Build vs. Buy vs. Co-Manage: Hybrid SOC Models That Rent the Engineering and Keep the Judgment
Most security teams already run a hybrid SOC. Here is the case for renting the engineering and tooling while keeping analyst judgment in-house, and the places where that split fails.
The outsourcing line most SOCs draw by accident
Almost nobody chooses between a fully internal SOC and a fully outsourced one anymore. The real decision is where the line between the two sits, and most organizations let a vendor's packaging draw it for them.
The big picture: A hybrid SOC splits security operations between an internal team and an outside provider or platform. That split can run in two directions. One version rents the people: an outside team watches the queue, triages, and escalates, while the customer keeps the tools. The other version rents the engineering: an outside provider or platform owns the integrations, pipelines, automation, and uptime, while the customer's analysts make the calls. Both get sold under the same "co-managed" label. They produce very different security programs five years later.
Why it matters: The first post in this series showed that every operating model has a variable that breaks it at scale. Hybrid models add a second question on top of cost: which capability are you building, and which are you leasing? Engineering work is largely the same from one company to the next. Judgment is specific to one environment and takes years to form. Lease the wrong one and you end up owning plumbing that any vendor could run while depending on a third party for the one thing nobody outside your company can know.
By the numbers:
- Among organizations planning to build a SOC, 64% intend to outsource part of it, 26% plan to go fully to SOC-as-a-Service, and only 9% plan to build entirely in-house, per a Kaspersky survey of organizations with 500 or more employees across 16 countries.
- The same survey shows the market renting both halves at once. The most commonly delegated tasks are solution installation and deployment (55%), solution development and provisioning (53%), and SOC design (47%). At the same time, the external roles in highest demand are first-line analysts (61%) and second-line analysts (52%).
- In the SANS 2025 SOC Survey, about 41% of respondents outsource alert triage and escalation fully or partially, compared with about 31% for SOC architecture and engineering. Those percentages are our calculation from the published response counts (183 of 443 and 133 of 432).
- Only 37% of enterprise MDR customers say their provider's analysts consistently deliver high-quality analysis. Another 38% say the analysis occasionally misses context or depth, and nearly 22% call it adequate at best, per IDC's 2026 MarketScape for enterprise MDR.
- In that same IDC research, only 15% of respondents said their MDR provider always meets its SLAs.
- 95% of cybersecurity professionals report at least one skills gap on their team, and 88% have experienced at least one security incident or operational issue tied to a skills shortage, according to reporting on the 2025 ISC2 Cybersecurity Workforce Study.
- 62% of SOC professionals say their organization is not doing enough to retain top talent, and the most common SOC tenure is three to five years, per SANS.
Read together, the data describes a market that outsources triage more readily than engineering, then reports that the outsourced analysis lacks context. That is the pattern this post argues against.
Two kinds of SOC work
A SOC does two jobs that look similar on an org chart and behave very differently under pressure.
Engineering and tooling work keeps the machinery running. It covers data source connectors, log pipelines, parsers, SIEM and platform administration, automation maintenance, API changes, uptime, and around-the-clock mechanical coverage. Increasingly it also covers the evaluation work that confirms an AI system still reaches correct conclusions after a model update. This work is hard and never finished. It is also close to identical across companies. A connector to a major identity provider works the same way for a bank as it does for a retailer.
Judgment work decides what the evidence means. Is this login unusual for this person, or is she in Singapore every October? Does this service account normally touch that database? Is the finance team's new file-sharing habit a policy violation or a workaround for a broken process? Should we isolate a production host at 2 p.m. on the last day of the quarter? None of those answers transfer between environments. They come from analysts who have worked the same estate long enough to know what normal looks like.
SANS survey author Christopher Crowley makes the same distinction when he explains why some functions stay internal: those areas "demand a deep understanding of internal systems, business priorities, and organizational context." Outsourcing, he writes, "makes strategic sense for tasks that are highly specialized, repeatable, and resource intensive."
Engineering fits that second description. Judgment fits the first.
What to rent, and what to keep
Function | Rent or keep | Why |
|---|---|---|
Data source connectors and integrations | Rent | Identical across customers; vendor API changes break them on someone else's schedule |
Pipelines, parsing, platform administration, uptime | Rent | Continuous operational load with no competitive value in owning it |
24x7 first-pass coverage (human or automated) | Rent | The staffing math from post one: about 4.9 people per continuously filled seat |
AI evaluation and regression testing | Rent | Expensive to build, amortized across many customers by a provider |
Detection logic specific to your environment | Keep | Only your team knows what normal looks like |
Investigation conclusions and escalation decisions | Keep | Depends on business context no outside party holds |
Containment and response authority | Keep | The organization that carries the business impact should make the call |
Custom investigative logic and playbooks | Keep | This is your institutional knowledge in executable form |
Accountability to the board, regulators, and insurers | Keep | It cannot be transferred by contract |
The math on the rented side: Using the reference figures from the first post, a detection engineer costs about $162,895 in base pay, or roughly $233,000 fully loaded at the 1.43x multiplier. If we assume platform and integration engineers cost about the same, a two-person bench to own connectors and automation runs about $466,000 a year before tooling. A bench of two also means every vacation and resignation is a coverage gap. That is our assumption for illustration, and your market will differ. The point is that the engineering bench is a permanent cost center that produces no advantage a competitor could not buy.
The math on the kept side: The first post sized a retained team for the reference organization at five people: two Tier 2 analysts, one senior investigator, one detection engineer, and one SOC manager, at about $1.0 million fully loaded. A hybrid model does not shrink that team much. It changes what the team spends its hours on. In a model that rents the people, the retained analysts spend their time re-investigating escalations that arrived without context. In a model that rents the engineering, the same analysts spend their time on conclusions.
Three hybrid patterns
Pattern | What you rent | What you keep | Watch for |
|---|---|---|---|
Co-managed MDR | 24x7 monitoring and first-pass triage by provider analysts | Senior investigation, containment authority, vendor oversight | Escalations that arrive as an alert plus a paragraph; expertise that accrues to the provider |
Co-managed SIEM or platform engineering | Pipelines, content upkeep, platform operations | The full analyst bench and all investigation | Detection rules written in a format or tenant you cannot take with you |
AI SOC platform as substrate | Connectors, the investigation engine, evaluation, uptime | Analysts who direct, verify, and decide, plus your own detections and investigative logic | Opaque reasoning, usage pricing under load, a thinning talent pipeline |
The first pattern is the most common and the one most likely to rent the wrong half. IDC's survey data describes the result: providers contain the threat and then, in IDC's words, "Containment is being delivered. Connective insight is not, at least not consistently." The customer's analysts fill in the missing context after the fact.
The second and third patterns rent the engineering. They differ in how much of the mechanical work a platform does without a person in the loop. That gap is narrowing fast. As the first post noted, Gartner expects AI to handle most initial MDR findings without human action by 2029. Gartner's 2026 MDR research also says buyers should not expect lower prices from that automation and that some organizations may bring MDR functions back in-house as AI SOC tools mature, according to NHIMG's summary of the research.
IDC's advice to enterprise buyers applies to all three patterns: "Insist on a genuine co-management and federation model rather than a binary fully managed relationship." The firm recommends a formal RACI structure that defines which actions the provider takes on its own, which need the customer's authorization, and which the internal team retains.
Where the hybrid model breaks down
Renting the engineering is the stronger split. It still has failure modes, and most of them are quiet.
- The seam becomes the weak point. Every hybrid model has a handoff. If the rented layer hands over a verdict without the evidence and reasoning behind it, the internal analyst has to redo the work or trust it blind. Both outcomes defeat the purpose.
- Kept judgment can atrophy. Analysts who only approve machine or provider conclusions stop building the skill the model depends on. Command Zero CTO Dean De Beer puts a number on the warning sign: "An override rate of zero is not evidence of excellent agent performance; it is evidence of rubber-stamp review."
- Your logic can end up living in someone else's house. Custom detections and playbooks are the part you are supposed to own. If they exist only inside a provider's tenant or proprietary format, you have rented them too. Ask how they export before you sign.
- The junior pipeline still needs a starting point. Senior judgment grows out of years of routine cases. A hybrid model that removes every entry-level task also removes the place where your next senior analysts would have learned the environment. We took up that question in Does the Tiered Model Survive AI?
- Some constraints rule out renting. Air-gapped environments and strict data residency rules can make an external platform impossible. In those cases the engineering has to be built and funded internally, with eyes open about the permanent cost.
- Accountability does not move. A provider can share the work. The breach notification, the regulator's questions, and the board conversation still belong to you. We looked at where human judgment has to stay in the loop in Autonomous Investigation vs. Autonomous Response.
What industry experts are saying
Command Zero cofounder and CPO Alfred Huger has made the rent-versus-own argument directly to teams considering a custom AI SOC. "Build the parts that are differentiated to you. Rent the parts that aren't," he wrote in Yes, Build Your Own AI SOC. He is specific about which side each piece lands on: "Your detections, your workflows, your data topology, those are yours, and they're where a build earns its keep." On owning the rest, he is blunt: "The moment you build this, you are running a software business."
Command Zero cofounder and CTO Dean De Beer explains why the judgment half resists outsourcing. "Senior security judgment is built from knowing one environment well enough that anomaly detection becomes intuitive," he writes in The Recomposition of Security Work. When enterprises handed analyst work to providers in earlier waves, he argues, "the developmental benefit moved to the vendor and the expertise gap remained with the organization." He applies the same test to tooling: "Platforms that present conclusions without reasoning chains are headcount reduction tools. Platforms that expose reasoning chains are formation infrastructure."
IDC research vice president Craig Robinson sees the governance of the split becoming the buying criterion. "Buyers who treat MDR/MXDR as a commodity purchase will increasingly find that the details of how a service is automated, governed, and delivered determine whether it meets their risk tolerance," he says in the firm's 2026 MarketScape for enterprise MDR. The same report observes that "nearly every enterprise organization retains some internal security capability."
Sergey Soldatov, who heads the security operations center at Kaspersky, describes the intent behind most hybrid decisions: "By shifting routine and technical tasks externally, organizations are able to concentrate on high-value activities such as strategic decision-making and orchestrating responses to sophisticated threats," he said in the survey announcement.
SANS faculty fellow Seth Misner cautions against using tooling to paper over a people problem. "My concern is that leadership may see AI as a shortcut to fill staffing gaps, instead of investing in the talent and thoughtful integration of AI needed for substantive SOC improvement," he wrote in the SANS 2025 SOC Survey.
The limits of the split
Between the lines: The line between engineering and judgment is cleaner on a slide than in a SOC. Detection engineering sits on both sides. The pipeline that delivers a rule is plumbing, and the logic inside the rule is knowledge of your environment. The data behind this post has limits as well. The Kaspersky survey covers organizations that have not yet built a SOC and includes no U.S. respondents. The SANS percentages are our arithmetic on published counts. The IDC figures come from a vendor-hosted excerpt of a larger report, and the Gartner findings arrive secondhand. No independent study has yet compared outcomes between hybrid models that rent people and hybrid models that rent engineering, so the argument here rests on structure and practitioner experience more than on measured results.
Command Zero has a stake in this argument. We sell a platform that sits on the rented side of the line, which is the reason to test the claim against your own environment before accepting it.
The bottom line: Hybrid is already the default operating model. The decision that matters is which half you lease. Rent the work that is the same everywhere: connectors, pipelines, uptime, evaluation, and around-the-clock mechanical coverage. Keep the work that only makes sense inside your walls: what normal looks like, what a finding means for the business, and who decides to act. Then write the split down. For every function in the SOC, name who does the work, who can see the reasoning, who makes the decision, and who could take it over if the contract ended tomorrow. If a row has a vendor's name in all four columns, that function has been outsourced whether or not the contract says co-managed.
Terms in this post
Terms defined in Command Zero's glossary are linked below. Terms without a glossary entry yet are defined here.
- SOC (Security Operations Center)
- AI SOC
- MDR (Managed Detection and Response)
- MSSP (Managed Security Service Provider)
- SIEM
- SOAR
- SOC Tier 2
- Alert triage
What is a hybrid SOC model?
A hybrid SOC model is an operating model in which an organization divides security operations work between its internal team and one or more outside providers or platforms, keeping some functions in-house and renting others.
What is a co-managed SIEM?
A co-managed SIEM is an arrangement in which an outside provider handles the engineering and upkeep of a SIEM, such as data onboarding, parsing, and content maintenance, while the customer's analysts use it to investigate and respond.
What is SOC-as-a-Service?
SOC-as-a-Service (SOCaaS) is a fully outsourced model in which a provider delivers detection, investigation, and response around the clock using its own staff and technology.
What is undifferentiated engineering?
Undifferentiated engineering is technical work that every organization in a category must do and that gives none of them an advantage, such as maintaining data source connectors or keeping a platform online.
What is institutional knowledge in a SOC?
Institutional knowledge is the accumulated understanding of an organization's systems, users, business processes, and past incidents that lets analysts tell normal activity from suspicious activity in that specific environment.
What is a RACI structure?
A RACI structure is a chart that assigns who is responsible, accountable, consulted, and informed for each task. In a hybrid SOC, it defines which actions a provider takes alone, which need customer approval, and which stay internal.
What is an evaluation harness?
An evaluation harness is the testing system that checks whether an AI system still produces correct results after a change, such as a model upgrade, by rerunning known cases and comparing the outcomes.



