SOCaaS
SOC as a Service (SOCaaS) is a SOC operated by an external provider and delivered as an ongoing service.
SOC as a Service (SOCaaS) is a SOC run by an external provider and delivered as a continuous service. The organisation receives monitoring, detection and response without building its own round-the-clock team.
How it works
The provider connects to existing log sources, such as Microsoft 365, EDR, firewalls and cloud services. They then handle triage, investigation, and agreed-upon response actions. The client receives Cases with evidence and recommendations, along with regular reports on key metrics.
For example, an insurance company with 800 employees has two in-house security specialists. They cover office hours but not nights. With SOCaaS, monitoring runs continuously, and the internal team can focus on architecture and projects.
What to look out for
- Mandate: What containment actions can the provider perform independently, and which require your approval?
- Scope of response: Clarify what is included for a major incident and what is billed separately.
- Data location: Where are logs stored and processed?
- Contract term and exit: Who owns detection rules and data after the contract ends?
- Reporting: Do you receive key metrics that senior management can also understand?
Switzerland and regulation
When outsourcing to a service provider, financial institutions must follow FINMA circular 2018/3 on outsourcing. For personal data in logs, the revFADP (revised Federal Act on Data Protection) is decisive, especially for cross-border processing.
Typical mistakes
SOCaaS is often compared solely on price. However, offerings differ mainly in their mandate and scope of coverage. A cheap offer that only forwards Alerts shifts the work back to your own team. A second mistake is a brief onboarding process without baselining. This creates a lot of noise in the first few months, reducing trust in the service. Plan several weeks for onboarding and set goals for the first 90 days.
How we implement it
Our SOCaaS is priced as an annual Flat Fee, based on the number of endpoints. Response within the agreed mandate is included, while major incident response is billed separately.