August 27, 2026

How MSPs answer the “why not just hire someone” question

building vs. buying a SOC

Estimated reading time: 5 minutes

Every MSP gets this question eventually, usually from a client who just saw a security quote and did some quick mental math. Why not just hire someone? It sounds like a fair alternative. It’s also a question with a real, calculable answer, and once you walk through it, it rarely favors building anything in-house.

Two things are pushing clients to ask about it more often. Commercially, security line items have gotten bigger and more visible on renewal invoices, and a client staring at that number naturally starts pricing alternatives; one hire feels cheaper than a managed contract until you run the actual math. Operationally, the threat landscape has made “we’ll just keep an eye on it” a much riskier answer than it used to be: 6,604 ransomware attacks were recorded in 2025, up 52% year over year, and 297 supply chain attacks, up 93%. Clients are more aware of the stakes and more willing to ask hard questions about their coverage.

The instinct is to think one good analyst solves the problem. It doesn’t, and the reason is arithmetic, not opinion. A year has 8,760 hours. Nobody works all of them. Once you account for shift rotation, PTO, sick time, and the training time that pulls someone off the floor entirely, covering a single seat around the clock takes real redundancy, not one hire, which is exactly what managed SOC services are built to provide.

That redundancy is where the real number comes from. Staffing a security operations center to industry standard runs upwards of $1.3M a year in salary alone, before tools, benefits, or overhead. That figure isn’t a vendor estimate. It’s built from two independent, vendor-neutral sources: SANS’s 2025 SOC Survey, which puts a typical SOC team at 10 full-time analysts, and the U.S. Bureau of Labor Statistics’ May 2025 data (the most current release available), which puts the median salary for an information security analyst at $132,510. Ten analysts times that median salary is $1,325,100.

For an MSP specifically, that number doesn’t shrink as the book of business grows. A team sized for ten clients is roughly the same team sized for two hundred, until it isn’t, and then you’re hiring again.

Once you lay the numbers out, the case stops being about opinion and starts being about arithmetic:

The $1.3M+ figure is salary only. Add tooling, benefits, and management overhead, and the real number climbs further; this is a floor, not a ceiling.

The cost is fixed, not variable. An in-house team’s cost doesn’t move with client count until it hits a hiring wall; then it jumps.

Managed security spreads the same cost across an entire book instead of one client’s balance sheet, the same principle a co-managed SOC runs on for MSPs that already have some internal capability.

None of this is a discount. It’s a different cost structure, and it’s the reason the math almost never favors building it yourself once you’re honest about what building it yourself actually requires.

For the MSP making this case to a client, three things carry the argument:

Margin holds as the book grows. A managed model doesn’t force a hiring decision every time the client count crosses a threshold.

The evidence trail is already built. Compliance and Governance Services produce standardized reporting so you’re not assembling audit or QBR documentation from scratch

The client’s alternative is a real number, not a guess. Once they see $1.3M+ next to a managed quote, “just hire someone” no longer sounds like the cheaper option.

If a client (or you) is seriously weighing build versus buy, three questions settle it fast: What does true 24/7 coverage actually require in headcount, not just one hire? What’s the fully loaded cost once benefits and tooling are added to salary? And what happens to that cost structure as the client base grows, does it stay fixed while revenue scales, or does it jump every time you cross a staffing threshold?

The $1.3M+ number isn’t meant to be a scare tactic; it’s what the honest math says building real 24/7 coverage costs. Most MSPs land on the same conclusion once they see it laid out: buying spreads that cost instead of carrying it alone. See where your own numbers land.

Run your own numbers against your actual client count and current spend with the cybersecurity ROI calculator; it’s built around this exact math.


Frequently Asked Questions

What does it actually cost to build an in-house SOC?

Upwards of $1.3M a year in salary alone, based on a typical 10-analyst team (SANS 2025 SOC Survey) at the median information security analyst salary of $132,510 (BLS, May 2025). That’s before tools, benefits, or overhead.

Why can’t one analyst cover security around the clock?

A year has 8,760 hours and no one person works all of them. Shift rotation, PTO, and training time mean real 24/7 coverage takes a team, not a hire.

Does the cost of an in-house SOC scale with client count?

No, and that’s the problem. The cost stays roughly fixed until you hit a staffing wall, then it jumps. Managed security spreads that same cost across an entire book instead.

Is $1.3M the fully loaded cost of an in-house SOC?

No, it’s salary only. Add tooling, benefits, and management overhead and the real number is higher. Treat $1.3M+ as a floor.

CONTENTS

Related Articles