Should you build an in-house SOC or outsource to MSS/MDR? This guide covers the personnel and costs required for in-house operations, the coverage and "alert-only" pitfalls of outsourcing, a 5-point comparison framework, hybrid models, and a third option: AI agents. Includes a decision-making checklist.

How to establish a security monitoring structure has become a management issue that many Japanese companies can no longer afford to postpone. In the "Top 10 Information Security Threats 2026" published by the IPA, "damage from ransomware attacks" ranked first and "attacks targeting supply chains and contractors" ranked second as threats to organizations (IPA, 2026). The focus has shifted from completely preventing intrusion to "how quickly to detect and stop the spread of damage." At the core of this effort is the SOC (Security Operations Center: a specialized organization responsible for security monitoring, analysis, and response). However, whether you build this in-house or outsource it to an MSS (Managed Security Service: a service that operates and monitors security equipment) or MDR (Managed Detection and Response: a service that includes post-detection investigation and response support) leads to different outcomes in terms of cost, talent, quality, and speed.
This article outlines the components and staffing required for an in-house SOC, the coverage and limitations of outsourcing, and compares the two approaches across five key metrics. We will then discuss the hybrid operations model—the realistic solution adopted by many organizations—and introduce a "third option" powered by AI agents. For details on the role of the SOC itself, its tier structure, and the basics of 24/7 operations, please refer to our pillar article, "What is a SOC? Roles, Tier Structures, and the Basics and Limits of 24/7/365 Operations." Note that this article does not discuss the pricing or specifications of specific vendors, but aims to provide a decision-making framework focusing on "traditional MSS" and "MDR" as categories.
Components and Staffing of an In-House SOC
An in-house SOC consists of three major elements: People, Process, and Technology. On the technology side, a suite of tools is required, including EDR (Endpoint Detection and Response: a mechanism to monitor endpoint behavior and detect suspicious activity), SIEM (Security Information and Event Management: a platform to aggregate and analyze various logs), threat intelligence, and ticket management. On the process side, you need alert triage (prioritization) procedures, escalation criteria, incident response playbooks (runbooks), KPI definitions, and regular reviews. The most difficult and costly element of all, however, is the "People."
Required Staffing to Fill a 24/7/365 Shift
A week has 168 hours. Assuming a 40-hour work week per analyst, filling a single seat 24/7/365 requires approximately 4.2 full-time equivalents (FTEs) by simple calculation. When factoring in paid leave, sick leave, training, and transition periods during turnover, it is generally accepted that "at least 5 to 6 people are required per seat, and around 8 to ensure a buffer." Furthermore, practical operations require a system that does not rely on a single decision-maker during night shifts (allowing for mutual verification), separate Tier 2/Tier 3 escalation analysts, engineers to maintain SIEM detection rules, and a manager to oversee the entire operation. As a result, even a minimal setup requires around 10 specialists, while a full-scale operation continuously demands dozens of specialized personnel.
Many managers already know how difficult it is to recruit and retain specialized talent at this scale. According to an ISC2 study, the global cybersecurity workforce is estimated at approximately 5.47 million, while the workforce gap—the shortage of needed professionals—reached approximately 4.76 million, a 19.1% increase from the previous year (ISC2 Cybersecurity Workforce Study, 2024). In the same study, 90% of respondents reported at least one skill gap within their team, citing "budget" as the primary cause of both staffing and skill shortages. A lack of personnel, tight budgets, and the constant risk of losing trained talent within a few years are structural weaknesses of an in-house SOC.
While many companies substitute night and weekend monitoring with "on-call IT department staff," the reasons why this model is unsustainable are detailed in our article "Why Night and Weekend Security Monitoring Fails to Work."
Outsourcing (MSS/MDR): Coverage and Limitations
Outsourcing seems to solve this "People" problem instantly. Traditional MSS handles security device operations and alert notifications, while MDR provides post-detection investigation and containment support using vendor personnel and tools. Eliminating the need for internal hiring, training, and shift management, and being able to start 24/7/365 monitoring relatively quickly after signing a contract, is a major advantage hard to achieve in-house.
However, outsourcing has structural limits. First, the scope of most traditional MSS is limited to "alert notification," leaving the subsequent investigation, decision-making, and remediation to your internal team. If a "High Severity" alert arrives in the middle of the night and no one internally can make a decision, it will either be left unaddressed until the next morning or handled blindly by whoever received the notification. Outsourcing monitoring does not guarantee that you have outsourced "response."
Second, the context of your internal environment is rarely fully understood by the vendor. Critical context that determines monitoring accuracy—such as "this is a core production server," "this account is for contractor maintenance," or "this traffic is a normal monthly batch job"—is difficult for a vendor serving multiple clients to grasp in detail and keep up with over time. This results in either high volumes of false positives that exhaust your internal responders, or excessive noise suppression by the vendor that buries critical indicators of compromise.
Third is the SLA (Service Level Agreement). In many contracts, while "time to notification" is defined, "time to complete investigation" and "time to complete containment" are typically excluded or offered as separate, optional add-ons. You must verify whether the contract SLA aligns with your actual goal: "time to stop the spread of damage." The differences in service scope among MSS, MDR, XDR, and AI SOC are summarized in "Differences Between MDR, MSS, XDR, and AI SOC: How to Choose a Security Operations Service."
Comparing In-House and Outsourcing Across 5 Metrics
Here, we compare in-house and outsourced models across five key metrics. Rather than determining "which is always better," evaluate these points based on "which risks your organization is prepared to accept."
1. Cost Structure: Upfront vs. Ongoing Costs
In-house operations incur annual costs for SIEM and EDR licensing, log storage, ticketing tools, and the personnel costs mentioned above. Labor costs are not a one-time setup fee but a fixed cost that persists as long as you maintain the team, and the market rate for security talent is generally rising. Conversely, MSS and MDR costs consist primarily of monthly service fees. While upfront costs are lower, most contracts scale based on the number of monitored devices or log volume, driving up costs as coverage expands. Furthermore, the internal labor cost for "post-notification response" does not disappear with outsourcing. When comparing SOC costs, you must add "internal response labor" to the outsourced service fees.
Additionally, consider not only the monitoring costs but also the potential loss from a breach. According to IBM, the global average cost of a data breach reached $4.99 million per incident, a 12% increase from the previous year and an all-time high (IBM Cost of a Data Breach Report, 2026). When compared against the potential losses from a monitoring gap, the "cheapest" structure cannot be judged solely by quotation figures. For practical cost estimates and steps for mid-sized enterprises to build 24/7 monitoring, see "SOC Construction Costs and Steps: A Realistic Approach to 24/7 Monitoring for Mid-Sized Enterprises."
2. Recruitment & Training: Where the Talent Risk Lies
With an in-house model, recruitment, training, and retention risks lie entirely with your organization. Training an analyst takes time, and once trained, their value in the job market increases. Outsourcing transfers this talent risk to the vendor. However, because vendors recruit from the same talent market, this risk can manifest indirectly through varying analyst experience levels or frequent staff turnover. Additionally, continuous outsourcing prevents internal knowledge accumulation, creating a "lock-in" risk where you lose the ability to evaluate vendor quality or transition to another provider. Even when outsourcing, keeping at least one internal lead capable of communicating with vendors on equal terms is a common best practice.
3. Quality and Accountability
In terms of quality, in-house SOCs excel at deep context of the internal environment, while outsourced services offer broad threat intelligence gathered across multiple clients. Neither is universally superior, but accountability remains clear. The Ministry of Economy, Trade and Industry's "Cybersecurity Management Guidelines Ver3.0" permits the use of external vendors when internal talent is scarce, yet explicitly requires management to ensure supply chain security (including business partners and contractors) and to clarify roles and responsibilities in contracts (METI, 2023). In short, while outsourcing is permitted, accountability for the impact of an incident remains with your organization—and ultimately, executive leadership. Saying "we outsourced it, so we don't know" is not an acceptable explanation to clients, regulators, or shareholders.
4. Response Speed
The time from detection to mitigation directly dictates the scale of damage. The strength of an in-house SOC is that decision-making and execution stay within the same organization, allowing actions like "isolate the endpoint" or "disable the account" to proceed without back-and-forth approval loops. Outsourcing often introduces delays: vendor notification, internal verification, instructions back to the vendor, and final execution. This process can stall during nights and weekends due to delayed internal approvals. While services like MDR can execute containment on your behalf, this requires prior agreement during contracting on the exact scope of pre-authorized actions. In either model, measuring and regularly reviewing Mean Time to Detect (MTTD) and Mean Time to Remediate (MTTR) is essential to maintaining speed.
5. Audits and Compliance: Operational Points for Japanese Companies
In regulated industries, the monitoring structure itself is subject to audits and inspections. The Financial Services Agency's "Guidelines for Cybersecurity in the Financial Sector" requires the establishment of monitoring systems like a SOC, allowing for "the utilization of external resources," and recommends continuous monitoring (24/7/365) based on the nature of customer services. Simultaneously, as part of third-party risk management, it requires clearly defining roles, responsibilities, audit rights, and incident response/reporting in contracts or SLAs, alongside continuous monitoring based on risk severity (FSA, 2024). This means that while outsourcing is allowed, the prerequisite is that the client organization must manage and remain accountable for the vendor.
Auditors look for records of "who, when, what was reviewed, and why that decision was made." An in-house model allows you to control the logging format, but risks creating siloes where context lives only in individual analysts' minds. Outsourcing provides standardized reports, but whether the vendor discloses the specific reasoning for closing an alert as "no issue" depends on the contract. Regardless of the model, ensuring the investigation trail is fully traceable is the key to passing audits.
The Realistic Solution: Hybrid Operations
This comparison shows that the core issue is not a binary choice between "in-house vs. outsource," but rather the "design of role division"—determining which functions to keep and which to delegate. The IPA's "Cybersecurity Management Guidelines Ver3.0 Practice Collection" showcases examples of companies that defined their internal and external boundaries, retaining the internal capability to communicate with specialized vendors post-outsourcing. It also highlights practices such as clarifying the scope of outsourcing, securing verification through contracts and third-party audits, and sharing and accumulating information to prevent CSIRT operations from becoming siloed (IPA, 2023).
A realistic division of labor adopted by many organizations is as follows:
Outsource 24/7/365 tier-1 monitoring (alert reception and triage) to secure coverage during nights and weekends.
Keep decisions requiring internal environment context (final severity assessment, business impact evaluation, and remediation approvals) in-house.
Retain incident response leadership (CSIRT decision-making, reporting to executives, authorities, and business partners) internally.
Lead the maintenance of environmental context (such as asset inventories and detection rules) internally, sharing updates continuously with the monitoring team.
Regularly evaluate vendor quality (notification accuracy, response times, report quality) and reflect findings in contracts.
The weakness of the hybrid model is that friction concentrates at the "hand-off point." It is common for an outsourcing vendor to send a notification only for the internal decision-maker to be unreachable at night, or for the notification to lack sufficient detail, delaying response due to further investigation. The success of a hybrid model depends on who can handle the "investigation and decision-making" step between detection and response, and how quickly and accurately they can do it.
The "Third Option" with AI Agents
An emerging third option, known as "AI SOC," uses AI agents instead of human analysts to manage this "investigation and decision-making" step. In an AI SOC, an AI agent receives alerts from EDR or SIEM, collects relevant logs, correlates findings with threat intelligence, identifies the scope of impact, and proposes containment steps, replicating the investigation methods of a tier-3 analyst. The underlying technology and differences from traditional SOCs are explained in our pillar article, "What is an AI SOC? Mechanisms, Differences from Traditional SOCs, and Key Benefits Explained."
When applied to our five metrics, the position of an AI SOC is clear. For staffing, it eliminates the need to recruit and train 24/7/365 shift workers, resolving the "People" issue just like outsourcing. For context, because the AI agent continuously learns your unique assets, operations, and past decisions via context memory, you retain the primary benefit of an in-house SOC: "understanding your environment." For accountability, the entire investigation process and reasoning are recorded, making it easier to answer "why that decision was made" during audits. In short, the AI SOC approach aims to deliver both the contextual retention of in-house models and the resource efficiency of outsourcing.
Yagura AI SOC uses AI agents to automate alert investigations, reducing the burden on team members in both in-house and outsourced setups. Review its impact by comparing your investigation rate, manual analysis time, and overall response effort before and after deployment. Because it integrates with over 100 security products including EDR, SIEM, and identity providers, it can be deployed without replacing your existing monitoring tools, allowing for a smooth transition from either in-house or outsourced setups. On a broader scale, IBM's study reports that organizations using AI and automation extensively in security experienced average breach costs that were $1.93 million lower than those that did not use them at all (IBM Cost of a Data Breach Report, 2026).
However, an AI SOC does not eliminate human involvement entirely. Final approval for response actions, executive and regulatory reporting, and business decisions must still be handled by humans, requiring an internal lead capable of evaluating and supervising the AI's findings. An AI SOC is an option to accelerate and standardize "investigation and decision-making," not a replacement for CSIRT decision-making or vendor management responsibilities.
Decision-Making Checklist
Regardless of whether you choose in-house, outsourced, hybrid, or AI SOC, review these key items before making a final decision:
Have you defined critical assets and acceptable downtime (prioritizing core systems, customer-facing services, and sensitive data)?
Who, how many people, and through what means will handle 24/7/365 tier-1 monitoring?
Who will perform the post-notification "investigation, decision-making, and response" within how many minutes, including nights and weekends?
If outsourcing, have you verified in the contract whether the SLA covers "up to notification" or "up to investigation and containment"?
Is there a mechanism to continuously feed internal context (asset inventory, normal traffic patterns, privileged accounts) to the monitoring team?
Are investigation steps and decision-making logic recorded in a format that can be presented during audits?
Have you set metrics to evaluate vendor or AI outputs (notification accuracy, response times, false positive rates) and determined review frequencies?
Do you have a plan to secure and train at least one internal staff member capable of supervising and evaluating the vendor or AI outputs?
Have you compared the 3-to-5-year Total Cost of Ownership (tools, labor, outsourcing fees, and remaining internal efforts) under the same assumptions?
Have you verified the monitoring and vendor management requirements mandated by industry guidelines or key business partners?
Any item you cannot answer clearly represents a vulnerability in your current setup. Items 3 and 6, in particular, are frequently overlooked in both in-house and outsourced models, yet they directly dictate the final scale of a breach and your ability to remain accountable afterward.
Summary
An in-house SOC excels in environmental context and response speed but faces major hurdles in hiring and retaining 24/7/365 staff. Outsourcing (MSS/MDR) shifts talent risks and enables quick deployment, but leaves post-notification investigation and decision-making to your team, with efficacy dependent on context and SLA scope. Because accountability ultimately remains with your organization, a hybrid operations model with well-designed roles is the realistic choice for most. In this setup, the AI SOC—which delegates the intermediate investigation and decision-making steps to AI agents—serves as a third option that combines contextual intelligence with operational efficiency. We recommend evaluating your current status against the checklist, starting with a review of "who does what when a notification arrives at night."
Related Service: Discover how Yagura AI SOC leverages AI agents to autonomously investigate and respond to EDR and SIEM alerts 24/7/365, delivering the context of an in-house SOC with the efficiency of outsourcing.
References and Sources
IPA "Top 10 Information Security Threats 2026" (2026): https://www.ipa.go.jp/security/10threats/10threats2026.html
ISC2 "2024 ISC2 Cybersecurity Workforce Study" (2024): https://www.isc2.org/Insights/2024/10/ISC2-2024-Cybersecurity-Workforce-Study
Ministry of Economy, Trade and Industry "Cybersecurity Management Guidelines Ver3.0" (2023): https://www.meti.go.jp/policy/netsecurity/downloadfiles/guide_v3.0.pdf
IPA "Cybersecurity Management Guidelines Ver3.0 Practice Collection 4th Edition" (2023): https://www.ipa.go.jp/security/economics/csm-practice.html
Financial Services Agency "Guidelines for Cybersecurity in the Financial Sector" (2024): https://www.fsa.go.jp/news/r6/sonota/20241004/18.pdf
IBM "Cost of a Data Breach Report 2026" (2026): https://www.ibm.com/reports/data-breach
Yagura Co., Ltd. "Yagura AI SOC": https://yagurasec.com/ai-soc



