Saturday, 2 AM. A credential-stuffing attack starts hammering your Microsoft 365 tenant. Your IT team is asleep because they’re an IT team, not a SOC. The on-call rota covers server outages, not log analytics. By Monday morning an attacker has read through your finance shared mailbox and exfiltrated the customer list. Nobody knew until the phishing campaign that followed landed in a customer’s inbox and they rang to ask what was going on.
That’s the gap a managed SOC fills. It’s also why the service has stopped being an enterprise-only thing and started showing up in 100-to-500 person companies across the Nordics. Falconer Security runs managed SOC on Microsoft Sentinel for Swedish SMBs and MSPs. This piece walks through what the service actually includes, what it costs, and how to tell a real provider from alert-forwarding theatre.
What a managed SOC is, in plain terms
A managed SOC is a team of security analysts, living at a provider, watching your environment around the clock. They investigate alerts. They respond to threats. They do it on your behalf instead of you hiring a headcount for each shift. You subscribe. They watch.
It’s worth separating two things that get confused. Microsoft Sentinel (or Splunk, or Chronicle) is a SIEM. The SIEM collects logs and generates alerts. It’s a tool. A managed SOC is the team that reads the tool, makes sense of what it’s saying, and acts. A SIEM without a SOC is a smoke detector in an empty building. It’ll beep when there’s a fire. Nobody will hear.
In practice, the service wraps around a handful of functions: constant monitoring of logs and alerts, human-led investigation of anything suspicious, coordinated incident response when something’s real, threat intelligence plumbed into the detection logic, monthly reporting your board can read, and ongoing detection engineering so the rules stay sharp instead of stale.
Why SMBs need this in 2026
The CrowdStrike 2026 Global Threat Report puts average breakout time at 29 minutes. That’s the window from an attacker landing on one endpoint to the first lateral movement. Less than half an hour. A part-time IT manager checking Defender alerts during office hours is not going to catch that.
Three trends made this the year mid-market companies started buying SOC services in volume.
Regulation is the loudest of them. NIS2 demands continuous monitoring and incident response from organisations in essential and important sectors, and Swedish enforcement has started chasing it properly. For most affected SMBs, outsourcing to a managed SOC is the only realistic way to satisfy Article 21 without pretending you’re going to hire your way to a 24/7 operation.
Talent is the second. The ISC2 2025 Workforce Study reports persistent shortages, with 33% of organisations blaming budget constraints. Enterprises with nine-figure security budgets struggle to hire senior SOC analysts in Stockholm. A 200-person industrial firm in Västerbotten is not winning that recruitment fight.
The third trend is target selection. The Verizon 2025 DBIR found 88% of system-intrusion breaches involved stolen credentials, and SMBs typically lack the detection coverage to notice credential abuse in time to stop it escalating into ransomware. Attackers know this and price their effort accordingly.
Managed SOC vs building your own
The instinctive CFO question is whether you can build this internally and come out ahead. For companies under roughly a thousand employees, the answer is no. Here’s the maths.
A functional 24/7 SOC needs at minimum five or six analysts across three shifts with holiday and sickness cover, plus a team lead who can actually run the operation. Add a SIEM licence, threat intelligence feeds, a SOAR platform for automation, and training budget for people who will cycle out to higher-paying employers every 18 to 24 months. Industry data lands the all-in annual number somewhere between $1M and $2.5M.
| Cost component | In-house SOC (annual) | Managed SOC (annual) |
|---|---|---|
| Analyst salaries (5-6 FTEs for 24/7) | $400,000 – $720,000 | Included |
| SOC manager / team lead | $100,000 – $150,000 | Included |
| SIEM platform licensing | $50,000 – $200,000+ | Included or BYO |
| Threat intelligence feeds | $20,000 – $80,000 | Included |
| SOAR / automation tooling | $30,000 – $100,000 | Included |
| Training and certifications | $15,000 – $40,000 | Included |
| Recruitment and turnover costs | $30,000 – $60,000 | N/A |
| Total estimated annual cost | $645,000 – $1,350,000+ | $120,000 – $360,000 |
Managed SOC for a 100-to-500-person company runs $10,000 to $30,000 a month, depending on monitored assets and service depth. That’s maybe a quarter of the internal number at the low end. You also get operational coverage from week one, rather than the six to twelve month slog of hiring, tooling, tuning, and hoping the first analyst doesn’t quit two months in.
What a real SOC includes, and what’s usually missing
Not every provider badged as “managed SOC” is actually running one. Some are alert-forwarding services in a trench coat, sending you raw SIEM notifications with minimal analysis and calling that “managed”. Knowing which is which is the most important part of the evaluation.
The table stakes you should refuse to compromise on:
- Actual humans on shift around the clock, triaging events. Not an AI tool generating tickets to a queue nobody reads.
- Investigation and response when something looks off. Determine scope, contain the threat, escalate with next steps, all under a clock.
- Detection engineering that adapts to your environment instead of running vendor defaults. Generic rules produce noise and miss the quiet stuff.
- Scheduled threat hunting. Proactive searches for the things automated detection won’t catch. Not a quarterly marketing gesture, a weekly cadence.
- Monthly reporting that your operations director can read in ten minutes. What was detected, what was handled, what’s been tuned.
Red flags I’ve seen on actual contracts, in descending order of how badly they bite:
- “Alert forwarding” pretending to be SOC. You get raw alerts. You investigate. That’s not a managed service, that’s a mailing list.
- No detection engineering. The provider uses out-of-the-box Sentinel rules forever. You get the noise and miss the real signals.
- Opaque pricing with hidden ingest fees, user-count padding, or “premium incident response” tiers that activate exactly when you need the service most.
- Zero compliance chops. If you’re under NIS2 or GDPR and your provider can’t generate audit-ready reporting, you’ve bought half a service.
Delivery models and where they fit
“Managed SOC” covers several flavours of engagement. Matching the model to your maturity saves money and frustration.
| Model | Best for | What you get | Typical cost |
|---|---|---|---|
| Fully managed SOC | SMBs with no internal security team | Provider runs the SIEM, the monitoring, the response, the reporting | $10,000 – $30,000/month |
| Co-managed SOC | Companies with one or two internal security staff | You handle day-to-day, provider covers 24/7 and escalations | $7,000 – $20,000/month |
| MDR | Companies focused on endpoint detection | Endpoint and identity monitoring with response, narrower scope than full SOC | $3,000 – $15,000/month |
| SOC + vCISO | SMBs needing operations and strategy together | Managed SOC plus strategic security leadership, policy, and compliance guidance | $15,000 – $40,000/month |
Falconer delivers both fully-managed and co-managed SOC on Microsoft Sentinel. When a client needs strategic direction alongside operational coverage, we pair managed SOC with CISO as a Service. If you’re trying to decide whether you need the strategy piece, the CISO-as-a-service guide unpacks that.
How to evaluate a provider properly
Picking a managed SOC provider is not procurement. You’re giving an outside team access to the most sensitive detection data in your environment, and trusting them to act on it at 3 AM without waking you. Take it seriously.
First thing to understand is the technology stack. Providers built on established platforms, Sentinel, Splunk, Chronicle, bring mature detection ecosystems. Providers running their own proprietary, closed tooling where you can’t see or export your data are a trap. When the contract ends, you walk away with nothing. If you’re already invested in Microsoft 365 and Azure, a Sentinel-based provider is almost always the right call because your existing licences are already generating the signals. You’re not paying twice for data collection.
Second, press on what “response” means in practice. Ask specifically what happens when a critical alert fires at 2 AM on a Sunday. Some providers notify you and wait. Others can isolate a compromised device, disable a user account, or block a malicious IP inside the first few minutes, and that’s the service you actually want. Containment authority is the difference between a contained incident and a breached tenant.
Third, detection maturity. How many custom rules does the provider maintain for environments like yours? Do they write detections specific to your business, or rely on vendor defaults? On Falconer engagements, replacing default Sentinel content with custom-tuned detections typically drops false positives by 60 to 80% while catching threats the generic rules miss entirely. If the provider can’t name a few custom rules they’ve written, they’re not engineering, they’re running what came in the box.
Compliance and reporting matters when auditors turn up. For organisations under NIS2, the provider needs to produce documentation showing continuous monitoring, incident handling procedures, and reporting timelines. Ask for a sample monthly report from another customer. If they won’t send a redacted version, assume it doesn’t exist.
Data ownership is non-negotiable. Your security telemetry is yours. If the provider hosts the SIEM, clarify what happens when you leave. The cleanest setup is the provider running Sentinel in your Azure tenant. You own the data by default, you see everything, and if the relationship ends you retain the analytics platform and can plug a new team into it.
Last piece, communication. In a real incident, dashboards don’t help. What helps is a dedicated Slack or Teams channel, direct phone numbers for the analysts on shift, and a clear escalation path that doesn’t route through a first-line service desk. Ask to meet the people who’ll actually be on your tenant during an incident. If you can’t, that’s a signal.
Managed SOC and NIS2
For Swedish and wider Nordic companies pulled into NIS2, a managed SOC discharges several operational obligations under Article 21 directly. The directive expects measures for incident handling, security monitoring, and supply-chain security. Those are exactly the operational pieces most SMBs can’t implement internally without enormous cost, and exactly what a managed SOC is paid to do.
Concretely, a managed SOC typically covers:
- Defined incident handling procedures with measurable MTTD and MTTR targets.
- 24/7 oversight of network and information systems, not business hours only.
- Support for the NIS2 reporting timelines: 24-hour initial notification to authorities, 72-hour detailed report.
- Monitoring of third-party access and supplier connectivity into your environment.
- Audit-ready documentation and evidence of the security measures a regulator will ask for.
Worth being clear: a managed SOC on its own doesn’t make you NIS2-compliant. You still need policies, risk assessments, governance, and an incident response plan signed off at board level. What the SOC does is handle the operational detection-and-response side that most affected SMBs don’t have the headcount to build internally, and that’s the piece regulators look at first when something goes wrong.
Questions to ask before you sign
When you’re in the contract conversation, press on these. Vague answers mean vague service.
- What’s the documented MTTD and MTTR, and how do you measure it? Good providers commit to MTTD under 15 minutes and MTTR under one hour for critical threats. Written SLAs, not aspirations.
- When you say “response,” what does that actually mean? Containment authority or a ticket in my queue? The difference matters.
- How do you tune out false positives? Ask about the process, the cadence, and the people who own it. “We’ll tune when we see a pattern” is not an answer.
- What’s in the base price, and what’s an add-on? Incident response, threat hunting, and compliance reporting should be bundled, not upsold mid-incident.
- What does onboarding look like? Two to four weeks is realistic. “Plug and play” deployment claims mean they’re running untuned defaults on your data.
- Do I own the data and the detection rules? If the answer is “we own the rules,” you’re renting visibility and you’ll lose it when the contract ends.
- What’s the contract term and the exit process? Annual with 90-day notice is the sweet spot. Multi-year lock-ins before you’ve had a real incident are a bad deal.
Frequently asked questions
What is the difference between a managed SOC and an MSSP?
A managed SOC puts dedicated analysts on your environment to monitor, investigate, and respond. An MSSP is a broader service category that may also include firewall management, vulnerability scanning, patch coordination, and other security operations. Some MSSPs include a SOC. Many don’t, or they offer a thinner version. A managed SOC is focused; an MSSP is wider but sometimes shallower. Our SOC as a Service vs MSSP comparison covers the differences in detail.
How much does a managed SOC cost for a small business?
For a company of 100 to 500 people, managed SOC typically runs $10,000 to $30,000 per month, depending on monitored assets, data volume, and service depth. Compare that to $1M-plus annually for an in-house build. Most providers tier pricing around size and complexity. The SOC as a Service pricing guide breaks it down further.
Do I need a managed SOC if I already have Microsoft Defender?
Defender is the alarm system. A managed SOC is the humans who respond when the alarm goes off. Defender generates alerts and blocks obvious threats. It doesn’t investigate the non-obvious ones, doesn’t correlate across identity, email, and endpoint, and doesn’t respond at 3 AM. The MDR vs SIEM guide shows how these layers fit together.
Is a managed SOC required for NIS2 compliance?
The directive doesn’t name it by that word. Article 21 requires continuous monitoring, incident handling, and timely reporting, and a managed SOC is how most SMBs without an internal security team meet those operational requirements in practice. The scope covers essential and important sectors across the EU, Sweden included.
How long does it take to onboard with a managed SOC provider?
Two to four weeks for a proper onboarding. That window covers connecting your data sources, tuning detection rules to your environment, establishing communication channels, and building response playbooks. If a provider promises same-day deployment, they’re running generic, untuned detections against your data and you’ll drown in noise for the first three months.