Home · Blog
Security Operations

Managed SOC for SMEs: who responds at 3am?

2 October 2026 · 8 min read · ODCUS
A person sitting alone at a desk at night in front of a screen showing a single alert, with a ringing telephone beside them

The quote for a managed SOC has been on the table for three weeks, and nobody is deciding. The IT lead thinks it makes sense. The executive team sees a monthly amount with no visible effect. And the question the whole thing hangs on has not been asked yet: what happens here when that SOC calls at 03:40 on a Sunday?

The monitoring discussion in an SME almost always goes wrong in the same direction. It covers coverage, data sources, log volumes, minutes in the SLA. Those are answerable questions, and good providers do answer them. The other one stays open: who in your company is allowed to take a laptop off the network at 03:40, lock an account or stop a production server, without first waking someone who might say no.

TLDR

A managed SOC buys you eyes, not hands. It watches, it triages, and it escalates to you. Someone at your company still has to respond, at night too. You are deciding about authority first, and about data sources and price only after that. In our experience that makes the quote smaller, not bigger.

What are you buying when you buy a managed SOC?

You are buying three things: observation around the clock, a judgement on what the alerts mean, and an escalation to you. You are not usually buying a response that carries business consequences. That stays with you, at four in the morning as well. Anyone who reads the quote that way is reading it correctly.

The word "response" in SOC and MDR quotes usually means containment inside a boundary agreed in advance: isolating a device, locking an account. Everything beyond that stays with you. This is not a provider trick. It is right that way. An external team cannot know whether the server it would shut down is the one carrying the night shift. It does mean somebody at your company has to be reachable, and with a mandate rather than good intentions.

What gets misread most often is the response time in the SLA. If it says fifteen minutes, that means somebody looks within fifteen minutes. It does not mean the attack stops within fifteen minutes. Between looking and stopping sits a decision, and that decision is yours. The sentence tends to produce silence in the steering meeting, in both directions. IT suspected it, the executive team did not.

What the quote coversWhat stays with you anyway
Observation of the agreed sources, around the clockThe decision on which sources matter in the first place
Triage and prioritisation of alertsThe context: which system is carrying the business right now
Escalation along a defined pathA person at the end of that path, at night, with authority
Containment inside the agreed boundaryEvery decision affecting production, customers, revenue
A monthly reportThe consequence of it: actions, budget, priorities

The debate in an SME circles around detection. The hole sits one step later. The NIST Cybersecurity Framework separates Detect from Respond not out of tidiness, but because detecting and acting are two different capabilities. The second one is considerably harder to buy than the first. A SOC that reaches nobody at 03:40 has correctly detected the attack and prevented nothing.

Chain from alert through triage to action, with the gap at the point where decision authority is missing in an SME
Detection can be bought. The decision in the middle stays in house.

When does a managed SOC pay off for an SME?

When three things are already in place: identities and endpoints are broadly under control, there is a named person with the authority to act at night, and it has been settled in advance what an outside party may touch without asking. If one of those is missing, you are paying for transparency that nobody translates into action.

These pre-decisions do not belong in the SOC contract. They belong in your incident readiness. They are a handful of questions that need answering before the first alert: who may isolate, who gets woken, what goes to the executive team instead. Unspectacular, which is exactly why it gets left undone. What this looks like in an SME is something we took apart in our piece on the incident response plan for SMEs.

Then there is the case where the trigger comes from outside. A large customer requires monitoring contractually. Or the reporting duty applies: operators of critical infrastructure report a cyberattack to the Swiss Federal Office of Cybersecurity (BACS) within 24 hours, and missing details can follow within 14 days (BACS information for companies). Suppliers inherit the same requirements through contracts. Those 24 hours are a clock that only starts running once you notice something. Noticing three weeks later satisfies the duty on paper and still costs you three weeks.

The reverse holds too. If multi-factor sign-in still has gaps, backups have never been restored, or nobody can say which devices are on the network, monitoring is the expensive way to learn things you already know. Detection does not remove the need for basic hygiene. You simply see more clearly where it is missing. That is the sequence we correct most often, and it costs more patience than technology.

The monitoring you already pay for

Before monitoring gets added, the monitoring already running is worth a look. In most tool landscapes we open up, a good share of the detection already sits in licences that have been paid for years: endpoint protection, the identity platform, mail security. The signals are there. What is missing is somebody who reads them and notices when they stop arriving.

In that situation you are paying for a second pair of eyes on data the first pair could already have seen. That is a sizing problem, not a security problem. Too many tools, too little overview, too much cost for too little actual protection. The lever sits with ownership rather than procurement, which is why coverage and cost can often improve at the same time. More on this: consolidating security tools.

None of that means existing licences replace a SOC. It means the question of how big the SOC should be can only be asked sensibly once you know what would already be visible without an additional contract. That sequence saves no project time, but it often saves recurring licence cost.

From practice: a logistics company with 310 employees

Three sites, warehouse on two shifts, night dispatch. On the table was a quote for round-the-clock monitoring, triggered by a security questionnaire from a large customer. The case looked clear cut. Somebody is working there at night anyway.

Looking closely produced something else. The night was staffed, but nobody on the night shift had the authority to take a system off the network. The dispatch system ran the routes, an unplanned outage at two in the morning costs delivery windows, and so the unwritten rule held: touch nothing, call the IT lead in the morning. A SOC would have sent its alerts straight into that rule.

What changed first was not the monitoring. It was the decision. A written list: which devices and accounts may be isolated at night without asking, by whom, and what goes directly to the executive team instead. Five cases, two sentences per case, one hour of discussion with the operations lead, who contributed the harder half of it.

After that the monitoring question was easy. The scope came down, because some of the sources in the quote had nothing to do with any of the five cases. The customer questionnaire could be answered honestly, with a response time the company was able to stand behind.

What does a managed SOC cost for an SME?

We are not naming a market price here, because quotes differ by factors depending on data volume, coverage and the scope of response. They only become comparable once every provider is pricing the same scope, and that scope is defined by you, not by the provider. The larger part of the cost is not in the quote anyway.

The second bill comes from inside your own house. Connecting the sources, the first weeks of tuning until the alert volume is bearable, and the internal availability you commit to with the contract. None of those line items appear in any quote, and in our experience they take more of your own IT team's time than expected. A monitoring contract without somebody who owns the output is a subscription to a dashboard.

In front of the executive team the question therefore only survives as a business decision. Which risk drops demonstrably, what does it cost per year, and what gets dropped in exchange. The third part is missing from almost every proposal we see, and it is the part that decides whether the request gets approved.

How we price security leadership is stated openly on the site. The Cyber Assessment at CHF 1'900 establishes where you stand within two weeks, including a review of existing tools and licences. The CISO Retainer starts at CHF 4'900 per month and brings the person who makes decisions like these and represents them to the executive team and the board. Minimum term six months, cancellable monthly after that.

Frequently asked questions

Can a managed SOC replace an in-house night shift?

The watching yes, the deciding no. For most companies with 50 to 500 employees that is the right split: you buy in the night watch and keep a reachable decision maker internally. Who that is and what they are allowed to do has to be settled before the contract. Otherwise the alert lands on a voicemail.

Our IT provider already monitors things. Is that a SOC?

Usually not. Availability monitoring answers the question of whether something is running. Attack detection answers the question of whether somebody is doing something they should not. Different data, different contract. Which of the two is in your contract is usually there in writing, and it is not always the one everyone in the building assumes.

What if the first alerts are all false positives?

That is the normal start. Every new monitoring setup produces noise in the first weeks. The open question is who has the right to get tired of it. If the escalation path has no owner, the alerts get quietly ignored after a few weeks while the contract keeps running. That is the most expensive outcome, and we see it regularly.

The decision about monitoring is rarely a product question. It is the question of who at your company is allowed to act at night, and who answers for it afterwards. Once that is settled, half the quote is no longer needed, and the other half can finally be judged.

Not sure whether a fractional CISO fits your company?

In a free intro call we work out whether senior security leadership on a mandate makes sense for your company, and in what form. Honest answer included, even when it is "not yet".

Book a free intro call