Back to blog
Buyer Guides

Build a SOC or buy MDR? The honest comparison

Round-the-clock detection needs roughly eight to ten analysts, which most organisations cannot justify. What outsourcing genuinely gives you, what it cannot, and the hybrid most teams end up with.
GRC Copilot Team
Build a SOC or buy MDR? The honest comparison

The decision usually comes down to arithmetic. Covering 24x7 with any resilience requires roughly eight to ten analysts once you account for shifts, holiday, sickness and attrition. Most organisations cannot justify that headcount for security monitoring alone, which is why managed detection and response exists.

What you are actually buying

MDR providers typically supply monitoring, triage, detection content, threat intelligence and some degree of response. The variation between providers is enormous and concentrated in one question: what happens at 3am when something real fires?

  • Do they only notify you, or do they contain?
  • If they contain, what are they authorised to do - isolate a host, disable an account, block an IP?
  • What is the contractual time to triage, and to escalate?
  • Do they investigate, or hand you an alert to investigate?
A provider that only forwards alerts has moved the problem, not solved it. If you still need someone available at 3am to act on what they send, you have bought a more expensive alert queue.

What outsourcing cannot give you

  • Context. A provider does not know that this server always talks to that one, or that the finance team runs an odd script at month end. Expect false positives that your own team would dismiss instantly.
  • Accountability. The risk remains yours regardless of who watches the screen.
  • Coverage of what you did not send them. Their visibility is exactly the telemetry you forward - no more.
  • Fixing the underlying issues. They will tell you the same misconfiguration recurs; remediating it is yours.

Keep detection evidence tied to your control set

GRC Copilot maps monitoring and incident evidence to the controls each framework requires, whether the work is in-house or outsourced.

The hybrid most organisations land on

Provider handles out-of-hours monitoring, triage and first-line response. Internal team owns business hours, threat hunting, tuning, remediation and the relationship with the provider. That internal role is not optional - an MDR contract with nobody internally managing it degrades within a year, because tuning stops, context is never fed back, and alert quality drifts.

Budget for at least one internal person who owns detection outcomes, even when the watching is outsourced.

Evaluating providers

  1. Ask for a real incident walkthrough - what they saw, what they did, how fast, and what they escalated. Vague answers here are disqualifying.
  2. Establish response authority precisely, and get it in the contract.
  3. Confirm data ownership and portability - can you take your logs and detections with you? Detection content built on their platform frequently cannot leave, which is a lock-in most buyers discover at renewal.
  4. Check coverage of your actual estate - cloud control plane, SaaS, identity, OT if relevant. Many providers are strong on endpoint and thin elsewhere.
  5. Ask how tuning requests are handled and how long they take.
  6. Understand the escalation path and who you reach at 3am.

When building in-house makes sense

When you are large enough to justify the headcount; when your environment is unusual enough that external context is genuinely hard to acquire; when regulation or data sensitivity constrains sending telemetry to a third party; or when detection capability is itself part of your product proposition.

Frequently asked questions

How many analysts for 24x7?

Roughly eight to ten for sustainable coverage with leave and attrition. Fewer means gaps or burnout.

Is MDR cheaper?

Usually, below a certain scale - and it converts a hiring problem into a contract. It does not remove the need for internal ownership.

What is the most common mistake?

Signing an MDR contract and assigning nobody internally to manage it. Alert quality then drifts and the value erodes quietly.

Can we start hybrid?

Most do, and it is usually the right answer - outsource the hours you cannot staff, keep tuning and remediation in-house.

Key takeaways

  • 24x7 needs eight to ten analysts - the arithmetic drives the decision.
  • Ask precisely what the provider does at 3am, and get authority in the contract.
  • Check whether your detection content can leave with you.
  • Assign internal ownership or the contract degrades within a year.
#soc #mdr #mssp #outsourcing #24x7 #detection #response #staffing