SOC & Detection

Managed SOC vs. Internal SOC vs. MSSP: Which Security Operations Model Is Right for German Mid-Sized Companies?

Bilal El Hassani·Last updated: ·10 min read

Quick summary

Choosing between an internal Security Operations Center (SOC), a traditional Managed Security Service Provider (MSSP), and a managed SOC is one of the most important cybersecurity decisions for mid-sized companies.

In short, choose an in-house SOC if you need maximum control and can staff it 24/7. Choose an MSSP if you want broader outsourced security services. Choose a managed SOC if you need continuous detection and response without building the team yourself.

For organizations in sectors such as manufacturing, logistics, and energy, where cyber incidents can disrupt production, supply chains, or critical services, the right operating model is increasingly a business decision rather than purely a technical one.

Why this decision matters

Cyberattacks no longer target only large enterprises. Mid-sized organizations are increasingly affected because they often operate complex IT environments while having fewer dedicated security resources.

For manufacturers, a ransomware attack can halt production. Logistics companies risk disruptions to warehouse management and transport systems. Energy providers must protect both corporate IT and operational environments while meeting growing regulatory expectations.

The regulatory landscape has also changed. Since December 6, 2025, Germany's NIS2 implementation act (NIS2UmsuCG) has been in force without a transition period. Approximately 29,500 German organizations with at least 50 employees or €10 million in annual turnover across 18 sectors are affected. Organizations must implement appropriate cybersecurity measures and meet incident reporting obligations under Section 30 BSIG, with significant financial penalties for non-compliance.

At the same time, recruiting experienced cybersecurity professionals remains difficult. According to Bitkom, Germany faces a shortage of approximately 109,000 IT professionals.

Against this backdrop, many IT leaders ask the same question: Should we build an internal SOC, work with a traditional MSSP, or partner with a managed SOC provider?

This guide compares each option, explains where each makes sense, and outlines what mid-sized organizations should consider before making a decision.

For most mid-sized companies, the choice comes down to control, available security staff, and how much of the operation they want to outsource. An in-house SOC offers the most control, a managed SOC usually reduces the staffing burden, and an MSSP can make sense when a broader set of managed security services is needed.

What does a Security Operations Center (SOC) do?

A Security Operations Center is responsible for continuously monitoring an organization's IT environment to detect, investigate, and respond to cyber threats.

Typical responsibilities include:

  • Continuous security monitoring
  • Threat detection and alert triage
  • Incident investigation and response
  • Threat hunting
  • Detection engineering
  • Security reporting
  • Continuous improvement of detection rules and playbooks

Most modern SOCs rely on technologies such as Security Information and Event Management (SIEM), Endpoint Detection and Response (EDR), identity monitoring, cloud security telemetry, and automation to identify suspicious activity across the environment.

The difference between operating models is not whether these functions exist, but who performs them and how they are delivered. A SOC is a security function, an MSSP is a provider type, and a managed SOC is an outsourced operating model for that function.

Option 1: The internal SOC

Building an internal Security Operations Center gives your organization complete control over security operations. Your team defines detection logic, response processes, and priorities while developing deep knowledge of your own environment.

The trade-off is operational complexity. Running a mature SOC requires both specialist expertise and continuous investment in people and technology.

Key considerations:

  • Full control over processes, tooling, and priorities.
  • Typically requires 8 to 12 security professionals to provide genuine 24/7 coverage.
  • Ongoing investment in SIEM, EDR, threat intelligence, detection engineering, and analyst training.
  • Recruiting and retaining experienced security talent remains one of the biggest challenges for German mid-sized companies.

For most organizations, an internal SOC only becomes economical once security operations have reached a significant scale. It is therefore often not yet suited to mid-sized companies.

Option 2: The classic MSSP

Many mid-sized companies already rely on an MSSP to operate parts of their security infrastructure. This reduces operational effort and provides access to external expertise without building an in-house SOC.

However, the scope and quality of MSSP services differ considerably, making it important to understand exactly what is included.

Things to evaluate:

  • Is monitoring and incident response available 24/7, or only during business hours?
  • Are alerts investigated by experienced analysts or simply forwarded to your team?
  • Is pricing predictable, or based on events, data volume, or individual services?
  • Are analysts familiar with your environment, and where is the team located?

An MSSP is often a good fit for organizations looking to outsource infrastructure and security management together, provided the service aligns with their operational needs.

Option 3: A specialized managed-SOC partner

A managed SOC focuses specifically on continuous threat detection, investigation, and incident response. Rather than simply forwarding alerts, analysts validate incidents, support containment, and work alongside internal IT teams during security events.

When comparing providers, the operating model often matters more than the feature list.

Look for providers that offer:

  • Genuine 24/7 monitoring with human analysts.
  • Fast escalation of critical incidents.
  • Transparent, predictable pricing.
  • Continuous improvement of detections and playbooks.
  • Executive and technical reporting for security and compliance.

One example is Pently's Managed SOC, which combines Microsoft Sentinel and Defender XDR with a Germany-based analyst team, transparent pricing per managed asset, and direct phone escalation to customer IT teams. Onboarding with Pently typically takes 2 to 4 weeks, depending on the complexity of the environment.

The direct comparison

Comparison of an internal SOC, a classic MSSP and Pently Managed SOC
CriterionInternal SOCClassic MSSPPently Managed SOC
24/7 securityRequires a large teamCoverage can vary24/7 expert support
Fast responseDepends on availabilityOften ticket-basedEscalation in under 30 minutes
Local expertiseInternal teamOften offshoreGermany-based team, no contractors
Predictable costsHigh fixed costsOften complex, usage-basedSimple flat price per asset
Existing toolsBuild and maintain your own stackMay require new toolsWorks with existing Microsoft licenses
False-positive rateDepends on team experienceVaries widely, rarely disclosedUnder 10% false positives
Getting startedMonths to yearsWeeks to months2–4 week onboarding
NIS2 supportBuild internallyOften extraBuilt into the service
StaffingRecruitment requiredOutsourcedNo hiring required

What operationally critical mid-sized companies should watch for

For companies where downtime directly threatens delivery, supply, or production capability, a few patterns come up repeatedly:

  1. Identity and cloud matter as much as endpoints

    Where operations depend on interfaces with customers, partners, or subcontractors, identities and cloud workloads are often the more realistic attack vector, not just laptops and servers.

  2. IT/OT convergence widens the attack surface

    Where control systems or industrial components are network-connected, standard endpoint monitoring alone isn't enough; use cases need to account for that overlap.

  3. Response speed determines the size of the damage

    A ransomware incident that reaches a production line, warehouse system, or control environment is far more costly the longer it takes to escalate and contain. Minutes matter more than hours here.

Regulatory exposure under NIS2 is also frequently underestimated. A gap analysis of your own NIS2 obligations should come before any decision for or against a managed SOC.

NIS2 and security operations

Does NIS2 require a SOC? No. NIS2 does not prescribe a specific SOC model, but it does require appropriate risk-management and incident-handling measures.

Organizations remain responsible for implementing appropriate technical and organisational security measures regardless of whether security operations are managed internally or externally.

However, a mature managed SOC can support compliance by providing:

  • Continuous monitoring
  • Documented incident response
  • Executive reporting
  • Security playbooks
  • Evidence for audits
  • Security event documentation

A managed SOC should therefore be viewed as one component of a broader cybersecurity and governance strategy rather than a replacement for an Information Security Management System (ISMS). Test here if NIS2 applies to your organisation.

How to evaluate a managed SOC provider

When comparing providers, consider asking:

  • Is monitoring genuinely available 24/7?
  • Who investigates alerts?
  • Are analysts located locally?
  • How are incidents escalated?
  • Is pricing predictable?
  • Which Microsoft security technologies are supported?
  • How are detections continuously improved?
  • What executive reporting is provided?
  • How quickly can onboarding be completed?
  • How is incident response coordinated with internal IT teams?

These questions often reveal larger differences than marketing material alone.

Frequently asked questions

Is an internal SOC suitable for mid-sized companies?+

Yes, but it is generally most appropriate for organizations with mature security teams, stable budgets, and sufficient staffing to maintain continuous operations.

What is the difference between a managed SOC and an MSSP?+

While the terms are sometimes used interchangeably, managed SOC providers generally focus on continuous security operations, threat detection, and incident response. Traditional MSSPs often provide broader managed IT and security services, with capabilities varying by provider.

Do we need Microsoft E5?+

Not necessarily. Many managed SOC providers support Microsoft E3 with Defender add-ons as well as hybrid environments using third-party security technologies.

How long does implementation take?+

Deployment depends on environment complexity and required integrations. Specialized managed SOC providers can often complete onboarding within two to four weeks.

Does a managed SOC guarantee NIS2 compliance?+

No. A managed SOC supports security operations and evidence collection but does not replace governance, risk management, or an Information Security Management System.

What does a managed SOC cost?+

A managed SOC typically uses a monthly subscription based on the number of assets, users, or systems monitored. Pently uses predictable, fixed pricing per asset, with no additional charges based on event volume, data volume, or use cases.

Managed SOC vs. MDR: what's the difference?+

The main difference is scope. MDR, or Managed Detection and Response, focuses on detecting and responding to cyber threats. A managed SOC provides broader security operations, including 24/7 monitoring, alert analysis, threat hunting, incident response, reporting, and continuous improvement of detection rules.

Can a managed SOC replace an internal security team?+

A managed SOC can complement or reduce the workload of an internal security team, but it does not always replace it. The managed SOC handles 24/7 security monitoring, threat detection, and incident response, while internal teams can focus on security strategy, IT operations, risk, compliance, and business priorities.

Conclusion

There is no universally correct operating model.

An internal SOC offers maximum control but requires significant long-term investment.

Traditional MSSPs can reduce operational effort, but service quality and response capabilities differ considerably between providers.

A managed SOC offers an alternative for organizations seeking continuous monitoring, specialist expertise, and predictable operational costs without building an in-house security operation.

For many German mid-sized companies, for instance in manufacturing, logistics, and energy, the right choice depends on operational risk, available resources, compliance obligations, and the maturity of the existing security program.

If you are evaluating your current security operations, Pently offers a no-obligation assessment of your Microsoft security environment to help determine whether an internal SOC, a traditional MSSP, or a managed SOC best fits your organization's needs.

About the author

Bilal El Hassani

Lead Security Advisor at Pently

Bilal El Hassani guides mid-sized companies from the initial applicability assessment through building an ISMS to audit preparation. His focus is on information security, IT security and strategy. He translates regulatory requirements such as NIS-2 into measures that an IT team without a dedicated security department can actually run.

More articles

Assess your security operations together

In a no-obligation assessment of your Microsoft security environment we clarify which operating model fits your risk profile, your resources and your compliance obligations.

Request an assessmentSee Managed SOC