Most cybersecurity content aimed at organizations assumes the answer to a question that was never asked: should this capability exist inside the company at all?
Job postings, certification paths, and salary guides all point in one direction, toward hiring. That is the right answer for some organizations and a genuinely expensive mistake for others. A company that hires two analysts and believes it now has a security operations capability has purchased something considerably narrower than it thinks.
This article works through the actual decision. Not which vendor, not which certification, but whether the capability belongs inside, outside, or split between the two, and what the arithmetic looks like in each case.
Why This Decision Gets Made Badly
Three patterns account for most poor outcomes.
- The decision gets made after a scare. An incident, an audit finding, or a customer questionnaire creates urgency, and urgency produces hiring because hiring feels like control. The role gets posted before anyone has defined what the person will actually do at 3am on a Saturday.
- Headcount is compared against license cost. An analyst salary gets weighed against a managed service quote, and the salary looks competitive. It is not a fair comparison, because one number is a fully loaded operational capability and the other is one person’s base pay before benefits, tooling, training, recruiting, and the coverage gaps that person cannot fill alone.
- Nobody separates the functions. Security is not one job. Monitoring, incident response, vulnerability management, architecture, governance, compliance, and awareness training are distinct disciplines with different staffing economics. Deciding to build or buy all of them together guarantees a wrong answer for at least some of them.
The Real Cost of 24/7 Coverage
This is the number that reframes the conversation.
Continuous monitoring means someone is watching every hour of every day. There are 168 hours in a week. A full-time employee covers roughly 40, and that is before accounting for vacation, sick leave, training, statutory holidays, and turnover.
Covering 168 hours with reasonable shift structure, handover, and coverage for absence takes somewhere between five and eight people depending on how you organize it. Not two. Not three. Five to eight, minimum, and that is for monitoring alone. It does not include the people doing vulnerability management, engineering, or response.
Now add the costs that never appear in the headcount request:
- Recruiting and turnover. Security analyst turnover runs high, and each replacement carries recruiting cost plus a ramp period during which coverage is degraded.
- Tooling. A SIEM, log retention, threat intelligence feeds, and the engineering time to tune all of it. Tuning is not a one-time task; a poorly maintained SIEM produces alert fatigue within months.
- Training and certification. Keeping analysts current is not optional in this field, and it removes them from the rotation while they do it.
- Management overhead. A team of six needs a manager, and that person is not watching alerts.
The result is that genuine 24/7 in-house monitoring is a seven-figure annual commitment for most organizations before the first alert is triaged. That is not an argument against doing it. It is an argument for knowing the number before committing.
Why Small Teams Cannot Cover an On-Call Rotation
A common compromise is business-hours staffing with an on-call rotation covering nights and weekends. It sounds reasonable and it fails predictably.
With three people, each is on call one week in three. That is roughly 17 weeks a year of carrying a phone, and it compounds with their day job rather than replacing it. Someone paged at 2am is still expected at the 9am standup.
When one person leaves, the rotation becomes one week in two, which is unsustainable, which accelerates the next departure. Small security teams do not decay gradually. They collapse, because the rotation math turns hostile the moment it loses a person.
There is a second problem. On-call assumes the person paged can resolve what they find. A generalist analyst woken at 2am facing suspected ransomware needs forensic capability, malware analysis, and containment authority. Very few three-person teams have all three, which means the escalation goes to a vendor anyway, at emergency rates, without a prior relationship.
The Skills Problem Nobody Budgets For
Certain security disciplines are needed rarely and required urgently.
Digital forensics, malware reverse engineering, ransomware negotiation, and legally defensible evidence handling fall into this category. An organization might need them once every three years. Staffing them full-time means paying a specialist to do unrelated work for thirty-five months and the job they were hired for in the thirty-sixth.
Almost nobody does this, and correctly so. But the alternative requires acknowledgment: if these capabilities are not staffed internally, they have to be arranged externally in advance. Sourcing them during an active incident means competing for scarce responders at the worst possible moment, on emergency terms, with a firm that has never seen your environment.
Retained access to cyber security services solves that specific problem cleanly. The commercial terms, scope, response commitment, and escalation contacts get settled while nothing is on fire, and the provider builds familiarity with the environment before they need it. Most arrangements also allow unused hours to be applied toward assessments, architecture review, or tabletop facilitation, which means the spend is not stranded in a quiet year. The evaluation criteria that matter are the response time commitment and what triggers it, whether the scope covers forensic and legal support or only initial triage, and whether the provider can demonstrate experience in environments comparable to yours.
Where Co-Managed Models Fit
The framing of build versus buy is misleading because the most common successful arrangement is neither.
In a co-managed model, the external provider handles continuous monitoring, initial triage, and after-hours coverage. The internal team owns context, decision authority, architecture, and the relationships that make remediation actually happen.
That split works because it assigns each side what it is genuinely better at. A provider watching thousands of environments sees attack patterns before any single organization does, and can staff a rotation across many clients that no individual client could staff alone. An internal team knows which server the finance close runs on, which vendor has legitimate remote access, and who can authorize taking production offline at midnight.
Pure outsourcing fails when there is nobody internal who understands the environment well enough to receive an escalation. Pure in-house fails when the coverage math does not work. Co-managed addresses both, provided the boundary is documented clearly enough that neither side assumes the other is handling something.
How the Math Changes by Organization Size
- Under roughly 200 employees. In-house security operations are almost never justifiable. The right structure is typically one internal owner who understands the business and manages vendors, with monitoring, response, and specialist work sourced externally. Attempting a SOC at this scale produces a very expensive single point of failure.
- Roughly 200 to 2,000 employees. This is where co-managed makes the most sense and where most organizations get it wrong in one of two directions. Some hire two or three people and call it a security team, then discover the coverage gap during the first real incident. Others outsource everything and have nobody internal capable of making a decision when the provider escalates. The workable answer is a small internal team focused on architecture, risk, and vendor management, with operations sourced externally.
- Above roughly 2,000 employees. In-house operations become viable, though rarely optimal in isolation. Even large organizations commonly retain external capability for specialist disciplines and surge capacity. Scale makes building possible; it does not make building complete.
Two factors override headcount entirely. Regulatory environments that mandate specific controls or data handling can force capability inside regardless of size. And organizations whose product is itself technology often already have the engineering culture to absorb security operations more efficiently than their headcount would suggest.
What to Keep In-House Regardless
Some functions do not outsource well at any size.
Risk decisions belong internally, because accepting risk on behalf of the business is a business function. No provider can decide how much exposure the organization tolerates.
Business context belongs internally. Which systems matter, which data is sensitive, which downtime is survivable, who to call. A provider can learn some of this and never all of it.
Vendor management belongs internally. Someone has to hold the provider accountable to the contract, review the reporting, and notice when service quality drifts.
Security culture belongs internally. Awareness, secure development practice, and the relationships that get remediation prioritized all depend on people who work there.
Making the Decision
A workable process runs in this order.
First, list the security functions separately rather than treating security as one thing. Monitoring, response, vulnerability management, architecture, governance, compliance, awareness. Each gets its own answer.
Second, calculate honest coverage requirements for each. If a function needs continuous availability, apply the 168-hour math rather than assuming an on-call rotation covers it.
Third, identify what genuinely requires internal context and what does not. Alert triage rarely does. Deciding to shut down production always does.
Fourth, price the internal option fully. Salary, benefits, recruiting, tooling, training, management, and the cost of the coverage gap during turnover. Compare that number to the external quote, not the base salary alone.
Fifth, revisit annually. The answer changes with growth, with regulatory shifts, and with turnover. An arrangement that fit at 300 employees frequently does not fit at 900.
Conclusion
The security industry has spent a decade telling organizations to hire, and the career content reflects that. It is sound advice for individuals and incomplete advice for the companies doing the hiring.
The organizations that get this right stop asking whether to build or buy and start asking, function by function, what coverage each one requires and where the context to act on it actually lives. That usually produces a split rather than a clean answer, and the split is the point.
Two analysts and a SIEM is not a security operations capability. Recognizing that early is considerably cheaper than discovering it at 2am.

