A security operations center (SOC) is an organizational unit that continuously monitors, detects, investigates, and responds to cybersecurity threats across an enterprise's entire technology surface. See also: container security.
Most teams that fail at building a SOC fail on org design, not tool selection. They hire two analysts, buy a SIEM, and discover six months in that overnight alerts go unanswered, MTTR drifts past 48 hours, and the budget cannot stretch to the headcount the rotation arithmetic actually requires. The operator-grade question is how to size the analyst tier ladder, the on-call pattern, and the five-tool stack against MTTD and MTTR targets that the business will defend in a board review.
This article maps the build decisions that determine whether a SOC clears its detection and response targets in year one or burns through analyst tenure trying to. The arithmetic is unforgiving: a 24/7 follow-the-sun rotation, a Tier-3 threat hunting cycle, and a tuned correlation ruleset all carry concrete FTE costs that the hire-vs-MSSP framework has to price out before the first hire signs.
SOC Analyst Tier Model: Roles and Responsibilities

A SOC structures its analyst workforce as a three-tier ladder with distinct skill thresholds, escalation rights, and ownership of the operating metrics. The tier model is not a job-title hierarchy; it is a function map that allocates alert triage, incident response, and proactive threat detection across analysts whose experience and tooling access differ by an order of magnitude. The SOC Manager role sits outside this ladder as operational overhead, not as a fourth tier. The data-layer scope a SOC monitors is shaped by the pseudonymisation choices covered in the difference between encryption and tokenization, since tokenized fields generate different alert patterns than encrypted ones. The NIST SP 800-53 Rev 5 IR (Incident Response) and SI (System and Information Integrity) control families codify the function-to-tier mapping that most enterprise SOCs use as their reference baseline.
- Tier-1: Alert monitor and triage analyst
- Owns alert triage from the SIEM queue, performs initial classification against playbook criteria, and escalates verified incidents to Tier-2. Typically 1-2 years of SecOps experience. The Tier-1 cohort is the volume layer of the SOC; staffing it correctly is the precondition for 24/7 coverage.
- Tier-2: Incident responder
- Owns root-cause analysis, containment actions, and the MTTR clock once a Tier-1 escalation arrives. Investigates EDR artifacts, pivots across log sources, and authors the incident report. Typical experience floor is 3-5 years across SecOps and systems administration.
- Tier-3: Threat hunter and senior analyst
- Drives proactive threat detection through hypothesis-led hunts mapped to MITRE ATT&CK techniques, authors and tunes SIEM correlation rules, and serves as escalation backstop for novel incidents. Typically 6+ years and the rarest hire in the SOC market.
- SOC Manager (overhead role, not a tier)
- Owns shift scheduling, vendor relationships, metric reporting to leadership, and the analyst career ladder. The manager is a coordination role and does not carry an analyst caseload.
The escalation path runs Tier-1 to Tier-2 on incident confirmation, Tier-2 to Tier-3 on novelty or sustained adversary presence, and Tier-3 to the SOC Manager only for cross-functional coordination (legal, executive comms, breach disclosure). Shift handoffs happen on a structured handover at the start of every shift; the outgoing Tier-1 walks the incoming Tier-1 through open tickets, suppressed alerts, and any escalation in flight. The handover ritual is a control, not a courtesy. Without it, MTTD degrades on every shift boundary because context fails to transfer.
On-Call Rotation Patterns for 24/7 SOC Coverage
A SOC running 24/7 coverage is bound by rotation arithmetic before it is bound by tooling budget. The on-call rotation pattern dictates the minimum Tier-1 headcount, the annual FTE cost, and the recovery time the team can sustain through alert triage spikes and live incident response. Three patterns dominate enterprise SecOps team design, each with a different break-even point and a different MTTR profile.
| Rotation pattern | Minimum Tier-1 FTEs | Annual loaded cost | MTTR impact | Best fit |
|---|---|---|---|---|
| Follow-the-sun (3 regional pods) | 9 analysts (3 per pod) | $900k-$1.2M | Sub-1-hour Tier-1 acknowledge any timezone | Global enterprise, 5,000+ employees |
| DuPont 12-hour rotation (4 teams, 8-week cycle) | 6 analysts (4 working, 2 reserve) | $600k-$850k | Sub-2-hour Tier-1 acknowledge, shift-edge gaps | Mid-size SOC, 500-5,000 employees |
| 4x10 plus on-call overlay | 4 analysts plus pager rotation | $400k-$550k | 4-8 hour MTTR overnight, business-hours optimal | Sub-10-analyst SecOps team, sub-500 employees |
The headcount floor matters more than the cost ceiling. A 24/7 follow-the-sun SOC requires a minimum of six Tier-1 FTEs before any Tier-2, Tier-3, or manager overhead is layered on; the headcount math accounts for vacation, sick leave, training, and the on-call rotation reserve that keeps a single resignation from collapsing weekend coverage. Teams that try to run 24/7 with four analysts always hit MTTD degradation by month four when accumulated leave days expose the gap.
MTTD and MTTR: The Operating Metrics That Drive SOC Decisions

A SOC is graded by two operating metrics, and every staffing or tooling decision flows from them. Mean time to detect (MTTD) measures the elapsed time from initial adversary action to confirmed alert in the SecOps team's queue. Mean time to respond (MTTR) measures elapsed time from confirmed alert to contained or remediated incident. Industry-median MTTD for externally-detected breaches sits near 194 days in IBM X-Force and Ponemon reporting; SOC-run environments with a tuned SIEM and active threat hunting consistently target sub-24-hour MTTD for high-severity alerts and sub-1-hour MTTD for critical-priority detections. MTTR for critical incidents should hold under four hours of containment.
These two metrics cascade through the SOC operating plan. MTTR targets drive Tier-2 headcount because containment time is directly bounded by responder availability. MTTD targets drive SIEM tuning investment, detection rule coverage, and the Tier-3 threat hunting cadence because earlier detection requires better correlation logic, not more analysts. The NIST Cybersecurity Framework 2.0 DETECT and RESPOND function areas map directly onto these two metrics, and the CISA Cross-Sector Cybersecurity Performance Goals publish baseline detection and response targets that a SecOps team should benchmark against.
Four input variables determine MTTD in any SOC, and tuning each one yields a measurable improvement:
- Log ingestion latency. The elapsed time from event generation at the source to availability in the SIEM correlation engine. Above 15 minutes, sub-15-minute MTTD is architecturally impossible.
- Detection rule coverage. The percentage of MITRE ATT&CK techniques relevant to the environment that have an active correlation rule. Coverage gaps directly extend MTTD on any technique not modeled.
- Alert queue depth. The volume of pending Tier-1 alert triage items. Queue depth above 50 per analyst per shift produces context loss and missed correlations.
- Analyst shift gap. The gap between outgoing and incoming shift coverage at the handover boundary. Gaps as short as 15 minutes degrade MTTD on alerts that fire at the seam.
The SOC Tooling Stack: Five Integrated Layers
A SOC runs on five integrated tooling layers, and the integration matters more than the individual product choices. The SIEM is the event backbone; the SOAR layer reduces analyst load; EDR supplies the host-side evidence base; the threat intelligence platform supplies external adversary context; and ticketing integration binds the workflow to change management. Tool selection is downstream of this layer map, and the layer dependencies (SOAR requires SIEM as its event source; the threat intelligence platform enriches SIEM correlation rules) are non-negotiable. The NIST SP 800-92 Guide to Computer Security Log Management defines the log-management requirements that govern the SIEM ingestion layer and the retention policies a SOC has to enforce.
- SIEM (security information and event management)
- The log aggregation and correlation engine that ingests telemetry from every in-scope source and runs detection rules against it. Vendor selection at this layer drives total tooling cost; see Splunk vs QRadar pricing for the SIEM-tier vendor comparison.
- security orchestration automation and response (security orchestration automation and response)
- The playbook automation and case management layer that handles repeat alert triage actions without analyst intervention. Well-tuned playbook automation routinely cuts Tier-1 manual workload by 40-60% and is what makes a six-analyst SOC viable at enterprise alert volumes.
- EDR (endpoint detection and response)
- The endpoint telemetry and host-based detection layer that supplies the primary investigation artifacts for Tier-2 incident response. For vendor selection on this layer see Best CrowdStrike Alternatives For Endpoint Detection.
- Threat intelligence platform (TIP)
- The external adversary context layer that feeds indicator-of-compromise data and adversary tradecraft into SIEM correlation rules and Tier-3 hunting hypotheses. MITRE ATT&CK is the canonical mapping framework that the TIP layer normalizes incoming threat intelligence against.
- Ticketing and ITSM integration
- The incident lifecycle layer that ties SecOps team workflows to organizational change management, vendor escalation, and breach reporting obligations. Without this binding, incidents close in the SIEM but never close in the systems of record that auditors inspect.
Cloud telemetry feeds into this stack from the posture management layer; the upstream context of cloud-native event sources is covered in Best CSPM Tools For AWS. The application layer telemetry that Tier-1 analysts rely on for triage workflow is shaped by the logging requirements in the OWASP Application Security Verification Standard Section 7 (Error Handling and Logging), which most enterprise application teams cite as their log-instrumentation baseline.
Hire In-House vs MSSP: The Build Decision Framework
A SOC build decision is fundamentally a break-even calculation between in-house headcount and a managed security service provider (MSSP) contract. An in-house 24/7 SOC with seven to ten FTEs at $85k-$130k loaded cost runs $600k to $1.3M annually on labor alone, before SIEM licensing, EDR seats, threat intelligence platform subscriptions, and training budget. A typical MSSP contract ranges from $50k to $500k annually depending on log volume, SLA tier, and scope of incident response coverage. The decision turns on three variables: the all-in in-house cost, the MSSP price for an equivalent SLA, and the MTTD/MTTR differential between an in-house SecOps team on site and an MSSP shared-analyst pool covering many clients in parallel.
| Decision factor | Build in-house SOC | Engage an MSSP |
|---|---|---|
| Headcount profile | Existing security engineering team, hiring pipeline open | No dedicated security hiring track, sub-200 employee org |
| Annual security budget | Above $700k for tooling and staff combined | Below $300k for full coverage scope |
| Data residency posture | Regulated industry, log data cannot leave environment | No residency constraint, vendor SOC-2 acceptable |
| M&A and change velocity | Frequent acquisitions, novel scope every quarter | Stable footprint, predictable telemetry sources |
| MTTD and MTTR control | Direct ownership, in-house tuning of SIEM and playbooks | Vendor SLA, shared pool MTTR, contractual escalation path |
A hybrid model often beats either pure option. The MSSP covers Tier-1 alert review overnight and on weekends, while an in-house Tier-2 and Tier-3 team handles daytime incident response, threat hunting, and SIEM tuning. The hybrid splits the cost curve roughly $200k-$400k MSSP contract plus three to four in-house FTEs and produces tighter mean time to respond on critical incidents than a pure MSSP can deliver, since the in-house responders have direct system access and contextual familiarity with the environment.
Further reading
- Difference Between Encryption and Tokenization (hub guide on data-layer pseudonymisation choices that shape SOC alert patterns)
- Splunk vs QRadar Pricing (SIEM-tier vendor and licensing comparison for the security operations center tooling stack)
- Auth0 Alternatives and Identity Platforms (identity-as-a-service tooling that SOC teams integrate into access monitoring and privileged-user alert rules)
- Cloud Security vs On-Prem Security (deployment model comparison that determines where SOC data residency and telemetry routing decisions land)
- Best CSPM Tools For AWS (cloud posture telemetry that feeds the security information and event management ingestion layer)
Frequently Asked Questions
How many analysts does a 24/7 in-house SOC require at minimum?
A 24/7 in-house SOC requires a minimum of six Tier-1 analysts to sustain continuous coverage across three 8-hour shifts with one backup per shift rotation. That six-analyst floor assumes a DuPont or similar 4-team rotation model, accounts for vacation and sick leave, and does not include Tier-2 incident responders, Tier-3 threat hunters, or the SOC Manager role. Teams below six Tier-1 FTEs will experience coverage gaps on overnight and weekend shifts, which directly degrades MTTD for alerts that land outside primary business hours.
What is a realistic MTTD target for a well-tuned SOC?
A well-tuned SOC should target sub-24-hour MTTD for high-severity alerts, with a sub-1-hour MTTD goal for critical-priority detections triggered by SIEM correlation rules. Industry-wide median MTTD for breaches detected externally runs above 100 days; SOC-run environments with active threat hunting and tuned detection rules consistently outperform that baseline by an order of magnitude. The practical floor is set by log ingestion latency from endpoint and network sources. If raw telemetry takes 15-30 minutes to reach the SIEM, sub-15-minute mean time to detect is not achievable without architectural changes to the pipeline.
When does an MSSP become more cost-effective than an in-house SOC?
An MSSP becomes cost-effective when an organization's annual security operations budget is below approximately $400k-$500k, which is the rough breakeven point where a full-staffed in-house 24/7 SOC (headcount plus tooling) crosses MSSP contract pricing for equivalent SLA tiers. Below that budget, an managed security service provider with a dedicated account team typically delivers broader 24/7 coverage than an in-house team of two or three analysts. Above that threshold, in-house control of tooling, data residency, and investigation depth typically justifies the cost premium, particularly for regulated industries where log data cannot leave the organization's environment.








