Skip to main content
Managed SOC, Explained

WhatisaManagedSOC?

A managed SOC is an outsourced 24/7 security operations centre: an external team of analysts who monitor, investigate, and contain threats on your behalf, delivered as a monthly subscription rather than a team you recruit and staff yourself. Human analysts triage alerts and correlate signals across your SIEM, endpoint, and cloud telemetry in shifts, so coverage runs around the clock. In the UK, managed SOC services typically start from £900 a month.

A plain-English guide to managed SOC services: what they are, what they cost, what should be included, and how a managed SOC compares to MDR and building an in-house team.

From £900/month
Operational in 2-3 weeks
24/7 human analysts
Scroll
3,000+ Assessments DeliveredTriple-CREST Accredited24/7 UK SOC in NewcastleReports Accepted by Insurers & RegulatorsEst. 2018
The Definition

A managed SOC, in plain English

A managed SOC is an outsourced 24/7 security operations centre: an external team of analysts who monitor, investigate, and contain threats on your behalf, delivered as a monthly subscription rather than a capability you build and staff in-house. It bundles the SIEM platform, tooling, analyst team, and management into a single service.

This guide covers buying a managed SOC service: what it costs, what should be included, and how to choose between providers. If you want to understand what a security operations centre itself is as a concept, our glossary entry on what a SOC is covers that in more depth.

The two most common delivery models are an outsourced SOC, where a third-party team runs the whole function for you, and SOC as a service, the cloud-delivered, subscription-priced version of the same thing. Most buyers use the terms interchangeably.

Capabilities

What a managed SOC actually does

Four functions, delivered together as one service rather than bought separately.

24/7 Monitoring

24/7 monitoring

Human analysts work rotating shifts, correlating telemetry across your whole estate: SIEM logs, endpoint (EDR), identity, cloud and network, not just one layer. The screens are always watched by someone whose only job is threat detection.

Human Triage

Alert triage

Critical alerts get human analyst investigation within 10 minutes of firing, 24/7/365, with a named L3 incident response lead paged for any Critical or High severity alert. This is triage by an analyst, not a ticket sitting in a queue until Monday.

Containment

Incident response

On confirmation, analysts contain the threat, isolate affected endpoints, and preserve forensic evidence. You get a phone call within the first hour for incidents that need your team's involvement, with written updates as the investigation progresses.

Active Pursuit

Threat hunting

Proactive sweeps against the full MITRE ATT&CK Enterprise matrix, surfacing enablers of compromise automated tools miss: dormant lateral movement paths, misconfigured access policies, and overprivileged accounts waiting to be exploited.

Managed vs In-House

What a managed SOC costs, and what building one costs

Even a small in-house SOC team of three analysts costs upwards of £210,000 per year in salaries alone, before SIEM licensing, threat intelligence subscriptions, training, and management overhead. A genuine 24/7 rota needs 8 to 12 analysts across three shifts, which puts the honest fully loaded cost at £600,000 to £1,200,000 per year.

An outsourced managed SOC delivers equivalent coverage from £900 per month, and is typically operational within 2 to 3 weeks of signature, against 6 to 12 months to build and accredit an in-house team.

Full managed SOC cost guide by tier
In-house, 3 analysts£210,000+/yr
In-house, true 24/7£600k to £1.2M/yr
Managed SOC, from£900/mo
Operational in2 to 3 weeks
Terminology

Managed SOC vs MDR vs SIEM

A SIEM is the technology that collects and correlates security logs. A SOC is the people and process that use it; a SIEM without a SOC just generates alerts nobody is watching. MDR is endpoint and cloud workload focused, with EDR as the primary telemetry source, while a managed SOC is broader, correlating network, identity, cloud, application and firewall telemetry alongside endpoints across the whole estate. In practice the categories overlap, and most UK providers deliver SOC and MDR from the same analyst team.

Full MDR vs SOC vs SIEM comparison
Buying Checklist

What managed SOC services should include

Four things to check before signing, regardless of which provider you choose.

UK SOC location

Where the security operations centre and its analysts physically sit. A UK-based, DBS-checked analyst team with no offshoring and no follow-the-sun handover matters for data residency and accountability.

A human SLA, not just an alert SLA

A committed time for a human analyst to investigate a Critical alert (Precursor commits to 10 minutes, 24/7/365), not just a promise that an alert will be raised.

Incident response included

Containment, evidence preservation, and executive communication included in the monthly fee as standard, not billed separately as a per-incident retainer.

SIEM and EDR flexibility

The ability to co-manage the SIEM and EDR you already have, rather than a rip-and-replace onboarding that forces you onto the provider's own stack.

How To Choose

How to choose a managed SOC provider

Four questions that separate a genuine 24/7 SOC from a SIEM dashboard that emails you alerts overnight.

  1. 01

    Ask where the analysts physically sit.

    Not the sales office, the SOC floor. A UK phone number is not a UK SOC. Ask for the SOC location and, ideally, a tour.

  2. 02

    Ask for the containment SLA, not the alert SLA.

    An alert SLA only promises you will be told. A containment SLA is a commitment that a human will act. Get the number in writing.

  3. 03

    Confirm incident response is included.

    A provider that bills incident response as a separate retainer on top of the monthly fee is optimising for extra invoices, not your outcome.

  4. 04

    Check whether testing feeds detection.

    Providers that also run penetration testing can write detection rules for the exact attack paths their testers find, sometimes called the closed-loop model. Most managed SOC providers are defensive-only.

Compare Specific Providers

Ready to shortlist? See our comparison of the best managed SOC providers UK, which ranks seven providers on SOC location, staffing, and pricing.

Compare providers
Scope It In 30 Minutes

See what a managed SOC costs for your environment.

A physical UK SOC in Newcastle, human analysts, and fixed monthly pricing from £900. No POA, no per-incident fees.

CREST Triple Accredited|Fixed Price Quotes|Free Scoping Call|UK Based Team
FAQs

Managed SOC, the short answers

The questions buyers ask most before scoping a managed SOC.