Telappliant
Cyber Security Guide · 2 June 2026

Managed security operations centre (SOC): what it is and when you need one

In-house SOC, managed SOC or MDR - coverage, detection versus response, and the questions to ask a provider.

By the Telappliant team

Managed SOC analyst monitoring alerts out of hours

Buying detection tooling is easy. Having someone qualified look at what it produces at three in the morning is the hard part, and it is the part that decides whether an intrusion becomes an incident. That is what a security operations centre exists to do.

What a SOC actually does

  • Collects telemetry from endpoints, identity, email, firewalls and cloud services
  • Correlates it so a weak signal in one place is read alongside the others
  • Triages alerts so real detections are separated from noise
  • Responds: isolating a device, disabling an account, killing a session
  • Hunts proactively for patterns no rule has been written for yet
  • Reports on what happened, what was tuned and what remains exposed

In-house, managed or MDR

An in-house SOC with genuine 24/7 cover needs roughly eight to ten analysts once you allow for shifts, holiday and attrition, which puts it out of reach for most UK organisations below enterprise scale. A managed SOC gives you that rota as a service. MDR is narrower: strong detection and response, usually centred on endpoint and identity, without the wider log management and compliance reporting a full SOC provides. For most mid-sized UK businesses, managed SOC or MDR is the honest answer.

Detection is not response

Ask precisely what the provider is permitted to do without ringing you first. A service that can only email an alert at 2am is a monitoring service, not a response service. Contained-in-minutes and reported-by-morning are very different outcomes.

Questions worth asking a provider

  • Is cover genuinely 24/7/365, with UK-based analysts on shift, or follow-the-sun?
  • What is the contractual mean time to detect and mean time to respond?
  • Which containment actions can you take autonomously?
  • What log sources are included, and what does adding one cost?
  • Where is our data stored and for how long is it retained?
  • What happens to our detections and tuning if we leave?

What drives the cost

Pricing usually keys off user or endpoint count, the number and volume of log sources, retention period and response depth. Cheap quotes tend to narrow the log sources or push response back onto your team. Compare like for like: coverage hours, sources ingested and who performs containment.

What you should get out of it

Beyond the alerts, a good SOC engagement steadily reduces your attack surface: fewer standing admin accounts, tighter conditional access, better patch discipline, and a monthly report your board and your insurer can both read.

Next steps

Frequently asked questions

Further reading

Related guides

More practical guidance from the Telappliant team on the same topic.

Talk to a UK technology partner

Book a practical, no-pressure consultation. We'll review your current setup, show where AI communications, cloud telephony or managed IT could improve customer experience and reduce admin - and tell you straight if you don't need us.

  • UK-based people, real account management
  • Honest recommendations - even if it's not us
  • Practical AI where it adds value, not hype
UK business team reviewing plans together before a consultation
Call us Book consultation