forumNew topic

We got three SOC proposals — what kind of matrix should I build to compare scope and SLAs?

DDoruk G***New memberCommunity member
Joined
Jun 2026
Message
8
#1

We are a 60-person tech company developing B2B SaaS and logistics software. Our infrastructure consists of around 35 hybrid cloud servers, 2 database clusters, and roughly 80 end-user workstations. Due to regulatory compliance and client audits, we decided to outsource our Security Operations Center (SOC) services.

We received proposals from three well-known local cybersecurity firms. The monthly rates are pretty close to each other; they quoted 75,000 TL, 82,000 TL, and 90,000 TL respectively. However, digging into the technical specifications and annexes completely baffled us. Even though the prices look similar, the services they're pitching seem to belong to entirely different worlds.

One vendor's idea of 24/7 monitoring is literally just forwarding automated SIEM alerts, while another bundles 5 hours of monthly incident response (IR) support. One charges by log source, while another caps you by events per second (EPS). What line items should I include in a comparison matrix to present this to the board and make an apples-to-apples evaluation?

ÖÖzge T***Member
Job title
Quality control inspector
Sector
Jewelry
Organization type
workshop
Joined
Feb 2023
Message
193
Most Helpful#2

Short answer: To normalize the proposals, do not evaluate cost based purely on sticker price; build a weighted scoring matrix broken down into four core pillars: monitoring depth, response authority, data quota, and SLA breach penalties. Looking strictly at the monthly base fee is a guaranteed way to see your invoice double during the very first crisis.

When drafting your matrix, start by leveling the scoping model. Have each vendor clarify their limits either in EPS (events per second) or daily log volume in GB. In that same row, document the exact overage fee per additional GB if your projected volume for those 35 servers and 80 users is exceeded. A critical distinction is whether ingestion and monitoring completely halt once the quota is hit.

The second pillar is the level of analysis and intervention. An L1 analyst simply pinging you via email isn't a SOC service, it's a ticketing desk. Add rows for: 'Are L2 and L3 analyst interventions included?', 'How many emergency response hours are allocated per month?', and 'Who handles false positive tuning and rule development?'

The third pillar is SLA metrics. Split the proposed timelines into two: Mean Time to Detect (MTTD) and Mean Time to Respond (MTTR). If a vendor promising 'action within 15 minutes on critical alerts' doesn't back it up with penalties or service credits in the contract, disregard that metric entirely. Once you lay these items side by side, you'll quickly realize that the cheapest proposal is often the most expensive option.

ÜÜlkü K***Member
Job title
Content Editor
Sector
Sports and fitness
Organization type
40-person manufacturing company
Joined
Dec 2024
Message
330
#3

Pay close attention to when the SLA clock actually starts ticking for MTTD and MTTR. Many firms don't start the timer when the alert hits their SIEM, but rather when an on-duty analyst manually acknowledges the ticket. That can easily turn a 15-minute response window into an actual 2-hour wait.

KKemal T***MemberCommunity member
Joined
Feb 2023
Message
4
#4

We signed a deal last year with an 80,000 TL budget for a similar setup. Because they underestimated our log quota, our servers blew past the cap by month three, and we got hit with a 28,000 TL surprise bill. Lock in the daily overage pricing per GB in writing before signing anything.

NNeslihan E***Member
Job title
Board member
Sector
Security services
Organization type
8-person team
Joined
Apr 2025
Message
35

Doki · Corporate website · 2023

#5

Never blindly trust the "24/7" badge in proposals. At many shops the graveyard shift is just an intern or an L1 contractor staring blankly at a dashboard. If a suspected ransomware incident kicks off at 3 AM will there be an actual L2/L3 engineer on call ready to isolate the server or will you be waiting for the 9 AM morning shift?

İİlknur Y***MemberCommunity member
Joined
Feb 2023
Message
98
#6

The 4 most critical checkpoints you need in your comparison matrix: 1) Cost of daily log GB and EPS overages. 2) Whether unused monthly incident response hours roll over. 3) Frequency of detection rule updates and tuning. 4) Historical log retention and indexing periods required for audit compliance.

EErcan Ç***Member
Job title
Graphic Designer
Sector
Furniture manufacturing
Organization type
sole proprietorship
Joined
Aug 2023
Message
57
#7

false positives were our biggest headache. getting fifty useless alerts a day meant everyone just started ignoring them. make sure to put a line in the matrix for how many man-days/hours per month they commit to rule tuning and maintenance.

note: I wrote this based on my own experience, it might not apply to everyone.

OOsman T***Member
Job title
Technical service technician
Sector
Furniture manufacturing
Organization type
a company within a holding
Joined
Jan 2022
Message
3
#8

When presenting to the board, skip the technical jargon and focus on risk vs. total cost. Add an 'out of scope' column right next to the bids. If you don't clearly map out which steps fall on your internal team versus what the SOC vendor actually owns, both sides will just point fingers at each other when an incident hits.

KKemal Ç***Member
Job title
Field sales representative
Sector
Plastic
Organization type
120-person company
Joined
Oct 2022
Message
140

Doki · Interface design · 2023

#9

Demand a 15-day Proof of Concept (PoC) before signing any contract. Hook up at least two critical servers and a handful of endpoints. Do not commit that kind of money without seeing their dashboard usability and alert response speeds with your own eyes in real time.

MMehmet C***Member
Job title
Store associate
Sector
Electrical-electronics
Organization type
120-person company
Joined
May 2025
Message
263
#10

Who is managing the EDR on the endpoints? Are these vendors just ingesting the telemetry, or do they have the authority and tooling to actively isolate a compromised host from the network the moment a threat is confirmed?

OOrhan E***Member
Job title
Export manager
Sector
Law
Organization type
chain store
Joined
Dec 2025
Message
91

Doki · Vulnerability scanning · 2023

#11

I'm a small business, let me explain from my side. Don't hesitate to ask; those who don't ask always pay more.

Of course, it varies if your situation is different.

FFatma E***MemberCommunity member
Joined
Oct 2025
Message
89
#12

here's how it went for us then if 2FA is on a stolen password alone is useless.

if I were you, Id go this route.

NNilMember
Job title
Content manager
Organization type
a company within a holding
Joined
Apr 2024
Message
156
#13

My questions are cleared up, thanks.

NNeşeNew member
Job title
Hair salon
Joined
Oct 2024
Message
21
#14

Ive been dealing with this for a long time. An automated scan report is not the same as a penetration test.

When making a decision, first look at what data you have on hand.

SSelim K***Member
Job title
Sales Manager
Sector
Media and publishing
Organization type
120-person company
Joined
Mar 2025
Message
305

Doki · SEO consulting · 2024

#15

Good call starting this thread.

MMusaNew member
Job title
Intercity freight
Joined
Oct 2024
Message
34
#16

Great work.

HHilal Ö***Member
Job title
Business Owner
Sector
E-commerce
Organization type
medium-sized business
Joined
May 2023
Message
371
#17

Sorry, but this doesn't apply in every case. If the notification path is long, notifications don't arrive; missing notifications mean delayed incident detection.

ZZübeyde K***MemberCommunity member
Joined
Oct 2023
Message
43
#18

I'm curious too.

HHavva Y***Member
Job title
Company Owner
Sector
Catering
Organization type
40-person manufacturing company
Joined
Jul 2023
Message
6

Doki · Mobile app · 2024

#19

I completely agree. Payment information changes are never verified through the channel they came from.

ÖÖzge U***Member
Job title
Marketing manager
Sector
Real estate
Organization type
120-person company
Joined
Apr 2023
Message
18
#20

Quick summary for newcomers: When making decisions, write down the worst-case scenario too, not just the best.

Most incidents start with a leaked password, not a vulnerability.

Reply