A median advertised cyber security salary in the UK is now £58,050. In London, the mean is £70,200. And one security analyst doesn't give you a 24/7 SOC.
That is why comparing the cost of outsourced cyber security services with an employee's salary gives you the wrong answer.
An effective security operations capability needs people, technology, threat intelligence, processes and sufficient coverage to investigate an incident when it happens. Building that capability internally means carrying those costs yourself. Outsourcing transfers some of them to a specialist provider.
Neither model is automatically cheaper or better.
The useful question is: what does it cost to achieve the detection and response capability your organisation actually needs?
What does an in-house SOC really cost?
People are the obvious place to start.
The UK Government's 2026 cyber security labour market research found that the median advertised salary for a core cyber security role was £58,050 in 2025, while the mean was £60,800. In London, the mean advertised salary reached £70,200. Of vacancies that disclosed salary information, 15% offered £90,000 or more.
But salary alone doesn't represent the cost of an internal SOC.
An organisation also needs to account for employer costs, pensions, benefits, recruitment, training and certifications. Then there is holiday, sickness, staff turnover and management.
More importantly, one person isn't a SOC.
If you need 24/7 detection and response, somebody needs to cover nights, weekends, annual leave and absence. You may also need different levels of expertise for initial triage, detailed investigation, security engineering and incident response.
Technology adds another layer of cost.
Depending on the operating model, an internal SOC may need:
- SIEM
- EDR or XDR
- SOAR and automation
- Threat intelligence
- Vulnerability management
- Log ingestion and retention
- Case management
- Reporting tools
Those platforms then need to be integrated, configured, maintained and tuned.
The question isn't therefore, "Can we afford a security analyst?"
It's, "What will it cost us to build and sustain the complete capability?"
The hidden cost of 24/7 security operations
Continuous coverage changes the economics considerably.
A business-hours team can investigate what happens between 9am and 5pm. Threat actors don't work the same schedule.
Providing continuous coverage means building sufficient resilience into the team to account for shifts, weekends, annual leave, sickness, training and employee turnover.
Then consider skills.
The Government's 2026 labour-market research estimates that approximately 145,900 people work in the UK cyber security workforce. Demand is also growing: core cyber security job postings increased by 7% in 2025.
Finding enough people isn't the only issue. You need the right expertise.
The same research found that 57% of UK businesses had a basic technical cyber security skills gap, equivalent to approximately 808,000 businesses. More advanced capabilities create further challenges: 27% reported an advanced technical skills gap.
Incident response stands out. Among businesses that had not outsourced the function, 47% of people responsible for cyber security lacked confidence in dealing with breaches or attacks.
That's an important distinction when assessing SOC costs.
You're not simply paying for somebody to watch a screen. You're paying for the ability to determine whether activity represents a genuine threat and take the right action quickly.
What do outsourced cyber security services actually cover?
Outsourced cyber security services shift some of the cost and operational responsibility to a specialist provider.
Depending on the service, that can include:
- 24/7 monitoring
- SIEM management
- EDR/XDR
- Threat detection
- Alert triage
- Investigation
- Threat hunting
- Incident response
- Containment
- Reporting
- Security engineering
- Access to specialist analysts
The phrase "depending on the service" matters.
Outsourcing alerts isn't the same as outsourcing security operations.
A provider could monitor your environment and notify your internal team when it detects suspicious activity. Your people then investigate the alert, establish whether it's genuine and decide what to do.
An MXDR service can go further, combining detection with investigation and response.
The commercial question should therefore be very specific:
Who owns the incident at 2am?
If the answer is still your internal IT team, factor that into the cost comparison.
External expertise is already an established part of many UK organisations' security models. The Government's 2025/26 Cyber Security Breaches Survey found that 48% of UK businesses had an external cyber security provider. This rose to 70% of medium businesses and 64% of small businesses.
Outsourcing doesn't necessarily mean replacing an internal security team. It can provide specific capabilities or additional capacity that would otherwise need to be built internally.
In-house SOC vs outsourced cyber security: compare the costs
A useful comparison needs to consider the entire operating model.
| Cost or requirement |
In-house SOC |
Outsourced cyber security |
| Security analysts |
Direct employment cost |
Included depending on service |
| 24/7 coverage |
Must be staffed internally |
Can be included |
| Recruitment |
Organisation carries cost |
Provider manages its workforce |
| Training |
Ongoing internal investment |
Provider typically manages analyst training |
| SIEM/XDR |
Purchased and managed internally |
May be included or existing tooling used |
| Threat intelligence |
Separate capability/cost |
May be incorporated |
| Absence and turnover |
Organisation carries staffing risk |
Provider manages resourcing |
| Specialist incident expertise |
Hire or contract |
May be available within service |
| Scaling |
Recruit and expand technology |
Expand service agreement |
| Management |
Internal |
Shared with provider |
This isn't an argument that every capability should be outsourced.
An organisation still owns its cyber risk.
Governance, business context, risk appetite and strategic decisions can't simply be transferred to a supplier. Someone internally also needs to manage the provider and ensure the service continues to meet the organisation's requirements.
What is the cost of getting detection and response wrong?
The cost equation also needs to consider what the security operation exists to achieve.
The Government's 2025/26 Cyber Security Breaches Survey found that 43% of UK businesses identified a cyber security breach or attack during the previous 12 months.
Larger organisations face particularly high exposure. The same research found phishing attacks had been identified by 60% of medium businesses and 63% of large businesses, while 12% of medium businesses and 23% of large businesses identified devices targeted with malware.
Detection is only part of the challenge.
A SOC needs to establish what's happening, prioritise it and respond quickly enough to limit the impact.
IBM's 2025 UK Cost of a Data Breach research provides some context for the potential financial consequences. Its study, based on real-world breaches at 600 organisations globally including UK organisations, found UK organisations extensively using AI and automation in security operations had average breach costs of £3.11 million, compared with £3.78 million for organisations that weren't using those technologies extensively.
That doesn't mean automation automatically saves every organisation £670,000, nor does it tell us whether an internal or outsourced SOC will perform better.
It does demonstrate why the economics of security operations shouldn't be reduced to the price of the service itself.
Speed, automation and the ability to respond effectively have financial consequences too.
When does an in-house SOC make sense?
Keeping security operations in-house can make sense for organisations with the scale, skills and resources to sustain the capability.
It may be appropriate where you:
- Already have an experienced security team
- Need tight operational control
- Have specialist or unusual security requirements
- Have mature security engineering capabilities
- Can recruit and retain the required expertise
- Have enough scale to justify dedicated resources
There can also be significant value in retaining deep organisational knowledge internally.
An internal analyst understands your architecture, users, processes and risk profile. That context can make investigation and decision-making faster.
But it only works if the team has sufficient capacity and expertise.
When do outsourced cyber security services make sense?
Outsourcing becomes attractive when the gap isn't necessarily technology, but people and operational coverage.
It may make sense if you need:
- 24/7 monitoring without building a shift-based internal team
- Additional capacity for a small security function
- Specialist detection and response expertise
- Support for an existing SOC
- Threat hunting or incident-response capability
- More value from security platforms you already own
That last point is often overlooked.
Buying more security technology doesn't necessarily improve security. If your organisation already owns capable SIEM, EDR or XDR technology but lacks the people to configure, monitor and respond to it effectively, the better investment may be expertise rather than another tool.
The third option: a hybrid SOC
The choice isn't binary.
For many organisations, a hybrid model offers another route.
Your internal security team can retain responsibility for strategy, governance, risk and business context while an external provider handles defined operational functions.
That could include 24/7 monitoring, triage, investigation, threat hunting or specialist response.
It means the internal team doesn't have to reproduce every skill the provider has, while the organisation retains the knowledge and decision-making capability that makes sense to keep close to the business.
The balance can also change.
As an internal security function grows, responsibilities can move in-house. Equally, organisations can add external capability when they need additional scale or expertise.
How do you calculate which model really costs less?
Start by making the comparison equivalent.
For an internal SOC, calculate:
Salaries + employment costs + recruitment + training + SIEM/XDR + data ingestion and storage + threat intelligence + management + out-of-hours coverage + specialist support.
For outsourced cyber security services, calculate:
Service fees + onboarding + technology not included in the agreement + internal service management + retained internal capability + any additional incident-response costs.
Then compare what each model actually delivers.
If one gives you business-hours monitoring and another provides 24/7 investigation and containment, their prices aren't comparable.
Start with the outcome instead.
What needs to be monitored? Who investigates? What response do you expect? How quickly do you need it? Which capabilities already exist internally, and which are you paying to reproduce?
Celerity works with organisations to assess their existing cyber security environment and determine where technology, internal expertise and managed services should sit. That means using the capabilities you already have where they make sense and adding external expertise where it delivers a clear operational outcome.
Because the question isn't simply whether an outsourced SOC costs less.
It's whether you're paying for the security capability you actually need.
Talk to Celerity about the right security operating model for your organisation, and where managed expertise can deliver the most value.