Managed vs in-house SOC: which model pays off in Switzerland, and when
An in-house 24/7 SOC needs 8,760 hours of cover per seat; at roughly 1,700 productive hours per full-time role, that means at least 5 to 6 roles, plus platform and training. Economically, running your own SOC only pays off with a large environment and a dedicated team, when regulation, data sovereignty or OT proximity demand it.
How this compares to neighbouring topics
This page compares operating models. For raw prices see SOC cost Switzerland, for billing models SOC pricing models, for the full economics SOC ROI. For what a SOC does, see What is a SOC.
What an in-house SOC structurally requires
- At least 5 to 6 full-time roles per 24/7 seat: 8,760 hours divided by roughly 1,700 productive hours per role, before management and cover.
- A capable platform with licences, storage and operations, whose cost grows with data volume and sources.
- Playbooks, runbooks and handover processes that are maintained continuously.
- Ongoing training and replacement when people leave, so knowledge stays in the team.
- Threat intel feed, detection engineering and regular red team cycles.
Annual cost comparison
| Cost block | In-house SOC | Managed SOC |
|---|---|---|
| Personnel | 5 to 6+ full-time roles, calculated with your own payroll cost | Included in the service |
| Platform | SIEM/XDR licences, storage and operations | Included in the service |
| Training and turnover | Ongoing, including replacement when people leave | Carried by the provider |
Running your own SOC only pays off economically with a large environment and a dedicated team. In smaller environments, in-house structurally pays more for the same capability. See [What a SOC costs](/en/soc/soc-cost-switzerland) for the calculation.
When in-house is still the right answer
- Very tight data sovereignty (defence, classified environments) with no delegation option.
- Large OT or production-critical environments that wire the SOC directly into plant processes.
- Group CISOs with a clear scaling plan and budget for multi-site operations.
- Existing SOC team that is to be retained and extended with managed extended detection (hybrid).
Hybrid: the frequently overlooked model
A hybrid model is the most pragmatic route for many mid-sized Swiss organisations. Internal analysts provide domain knowledge during business hours. A managed SOC covers nights, weekends and peak load. This reduces turnover risk, keeps context in-house and makes 24/7 coverage affordable.
Hybrid only works with clear handover, shared playbooks and a single alert channel. Two disconnected detection worlds create blind spots exactly where attackers look. If the split should run not by time but functionally per alert type, [Co-Managed SOC](/en/soc/co-managed-soc) is the right model.
Placement in SOC operations
See SOC as a Service Switzerland for details of the managed operating model.
Frequently asked questions
Is in-house safer than managed SOC?
An in-house SOC is not automatically safer. In-house maximises data sovereignty; managed SOC gives access to a larger analyst pool, threat intel from other environments and continuous tuning. Both models can provide strong security or operate poorly.
Why at least 5 to 6 roles for an in-house SOC?
A 24/7 seat covers 8,760 hours per year. After holidays, public holidays, sickness and training, a full-time role delivers roughly 1,700 productive hours. That means at least 5 to 6 roles per seat.
Can we start managed and build in-house later?
Yes, this is a common and workable path. What matters is that playbooks, rules and reports are documented from day one so they remain transferable. See [SOC Onboarding Switzerland](/en/soc/soc-onboarding-switzerland).
What does a clean hybrid model look like in practice?
Internal L1/L2 analysts during business hours handle known alert types; managed SOC handles off-hours, complex cases, threat hunting and reporting. Both teams share an alert channel and ticketing system, with clearly assigned playbooks for each alert type.
When does an in-house SOC pay off economically?
Economically, only with a large environment and a dedicated team. Regulatory or data sovereignty reasons can force in-house in smaller environments too, then as a conscious premium over managed SOC.
Related terms
- SOCaaS SOC as a Service (SOCaaS) is a SOC operated by an external provider and delivered as an ongoing service.
- SOC A Security Operations Center (SOC) is the team that constantly monitors an organisation's IT for attacks and intervenes during incidents.
- MSSP A Managed Security Service Provider (MSSP) operates specific security services for its clients, such as firewalls or monitoring.
- Tier-less SOC A Tier-less SOC is a model that operates without the traditional T1, T2, and T3 analyst hierarchy.