Wethaq ICT | وثاق
Get a Quote
Insights

Building a SOC: in-house, outsourced or hybrid?

GovernmentPrivate sectorBanks & finance
24/7/365

A security operations centre (SOC) is the function that watches your environment, detects hostile activity and coordinates the first response. Many organisations buy a SIEM and assume they now have a SOC, only to discover that unread alerts and unmonitored nights and weekends leave them exposed. The real decision is not which product to buy, but which operating model you can sustain.

The three building blocks

  • People. Analysts at several tiers, a SOC lead, and engineers who maintain detections and integrations. Round-the-clock coverage typically needs a surprisingly large team once shifts, leave and training are counted.
  • Process. Triage procedures, escalation paths, severity definitions, playbooks and a link to incident response following NIST SP 800-61. Without process, tools produce noise.
  • Technology. A SIEM for collection and correlation, EDR on endpoints, network visibility, threat intelligence, and a case management or orchestration tool to track work and automate routine steps.

Start from use cases and log sources

Do not try to collect everything. Begin with the threats that matter to you and work backwards to the data needed to detect them. Map use cases to MITRE ATT&CK techniques, for example suspicious authentication, privilege escalation, lateral movement, data exfiltration and malicious persistence. Priority log sources usually include identity providers and directory services, email, VPN and remote access, firewalls, DNS, endpoints, key servers and cloud audit logs. Banks will add payment, core banking and SWIFT-related systems; government bodies will add citizen-facing portals and records systems. Confirm that time synchronisation and log retention meet your audit needs.

Compare the models

  • In-house. Maximum control and deep knowledge of your business, and suitable where data must not leave the institution. The trade-offs are cost, difficulty hiring and retaining analysts, and the time needed to reach maturity.
  • Outsourced (SOC-as-a-Service or managed detection and response). Faster start, round-the-clock coverage and access to broader threat experience. The trade-offs are less contextual knowledge, dependence on the provider, and the need to settle data location, access rights, confidentiality and exit terms contractually.
  • Hybrid. Your team owns business context, decisions and escalation, while a partner provides off-hours monitoring, threat hunting or specialised skills. For many organisations in our region this is the most realistic path to maturity.

Whatever the model, accountability for risk remains with you. Define clearly who can isolate a host, disable an account or call the regulator.

Measure what matters

Choose a small set of indicators and review them monthly:

  • Mean time to detect (MTTD): the average time between the start of malicious activity and the moment it is identified.
  • Mean time to respond (MTTR): the average time from detection to containment or resolution.
  • Detection coverage: the share of relevant ATT&CK techniques for which you have tested detections.
  • Log source health: how many critical sources are reporting as expected.
  • False-positive rate and analyst workload: signals of tuning quality and burnout risk.

Set your own targets from a baseline rather than copying someone else's figures, and validate detections with regular purple-team exercises.

A maturity path that works

  1. Establish visibility: core log sources, endpoint coverage and a clear escalation procedure.
  2. Stabilise operations: tuned alerts, documented playbooks and defined reporting.
  3. Add proactive capabilities: threat hunting, intelligence-driven detection and automation.
  4. Optimise continuously, feeding incident lessons into new detections.

How Wethaq ICT helps

Wethaq ICT designs, builds and operates security monitoring for government bodies, private companies and financial institutions, whether as a fully managed service or as an extension of your own team. We help you choose the model, define use cases and log sources, tune detections and report on meaningful metrics, so that your SOC grows in capability without losing sight of your data and your risk.

Back to insights

Let’s build a secure foundation for your digital future

It starts with a free consultation: we learn your challenges and goals, then propose a service package tailored to your needs and budget.