Skip to main content
Back to blog
Security

Choosing managed detection: what to ask before buying a SOC service

Managed detection is sold on dashboards and staffed by people. The questions that matter are about the people, the response and what happens at 3am.

2026-08-176 min readBy Mohd Ahsan, Head of Managed Services
Security operations dashboard showing incident timelines

Managed detection and response is usually demonstrated with a dashboard. Dashboards are the least important part. What decides whether the service is worth anything is who is watching, what they are allowed to do, and how quickly that happens at three in the morning.

Ask what "24/7" actually means

It can mean analysts on shift around the clock. It can mean automated alerting overnight with a human looking in the morning. Both are legitimate products at very different prices, and both get described the same way.

Ask directly: at 3am on a Sunday, who sees an alert, how quickly, and what are they able to do about it?

Detection or response?

Many services detect and notify. Fewer respond. The difference matters most in the scenario you are buying for: if an endpoint is compromised at 3am, can the provider isolate it immediately, or do they call you and wait?

If they can act, agree the authority in advance and in writing. What are they permitted to isolate, disable or block without asking. Getting that agreed during an incident wastes the hours that matter.

Alert quality over alert volume

A service producing hundreds of alerts a week is not more thorough, it is untuned, and it will train your team to ignore it. Ask what tuning happens during onboarding, how false positives are handled, and what the alert volume looks like for a client of your size after three months.

Ask to see a real alert, redacted. Does it explain what happened and what to do, or is it a log line with a severity attached?

Coverage

What data sources are included, and what costs extra? Endpoint is usually included. Identity, email, cloud, network and SaaS frequently are not, and identity is where a large share of real incidents begin. A service watching only endpoints will miss a compromised account being used entirely legitimately from an attacker's machine.

Onboarding

Ask how long it takes to reach useful detection, and what you have to provide. A realistic answer is weeks, including a tuning period. An answer of a few days usually means default rules and a noisy first quarter.

Exit

If you leave, what do you keep? Your logs should be yours. Detection rules built for your environment should be documented. A provider whose answer is vague is planning for leaving to be difficult, and that is worth knowing before you sign rather than after.

What to have in place first

Managed detection on top of missing basics is money badly spent. Multi-factor authentication everywhere, endpoint protection deployed properly, tested backup and centralised logging come first. Detection tells you something bad is happening; it does not prevent the routine attacks that basic controls stop outright.

A short question list

Who watches at 3am and what can they do. Detection only or response included, and with what authority. Which data sources are in scope. What alert volume looks like after tuning. How long onboarding takes. What we keep if we leave. Six questions, and the answers separate the services quite quickly.

Talk to the team

Have a question about this topic?

If you would like help applying any of this to your environment, send us the specifics and an engineer will reply.