move.
Treat the exit like an engineering project

A migration goes sideways when the logic lives in someone else’s box. It goes smoothly when you own the rules and can move them. This is one of the biggest reasons businesses switch providers.
I have watched a team get word their provider was closing the next Monday. That forced a seven-day switch, and the only reason it worked was that their detection logic was portable.
The six-step playbook
- Inventory and export every detection rule and automation, version-controlled.
- Confirm exit and portability clauses in writing, including data export rates.
- Run the new provider in parallel before you cut anything over.
- Validate use-case coverage rule by rule against your old setup.
- Migrate historical logs so investigations keep their depth.
- Decommission the old tooling only after validation passes.
Parallel running is the step teams skip and regret. On large SIEM builds, we have validated 35 of 37 fully defined use cases inside 12 weeks, which proves a migration can be planned rather than panicked. NIST SP 800-61 backs continuity of monitoring through any transition, the goal of continuous security monitoring.
What buyers say about messy exits
“We received little value. Anything you want to look at or changes you need to make in the product must go through their engineering team.”
Matt C., Manager, Cybersecurity Services Arctic Wolf G2 Verified Review
“It pulls in data from all our existing security tools, so we didn’t have to rip and replace anything.”
Verified User in Marketing and Advertising UnderDefense G2 Verified Review
At UnderDefense, onboarding logs into your existing SIEM and XDR and runs alongside your current setup, so a switch becomes an engineering task. For urgent exits, our incident response team can stand up coverage fast.
Q12. So Which Managed SOC Model Is Right for Your Organization?
Pick the model by your constraint. Scaling tech teams need vendor-agnostic integration that grows without re-platforming. Regulated healthcare needs retention and notification SLAs mapped to HIPAA and breach rules. PE portfolios need transparent, portable cost across many companies. Across all of them, choose the provider whose contract leaves your detection logic and data in your hands.
One principle under every decision
Everything in this guide collapses into three moves. Own your logic, demand transparent pricing, and buy response rather than alerts.
Pricing, lock-in, contract clauses, and the AI SOC are all the same question wearing different clothes. Who holds the keys to your visibility when the relationship ends? Our SOC service is built so that answer always favors you.
A rubric by org type
| Your situation | What to prioritize |
|---|---|
| Scaling tech (500 to 2,000) | Vendor-agnostic integration, no re-platforming |
| Mid-market enterprise | Real response SLAs, portable detection logic |
| Regulated healthcare | Retention plus notification SLAs mapped to breach rules |
| PE portfolio company | Transparent, repeatable cost across entities |
The thread running through all four is ownership. A black box that performs well today still resets your maturity the day you leave it. Regulated teams can see how this plays out in our MDR for Healthcare work.
What I keep coming back to is a simple test for any provider: would they hand you your logic and data tomorrow without a fight? We built UnderDefense to answer yes, and if you want to pressure-test that against your own environment, the door is open through a quick conversation with our team.
Ready for round-the-clock detection and response? Talk to a team that runs SOCs for companies like yours
1. What is a managed SOC, and what am I really buying when I outsource it?
A managed SOC, sold as SOC-as-a-Service or an outsourced SOC, is a third-party team and stack that monitors, detects, investigates, and responds to threats around the clock. What you buy goes deeper than alerts.
You are really buying institutional memory: the correlation rules, the tuning, and the detection logic built over years. The contract decides whether that memory stays yours.
- Monitoring tools send alerts but never triage them for you.
- Many MSSPs manage devices and forward alerts, often stopping at “here is an alert.”
- MDR detects and responds with analysts, though the logic may live in their box.
- SOCaaS delivers a full outsourced SOC team and stack, with scope and ownership that vary widely.
The honest reframe is that you are buying continuity of judgment, not a screen full of pings. The average company juggles around 76 security tools, and that sprawl is the real problem a coordinated SOC service solves. We run ours as a vendor-agnostic MDR service that monitors inside your stack rather than forcing your data into a box you cannot leave, so the maturity you build stays portable when the relationship ends.
2. How much does a managed SOC cost in 2026?
Managed SOC pricing in 2026 typically runs $10 to $20 per asset, $8 to $30 per endpoint, or $50 to $200 per user per month. Tiers stretch from roughly $3,000 monthly at entry to $40,000 and up at premium, plus onboarding fees of $5,000 to $20,000.
Vendors price the same service four different ways, and the model you pick changes both your bill and your risk:
- Per asset, best for mixed device estates.
- Per endpoint, best for endpoint-heavy organizations.
- Per user, best for people-heavy teams with few servers.
- Per GB of logs, suitable only for data-light environments.
For a 250-employee org on a mid tier, budget roughly $10,000 to $15,000 a month plus onboarding and SLA add-ons. The line item buyers forget is onboarding. The cost that wrecks budgets is per-GB ingestion billing, which quietly penalizes the high-fidelity logging that actually catches attackers. You can sanity-check these bands against our SOC pricing page or model your own scenario with the SOC cost calculator. We price by what you protect, never by surprise log volume.
3. What contract clauses and SLAs should I demand before signing a managed SOC contract?
Before signing, demand clauses that keep your detection logic yours and your exit clean. A contract is where sales promises either hold or evaporate.
- Response SLAs written separately: a 2-minute Alert-to-Triage and a 15-minute escalation for critical incidents, because a single blended number hides which one is slow.
- Penalty-free exit with a 30-day notice window, never 60.
- Data portability at a published export rate in a standard format.
- Detection-content ownership, so correlation rules and automation logic belong to you on exit.
- Interoperability, cost transparency, a named escalation path, and documented transition assistance.
Map those response clocks to the regulators who will judge you: the SEC four-business-day 8-K rule, GDPR Article 33’s 72-hour window, and NIS2 or ISO 27001 notification duties. A vendor whose escalation is slower than your legal clock is a liability on paper, which is why our compliance services tie response times to deadlines. The decisive question is the Termination Test: if you terminate, do all rules and detection logic stay in your SIEM? Our SLA guidance details how to write these in.
4. How do I avoid vendor lock-in with an outsourced SOC?
You avoid lock-in by treating your detection logic as an asset you own rather than something rented inside a vendor’s platform. Most buyers obsess over the platform and ignore the logic running inside it, but the platform is rented and the logic should be yours.
The practical move is to treat detection like software:
- Write rules in flexible languages, version them, and unit-test them.
- Deploy through CI/CD so they stay portable and auditable.
- Map coverage to MITRE ATT&CK so you see which techniques you detect and which you miss.
When detection lives as code, you can read it, test it, and carry it to another environment. That portability is also what makes an AI SOC trustworthy: the machine collects context at speed, and a human owns the call. Across our investigations, this model auto-closes more than 95% of items as false positives. This is exactly how we run the UnderDefense MAXI platform, where AI collects context, your team decides, and the logic stays yours. We explore the human-in-the-loop balance further in our view on whether AI saves the SOC.
5. How long should a managed SOC retain my data, and why does retention matter?
Plan for at least 40 days of immediate, online retention on fast storage, roughly six weeks, before data moves to slow long-term storage. That is the natural window where investigations and pattern analysis need rapid access. Shorter windows look cheaper while blinding your forensics.
The number matches how real investigations work. You rarely chase yesterday’s alert; you chase a pattern that spans weeks. Shallow logs miss the attacks that matter:
- In one case, an attacker abused a mail server memcache component to harvest more than ten credential pairs while staying invisible to EDR.
- An MTU mismatch once left an ICMP error trail that became the only thread back to the real entry point.
Retention should also track attacker dwell time. Mandiant’s M-Trends 2026 put global median dwell time at 14 days, and Verizon’s 2025 DBIR found a median 32 days to remediate edge-device exploitation. A 30-day window cannot reconstruct a 32-day remediation story. Our managed SIEM and incident response teams size retention to investigation reality, never to whichever tier is cheapest to bill.
6. Is my managed contract real security or just compliance theater?
Many “managed” contracts amount to compliance theater. Vendors use AI to answer security questionnaires while buyers use AI to ask them, and neither process prevents tomorrow’s incident.
The honest test of any control is simple: does it stop an incident tomorrow? A SOC 2 Type II report or an ISO 27001 certificate describes a process, never a guarantee of detection. Attackers move fast; the quickest break-in we have clocked sat around 51 seconds, shorter than most questionnaire review cycles.
Trade the paperwork for proof you can observe:
- Ask to see live triage and real response times.
- Verify how false positives get handled and measured.
- Confirm a 2-minute Alert-to-Triage and a 15-minute critical escalation in writing.
We would rather run a model we can watch misbehave and correct than trust one a vendor calls flawless. Transparency beats a clean attestation every time. Our concierge analysts act on threats rather than forwarding them, which is the proof an attestation cannot give you. Learn what warning signs to watch for in our breakdown of AI SOC red flags.
7. How do I switch managed SOC providers without losing years of tuning?
You switch without resetting your maturity by treating detection logic, correlation rules, and historical data as your property from day one. A migration goes sideways when the logic lives in someone else’s box and smoothly when you own the rules and can move them.
The playbook we walk clients through is straightforward:
- Inventory and export every detection rule and automation, version-controlled.
- Confirm exit and portability clauses in writing, including data export rates.
- Run the new provider in parallel before you cut anything over.
- Validate use-case coverage rule by rule against your old setup.
- Migrate historical logs so investigations keep their depth, then decommission old tooling.
Parallel running is the step teams skip and regret. On large SIEM builds, we have validated 35 of 37 fully defined use cases inside 12 weeks, which proves a migration can be planned rather than panicked. We have also watched a team forced into a seven-day switch when their provider closed, and portable logic saved them. Our onboarding logs into your existing stack, and for urgent exits our incident response team can stand up coverage fast. Many buyers reach us after deciding why businesses switch providers.
8. Which managed SOC model is right for my organization?
Pick the model by your constraint, because the right managed SOC depends on whether you want alerts or someone who acts on them. Everything collapses into three moves: own your logic, demand transparent pricing, and buy response rather than alerts.
- Scaling tech teams of 500 to 2,000 need vendor-agnostic integration that grows without re-platforming.
- Mid-market enterprises need real response SLAs and portable detection logic.
- Regulated healthcare needs retention plus notification SLAs mapped to breach rules.
- PE portfolio companies need transparent, repeatable cost across many entities.
The thread running through all four is ownership. A black box that performs well today still resets your maturity the day you leave it. Monitoring-only tools deliver context-free alerts, many MSSPs add people while holding your logic hostage, and AI-native providers with concierge response collect context at machine speed and respond with you. The simple test for any provider is whether they would hand you your logic and data tomorrow without a fight. We built our MDR service to answer yes, and regulated teams can see how this works in our MDR for Healthcare practice. To pressure-test fit, just start a conversation with our team.




