Security operations is both the most essential capability in a security programme and the most expensive to run well. A 24/7 internal SOC with skilled analysts, tooling, and management overhead can run $3 million to $8 million annually for a mid-market organisation. An MDR service providing equivalent coverage might cost $400,000 to $1.2 million. The gap is real — but so are the differences in what you actually get.
The build vs. buy vs. MDR decision is not a one-time call. As the threat landscape changes, as MDR providers mature, and as internal security talent markets fluctuate, the right model for an organisation in 2026 may not be the right model for the same organisation in 2028. CISOs who treat this as a fixed strategic choice rather than a revisable operational decision tend to overpay for the wrong model.
What “Security Operations” Actually Covers
Before comparing models, clarity on scope matters. Security operations encompasses:
- Detection: SIEM/SOAR, EDR, NDR, cloud security monitoring, alert triage
- Response: Incident investigation, containment, eradication, recovery coordination
- Threat hunting: Proactive hypothesis-driven search for undetected threats
- Vulnerability management operations: Prioritisation, remediation tracking, exception management
- Threat intelligence: Context for detections and hunting, indicator management
Most build vs. buy comparisons focus on detection and response, but the cost picture includes all five. An MDR contract typically covers detection, initial triage, and response coordination — threat hunting coverage varies significantly by provider, and vulnerability management operations are usually excluded.
The Internal SOC Cost Reality
A true 24/7 SOC requires minimum 8-10 analysts to maintain four shifts with redundancy, plus at least one senior analyst or SOC manager per shift. Loaded cost per analyst (salary, benefits, training, attrition replacement) in the UK runs £55,000–£85,000. Add tooling (SIEM licensing runs £150,000–£600,000+ annually depending on data volumes), infrastructure, and management overhead and a mid-market organisation is looking at £2–5 million per year for internal operations alone.
The hidden costs that rarely appear in initial SOC build-out projections:
Analyst attrition. SOC analyst turnover is chronically high — industry estimates range from 30% to 50% annually. Replacement costs (recruiter fees, 3-6 month ramp time, training) typically run 60-100% of the departed analyst’s annual salary. A 10-person SOC with 40% attrition is replacing four people every year.
Alert fatigue and coverage gaps. An undertrained or undersized SOC that is overwhelmed by alert volume produces worse outcomes than a well-configured MDR with proper tuning. The cost of a SOC that is nominally “built” but operationally ineffective is not just the budget spent — it’s the incidents that proceed undetected.
Tool sprawl. Internal SOCs accumulate tools over time. EDR from vendor A, SIEM from vendor B, SOAR from vendor C, NDR from vendor D. Integration costs, training costs, and the operational complexity of maintaining multiple contracts and vendor relationships add up.
The MDR Provider Market in 2026
The MDR market has matured considerably since 2022. The current landscape:
Tier 1 providers (CrowdStrike Falcon Complete, Microsoft Sentinel MDR, SentinelOne Singularity Complete, Palo Alto XMDR) offer platform-integrated MDR built on their own XDR stack. Strengths: deep integration, single platform, fast telemetry. Weaknesses: substantial platform lock-in, pricing tied to seat count and EDR deployment, variable threat hunting quality.
Specialist MDR providers (Arctic Wolf, Expel, Huntress, Sophos MDR) compete on detection quality and analyst availability. Strengths: often better threat hunting, dedicated analyst relationships, flexible tooling. Weaknesses: require integration with your existing stack, may not match platform-native detection speed.
MSSP-evolved MDR (traditional MSSPs transitioning to MDR positioning) are variable. The terminology has blurred — “MDR” from some providers means alert forwarding with a 15-minute SLA; from others it means genuine investigation and active response. Contract SLAs matter more than provider tier.
Key differentiators to evaluate:
| Factor | Questions to ask |
|---|---|
| Threat hunting | Is it included? How frequently? Can you see hunting reports? |
| Response authority | Can they isolate endpoints autonomously, or do they require your approval for every action? |
| Analyst quality | What certifications and tenure do the analysts assigned to your account have? |
| Technology requirements | Must you replace your EDR/SIEM, or do they work with what you have? |
| Data residency | Where is your telemetry stored? Relevant for UK/EU organisations under UK GDPR |
| Escalation SLA | What is the guaranteed time to triage a critical alert at 3 AM? |
A Framework for the Decision
The right model depends on four factors:
1. Threat profile. Organisations in sectors that are actively targeted by sophisticated adversaries — financial services, defence supply chain, critical infrastructure, healthcare — need genuine threat hunting and analyst expertise that many MDR providers do not consistently deliver. An internal SOC or a hybrid model may be the only way to get it.
2. Regulatory environment. Some regulated sectors (financial services under DORA, certain defence contractors) have specific requirements about where security monitoring data resides and who has access to it. These constraints may preclude certain MDR models.
3. Talent access. In markets where experienced security analysts are scarce and expensive, an internal SOC is a permanent hiring and retention problem. MDR providers have an economics-of-scale advantage on talent — they amortise senior analyst cost across many clients.
4. Integration complexity. Organisations with complex, hybrid, or legacy environments may find MDR providers struggle to integrate effectively. A highly customised detection environment built around your specific stack is often better served internally or by a specialist provider with demonstrated expertise in your architecture.
The Hybrid Model
Many mid-enterprise organisations in 2026 are running a hybrid model: MDR for L1 alert triage and initial response, combined with an internal team of three to five analysts for threat hunting, detection engineering, purple teaming, and the high-context investigations that require understanding of your specific environment.
This trades some cost saving (you still have internal headcount) for meaningful control over detection quality, while offloading the most operationally demanding and retention-intensive work (overnight triage) to a provider whose core business it is.
The hybrid model works best when:
- You have a defined internal team responsible for detection engineering (writing and tuning detections, not just consuming alerts)
- The MDR SLA includes genuine active response authority, not just escalation
- You review MDR performance metrics quarterly and retain the right to transition tooling if coverage gaps emerge
Making the Board Case
Security operations cost discussions with boards benefit from a consistent framing: the question is not “how do we spend less on security operations?” but “what detection and response capability does the organisation need, and what is the most cost-effective way to deliver it?”
For a board used to thinking in risk terms, the relevant metrics are:
- Mean time to detect (MTTD) for critical alerts — what is the SLA and what does the data show?
- Mean time to respond (MTTR) — how long from detection to containment?
- Coverage: what percentage of the MITRE ATT&CK matrix relevant to your threat profile do your current detections cover?
- Threat hunting frequency and findings — are hunts producing anything, or are they a checkbox?
These are metrics that translate whether you build or buy. An MDR provider who cannot tell you their MTTD/MTTR performance for your account, or who cannot show you hunt results, should not be paid for MDR.
The Decision Point in 2026
The current inflection in this market is AI-assisted detection. Several MDR providers and SIEM platforms are deploying ML-based alert prioritisation and investigation assistance that materially improves analyst throughput. This changes the cost equation for both internal SOCs and MDR — fewer analysts can cover more ground effectively.
CISOs evaluating either model in 2026 should ask specifically how AI-assisted investigation is being used in the platform or service, what the documented improvement in alert triage time has been, and whether the automation produces explainable outputs that analysts can validate. AI that reduces analyst burden without introducing automation bias is a cost-positive development. AI that speeds up triage but produces confident-sounding wrong answers has a different cost profile.
The decision to build, buy, or hybridise is ultimately a resource allocation choice that should be revisited as the market and your organisation’s threat profile evolve. CISOs who lock in a five-year SOC infrastructure investment without a review trigger are likely to find themselves with the wrong model before the contract expires.