Procurement insights for SOC services

A managed SOC is a promise about time.

Every provider can show you a dashboard. Far fewer can tell you who picks up the phone at 3am, what they are allowed to switch off, and what the second year costs. This page sets out what CYBORIUM tests before an Australian organisation signs a security operations contract.

Five clocks run inside every SOC contract

Most proposals describe the first clock in detail and leave the other four to the implementation call. The gap between them is where cost, risk and disappointment live.

  1. 01

    Detect

    Signal reaches the platform.

    Ask: exactly which log sources are inside the quoted price, and what happens to that price when volume grows.

  2. 02

    Triage

    A person decides it matters.

    Ask: is triage staffed in Australian hours, offshore overnight, or automated with a human only on exception.

  3. 03

    Escalate

    Your phone actually rings.

    Ask: who is called, on which channel, and what the provider does when the first two contacts do not answer.

  4. 04

    Contain

    The attacker loses access to something.

    Ask: may the provider isolate a host or disable an account without waiting for you, and who carries that decision.

  5. 05

    Evidence

    The record survives the incident.

    Ask: which artefacts are retained, for how long, and whether you can take them with you when the contract ends.

A response time in a service level table means nothing until you know which of these five clocks it is measuring.

Where SOC proposals quietly lose money

These are the patterns CYBORIUM keeps finding when a security operations agreement is opened up and read against what the organisation believed it bought.

Ingestion priced against a volume nobody measured

Data charges are often quoted per gigabyte per day using an estimate the decision owner supplied. Cloud audit logs and identity telemetry are the two sources that most often break the estimate in year one.

Coverage that stops at the endpoint

Endpoint agents are the easiest part to deploy and the easiest part to sell. Identity, email, software as a service and cloud control planes are where intrusions are increasingly visible first.

Response that turns out to mean advice

A proposal can promise response and deliver a well written recommendation at 2am. If nobody at the provider is contractually able to act, the containment clock is still yours.

Tuning treated as a project, not a service

Detection quality decays. If rule tuning, false positive reduction and use case development are not funded as ongoing work, alert fatigue arrives on schedule.

An exit that leaves the detections behind

Custom detection logic, enrichment and playbooks built during the term are frequently the provider's property. That single clause decides how expensive it is to change your mind.

Reporting written for the provider

Volume of alerts closed is a measure of the provider being busy. It is not a measure of your exposure falling, and a board reading it will ask the wrong questions.

Ten service categories that get bundled under one word

Decision owners ask for a SOC. Providers answer with whichever of these they sell. The categories are not interchangeable, and comparing them side by side without normalising the scope is how a market process produces a false result.

01

Fully managed SOC

Monitoring, triage, escalation and reporting delivered end to end by the provider on their platform.

Test the market when you have no internal analyst capability and no appetite to build one.

02

Co-managed SOC

Your team owns business hours and the provider carries nights, weekends and surge. Split responsibility is the hardest thing to document well.

Test the market when you already employ security analysts but cannot sustain a roster.

03

Managed detection and response

Detection plus a contractual right to take containment action. The word response is doing significant work in this category and must be defined.

Test the market when your risk appetite requires action overnight rather than notification.

04

Alert monitoring by a managed security provider

The lightest form. Alerts are watched and forwarded. Useful, cheaper, and frequently mistaken for the category above it.

Test the market when the driver is a contractual or insurance requirement rather than a threat model.

05

Platform plus tuning service

You license the detection platform directly and buy engineering time to run it. Licensing and labour stay separable, which protects the exit.

Test the market when you intend to keep the data and the detections in your own tenancy.

06

Threat hunting retainer

Scheduled proactive search for activity that existing detections did not raise. Sold by the hour or by the campaign.

Test the market when monitoring is mature and you need to prove the absence of something.

07

Incident response and forensics retainer

Pre agreed rates, guaranteed availability and an agreed scope of work for the day it goes wrong. Often priced as a drawdown.

Test the market when the current arrangement is an informal relationship with no service level.

08

Identity threat detection and response

Detection focused on directory, single sign on and privilege abuse rather than on hosts. Increasingly the first place an intrusion is visible.

Test the market when your workforce is cloud first and endpoint coverage is already sound.

09

Cloud detection and response

Control plane, workload and container telemetry. A different skill set and a different data volume profile to endpoint monitoring.

Test the market when production has moved to public cloud but monitoring has not followed it.

10

Operational technology monitoring

Passive monitoring of industrial and building control networks, where an agent is usually not permitted and availability outranks confidentiality.

Test the market when physical operations sit behind the same corporate network as email.

No provider is named on this page. Names belong inside an evaluation, next to the evidence that earned them a place on the shortlist.

The CYBORIUM position

Six rules we apply to every security operations evaluation

These are not preferences. They are the tests that decide whether a proposal survives to the shortlist.

  1. 01

    Define the log sources before the platform

    Scope is the price. Write down every source, its daily volume and its retention requirement, then let providers quote against one identical list.

  2. 02

    Price the second year, not the first

    Onboarding discounts, ramped ingestion and waived tuning fees make year one unrepresentative. Model years two and three or the comparison is fiction.

  3. 03

    Separate detection from response in the contract

    They have different service levels, different liabilities and different staffing. Bundling them hides which one you are actually paying for.

  4. 04

    Make the provider prove one real escalation

    A reference call is marketing. A walkthrough of a genuine out of hours escalation, with timestamps and the artefacts produced, is evidence.

  5. 05

    Own the detection content and the data

    Custom rules, enrichment, playbooks and historical telemetry should be portable by contract. Exit cost is decided at signature, not at termination.

  6. 06

    Score the reporting a board will read

    Ask for a genuine sample report with a customer redacted. If it cannot support a risk committee conversation, it will not support yours.

The pricing unit decides the argument you will have later

Six charging models dominate this market. Each one is defensible. Each one also has a predictable place where the invoice stops matching the expectation, and that place is worth naming during procurement rather than in month seven.

Common SOC pricing units and where each one escalates
Charging unitUsually suitsWhere it escalates
Per userStable office based workforcesContractors, service accounts and shared devices are counted inconsistently between providers.
Per endpoint or deviceDevice heavy operationsServers, virtual desktops and ephemeral cloud workloads may each be billed as an endpoint.
Per gigabyte ingestedOrganisations with measured log volumeVerbose cloud and identity logging can multiply volume without any change to headcount.
Per data source connectedSmall, well defined estatesEach new application becomes a commercial conversation, which discourages adding visibility.
Flat monthly retainerBudget predictabilityFair use clauses define the ceiling, and they are often written loosely enough to be argued either way.
Retainer plus drawdown hoursIncident response and forensicsUnused hours frequently expire, and the hourly rate for exceeding them is rarely capped.

A market evaluation normalises these into one comparable number. Skip it and the comparison runs between charging units rather than between offers.

What the Australian rules expect of a monitoring arrangement

Regulated entities cannot delegate accountability to a security provider. These are the public obligations most often engaged when monitoring is outsourced.

Prudential Standard CPS 234

Information security. It requires an APRA regulated entity to maintain information security capability commensurate with the threats it faces, and it applies where information assets are managed by a related party or a third party.

  • Notify APRA within 72 hours of becoming aware of a material information security incident.
  • Notify APRA within 10 business days of becoming aware of a material information security control weakness the entity expects it will not remediate in a timely manner.
  • Test control effectiveness, including controls operated by a service provider, and have those tests reviewed by internal audit.

apra.gov.au/standards/cps-234

Prudential Standard CPS 230

Operational risk management. A security operations provider will frequently meet the definition of a material service provider, which brings register, due diligence, monitoring and contractual obligations with it.

  • In force from 1 July 2025, with transitional arrangements for pre existing contracts.
  • Requires a register of material service providers and defined tolerance levels for disruption of critical operations.
  • Requires the entity to remain able to meet its obligations when a provider fails.

Full guidance: CYBORIUM CPS 230 due diligence and apra.gov.au/standards/cps-230

The assurance artefacts worth requesting, and what each one actually proves

ISO/IEC 27001 certificate
The provider operates a certified information security management system. Read the scope statement, because it frequently excludes the service you are buying.
SOC 2 Type II report
An auditor tested the provider's own controls over a period. It says nothing about the quality of the detections applied to your environment.
IRAP assessment
Relevant where Australian government data is in scope. Ask which system boundary was assessed and on what date.
Essential Eight maturity evidence
The ASD maturity model raises expectations for centralised event logging and monitoring as maturity increases, which is exactly what a SOC arrangement is meant to satisfy.

This page is the public half

Everything above sharpens the questions. A CYBORIUM evaluation answers them with the market.

  • A normalised requirementOne log source list, one response definition, one comparable scope issued to every provider.
  • A real market scanSuitable Australian and global providers identified against your sector, data residency and hours of operation.
  • Evidence scoringClaims tested against artefacts, escalation walkthroughs and reference conditions rather than capability statements.
  • Commercial benchmarkingEvery offer converted to a three year cost under the same volume assumptions, including exit.
  • A board ready recommendationA decision record that survives an audit question about why this provider and not another.

Questions decision owners ask us about managed SOC services

What is the difference between a managed SOC and MDR?

A managed SOC describes the function, which is continuous monitoring, triage, escalation and reporting. Managed detection and response describes an outcome, which is that the provider is able to take containment action on your behalf. Many providers use the terms interchangeably, so the only reliable test is to read what the contract permits the provider to do without your approval at 3am.

Do we need a SOC to comply with CPS 234?

CPS 234 does not mandate a security operations centre. It requires information security capability commensurate with the size and extent of threats to an entity's information assets, along with the ability to detect and respond to incidents in a timely way and to notify APRA within 72 hours of a material incident. For most regulated entities that combination is difficult to evidence without continuous monitoring in some form, whether internal, co-managed or outsourced.

How should we compare providers whose pricing units differ?

Normalise before you compare. Fix one set of volume assumptions, apply them to every charging model, extend the calculation to at least three years and add the cost of exiting. A per user price and a per gigabyte price are not comparable numbers until they sit on the same assumptions, and small differences in those assumptions routinely change the ranking.

Is offshore triage a problem?

Not automatically. It is a documented decision with consequences for data residency, contractual access, escalation quality and, in regulated sectors, service provider obligations. The problem is when it is discovered after signature rather than assessed during evaluation. Ask where analysts are located per shift, where telemetry is stored and processed, and how that maps to your own obligations.

What should we own at the end of the contract?

At minimum, your historical telemetry in a usable format, the custom detection logic and enrichment built for your environment, the case history and the documented playbooks. Anything the provider retains is something the next provider will rebuild at your cost, so exit terms belong in the evaluation criteria rather than in the legal review at the end.

How long does a market evaluation for SOC services take?

It depends on the size of the estate and how well the log source inventory is understood at the start. The requirement definition stage is usually the longest, because it is where scope is measured rather than estimated. Providers can respond quickly once they are all answering the same question, which is the point of doing the definition work first.

Testing this market changes the answer more than most

Security operations proposals are unusually hard to compare and unusually expensive to get wrong. CYBORIUM defines the requirement, runs the market, tests the evidence and builds the record behind a decision you can defend.