Managed vs in-house SOC: which model pays off in Switzerland, and when

An in-house 24/7 SOC needs 8,760 hours of cover per seat; at roughly 1,700 productive hours per full-time role, that means at least 5 to 6 roles, plus platform and training. Economically, running your own SOC only pays off with a large environment and a dedicated team, when regulation, data sovereignty or OT proximity demand it.

All

How this compares to neighbouring topics

This page compares operating models. For raw prices see SOC cost Switzerland, for billing models SOC pricing models, for the full economics SOC ROI. For what a SOC does, see What is a SOC.

What an in-house SOC structurally requires

  • At least 5 to 6 full-time roles per 24/7 seat: 8,760 hours divided by roughly 1,700 productive hours per role, before management and cover.
  • A capable platform with licences, storage and operations, whose cost grows with data volume and sources.
  • Playbooks, runbooks and handover processes that are maintained continuously.
  • Ongoing training and replacement when people leave, so knowledge stays in the team.
  • Threat intel feed, detection engineering and regular red team cycles.

Annual cost comparison

Cost blockIn-house SOCManaged SOC
Personnel5 to 6+ full-time roles, calculated with your own payroll costIncluded in the service
PlatformSIEM/XDR licences, storage and operationsIncluded in the service
Training and turnoverOngoing, including replacement when people leaveCarried by the provider
Break-even

Running your own SOC only pays off economically with a large environment and a dedicated team. In smaller environments, in-house structurally pays more for the same capability. See [What a SOC costs](/en/soc/soc-cost-switzerland) for the calculation.

When in-house is still the right answer

  • Very tight data sovereignty (defence, classified environments) with no delegation option.
  • Large OT or production-critical environments that wire the SOC directly into plant processes.
  • Group CISOs with a clear scaling plan and budget for multi-site operations.
  • Existing SOC team that is to be retained and extended with managed extended detection (hybrid).

Hybrid: the frequently overlooked model

A hybrid model is the most pragmatic route for many mid-sized Swiss organisations. Internal analysts provide domain knowledge during business hours. A managed SOC covers nights, weekends and peak load. This reduces turnover risk, keeps context in-house and makes 24/7 coverage affordable.

No wild growth

Hybrid only works with clear handover, shared playbooks and a single alert channel. Two disconnected detection worlds create blind spots exactly where attackers look. If the split should run not by time but functionally per alert type, [Co-Managed SOC](/en/soc/co-managed-soc) is the right model.

Hidden in-house costs that business cases regularly miss

  • Recruitment and turnover: every replacement carries a months-long ramp-up gap.
  • Growing log volume: platform cost rises with it, often without budget reserve.
  • Threat intel, red teaming and external assessments rarely appear in initial business cases but are operationally necessary.

Frequently asked questions

Is in-house safer than managed SOC?

An in-house SOC is not automatically safer. In-house maximises data sovereignty; managed SOC gives access to a larger analyst pool, threat intel from other environments and continuous tuning. Both models can provide strong security or operate poorly.

Why at least 5 to 6 roles for an in-house SOC?

A 24/7 seat covers 8,760 hours per year. After holidays, public holidays, sickness and training, a full-time role delivers roughly 1,700 productive hours. That means at least 5 to 6 roles per seat.

Can we start managed and build in-house later?

Yes, this is a common and workable path. What matters is that playbooks, rules and reports are documented from day one so they remain transferable. See [SOC Onboarding Switzerland](/en/soc/soc-onboarding-switzerland).

What does a clean hybrid model look like in practice?

Internal L1/L2 analysts during business hours handle known alert types; managed SOC handles off-hours, complex cases, threat hunting and reporting. Both teams share an alert channel and ticketing system, with clearly assigned playbooks for each alert type.

When does an in-house SOC pay off economically?

Economically, only with a large environment and a dedicated team. Regulatory or data sovereignty reasons can force in-house in smaller environments too, then as a conscious premium over managed SOC.