

In a joint advisory, CISA and the FBI reported that the actors behind Gunra ransomware run their reconnaissance and internal movement between 10:00 p.m. and 6:00 a.m., timed that way specifically to avoid being noticed by administrators. Once encryption lands, victims get five to seven days to negotiate before their data goes up for publication.
The overnight scheduling is the tactic, and it works because of how most managed service providers operate. Tickets get triaged in the morning. Alerts stack up in a console overnight. The weekend page goes to whoever is on call, and that person may not have enough context to tell a noisy false positive from the opening move of a ransomware deployment.
A 24/7 SOC for MSPs is what closes the gap, and closing it takes people watching the console at 3:00 a.m. on a Sunday who understand what they are looking at. Below is what a security operations center does hour by hour, why building one in-house rarely works for an MSP, and how a managed SOC service changes what you can honestly promise a client.
A security operations center is a function more than a place. Strip away the wall of monitors you see in the stock photography and you are left with four disciplines that run continuously.
The first two are mostly engineering work. The last two are why the phrase “analyst-led SOC” carries weight, and why an alert pipeline with nobody attached to it is better described as a monitoring product.
The gap between a SOC and a 24/7 SOC comes down to staffing, and the arithmetic is unforgiving.
A week contains 168 hours and a full-time analyst covers roughly 40 of them, so keeping one qualified person in the seat at all times takes about 4.2 full-time employees before anybody books a vacation or quits. Most SOCs want a second set of eyes overnight, which doubles it. The SANS 2025 SOC Survey puts roughly 10 full-time equivalents at the baseline for a functioning SOC, and found 79% of them already running around the clock.
Then comes payroll. The Bureau of Labor Statistics put the median wage for information security analysts at $132,510 in its May 2025 figures, across an occupation employing about 190,650 people. Ten analysts at the median runs roughly $1.33 million in salary alone, before benefits, before tooling, and before you hire anyone to manage the team.
Finding those ten is its own problem. Staffing ranked as the top operational challenge in the 2026 SANS SOC Survey, which also recorded a 27-point gap between leaders who say management pays close attention to SOC hiring and the practitioners who agree.
That expense is defensible because attackers deliberately go after the hours when coverage disappears. The Gunra advisory describes a pattern similar across multiple such advisories: reconnaissance and lateral movement scheduled for the middle of the night, when the people who would recognize it are asleep. Adversaries have read the same staffing guides you have, and they know when the lights go out.
For a 40-person accounting firm or a regional manufacturer, “24/7 SOC” translates into something specific and fairly unglamorous. If credentials get compromised at 11:00 p.m. on a Friday, somebody qualified sees it, decides what it is, and stops it before Monday.
That is the entire value proposition. The dashboard nobody logs into and the monthly report they skim are packaging around one person who is awake and authorized to act while the business sleeps.
Smaller companies get attacked plenty. Verizon’s 2026 Data Breach Investigations Report examined 22,000 confirmed breaches across 145 countries and found ransomware in 48% of them, at a median ransom of $139,875. What smaller companies lack is defense, which is a different problem, and it happens to be the one an MSP is positioned to solve.
Inside a Shift: How a Detection Becomes a Contained Incident
Phrases like “threat monitoring and incident response” hide what the work looks like in practice. Here is a composite of a fairly routine night.
Twenty-six minutes from detection to action. Without a 24/7 SOC, the outcome is vastly different.
The alert sits in a console until somebody notices it Monday at 9:00. Sixty hours of unmonitored mailbox access have gone by, the attacker has had two full business days to study the invoice thread, and your conversation with the client has moved from detection to explaining a fraudulent wire transfer. The FBI’s Internet Crime Complaint Center logged 24,768 business email compromise complaints in 2025 and $3.05 billion in associated losses, so that conversation happens more often than anyone would like.
Most MSP owners reach the same conclusion once they run the numbers.
None of this means an MSP cannot run security operations well. It does mean owning the whole stack is a capital-intensive business with margins that look nothing like managed services, and most MSPs come out ahead buying the capability instead of manufacturing it.
A managed SOC service, often sold as SOC as a service, puts an external analyst team behind your clients’ telemetry while you keep the relationship, the remediation work, and the account.
Plenty of buyers have already reached this conclusion. MarketsandMarkets sized SOC as a service at $7.37 billion in 2024 with a path to $14.66 billion by 2030, a 12.2% CAGR, and expects small and midsize enterprises to be the fastest-growing segment in that forecast, precisely because they face serious exposure without the in-house resources to answer it.
The operating model usually looks like this.
Some MSPs want their own engineers in the console, writing detections alongside the provider’s team. Others want a closed loop where they only ever see escalations. The choice comes down to whether you have security staff you want to develop or a service line you want to run without adding headcount. Ask which model a provider supports before you get deep into pricing, because retrofitting co-management onto a black-box service rarely goes well.
Co-managed makes sense when you already have a security-minded engineer or two and want them closer to the detection work. Your team gets console access, contributes tuning and detection logic for the environments they know best, and shares containment duties with the provider’s analysts. The tradeoff is that co-management only pays off if someone on your side has the hours to spend in the platform. Access nobody uses is just a line item.
Fully managed suits the larger number of MSPs who want a security outcome without hiring for it. The provider owns detection engineering, triage, and first-line containment, and you receive escalations as written cases and run remediation with the client. Coverage cost sits in a subscription instead of a payroll line, which makes margin predictable and lets the model scale as you add clients without changing your staffing plan.
A useful test: if an alert fired at 2:00 a.m. tonight, would anyone on your payroll want to look at it before morning? If the honest answer is no, you are buying fully managed no matter what the proposal calls it. Either way, get the division of duties in writing during onboarding, including who tunes detections, who has authority to contain, and who contacts the client first.
Six questions will separate the providers that hold up from the ones that will not.
Two things are landing on MSPs at once.
The first is that detection is getting slower while attacks are getting more expensive. IBM’s 2026 Cost of a Data Breach report put the global average at a record $4.99 million and mean time to identify and contain at 247 days, reversing five years of steady improvement. Losses reported to IC3 climbed 26% in 2025 to $20.9 billion across roughly a million complaints.
The second is verification. Cyber insurers have moved away from accepting self-attestation and toward demanding documented proof, and 24/7 monitoring with written response procedures now shows up routinely on applications and renewals. Compliance frameworks are heading the same direction. Your clients will increasingly have to demonstrate continuous monitoring rather than assert it, and the burden of producing that evidence lands on you.
For an MSP this is as much a positioning question as a security one. Continuous threat monitoring and analyst-led incident response separate selling IT support with security features from selling a security outcome. The second commands better margins and survives the procurement conversation where a client asks who is watching at 2:00 a.m. and expects a real answer.
Right now the MSPs pulling ahead are the ones who can answer that question without hedging, because they have a 24/7 SOC standing behind the promise.
Everything above describes a model. Todyl MXDR is one implementation of it, built for MSPs rather than adapted from an enterprise product.
The analyst team runs continuously, so a detection at 2:14 a.m. gets a human decision at 2:16 a.m. rather than a queue position. Containment authority is agreed during onboarding, which means the SOC can isolate a host, disable an account, or block an indicator on its own instead of calling you and waiting for approval. What reaches your team is a written case: what fired, what the analyst found, what was contained, and what remediation is left for you to run with the client.
The platform side matters just as much for an MSP. Telemetry from endpoint, identity, network, and cloud sources lands in a single multi-tenant console, so your technicians work one operational view across the book of business while each client’s data and reporting stay separated. Detection content is maintained centrally and applied across tenants, so a technique seen at one client becomes coverage for all of them.
The practical result is the answer you can give in a procurement conversation. When a prospect asks who is watching at 2:00 a.m., you name an analyst team, a response commitment, and a containment authority instead of describing a tool you resell.
A 24/7 security operations center collects telemetry from endpoints, identity, network, and cloud sources, writes and tunes the detections that decide what deserves an alert, triages every alert with a human analyst, and contains confirmed incidents by isolating hosts, disabling accounts, or blocking indicators. It runs continuously, so an attack at 3:00 a.m. gets the same response as one at 3:00 p.m.
It means somebody qualified is awake and authorized to act while the business sleeps. If credentials are compromised at 11:00 p.m. on a Friday, an analyst sees the alert, decides whether it is real, and stops it before Monday. The dashboards and monthly reports are packaging; the coverage itself is the product a small business is actually buying.
Continuous coverage takes roughly ten full-time analysts once you account for shifts, overnight second sets of eyes, vacation, and turnover. At the Bureau of Labor Statistics median wage of $132,510, that is about $1.33 million in salary before benefits, before a SIEM, EDR, threat intelligence, and orchestration stack, and before anyone to manage the team.
The functions are the same; the balance sheet is not. A managed SOC service, often sold as SOC as a service, puts an external analyst team behind your clients’ telemetry while you keep the relationship, the remediation work, and the account. You buy coverage as a subscription that scales with clients instead of building a payroll that scales with the clock.
Six things: whether it is genuinely analyst-led or automation with a service label, what the response SLA covers across acknowledge, triage, and contain, how much containment authority the SOC holds without calling you, how multi-tenancy separates client data while giving your team one view, what case file you receive after an incident, and whether it can produce evidence on demand.
Ready to put a 24/7 SOC behind your clients? Todyl’s analyst-led SOC gives MSPs continuous threat monitoring, pre-authorized containment, and written incident handoffs on a single multi-tenant platform. Talk to our team about what round-the-clock coverage would look like across your book of business.
Evaluate your security posture against AI-powered attacks and get recommendations to close any gaps.
Subscribe to our newsletter to get our latest insights.