Report 02 Oct 2025

Security Operations Center (SOC) – Make Or Buy? – InBrief Analysis

This report is a practical guide to selecting and implementing the right security operations center (SOC) model. It defines SOC value—continuous visibility, rapid detection and response, and measurable risk reduction—and anchors capabilities in frameworks like MITRE ATT&CK. Core building blocks span monitoring, investigation, incident response, automation, and governance with clear KPIs (MTTD, MTTR, dwell time).

Decision-making compares operating models—in-house, on-site provider operations, provider-built/insourced, outsourced MDR/MSSP, co-managed, and Build–Operate–Transfer (BOT)—against control, TCO, time-to-value, sovereignty controls , and resilience, with indicative ramp times and risk mitigations. The report includes a concise vendor landscape covering leading service providers and SOC platforms (SIEM/XDR/SOAR/NDR), balancing global scale and European options.

Europe-specific and country-level regulations—NIS2, GDPR, DORA, LPM(FR)—drive data residency, access locality, retention, and reporting design. Actionable guidance covers RACI, SLAs/OLAs, production-safe pilots, evidence handling, and exit planning to avoid lock-in. Use this guide to select, source, and scale an operating model that fits your risk, budget, and compliance needs—and prove value quickly with transparent metrics and repeatable runbooks.