Command Zero
SOC

Build vs. Buy vs. Co-Manage: The Real Cost of an Internal SOC, MDR, and an AI SOC Platform

Every SOC operating model looks affordable at the size it was priced for. Here is the math on in-house, managed, and AI-driven security operations, and the point where each one stops scaling.

James Therrien — avatarJames TherrienSeptember 29, 2026 · 19 min read
Build vs. Buy vs. Co-Manage: The Real Cost of an Internal SOC, MDR, and an AI SOC Platform — cover image

The math most SOC budgets never run

The pricing sheet tells you what a SOC costs this year. It says almost nothing about what that SOC costs when alert volume doubles, a new SaaS estate comes online, or your two best analysts resign in the same quarter.

The big picture: Security leaders choosing how to run detection and response have three realistic options. They can staff an internal 24x7 SOC, hand the work to a managed detection and response (MDR) provider, or put an AI SOC platform in front of a smaller in-house team. Each model gets sold on a cost number. Each of those numbers is accurate for one organization size, one alert volume, and one year. The costs that decide which model wins sit in the scaling curve, and very few buyers model the curve before they sign.

Why it matters: Boards and CFOs now expect security operations to show a unit cost the same way cloud spend does. That pushes SOC leaders toward the lowest year-one number, which is exactly the number least likely to hold. A model priced per endpoint scales with your asset count. A model priced on people scales with your hiring market. A model priced on AI usage scales with alert volume and with how efficiently the platform spends compute. Pick the wrong scaling variable for your environment and the budget breaks in year two, usually while the risk profile is getting worse.

By the numbers:

Put those together and the pressure is clear. People cost more every year and take months to replace, outsourced coverage is priced on assets that keep multiplying, and the newest option is still early enough that its long-run cost curve is unproven.

The reference organization

Cost comparisons fall apart when every vendor picks its own example. So we fixed one. The figures below model a mid-sized enterprise with about 5,000 employees and 5,000 managed endpoints, generating roughly 1,000 alerts a day after tuning and ingesting about 100 GB of security telemetry per day into a SIEM. The alert figure is deliberately conservative. Independent and vendor surveys have put the average between several hundred and more than 4,000 alerts a day, depending on company size and how much tuning has been done.

Assumption

Value used

Source

Tier 1 analyst salary

$102,250

Robert Half 2026, low band

Tier 2 analyst salary

$122,250

Robert Half 2026, midpoint

Tier 3 / senior analyst

$147,750

Robert Half 2026, high band

SOC manager

$144,919

Salary.com, Sept 2026

Detection engineer

$162,895

Glassdoor average total pay

Fully loaded multiplier

1.43x

BLS ECEC, June 2026

Productive hours per FTE

~1,800 / year

Our assumption: 2,080 hours minus ~35 days PTO, holidays, sick, and training

SIEM ingest (100 GB/day)

~$108,000 / year

Public cloud SIEM commitment-tier list price

SOAR / automation budget

~$345,000 / year

Ponemon, 2021 (dated; directional only)

Model 1: The internal 24x7 SOC

The math: A year has 8,760 hours. One full-time employee delivers about 1,800 productive hours once leave, holidays, and training come out. Keeping a single seat filled around the clock therefore takes about 4.9 people. No serious SOC runs one analyst per shift, because a single analyst cannot escalate, take a break, or work two incidents at once. Two seats at all times means roughly 10 analysts.

Add the people who make those analysts effective and the reference team looks like this: six Tier 1 analysts, four Tier 2 analysts, one senior Tier 3 investigator, one SOC manager, and one detection engineer. Thirteen people.

Line item

Annual cost

13 salaries (base)

$1,558,064

Fully loaded at 1.43x

$2,225,806

SIEM ingest, 100 GB/day

$108,040

SOAR and automation (directional)

$345,000

Estimated total

~$2.7 million per year

That lands close to the $2.86 million average annual in-house SOC cost Ponemon reported in 2020, which suggests salary growth and cheaper per-GB ingest have roughly offset each other since then. It also excludes EDR, identity, and email security licensing, which an organization pays for under all three models.

The capacity check: Two seats around the clock yields 48 analyst-hours a day. Spread across 1,000 alerts, that is under three minutes per alert before anyone opens a real investigation. If only 10% of those alerts need a proper look, and a proper look takes about 75 minutes, the team needs 125 hours of investigation time per day. It has 48. The gap gets closed the way it always does: with skimming, with suppression rules, and with alerts that never get opened.

Where it breaks at scale:

  • Headcount scales linearly, and hiring is slow. Doubling alert volume to 2,000 a day means adding two more round-the-clock seats, about 10 more people and roughly $1.6 million a year at a blended loaded cost of $160,000 per analyst. Each hire takes three to six months to land and more time to ramp.
  • Attrition quietly cuts capacity. Assume three of ten analysts leave in a year and each seat takes about seven months to refill and train, which matches earlier Ponemon research on SOC hiring. That is almost two analyst-years of lost capacity. A 10-analyst SOC runs like an 8-analyst SOC while still paying for 10.
  • Expertise stays concentrated in a few people. Complex investigations depend on the senior analysts who know the environment. When one of them leaves, the institutional knowledge leaves too.

The internal model wins on context and control. It loses on elasticity. It is the most expensive way to add capacity quickly and the slowest way to recover from turnover.

Model 2: Managed detection and response

The math: At $8 to $35 per endpoint per month, MDR for 5,000 endpoints runs $480,000 to $2.1 million a year. The spread is wide because the low end usually buys alert-only coverage on endpoints, and the high end buys active containment across more of the attack surface.

MDR does not remove the internal team. Someone has to receive escalations, provide business context, approve containment, remediate, and own the relationship. For the reference organization, a lean retained team of three Tier 2 analysts is a reasonable floor.

Line item

Annual cost

MDR service, 5,000 endpoints

$480,000 to $2,100,000

Retained team, 3 Tier 2 analysts, loaded

$523,929

SIEM ingest, 100 GB/day (if retained in-house)

$108,040

Estimated total

~$1.1 million to $2.7 million per year

At the low end, MDR costs well under half of an internal SOC. At the high end, once cloud, identity, and SaaS coverage are added, it approaches the same number.

Where it breaks at scale:

  • Pricing follows assets, while the threat is moving elsewhere. Every new endpoint, workload, and identity adds to the bill. Coverage for cloud, identity, and SaaS is frequently a separate SKU, and Gartner's 2026 Market Guide for MDR calls SaaS coverage "a key differentiator," as summarized by one MDR provider. Identity weaknesses played a role in nearly 90% of the incidents Unit 42 investigated, per its 2026 Global Incident Response Report.
  • Escalations come home. The hardest investigations, the ambiguous ones that need environment knowledge, get handed back to the customer. The retained team absorbs that work on the MDR's timeline, which is why it rarely shrinks as much as the business case assumed.
  • Expertise accrues to the provider. Detection logic, tuning decisions, and investigative instincts developed on your incidents belong to the provider's analysts. If you leave, you start over.
  • The service underneath is changing. Gartner expects that by 2029, 90% of initial MDR findings will be processed with AI support and without human action, up from 30% today. Buyers are increasingly paying a services margin on top of automated first-pass work, and Gartner advises them to "demand clarity regarding which services are AI-augmented."

Model 3: An AI SOC platform with a retained team

The math: An AI SOC platform takes over first-pass triage and investigation around the clock, so the human team no longer has to be sized for 24x7 shift coverage. It gets sized for judgment: the escalations, the hunts, the detection engineering, and oversight of what the machine concludes. For the reference organization, that is two Tier 2 analysts, one senior investigator, one detection engineer, and one SOC manager, with an on-call rotation for after-hours escalations.

Line item

Annual cost

Retained team of 5, loaded

$1,000,091

SIEM ingest, 100 GB/day

$108,040

Platform subscription

Vendor-quoted; get years 2 and 3 in writing

Estimated total

~$1.1 million plus platform

We left the platform line open on purpose. Vendors price by alert volume, by data volume, by endpoint, or by token consumption, and Gartner's guidance on evaluating AI SOC agents tells buyers to understand "how costs behave under load," as reported by BleepingComputer. That phrase is the whole ballgame for this model.

The compute underneath: Published benchmarks from security vendors put the raw model inference cost of a single AI investigation between roughly $0.70 and $3.80, depending mostly on architecture. One SIEM vendor's research team measured a 5.7x cost difference between two agent designs running the same investigations on the same model. At 1,000 alerts a day, full investigation of every alert at $1 to $3 each is $365,000 to $1.1 million a year in inference alone. At 4,000 alerts a day, it is $1.5 million to $4.4 million. Whether a platform absorbs that cost, passes it through, or avoids it with a more efficient design determines what you pay in year three.

This is where the architecture question becomes a finance question. A system that streams raw logs into a model and asks it to find the problem spends tokens in proportion to data volume. A system that decides which questions to ask first, and pulls only the evidence needed to answer them, spends tokens in proportion to the investigation. We wrote about the gap in The Hidden Cost of DIY Security Investigation Agents. It is the single biggest variable in whether an AI SOC stays cheaper as volume grows.

Where it breaks at scale:

  • Usage-based pricing can outrun headcount savings. If the platform charges per alert or per token and alert volume doubles, the bill doubles. That can erase the savings from a smaller team if nobody modeled it up front.
  • Verification is a real cost. A machine verdict needs to be checked. Sampling closed cases for accuracy, tracking escapes, and reviewing escalations all consume senior analyst hours, as we covered in Why MTTD and MTTR Are No Longer the Whole Story. A platform that cannot show its reasoning makes that review expensive.
  • Data access limits the investigation. An AI system can only reason over the sources it can query. Gaps in identity, SaaS, or cloud coverage produce confident verdicts on partial evidence.
  • The talent pipeline still needs feeding. Cutting Tier 1 entirely saves money now and creates a senior-analyst shortage later. The retained team has to include people who are learning the environment.
  • Building it yourself changes the math again. A custom AI SOC removes the subscription and adds permanent engineering, evaluation, and maintenance costs. We covered where that trade works in Yes, Build Your Own AI SOC.

The three models side by side


Internal 24x7 SOC

MDR + retained team

AI SOC platform + retained team

Est. annual cost (reference org)

~$2.7M

~$1.1M to $2.7M

~$1.1M + platform

Cost scales with

Headcount and the hiring market

Endpoints, users, and add-on SKUs

Alert volume and platform efficiency

Adding capacity

Slow: 3 to 6 months per hire

Fast, at contract terms

Fast, if pricing holds under load

Investigation depth

High, limited by hours available

Varies; hard cases return to you

High, if the platform reaches the data

Who keeps the expertise

You, until people leave

The provider

You, if reasoning is transparent and reviewable

Breaks first when

Volume doubles or seniors resign

Attack surface shifts to cloud, identity, SaaS

Usage pricing outruns savings, or verdicts go unchecked

What industry experts are saying

Command Zero cofounder and CPO Alfred Huger has been direct that the cost case for AI SOC is still being proven. "It is an unproven statement that AI SOC will end up being cheaper than MDR and MSSPs over time," he told CYBR.SEC.Media. His advice to buyers is to force the pricing curve into the open: "Your vendor should be able to give you clear, transparent models on how they do their pricing and a commitment for at least year two and three on their increase in pricing." He also argues the comparison is meaningless without a starting point. "You won't be able to measure how well your AI SOC vendor does for you if you don't truly know what your existing baselines are."

Command Zero cofounder and CTO Dean De Beer traces the MDR tradeoff back to its economic design. In his research paper The Recomposition of Security Work, he writes that with MDR "the economics were structurally identical to MSSP. Organizations traded internal headcount for vendor coverage." The cost of that trade shows up in context: "MSSP analysts see the surface of many environments and the interior of none." He warns the same pattern can repeat with AI: "The economics of AI deployment in security produce efficiency savings immediately and pipeline costs five to seven years later."

Command Zero cofounder and CEO Dov Yoran has made the same point about headcount. "You'll certainly still need those Tier 2 and 3 [analysts] that have the experience," he told CRN. "Where are those going to come from, if you all of a sudden kill your Tier 1 footprint?" He frames the payoff as capacity: "We can now cover more ground with that same team."

Eric Hulse, who leads research at Command Zero, has watched the escalation handoff play out in customer environments."When an MDR escalates, what usually lands on the internal team is the alert and a paragraph of context. The investigation still has to happen, and it happens on your clock with your people. That work is the line item that never shows up in the MDR quote." On the build path, he has written that "the failure mode that kills more AI SOC projects than any technical challenge is the 'hero developer' problem," in The AI SOC Prototype Trap.

Gartner's 2026 Market Guide for MDR describes the service model buyers should expect as "human-led, AI-augmented," as summarized by Expel, and recommends MDR for 24/7 capability "when there are no existing internal capabilities." Separately, Gartner analysts Craig Lawson and Andrew Davies predict that by 2028, 70% of large SOCs will pilot AI agents to augment Tier 1 and Tier 2 work, but only 15% will see measurable improvement without structured evaluation, per Help Net Security.

The limits of the math

Between the lines: Every figure above rests on assumptions that will not match your environment exactly. Salary data varies widely by region and by how "SOC analyst" is defined, and no independent source cleanly separates Tier 1, 2, and 3 pay. The best total-SOC-cost studies are several years old. MDR pricing is rarely published, so the ranges here come from a directory that aggregates public and vendor data. AI inference benchmarks come from vendors with a stake in the answer. Gartner's MDR and AI SOC research is gated, so several of the figures cited here arrive secondhand.

The model also leaves out the cost that matters most: the breach you did not catch. A cheaper SOC that misses an intrusion is the most expensive option on the list. With attackers reaching data exfiltration in 72 minutes in the fastest quarter of intrusions Unit 42 investigated, and average eCrime breakout time down to 29 minutes, per CrowdStrike's 2026 Global Threat Report, investigation speed and depth carry a price that no annual budget line captures.

The bottom line: No SOC model is cheapest at every scale. The internal SOC buys control and context and pays for it in hiring risk. MDR buys coverage and pays for it in context and escalation work that returns to your team. An AI SOC platform buys elastic investigation capacity, and its cost depends on pricing that holds under load and an architecture that spends compute on targeted questions. Before comparing quotes, model each option at today's volume, at double today's volume, and after losing two senior analysts. The option that still works in all three scenarios is the one worth budgeting for.

Terms in this post

Terms defined in Command Zero's glossary are linked below. Terms without a glossary entry yet are defined here.

What is a fully loaded cost?

A fully loaded cost is an employee's base salary plus the employer-paid benefits, payroll taxes, and related compensation costs. U.S. private employers pay about 1.43 times base wages on average, before facilities, tools, and training.

What is 24x7 coverage math?

24x7 coverage math is the calculation of how many full-time employees it takes to keep one position staffed around the clock. With 8,760 hours in a year and roughly 1,800 productive hours per employee, one continuously staffed seat requires about 4.9 people.

What is a co-managed SOC?

A co-managed SOC is an operating model where an internal security team and an outside provider or platform share detection, investigation, and response duties, with defined handoffs for escalation and remediation.

What is per-endpoint pricing?

Per-endpoint pricing is a billing model, common in MDR, where the provider charges a monthly fee for each protected device, so total cost rises with the number of endpoints regardless of alert volume or incident complexity.

What is inference cost?

Inference cost is the compute expense of running an AI model to produce an output. In an AI SOC, it is driven by how many tokens the system processes per investigation, which depends heavily on how the investigation is architected.

What is a retained team?

A retained team is the internal security staff an organization keeps after outsourcing or automating part of its SOC, responsible for escalations, context, remediation decisions, and oversight.

Keep reading

More from SOC.

Get Started

See what your team can achieve.

Live in under an hour. No migration. No friction.

Book a Demo
No training data requiredSOC 2 CompliantDirect-to-data