SOC as a service (SOCaaS) is a subscription in which an external provider runs some or all of your security operations centre: monitoring your systems around the clock, investigating alerts and starting the response. You keep the risk, any decision the contract does not hand over, and the recovery. For a UK buyer, four things decide whether a contract works: which data sources are in scope, what the provider may do without asking, where your data and the analysts sit, and how you leave.
This guide compares SOC as a service with the alternatives in one table, lists the questions to put to a provider, and explains honestly what drives the cost.
SOC as a service vs in-house SOC vs MDR vs co-managed
| SOC as a service | In-house SOC | MDR | Co-managed SOC | |
|---|---|---|---|---|
| Coverage | The sources and hours in the contract, often 24/7 across logs from several systems | Whatever hours and sources you can staff | Usually led by an endpoint agent, plus selected other sources | Split by agreement, for example you by day and the provider at night |
| Control | Provider runs tools and playbooks; you approve what the contract reserves | Full control of tools, content and decisions | Provider acts or guides within the contract | Shared; you usually own the tools and detection content |
| Data residency | Where the provider's platform and analysts sit; ask for the list of countries | Your choice | The vendor's cloud regions and analyst locations | Mostly your own tenancy, plus provider access |
| Cost drivers | Sources, log volume, devices, hours, response scope, retention | People (168 hours a week to cover), tools, data volume | Endpoints or users, service tier, sources added | Your staff plus the hours and scope you buy |
| Time to value | Depends on how many sources must be onboarded | Longest: hiring and building come first | Fast where the agent is already deployed | Depends on what you already run |
The labels are loose. Some providers call an endpoint-led service SOC as a service; some call a log-monitoring service MDR. Read the scope, not the name. Our guide to MDR vs MSSP explains how the two traditional models differ.
What a SOC service covers
CREST, which sets accreditation standards for security service providers including SOCs, describes a security operations centre as "a facility where enterprise information systems ... are monitored, assessed, and defended", and lists the services one may provide: "monitoring, detection, threat hunting, incident management, log analysis, forensic imaging, malware analysis, reverse engineering, mitigation advice and general good practice guidance" (CREST). No provider does all of these at every tier, which is why the scope schedule matters.
NIST's incident response guidance, SP 800-61 Revision 3 (April 2025), treats outsourcing as normal. It says incident handlers may be "on contract (e.g., outsourcing a security operations center [SOC] to a managed security services provider [MSSP])", and that a third party may fill "a primary role (e.g., an MSSP performing incident detection, response, and recovery activities)". It calls this "a shared responsibility model in which the organization transfers some of its responsibilities to a provider" (NIST SP 800-61r3).
Research on SOCs points to the same weak spot. A systematic review of the SOC literature by Vielberth and colleagues found that work focused on people and technology while "neglecting the connection of these two areas by specific processes (especially by non-technical processes)" (IEEE Access, 2020). With an outsourced SOC, those processes live in the contract: escalation paths, approvals and hand-overs. That is where buyers should spend their time.
Why UK organisations buy it
The government's Cyber Security Breaches Survey 2025 found that 44% of businesses had an external cyber security provider, rising to 62% of small, 68% of medium and 50% of large businesses. The 2025 skills study found nearly half (49%) of businesses had a basic skills gap, and around 3 in 10 had gaps in advanced skills such as forensic analysis.
The same breaches survey found only 53% of medium businesses had a documented incident response plan. That matters. A provider can watch and escalate, but it needs a plan on your side to escalate into. For the wider picture of how mid-sized firms structure security, see our mid-market cybersecurity guide.
What a UK buyer should ask a SOC provider
- Exactly what is in scope? List the data sources (endpoint, identity, email, cloud, network, applications), the hours, and what is excluded. Vendors' own documents show why. Microsoft states that its Defender Experts MDR "doesn't provide incident response services for an active compromise", and that its Plan 2 "isn't a managed security information and event management (SIEM) service"; you continue to own connectors, ingestion and retention (Microsoft Learn). Every provider has boundaries like these. Find them before you sign.
- What may the provider do without asking? NIST SP 800-61r3 says responsibilities "should be clearly defined in a contract", including "authority to act on behalf of the organization" and restrictions such as "making and implementing operational decisions (e.g., immediately deactivating certain services to contain an incident)". Ask for an action matrix: actions the provider takes alone (isolate a laptop, disable a user), actions that need approval, and who can approve at night.
- Where is our data, and where are the analysts? The NCSC's cloud security principles say a provider "should present a complete list of countries where your data is stored and processed, and where the service is managed and supported from", and that you need to identify "which legal jurisdiction(s) your data could be subject to" (NCSC, Principle 2). The same principle notes that logs, configuration data and derived metadata need the same thought as primary data. Ask to be told of any change.
- How is the provider's own access controlled? NIST warns that providers "often have privileged access to organizational systems", so the risk of a malicious insider or a compromised provider "should be considered and addressed". Ask how privileged access is granted, logged and revoked, and whether you can see that log.
- What independent assurance does the provider hold? Useful evidence includes CREST accreditation for SOC services, ISO 27001 certification, and, for incident response, membership of the NCSC's Cyber Incident Response scheme, which assures providers at Enhanced or Standard level. Note what schemes do not cover. NCSC CHECK is the scheme for authorised penetration tests of public sector and critical national infrastructure systems. It is evidence of testing capability, not of a monitoring service.
- How will we measure the service? Ask for time to acknowledge, investigate and contain, by severity, measured on your data and visible to you, not only a monthly summary.
- How do we leave? Agree the export format for your logs, cases and detection content, how long the provider keeps data after exit, and who owns detection rules written for you.
- Can the public sector buy it through a framework? Public sector bodies and charities can buy cloud services, including cloud support, through G-Cloud 14, whose agreement page lists three lots (cloud hosting, cloud software and cloud support) and an end date of 28 October 2026. Check the successor agreement if you buy after that date.
What SOC as a service costs
We do not publish a price range here because no honest one exists. Most providers quote on request, and the scopes differ too much for a single figure to mean anything. What we can say is what moves the price:
- Data sources and volume. Log-based services often price on sources or ingest. More sources widen coverage and raise cost.
- Devices and users. Endpoint-led services usually price per endpoint or per user.
- Hours and response scope. Round-the-clock response with authority to act costs more than monitoring with escalation.
- Retention. Longer searchable retention costs more storage.
- Incident response. Often a separate retainer or engagement, not part of the monitoring fee.
- Your own time. Someone internal still triages escalations, approves actions and manages the contract.
Tools and services are priced differently. CrowdStrike's US pricing page, for example, lists its endpoint plans per device (Falcon Go at $59.99 per device per year, billed annually) but its managed service, Falcon Complete Next-Gen MDR, as "Contact sales" (CrowdStrike pricing, checked 23 September 2026). The honest comparison is against building it yourself: covering one seat for 168 hours a week takes more than four full-time people before leave and training. Our managed SOC vs DIY guide works through that arithmetic.
A newer route is to keep a small in-house team and let a platform automate most triage and investigation, with people holding the decisions. Our explainer on the AI SOC sets out how that model works and where it fails.
Where SenseOn fits
SenseOn is a platform, and one option among several; it is not the right answer for every buyer. Its Data Fabric connects supported endpoint, network, identity, cloud, email and application signals without per-GB ingestion charges, and its Intelligence Fabric correlates them into cases. Horus, its agent orchestrator, coordinates defined security work while people set policy and make consequential decisions.
On the published figures, 92.5% of cases across customer environments are resolved by AI under human governance over a rolling 30-day window. Across managed-service customer environments, mean time to detect and respond is under 20 minutes over the same window. Every AI and analyst action writes to an append-only Decision Trace, which answers the "who did what, with what authority" question in point 2 above. SenseOn holds ISO 27001 certification through BSI and Cyber Essentials Plus. The method behind each figure is on the proof points page.
Sources
- National Institute of Standards and Technology, A. Nelson, S. Rekhi, M. Souppaya, K. Scarfone, SP 800-61 Rev. 3, Incident Response Recommendations and Considerations for Cybersecurity Risk Management: A CSF 2.0 Community Profile, April 2025, accessed 23 September 2026 (full text: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-61r3.pdf)
- Manfred Vielberth, Fabian Böhm, Ines Fichtinger, Günther Pernul, "Security Operations Center: A Systematic Study and Open Challenges", IEEE Access, 2020, https://doi.org/10.1109/ACCESS.2020.3045514 (open access)
- NCSC, Cloud security principle 2: asset protection and resilience, accessed 23 September 2026
- NCSC, Cyber Incident Response scheme, accessed 23 September 2026
- NCSC, CHECK penetration testing, accessed 23 September 2026
- Department for Science, Innovation and Technology, Cyber Security Breaches Survey 2025, 10 April 2025, accessed 23 September 2026
- Department for Science, Innovation and Technology, Cyber security skills in the UK labour market 2025, accessed 23 September 2026
- Government Commercial Agency, G-Cloud 14 (RM1557.14), accessed 23 September 2026
- CREST, Security Operations Centres, accessed 23 September 2026
- Microsoft Learn, What is Microsoft Defender Experts MDR?, updated 7 August 2026, accessed 23 September 2026
- CrowdStrike, Falcon pricing (US site, prices in USD), accessed 23 September 2026
How SenseOn writes, checks and corrects its content: editorial standards.
Frequently asked questions
What is the difference between SOC as a service and MDR?
The terms overlap. SOC as a service usually means a provider runs a broad security operations function for you: monitoring logs from many sources, investigating and escalating, sometimes with compliance reporting. MDR usually means a detection and response service built around the provider's own detection stack, often led by an endpoint agent, with the provider taking containment actions. Many providers sell both under different names, so compare the scope and response authority in the contract, not the label.
How much does SOC as a service cost in the UK?
There is no reliable public price range, and most providers quote on request. The main cost drivers are the number of data sources and the log volume in scope, the number of devices and users, the hours covered, the response actions included, the retention period, and whether incident response is included or a separate engagement. Ask every provider to price the same scope so the quotes compare.
Can a SOC provider act without asking us first?
Only if the contract gives it that authority. NIST SP 800-61r3 says the division of responsibilities, including the authority to act on behalf of the organisation and any restrictions on the provider, should be clearly defined in a contract. Agree a written list of actions the provider may take on its own, actions that need your approval, and who can approve out of hours.
Where will our security data be stored?
Wherever the provider's platform, analysts and support teams sit, which may be in more than one country. The NCSC's cloud security principles say a provider should give you a complete list of countries where your data is stored and processed and where the service is managed and supported from. Ask for that list in writing, including for logs, metadata and backups.
Is SOC as a service suitable for a mid-sized company?
Often, yes. The UK Cyber Security Breaches Survey 2025 found 68% of medium businesses already use an external cyber security provider. The fit depends on whether you can name an internal owner for decisions and the contract, and whether the provider covers the data sources where your risk sits.