Security Operations · Buyer Guide

How to evaluate a managed SOC provider

Look beyond dashboards and alert volume. Test the provider's ability to build context, engineer detections, investigate, escalate and improve.

13 August 20267-minute readSOC procurement

1. Define the outcome before the procurement

State the systems, identities, cloud services and business processes requiring coverage. Define operating hours, incident authority, evidence needs, regulatory constraints and the internal roles that remain accountable.

2. Test onboarding and context

  • How are log sources prioritised and validated?
  • Who maintains asset criticality, identity context and change information?
  • What happens when logs stop or fields change?
  • How is coverage measured beyond the number of connected sources?

3. Examine detection engineering

Ask for the lifecycle: hypothesis, required telemetry, rule development, testing, tuning, deployment, quality review and retirement. Determine which detections are included, which require extra work and how customer-specific threats influence the roadmap.

4. Walk through an investigation

Use a realistic scenario and ask who validates the alert, enriches it, contacts the customer, preserves evidence, recommends containment and closes the record. Service levels should distinguish acknowledgement, investigation and actionable escalation.

5. Clarify response authority

A provider cannot contain an incident safely without agreed authority and access. Define pre-authorised actions, approval channels, emergency contacts and cases that must remain with the customer's incident commander.

6. Review data and assurance

  • Where are logs, cases and evidence processed and stored?
  • Who can access customer data and how is privileged activity reviewed?
  • What retention, deletion, subcontracting and incident commitments apply?
  • What independent assurance is relevant to the actual service scope?

7. Plan transition and exit

Confirm ownership and portability of rules, parsers, playbooks, cases and data. Define transition assistance, deletion evidence and continuity if the platform or provider changes.

Score what matters

Weight technical capability, operating accountability, response integration, data governance, evidence quality, transparency, resilience and total cost. A low monitoring price can be expensive if the internal team must perform all investigation and engineering.