You cannot staff a 24/7 SOC with nobody in house. Someone has to own policy, sign off exceptions and hold the provider to account. Three options are real: outsource to an MDR or MSSP, keep one in-house owner on top of an AI-governed platform, or build a full analyst rota. This guide compares them on cost, control and who owns decisions.
That is the honest answer to the question most people are really asking when they search for how to build a SOC without an in-house team. The rest of this article shows the arithmetic behind it, what each option costs and controls, and how to choose in a fortnight rather than a budget cycle.
Why "no in-house team" is the wrong starting question
A security operations centre is not a room. It is four jobs that have to happen continuously: collect the telemetry, detect something worth acting on, decide what to do, and do it. The question is never whether you have those four jobs. Every organisation has them. The question is who performs each one, at what hour, and who is accountable when a decision turns out to be wrong.
"No in-house team" usually means no analyst rota. It almost never means no one. There is a person who takes the call at 03:00, approves isolating a finance director's laptop, and explains the incident to the board afterwards. If you do not name that person, you have not removed the role; you have left it vacant.
So the useful framing is not build versus buy. It is: which of the four jobs do you keep, which do you hand over, and what evidence do you get back so you can still answer for the ones you handed over?
The rota arithmetic: what 24/7 actually costs in people
Continuous coverage is an arithmetic problem before it is a hiring problem, and the arithmetic is unforgiving.
A year contains 8,760 hours. A full-time UK employee works roughly 1,700 to 1,800 hours a year once annual leave, public holidays, sickness and training are taken out. Dividing one number by the other, keeping a single seat occupied around the clock takes about five full-time people. That is one person watching, with nobody to escalate to, nobody covering a resignation, and no second pair of eyes on a major incident. A rota that can survive a busy night and a notice period is larger again.
That is not a statistic. It is division, and you should redo it with your own leave policy and shift pattern before accepting anyone's headcount claim, including ours.
Then put a price on it. The Department for Science, Innovation and Technology's Cyber security skills in the UK labour market 2025 reports a median advertised salary of £55,000 for core cyber security roles, with Security Analyst the single most common core role at 28% of postings. Five of those, at the median, is £275,000 in base salary before employer National Insurance, pension, tooling, recruitment and shift premiums. Whether that number is large depends entirely on what you are protecting, which is the point: it is a number you can now argue about honestly, rather than a vendor's.
Hiring is the other half. The same DSIT research finds 49% of businesses have a basic cyber skills gap and around 3 in 10 have gaps in advanced skills such as forensic analysis and interpreting malicious code. ISC2's 2025 Cybersecurity Workforce Study reports that 33% of organisations do not have the budget to staff their teams adequately and 29% cannot afford to hire people with the skills they need. The constraint is rarely the intention to build a SOC. It is the ability to fill and keep five seats.
Option 1: build the in-house SOC
Building gives you the deepest control. Your analysts learn your environment, your change windows, your odd-but-normal behaviour. Detection logic can be written for your threat model. Escalation has no contractual handoff in it.
The costs are the rota above, the tooling underneath it, and the management overhead of a shift-working team. There is a subtler cost too: an under-strength in-house SOC is often worse than an honest outsourcing decision, because coverage gaps are invisible from the inside. Nobody files a ticket saying "nothing was watched between 02:00 and 07:00 on Sunday".
Build when security operations are core to what you sell, when regulation or data sensitivity makes third-party handling genuinely difficult, or when you already have three or four of the seats filled and are closing a gap rather than starting from zero.
Option 2: outsource to MDR or an MSSP
Outsourcing buys coverage now. This is a mainstream choice, not a fallback: DSIT reports that 31% of businesses, 24% of charities and 58% of public sector organisations outsource some elements of their cyber security.
An MSSP typically manages tooling and monitors alerts. Managed detection and response goes further, taking on investigation and, within an agreed scope, response actions. The distinction matters commercially and operationally, and MDR vs MSSP sets out where the line falls.
Three things to interrogate before signing:
- What the provider may do without asking. Get the response authority in writing, per action type. "Contain the endpoint" and "disable the account" are different decisions with different blast radii.
- What evidence you receive. A monthly summary is not an audit trail. Ask for the record of every action taken in your estate, in a format you keep, not one you log into.
- Whose tooling it is. If the platform is the provider's, the switching cost at renewal is the platform plus the service, not the service alone.
The honest weakness of outsourcing is context. An external analyst serves several customers and cannot know that your year-end run started on Monday. Good providers close that gap with onboarding and named analysts; the gap never closes completely. DSIT also found 23% of businesses lacked confidence in judging whether an external provider was offering value for money, which is a governance problem as much as a commercial one.
Option 3: a small in-house owner plus an AI-governed platform
The third option changes the arithmetic rather than the org chart. If the first pass — collect, correlate, triage, investigate routine cases — runs at machine speed under a policy you set, the human requirement changes shape. You are no longer staffing a queue around the clock. You are staffing ownership: one person, or one small team, who sets policy, reviews what the platform did, and handles the exceptions.
This only works if two conditions hold, and both are checkable.
The first is that the machine genuinely closes the routine work rather than reordering it. The volume problem is real: across more than 30 million investigated cases over a rolling twelve-month window, SenseOn sees confirmed true positives at 0.68%. Roughly 99 in every 100 things worth looking at are not threats. In one Fortune 500 environment, 33.4B events are analysed monthly. SenseOn resolves 92.5% of incidents under human governance with a detect-and-respond time of <20 min. Those are our figures on our platform, and the right response is to ask any vendor, us included, for the same four numbers defined identically. Will AI reduce SOC work? sets out which parts of the job this genuinely removes and which it does not.
The second is that every action is evidenced, reversible and inside a boundary you set. Autonomy you cannot reconstruct is not a saving; it is an unbounded liability. SenseOn's Decision Trace is append-only and covers 100% of platform actions by design rather than by sampling, so the person who owns the outcome can answer for a decision they did not personally make. How AI is used in threat detection covers what the technology does today and, more usefully, what it still cannot do.
This is the hybrid most mid-sized organisations end up in. Cybersecurity for the mid-market covers the wider trade-offs at that size.
In-house SOC vs MDR/MSSP vs AI-governed platform compared
| In-house SOC | MDR / MSSP | AI-governed platform with a small team | |
|---|---|---|---|
| 24/7 coverage | Only with a full rota; gaps are invisible from inside | Contractual, from day one, within an agreed scope | Continuous machine first pass; humans own exceptions on a defined escalation path |
| Headcount | About five FTE to keep one seat filled, more for depth and cover | Near zero analysts, but you still need a named owner | One owner or a small team; no shift rota |
| Cost driver | Salaries, shift premiums, recruitment, tooling underneath | Per-endpoint or per-user subscription, plus the platform if it is theirs | Outcomes and platform; ingest volume is not the billed unit |
| Control over policy | Total, and yours to maintain | Negotiated, then reviewed at renewal | Yours, set per action type, changeable without a contract variation |
| Tooling ownership | Yours; you also carry the integration work | Often the provider's, which raises the switching cost | Yours, working alongside the EDR and SIEM you already run |
| Time to stand up | Hiring cycle first, then tuning | Weeks, once onboarding and log sources are done | Deployment then policy setting; no rota to recruit |
Most organisations are quietly in a fourth column: full tooling costs, partial coverage, and an owner who has not been named.
Watch the billing unit, not just the headcount
Two of the three options put a data platform underneath the people, and that is where budgets are usually lost. If ingest volume is the billed unit, every log source that improves detection also increases the bill, so the cheapest configuration is the blindest one. Teams then filter at source or shorten retention, and find during an investigation that the month they needed is gone. The SIEM tax sets out where those costs actually accrue.
Model this before you compare headcount. A managed service that looks cheaper than five analysts can cost more once the ingest bill underneath it is included, and the ingest bill grows with your estate rather than with your security outcomes. SenseOn charges £0 per GB, prices outcomes through credits, and removes ~40% of data at the edge before the pipeline starts; our pricing page sets out the model. Whatever you choose, ask the same question: does the commercial model reward visibility or punish it?
Who owns the decision at 03:00
Every model has to answer one question: when something is contained overnight, who decided, on what authority, and how do you prove it afterwards?
- In-house. Your analyst, under your runbook. Evidence quality depends on your ticketing discipline.
- MDR/MSSP. The provider, under the response authority in the contract. Get that scope written down per action type, and get the evidence exported to somewhere you control.
- AI-governed platform. The policy you set, executed by the platform, with exceptions escalated to your named owner. The record has to be complete and append-only or the model does not hold.
The regulated version of this question is sharper. Under NIS2, DORA or FCA operational resilience expectations, outsourcing the work never outsources the accountability. You will be asked what happened, in what order, and who authorised it. Choose the model whose evidence you could hand to a regulator without reconstructing it from memory.
How to choose in a fortnight
You do not need a procurement cycle to make this decision. You need two weeks of your own data.
- Count the hours you are actually covered. Not the hours a tool is running, the hours a competent human would see and act on something. Be honest about weekends.
- Measure your queue for a fortnight. Alerts raised, alerts a human opened, and how many were real. That gives you your own true-positive density, the number every vendor claim should be tested against. How to reduce alert fatigue explains how to cut that queue without cutting visibility.
- Redo the rota arithmetic with your own leave policy. Five FTE is the floor, not the plan.
- Name the owner. One person accountable for policy and exceptions, in every model. If you cannot name them, fix that before you buy anything.
- Ask all three options for the same four numbers. Cases a human had to open, detect-and-respond time, true positives as a share of investigated cases, and total cost including ingest.
- Ask to see one real investigation end to end. Not a slide about explainability. The evidence trail for a single decision, with timestamps.
If a provider or platform cannot show you the sixth item, the first five do not matter yet. You can see how the platform records and evidences its own decisions on the platform page, and the SOC automation guide covers which parts of the workflow are safe to automate first.
Frequently asked questions
Can I run a 24/7 SOC with no in-house staff at all?
No. You can remove the analyst rota by using MDR, an MSSP or an AI-governed platform, but you still need one named person who owns policy, approves exceptions and holds the provider to account. Regulators and boards ask who authorised an action, and a contract does not answer that. Treat the owner role as the irreducible minimum.
How many people does a 24/7 SOC actually need?
A year has 8,760 hours and a UK full-time role covers roughly 1,700 to 1,800 of them after leave, sickness and training. Keeping one seat filled continuously therefore takes about five full-time people, with no cover for escalation, resignations or major incidents. A rota that survives a bad night is larger. Redo that division with your own leave policy.
What does a SOC analyst cost in the UK?
DSIT's Cyber security skills in the UK labour market 2025 reports a median advertised salary of £55,000 for core cyber security roles, and Security Analyst is the most common core role at 28% of postings. Add employer National Insurance, pension, recruitment and shift premiums on top. Multiply by your rota size before comparing against any managed service quote.
Is MDR cheaper than building an in-house SOC?
Usually on day one, because you avoid five salaries and the hiring cycle. Over three years it depends on two things: whether the underlying data platform bills by ingest volume, which grows with your estate, and whether the provider's tooling is yours or theirs at renewal. Compare total cost including ingest, not the service line alone.
Can I keep my existing EDR and SIEM if I move to a managed or AI-governed model?
Yes. SenseOn deploys alongside the tools you already run — no rip-and-replace. The AI layer subscribes to the telemetry it needs while your existing tools keep doing prevention, retention and compliance reporting. What changes is who performs the first-pass triage and where the joined-up case record lives. Consolidating the tools underneath is a separate, later decision.
How do I keep control if an external provider or a platform responds on my behalf?
Set the boundary per action type, in writing, and insist on evidence you hold rather than evidence you log in to see. Every action should be recorded, attributable, reversible and inside a policy you set. Then test it: ask for the record of one real containment, and ask whether a rollback has ever actually been run.
Related reading: