Cyberuptive

Security operations · buyer decision guide

Co-Managed SOC vs Fully Outsourced SOC

Choose the operating model that matches your internal capacity, tool ownership, compliance context, and three-year cost—not the model with the shortest proposal.

Executive summary

The right answer is an ownership decision, not a label.

Co-managed SOC makes sense when your organization has security leaders who need to retain the SIEM, telemetry, detection logic, and operating context, but does not want to staff every monitoring shift. Fully outsourced SOC is usually the better choice when the priority is a fast, predictable path to coverage and your team does not yet have a mature security stack or a dedicated SecOps function. Both models can deliver 24/7 monitoring; the difference is who controls the platform and who makes the operating decisions.

Make the decision across four facts: internal capacity, existing tool investment, compliance and data-control requirements, and total cost over time. The most useful question is not “Do we outsource?” It is “Which responsibilities must remain ours, and which work should a specialist perform?” This matters because incident response is a business process as well as a technical one. NIST SP 800-61 Rev. 3 places incident response within broader risk management and links preparation, detection, response, and recovery.

The short version

Choose for control, capacity, and continuity.

  • Co-manage when you have a meaningful SIEM/EDR investment, internal security ownership, specialized integrations, or a need to keep data and detection control close.
  • Fully outsource when you need operational coverage quickly, have a small IT team, want bundled technology, and value a simpler monthly model.
  • Model retained work honestly. A provider may handle alerts, but someone still owns risk decisions, application context, executive communication, and service governance.
  • Make exit rights part of the design. Logs, rules, case history, and administrative control are continuity assets—not closing paperwork.

Definitions

Three SOC models, three different ownership patterns

Fully outsourced SOC

In a fully outsourced model, the provider commonly supplies the SIEM or equivalent monitoring platform, analysts, playbooks, and primary service operations. The customer supplies asset context, approves response authority, and receives cases and reports. This can shorten time to value because the service is packaged, but it makes provider diligence, data portability, and evidence delivery critical.

Co-managed SOC

In a co-managed model, the customer generally owns the SIEM, log data, endpoint tooling, and security roadmap. The provider adds 24/7 staffing, detection engineering, triage, threat expertise, and agreed response actions. It is a hybrid SOC model: operations are shared, while the customer preserves control over the data and architecture that make decisions defensible.

Hybrid variants

Real programs sit between these poles. You may retain Microsoft Sentinel while using a provider for night and weekend triage, keep CrowdStrike or Microsoft Defender while outsourcing detection engineering, or run Splunk or Elastic internally while using a service team for incident surge support. The contract should identify each tool owner, administrator, response authority, and evidence handoff instead of relying on the word “hybrid.”

Decision framework

Eight dimensions to compare before you compare price

Treat this as a direction-setting matrix. A single “co-managed” answer is not required; the point is to expose what your organization must own.

DimensionCo-managed signalFully outsourced signal
Internal security headcountTwo or three accountable security/IT owners can govern service, tools, and response.IT is lean and needs a provider to run day-to-day operations.
SIEM investment already madeExisting platform, retention, integrations, and detections are strategic assets.No viable platform exists, or the current one is not worth preserving.
Compliance frameworkYour team needs direct evidence access and fine-grained responsibility mapping.A packaged evidence cadence is sufficient if it is contractually defined.
Data sovereignty and controlYou need tight control over telemetry, access paths, retention, and exports.A provider-managed data design meets your requirements and is auditable.
Incident-response ownershipInternal leaders want to direct investigation and business decisions from their console.The provider should lead the technical workflow within agreed authority.
Tool licensingYou have committed licenses or specific requirements such as Trellix, Sentinel, Splunk, or Elastic.Bundled tooling and one accountable invoice are more useful than technology choice.
Budget modelYou can manage separate technology and operations budgets for greater control.You need a predictable bundled operating expense.
Growth trajectorySecurity maturity, acquisitions, or complex cloud/on-premises systems justify a reusable platform.Near-term scope is stable and speed matters more than platform customization.

Financial model comparison

Use three-year total cost of ownership, not monthly sticker price

The following is an assumption-led planning example for a 500-endpoint mid-market company, not a market-price claim. It illustrates why a co-managed model can cost more in cash while preserving assets the customer considers strategic. Replace every rate with your actual license, staffing, retention, and proposal data.

Three-year planning lineCo-managed assumptionFully outsourced assumption
TechnologyCustomer SIEM/EDR: $270,000 per yearBundled in provider fee
Provider operationsCoverage and tuning: $216,000 per yearBundled service: $504,000 per year
Retained customer labor2.5 FTE × $135,000: $337,500 per year0.5 FTE service owner × $135,000: $67,500 per year
Onboarding and transition$60,000 one time$60,000 one time
Illustrative 3-year TCO$2,527,500$1,774,500

The point is not that one number always wins. Co-managed can be rational when the SIEM, detections, retained data, and internal operating capability have value beyond the contract. Fully outsourced is often rational when those assets do not exist yet and the organization would otherwise absorb implementation and staffing risk. For a quote-normalization checklist, see the managed SOC pricing guide.

The staffing math

Coverage is a scheduling problem before it is a technology problem

A true 24/7 in-house SOC usually needs an eight-to-ten-FTE scheduling model once shifts, time off, training, management, and coverage gaps are accounted for. At a planning range of $110,000 to $160,000 per FTE, that is roughly $880,000 to $1.6 million per year before SIEM, EDR, training, and incident-response surge costs. Those are budgeting assumptions, not a wage survey; validate them against your labor market and role design.

Co-managed SOC commonly reduces the retained team to two or three accountable people: a security service owner, a technical approver, and an incident or business escalation owner. Fully outsourced SOC removes the 24/7 analyst roster, but it does not remove customer accountability. The SANS 2024 SOC Survey found that two to ten people remained the most common SOC size and identified staffing and automation constraints as persistent barriers, reinforcing why buyers should model both labor and operating scope. Read the public SANS survey summary.

When co-managed wins

Keep the platform when it is part of how you manage risk

Co-managed SOC is strongest when you already invested in a SIEM and security tools that the business depends on. It also fits organizations with a capable SecOps leader, specific tooling or integration requirements, hybrid on-premises and cloud environments, and regulated workflows where the customer needs close control over telemetry and evidence. In these conditions, the provider extends capacity without taking the operating model away.

It can also be the better design where your team must directly explain detection logic, alert disposition, and access paths to auditors or customers. You do not need to perform every task yourself; you do need a traceable story for who did what, in which system, with what evidence. Review Cyberuptive’s SOC as a Service and managed detection and response pages for the operational boundary to define.

When fully outsourced wins

Fully outsourced SOC is often the safer choice when there is no useful SIEM investment, the IT team is small, requirements are relatively standard, the budget needs a single monthly line, and coverage must begin quickly. A provider-owned stack can reduce implementation choices and improve accountability—if the scope, response authority, retention, reporting, and exit terms are explicit. Gartner’s public Journey Guide to Building a Security Operations Center is a useful starting reference for leaders evaluating the build-versus-partner decision.

CMMC and regulated implications

Both models work—evidence flow decides whether either is defensible

Both models can support CMMC and other regulated programs. Co-managed operations can keep SIEM records, detection changes, analyst notes, and SSP evidence close to the customer’s system boundary. Fully outsourced operations can be equally workable, but the provider must supply strong evidence pipelines: responsibility mapping, access records, incident cases, service reports, change documentation, retention information, and a clean handoff to the customer’s SSP and assessment narrative.

For CUI systems, write the service boundary alongside the technical boundary. Identify what the provider can see, who can administer tools, where records live, and who owns incident communications. Cyber AB roles do not replace technical and contractual diligence. Start with the CMMC compliance services overview, then use the CMMC MSSP vetting guide to test provider evidence, access, and escalation design.

Co-managed vetting framework

The 12 questions that reveal the operating model

Require written answers, then test the answers with the people who will operate the service.

  1. 01. What API access and data exports will we retain?

    Confirm export formats, rate limits, administrative roles, and what happens during a transition.

  2. 02. How deep is the SIEM integration?

    Ask which sources, fields, detection rules, dashboards, and cases the team can actually work.

  3. 03. Who owns playbooks and detections?

    Define authorship, approval, testing, documentation, and transfer rights.

  4. 04. What is the tuning cadence?

    Set an initial tuning plan, recurring reviews, and a measurable path for false-positive reduction.

  5. 05. What is the alert-triage SLA?

    Review severity definitions, acknowledgement, investigation, escalation, and after-hours coverage.

  6. 06. How does escalation work?

    Name technical, executive, legal, and business owners with their contact and decision authority.

  7. 07. What evidence is handed off?

    Request sample case records, reports, access reviews, change records, and evidence indexes.

  8. 08. What admin access stays with us?

    Keep clear break-glass, role-review, and privileged-account procedures.

  9. 09. How does offboarding work?

    Confirm logs, cases, configurations, rules, runbooks, accounts, and transition assistance.

  10. 10. Who owns data and derived content?

    Address raw telemetry, enrichment, dashboards, detections, notes, and retention separately.

  11. 11. Is cost transparent under growth?

    Identify endpoint, user, log-volume, coverage, engineering, and incident-response overages.

  12. 12. How will joint incident response run?

    Tabletop detection, containment, communications, evidence preservation, recovery, and lessons learned.

90-day co-managed pilot plan

Prove the shared model before you expand it

  1. Days 1–15: define ownership. Document tools, integrations, data flows, admin roles, response authority, escalation owners, and evidence needs. Freeze the pilot success criteria before onboarding begins.
  2. Days 16–30: connect priority telemetry. Start with identity, endpoints, email, cloud control planes, and the systems most relevant to business risk. Validate ingestion and retention with customer administrators.
  3. Days 31–45: establish detection and triage. Map existing rules, agree on severity, test case creation, and schedule a weekly tuning review. Do not expand sources until the initial workflow is usable.
  4. Days 46–60: test joint response. Run a tabletop that exercises alert handoff, containment authority, business decisions, evidence preservation, and executive communication.
  5. Days 61–75: validate the evidence pipeline. Review completed cases, change records, access reviews, reports, and ownership mapping against your compliance and audit expectations.
  6. Days 76–90: make the scale decision. Compare operational results to the baseline, approve the three-year model, set quarterly governance, and formalize exit and transition rights.

A pilot should create a working shared-responsibility model, not just a dashboard. If the provider cannot explain access, SLA, detection ownership, evidence, or exit after 90 days, expanding the engagement will make those gaps harder to fix.

FAQ

Co-managed SOC questions buyers ask next

Do we need a SIEM before co-managed SOC?

No. You can establish one during the engagement. The decision is whether the customer will own and govern the platform after implementation.

Who owns incident response in a co-managed model?

The provider can run contracted technical actions. The customer retains business, legal, and executive decisions. Document the exact handoff by severity.

Can we switch from fully outsourced to co-managed?

Yes. Plan a staged migration that transfers telemetry, historic cases, detections, playbooks, integrations, administrative access, and on-call knowledge before the former service ends.

What happens if we change providers?

A sound agreement specifies ownership and export of logs, cases, rules, documentation, API credentials, and privileged administration. Treat those clauses as an operational resilience requirement.

Can co-managed SOC support CMMC?

Yes. Both models can support CMMC when their service boundary, access model, responsibilities, operating evidence, and incident workflow are accurately documented.

SOC selection

Choose the SOC model around your operating reality

Bring your current tools, staffing model, and compliance requirements. We will help you define what to retain, what to delegate, and how to prove it works.