What a 24/7 SOC Does (And Why It Matters for MSPs)

In a joint advisory, CISA and the FBI reported that the actors behind Gunra ransomware run their reconnaissance and internal movement between 10:00 p.m. and 6:00 a.m., timed that way specifically to avoid being noticed by administrators. Once encryption lands, victims get five to seven days to negotiate before their data goes up for publication.

The overnight scheduling is the tactic, and it works because of how most managed service providers operate. Tickets get triaged in the morning. Alerts stack up in a console overnight. The weekend page goes to whoever is on call, and that person may not have enough context to tell a noisy false positive from the opening move of a ransomware deployment.

A 24/7 SOC for MSPs is what closes the gap, and closing it takes people watching the console at 3:00 a.m. on a Sunday who understand what they are looking at. Below is what a security operations center does hour by hour, why building one in-house rarely works for an MSP, and how a managed SOC service changes what you can honestly promise a client.

What Does a SOC Do?

A security operations center is a function more than a place. Strip away the wall of monitors you see in the stock photography and you are left with four disciplines that run continuously.

  • Telemetry collection and correlation: Endpoint detections, identity events, firewall and network flow data, cloud audit logs, email security signals, SaaS activity. A SOC pulls all of it into one pipeline so a failed login in Entra ID and a suspicious PowerShell execution on a laptop read as the same story instead of two unrelated blips in two separate consoles.
  • Threat monitoring and detection engineering: Someone has to decide what deserves an alert. Detection content gets written, tuned, and retired as attacker tradecraft shifts. When a new technique shows up in the wild, a mature SOC pushes coverage for it across every tenant it protects, including the ones where nothing has been seen yet.
  • Triage and investigation: Most of the work lives here. An alert fires and an analyst has to decide whether it represents real adversary activity, ordinary administrative behavior, or a misconfiguration. Making that call requires context the tool often does not have. Does this admin normally work from Lisbon? Is that script part of the client’s RMM deployment? Did the account belong to someone who left last month? The analyst must connect the dots to get to the root of the issue.
  • Incident response: Once something is confirmed, the SOC contains it: isolate the host, disable the account, block the domain, kill the process, preserve the evidence. Then it hands off a written account of what happened, what got touched, and what still needs remediation.

The first two are mostly engineering work. The last two are why the phrase “analyst-led SOC” carries weight, and why an alert pipeline with nobody attached to it is better described as a monitoring product.

What “24/7” Means in Practice

The gap between a SOC and a 24/7 SOC comes down to staffing, and the arithmetic is unforgiving.

A week contains 168 hours and a full-time analyst covers roughly 40 of them, so keeping one qualified person in the seat at all times takes about 4.2 full-time employees before anybody books a vacation or quits. Most SOCs want a second set of eyes overnight, which doubles it. The SANS 2025 SOC Survey puts roughly 10 full-time equivalents at the baseline for a functioning SOC, and found 79% of them already running around the clock.

Then comes payroll. The Bureau of Labor Statistics put the median wage for information security analysts at $132,510 in its May 2025 figures, across an occupation employing about 190,650 people. Ten analysts at the median runs roughly $1.33 million in salary alone, before benefits, before tooling, and before you hire anyone to manage the team.

Finding those ten is its own problem. Staffing ranked as the top operational challenge in the 2026 SANS SOC Survey, which also recorded a 27-point gap between leaders who say management pays close attention to SOC hiring and the practitioners who agree.

That expense is defensible because attackers deliberately go after the hours when coverage disappears. The Gunra advisory describes a pattern similar across multiple such advisories: reconnaissance and lateral movement scheduled for the middle of the night, when the people who would recognize it are asleep. Adversaries have read the same staffing guides you have, and they know when the lights go out.

What Does 24/7 SOC Mean for Small Business?

For a 40-person accounting firm or a regional manufacturer, “24/7 SOC” translates into something specific and fairly unglamorous. If credentials get compromised at 11:00 p.m. on a Friday, somebody qualified sees it, decides what it is, and stops it before Monday.

That is the entire value proposition. The dashboard nobody logs into and the monthly report they skim are packaging around one person who is awake and authorized to act while the business sleeps.

Smaller companies get attacked plenty. Verizon’s 2026 Data Breach Investigations Report examined 22,000 confirmed breaches across 145 countries and found ransomware in 48% of them, at a median ransom of $139,875. What smaller companies lack is defense, which is a different problem, and it happens to be the one an MSP is positioned to solve.

Inside a Shift: How a Detection Becomes a Contained Incident

Phrases like “threat monitoring and incident response” hide what the work looks like in practice. Here is a composite of a fairly routine night.

  • [02:14] An impossible-travel alert fires on a client’s Microsoft 365 tenant. A user authenticated from Denver at 6:40 p.m. and from Lagos eight hours later.
  • [02:16] The analyst pulls the sign-in log. The Lagos authentication succeeded and satisfied MFA, which points toward session token theft or an MFA fatigue attack instead of simple password spraying.
  • [02:19] Cross-referencing endpoint telemetry turns up no matching activity on the user’s laptop, so the compromise is cloud-side. Checking mailbox audit logs, the analyst finds a new inbox rule created four minutes after the successful login. It forwards anything containing “invoice” or “wire” to an external address and marks it read.
  • [02:23] That indicates that a business email compromise in progress. The analyst revokes all active sessions for the account, forces a credential reset, deletes the forwarding rule, and preserves a copy of it for the case file.
  • [02:31] A query across the tenant for the same rule pattern turns up one more mailbox. Same treatment.
  • [02:40] A written escalation lands in the MSP’s on-call queue: what happened, what got contained, which two accounts are affected, and what the client needs to do at open of business. Notify finance, verify no wire instructions changed, review sent items for anything the attacker sent as the user.

Twenty-six minutes from detection to action. Without a 24/7 SOC, the outcome is vastly different.  

The alert sits in a console until somebody notices it Monday at 9:00. Sixty hours of unmonitored mailbox access have gone by, the attacker has had two full business days to study the invoice thread, and your conversation with the client has moved from detection to explaining a fraudulent wire transfer. The FBI’s Internet Crime Complaint Center logged 24,768 business email compromise complaints in 2025 and $3.05 billion in associated losses, so that conversation happens more often than anyone would like.

Why Building Your Own SOC Breaks the MSP Model

Most MSP owners reach the same conclusion once they run the numbers.

  • The staffing math does not scale down. That 10-analyst baseline for continuous coverage stays put whether you have 30 clients or 3,000 endpoints, because coverage tracks the clock. You pay for the hours regardless of how much sits behind them.
  • Tooling is a second budget entirely. A SIEM, EDR, and XDR stack plus network telemetry, threat intelligence, and orchestration each carry their own annual line item, and the multi-tenant versions are rarely the cheap ones.
  • Retention is brutal. Staffing topped the list of operational challenges in the 2026 SANS SOC Survey, and BLS projects the field growing 29% through 2034 with roughly 16,000 openings a year. Every departure costs you a hire plus the six to twelve months a new analyst needs to reach full productivity on your environments.
  • Alert fatigue degrades everything else. The 2025 SANS Detection & Response Survey found 73% of organizations naming false positives as their number one detection challenge, with the share reporting “very frequent” false positives climbing from 13% to 20% year over year. A small internal team drowning in noise starts missing signal, which is the exact failure a SOC exists to prevent.

None of this means an MSP cannot run security operations well. It does mean owning the whole stack is a capital-intensive business with margins that look nothing like managed services, and most MSPs come out ahead buying the capability instead of manufacturing it.

How Managed SOC Works for MSPs

A managed SOC service, often sold as SOC as a service, puts an external analyst team behind your clients’ telemetry while you keep the relationship, the remediation work, and the account.

Plenty of buyers have already reached this conclusion. MarketsandMarkets sized SOC as a service at $7.37 billion in 2024 with a path to $14.66 billion by 2030, a 12.2% CAGR, and expects small and midsize enterprises to be the fastest-growing segment in that forecast, precisely because they face serious exposure without the in-house resources to answer it.

The operating model usually looks like this.

  • Onboarding and baselining. The provider connects to your clients’ identity, endpoint, network, and cloud sources. The first two to four weeks go toward learning what normal looks like in each tenant, so detections fire on genuine anomalies instead of ordinary business.
  • Continuous monitoring. Telemetry flows into the provider’s platform. Detection content gets maintained centrally and applied across all tenants, so a technique observed at one client produces coverage for everyone.
  • Analyst triage. Alerts reach a human. Good providers will tell you what percentage of alerts their analysts close without ever touching your queue, and that number is the real product you are buying. An escalate-everything model just relocates your alert fatigue.
  • Containment with defined authority. You agree up front on what the SOC can do on its own: isolate a host, disable an account, block an indicator. Pre-authorized containment is what makes 3:00 a.m. response possible. Without it the SOC calls you and waits.
  • Escalation and handoff. What reaches you should be a written case with findings, timeline, actions taken, and recommended remediation. Your technicians pick up work already in progress instead of starting an investigation from zero.

Co-Managed vs. Fully Managed SOC: Which Model Fits Your MSP?

Some MSPs want their own engineers in the console, writing detections alongside the provider’s team. Others want a closed loop where they only ever see escalations. The choice comes down to whether you have security staff you want to develop or a service line you want to run without adding headcount. Ask which model a provider supports before you get deep into pricing, because retrofitting co-management onto a black-box service rarely goes well.

Co-managed makes sense when you already have a security-minded engineer or two and want them closer to the detection work. Your team gets console access, contributes tuning and detection logic for the environments they know best, and shares containment duties with the provider’s analysts. The tradeoff is that co-management only pays off if someone on your side has the hours to spend in the platform. Access nobody uses is just a line item.

Fully managed suits the larger number of MSPs who want a security outcome without hiring for it. The provider owns detection engineering, triage, and first-line containment, and you receive escalations as written cases and run remediation with the client. Coverage cost sits in a subscription instead of a payroll line, which makes margin predictable and lets the model scale as you add clients without changing your staffing plan.

A useful test: if an alert fired at 2:00 a.m. tonight, would anyone on your payroll want to look at it before morning? If the honest answer is no, you are buying fully managed no matter what the proposal calls it. Either way, get the division of duties in writing during onboarding, including who tunes detections, who has authority to contain, and who contacts the client first.

Evaluating a Managed SOC Service

Six questions will separate the providers that hold up from the ones that will not.

  • Is it analyst-led, or is it automation with a service label on it? Ask how many alerts per month a single analyst handles. Ask what happens to an alert automation cannot classify. Ask whether the analysts are employees or a subcontracted pool.
  • What is the response SLA, and what does it cover? Time to acknowledge, time to triage, and time to contain are three separate commitments. Get all three in writing along with how each one gets measured.
  • What is the containment authority? If the SOC needs your approval to isolate a host, your response time is capped by your on-call rotation instead of theirs.
  • How does it handle multi-tenancy? You need per-client separation of data and reporting alongside a single operational view for your own team. Providers built for enterprises often deliver one of those well and the other poorly.
  • What do you get after an incident? A usable case file with timeline and indicators is what you hand a client, an auditor, or an insurer. A closed ticket does not do that job.
  • Can it produce evidence on demand? Increasingly this one decides the deal, for reasons worth spelling out.

Why This Matters Now

Two things are landing on MSPs at once.

The first is that detection is getting slower while attacks are getting more expensive. IBM’s 2026 Cost of a Data Breach report put the global average at a record $4.99 million and mean time to identify and contain at 247 days, reversing five years of steady improvement. Losses reported to IC3 climbed 26% in 2025 to $20.9 billion across roughly a million complaints.

The second is verification. Cyber insurers have moved away from accepting self-attestation and toward demanding documented proof, and 24/7 monitoring with written response procedures now shows up routinely on applications and renewals. Compliance frameworks are heading the same direction. Your clients will increasingly have to demonstrate continuous monitoring rather than assert it, and the burden of producing that evidence lands on you.

For an MSP this is as much a positioning question as a security one. Continuous threat monitoring and analyst-led incident response separate selling IT support with security features from selling a security outcome. The second commands better margins and survives the procurement conversation where a client asks who is watching at 2:00 a.m. and expects a real answer.

Right now the MSPs pulling ahead are the ones who can answer that question without hedging, because they have a 24/7 SOC standing behind the promise.

How Todyl MXDR Delivers 24/7 SOC Coverage for MSPs

Everything above describes a model. Todyl MXDR is one implementation of it, built for MSPs rather than adapted from an enterprise product.

The analyst team runs continuously, so a detection at 2:14 a.m. gets a human decision at 2:16 a.m. rather than a queue position. Containment authority is agreed during onboarding, which means the SOC can isolate a host, disable an account, or block an indicator on its own instead of calling you and waiting for approval. What reaches your team is a written case: what fired, what the analyst found, what was contained, and what remediation is left for you to run with the client.

The platform side matters just as much for an MSP. Telemetry from endpoint, identity, network, and cloud sources lands in a single multi-tenant console, so your technicians work one operational view across the book of business while each client’s data and reporting stay separated. Detection content is maintained centrally and applied across tenants, so a technique seen at one client becomes coverage for all of them.

The practical result is the answer you can give in a procurement conversation. When a prospect asks who is watching at 2:00 a.m., you name an analyst team, a response commitment, and a containment authority instead of describing a tool you resell.

Frequently Asked Questions

What does a 24/7 SOC do?

A 24/7 security operations center collects telemetry from endpoints, identity, network, and cloud sources, writes and tunes the detections that decide what deserves an alert, triages every alert with a human analyst, and contains confirmed incidents by isolating hosts, disabling accounts, or blocking indicators. It runs continuously, so an attack at 3:00 a.m. gets the same response as one at 3:00 p.m.

What does 24/7 SOC mean for a small business?

It means somebody qualified is awake and authorized to act while the business sleeps. If credentials are compromised at 11:00 p.m. on a Friday, an analyst sees the alert, decides whether it is real, and stops it before Monday. The dashboards and monthly reports are packaging; the coverage itself is the product a small business is actually buying.

How much does it cost to build an in-house SOC?

Continuous coverage takes roughly ten full-time analysts once you account for shifts, overnight second sets of eyes, vacation, and turnover. At the Bureau of Labor Statistics median wage of $132,510, that is about $1.33 million in salary before benefits, before a SIEM, EDR, threat intelligence, and orchestration stack, and before anyone to manage the team.

What is the difference between a managed SOC and an in-house SOC?

The functions are the same; the balance sheet is not. A managed SOC service, often sold as SOC as a service, puts an external analyst team behind your clients’ telemetry while you keep the relationship, the remediation work, and the account. You buy coverage as a subscription that scales with clients instead of building a payroll that scales with the clock.

What should an MSP ask when evaluating a managed SOC?

Six things: whether it is genuinely analyst-led or automation with a service label, what the response SLA covers across acknowledge, triage, and contain, how much containment authority the SOC holds without calling you, how multi-tenancy separates client data while giving your team one view, what case file you receive after an incident, and whether it can produce evidence on demand.

Ready to put a 24/7 SOC behind your clients? Todyl’s analyst-led SOC gives MSPs continuous threat monitoring, pre-authorized containment, and written incident handoffs on a single multi-tenant platform. Talk to our team about what round-the-clock coverage would look like across your book of business.

AI Defense Readiness Assessment

Evaluate your security posture against AI-powered attacks and get recommendations to close any gaps.

Stay on the Cutting Edge of Security

Subscribe to our newsletter to get our latest insights.