WhatisaManagedSOC?
A managed SOC is an outsourced 24/7 security operations centre: an external team of analysts who monitor, investigate, and contain threats on your behalf, delivered as a monthly subscription rather than a team you recruit and staff yourself. Human analysts triage alerts and correlate signals across your SIEM, endpoint, and cloud telemetry in shifts, so coverage runs around the clock. In the UK, managed SOC services typically start from £900 a month.
A plain-English guide to managed SOC services: what they are, what they cost, what should be included, and how a managed SOC compares to MDR and building an in-house team.
A managed SOC, in plain English
A managed SOC is an outsourced 24/7 security operations centre: an external team of analysts who monitor, investigate, and contain threats on your behalf, delivered as a monthly subscription rather than a capability you build and staff in-house. It bundles the SIEM platform, tooling, analyst team, and management into a single service.
This guide covers buying a managed SOC service: what it costs, what should be included, and how to choose between providers. If you want to understand what a security operations centre itself is as a concept, our glossary entry on what a SOC is covers that in more depth.
The two most common delivery models are an outsourced SOC, where a third-party team runs the whole function for you, and SOC as a service, the cloud-delivered, subscription-priced version of the same thing. Most buyers use the terms interchangeably.
What a managed SOC actually does
Four functions, delivered together as one service rather than bought separately.
24/7 monitoring
Human analysts work rotating shifts, correlating telemetry across your whole estate: SIEM logs, endpoint (EDR), identity, cloud and network, not just one layer. The screens are always watched by someone whose only job is threat detection.
Alert triage
Critical alerts get human analyst investigation within 10 minutes of firing, 24/7/365, with a named L3 incident response lead paged for any Critical or High severity alert. This is triage by an analyst, not a ticket sitting in a queue until Monday.
Incident response
On confirmation, analysts contain the threat, isolate affected endpoints, and preserve forensic evidence. You get a phone call within the first hour for incidents that need your team's involvement, with written updates as the investigation progresses.
Threat hunting
Proactive sweeps against the full MITRE ATT&CK Enterprise matrix, surfacing enablers of compromise automated tools miss: dormant lateral movement paths, misconfigured access policies, and overprivileged accounts waiting to be exploited.
What a managed SOC costs, and what building one costs
Even a small in-house SOC team of three analysts costs upwards of £210,000 per year in salaries alone, before SIEM licensing, threat intelligence subscriptions, training, and management overhead. A genuine 24/7 rota needs 8 to 12 analysts across three shifts, which puts the honest fully loaded cost at £600,000 to £1,200,000 per year.
An outsourced managed SOC delivers equivalent coverage from £900 per month, and is typically operational within 2 to 3 weeks of signature, against 6 to 12 months to build and accredit an in-house team.
Full managed SOC cost guide by tierManaged SOC vs MDR vs SIEM
A SIEM is the technology that collects and correlates security logs. A SOC is the people and process that use it; a SIEM without a SOC just generates alerts nobody is watching. MDR is endpoint and cloud workload focused, with EDR as the primary telemetry source, while a managed SOC is broader, correlating network, identity, cloud, application and firewall telemetry alongside endpoints across the whole estate. In practice the categories overlap, and most UK providers deliver SOC and MDR from the same analyst team.
What managed SOC services should include
Four things to check before signing, regardless of which provider you choose.
UK SOC location
Where the security operations centre and its analysts physically sit. A UK-based, DBS-checked analyst team with no offshoring and no follow-the-sun handover matters for data residency and accountability.
A human SLA, not just an alert SLA
A committed time for a human analyst to investigate a Critical alert (Precursor commits to 10 minutes, 24/7/365), not just a promise that an alert will be raised.
Incident response included
Containment, evidence preservation, and executive communication included in the monthly fee as standard, not billed separately as a per-incident retainer.
SIEM and EDR flexibility
The ability to co-manage the SIEM and EDR you already have, rather than a rip-and-replace onboarding that forces you onto the provider's own stack.
How to choose a managed SOC provider
Four questions that separate a genuine 24/7 SOC from a SIEM dashboard that emails you alerts overnight.
- 01
Ask where the analysts physically sit.
Not the sales office, the SOC floor. A UK phone number is not a UK SOC. Ask for the SOC location and, ideally, a tour.
- 02
Ask for the containment SLA, not the alert SLA.
An alert SLA only promises you will be told. A containment SLA is a commitment that a human will act. Get the number in writing.
- 03
Confirm incident response is included.
A provider that bills incident response as a separate retainer on top of the monthly fee is optimising for extra invoices, not your outcome.
- 04
Check whether testing feeds detection.
Providers that also run penetration testing can write detection rules for the exact attack paths their testers find, sometimes called the closed-loop model. Most managed SOC providers are defensive-only.
Ready to shortlist? See our comparison of the best managed SOC providers UK, which ranks seven providers on SOC location, staffing, and pricing.
See what a managed SOC costs for your environment.
A physical UK SOC in Newcastle, human analysts, and fixed monthly pricing from £900. No POA, no per-incident fees.
Managed SOC, the short answers
The questions buyers ask most before scoping a managed SOC.
A managed SOC is an outsourced 24/7 security operations centre: an external team of analysts who monitor your environment, investigate alerts, and contain threats on your behalf, delivered as a monthly subscription rather than a capability you recruit and staff yourself. It bundles the SIEM platform, tooling, and analyst team into one service.
Managed SOC services typically include 24/7 SIEM and log correlation, managed EDR across your endpoints, human-led alert triage, proactive threat hunting against known attack techniques, incident response and containment, and compliance reporting mapped to frameworks such as ISO 27001 and NIS2. A managed SOC bundles that monitoring, hunting, and response into a single contract, so you get the capability of an in-house SOC without the headcount.
A UK managed SOC costs from £900 per month for a small organisation (50 to 100 users, core log sources), £3,000 to £4,000 per month for a mid-sized environment with EDR and cloud logs, and £8,000 to £12,000 or more per month for large multi-cloud estates with a dedicated analyst team. Pricing is billed as a fixed monthly subscription rather than a day rate, with fixed pricing typically confirmed after a free scoping call.
MDR is endpoint and cloud workload focused, with EDR as the primary telemetry source. A managed SOC is broader, correlating network, identity, cloud, application and firewall telemetry alongside endpoints across the whole estate. Good managed SOC services include human threat hunters, while many MDR offerings are more heavily automated. In practice the categories overlap, and most UK providers deliver both from the same analyst team.
A number of UK and international providers offer managed SOC services, ranging from independent UK specialists to large global platforms. See our comparison of the best managed SOC providers UK, which ranks seven providers on SOC location, staffing, and pricing.



