SOC and MSSP: Effectively Outsourcing Network Security
Outsourced vs. in-house SOC (Security Operations Center): key considerations for IT departments. MSSP (Managed Security Service Provider), MDR (Managed Detection & Response), and SIEM as-a-Service. 2026 comparison guide.
SOC service tiers
- L1: 24×7 monitoring and triage
- L2: investigation
- L3: threat hunting and forensics
- Plus an in-house CERT for incident response
In-house SOC
- Full control
- Cost: a minimum of 8-15 people for 24×7 coverage = €700k-€1.5M/year
- Recruitment: scarce and expensive talent (analysts: €60-90k)
- Rationale: large enterprise with >5000 users
Outsourced MSSP
- Full outsourcing
- Price: €100-500/user/year, depending on scope
- Services: monitoring, alerting, and limited response
- Limitations: restricted remediation capabilities
MDR (Managed Detection & Response)
- MSSP with automated response actions
- EDR + MDR bundles (CrowdStrike, SentinelOne Falcon)
- Price: €10-30/endpoint/month
- Popular with SMEs and mid-sized companies
SIEM as-a-Service
- SaaS solutions: Splunk Cloud, Microsoft Sentinel, Google Chronicle
- No hardware to maintain
- In-house analysts use the SIEM
- Hybrid model: SaaS SIEM + MSSP operations
Providers in France
- Orange Cyberdefense
- Thales Cyber
- Capgemini Cybersecurity
- Advens
- Synetis
- Sopra Steria
- Stormshield + partners
Selection criteria
- Organization size: <2000 users → MSSP/MDR; >5000 → hybrid/in-house
- Criticality: financial services/healthcare → 24×7 coverage required
- OPEX budget vs. personnel CAPEX
- In-house expertise: retain L3 and outsource L1-L2
- Location: France-based vs. US-based MSSP (digital sovereignty)
MSSP SLAs
- Monitoring: 24×7
- Critical alert: <15 min
- Investigation: <1h
- Response: subject to contract terms (may require IT management approval)
- Reporting: dashboard + monthly review
Order from OPTINOC
Advisory services and MSSP/MDR selection. Sentinel/Splunk integration. SIEM deployment. Quote within 48h.
