Choosing managed detection: what to ask before buying a SOC service
Managed detection is sold on dashboards and staffed by people. The questions that matter are about the people, the response and what happens at 3am.

Managed detection and response is usually demonstrated with a dashboard. Dashboards are the least important part. What decides whether the service is worth anything is who is watching, what they are allowed to do, and how quickly that happens at three in the morning.
Ask what "24/7" actually means
It can mean analysts on shift around the clock. It can mean automated alerting overnight with a human looking in the morning. Both are legitimate products at very different prices, and both get described the same way.
Ask directly: at 3am on a Sunday, who sees an alert, how quickly, and what are they able to do about it?
Detection or response?
Many services detect and notify. Fewer respond. The difference matters most in the scenario you are buying for: if an endpoint is compromised at 3am, can the provider isolate it immediately, or do they call you and wait?
If they can act, agree the authority in advance and in writing. What are they permitted to isolate, disable or block without asking. Getting that agreed during an incident wastes the hours that matter.
Alert quality over alert volume
A service producing hundreds of alerts a week is not more thorough, it is untuned, and it will train your team to ignore it. Ask what tuning happens during onboarding, how false positives are handled, and what the alert volume looks like for a client of your size after three months.
Ask to see a real alert, redacted. Does it explain what happened and what to do, or is it a log line with a severity attached?
Coverage
What data sources are included, and what costs extra? Endpoint is usually included. Identity, email, cloud, network and SaaS frequently are not, and identity is where a large share of real incidents begin. A service watching only endpoints will miss a compromised account being used entirely legitimately from an attacker's machine.
Onboarding
Ask how long it takes to reach useful detection, and what you have to provide. A realistic answer is weeks, including a tuning period. An answer of a few days usually means default rules and a noisy first quarter.
Exit
If you leave, what do you keep? Your logs should be yours. Detection rules built for your environment should be documented. A provider whose answer is vague is planning for leaving to be difficult, and that is worth knowing before you sign rather than after.
What to have in place first
Managed detection on top of missing basics is money badly spent. Multi-factor authentication everywhere, endpoint protection deployed properly, tested backup and centralised logging come first. Detection tells you something bad is happening; it does not prevent the routine attacks that basic controls stop outright.
A short question list
Who watches at 3am and what can they do. Detection only or response included, and with what authority. Which data sources are in scope. What alert volume looks like after tuning. How long onboarding takes. What we keep if we leave. Six questions, and the answers separate the services quite quickly.
More from the Security desk

Top 10 Cybersecurity Threats Facing India Companies in 2026
Discover the most critical cybersecurity threats targeting companies in India and how to protect your organization.
Read post
Microsoft Defender: Complete Security Solution for SMEs
Comprehensive guide to implementing Microsoft Defender for small and medium enterprises in India.
Read post
Implementing Zero Trust Security in Your Organization
Learn how to implement Zero Trust security model to protect your organization from modern cyber threats.
Read postHave a question about this topic?
If you would like help applying any of this to your environment, send us the specifics and an engineer will reply.