We are a 60-person tech company developing B2B SaaS and logistics software. Our infrastructure consists of around 35 hybrid cloud servers, 2 database clusters, and roughly 80 end-user workstations. Due to regulatory compliance and client audits, we decided to outsource our Security Operations Center (SOC) services.
We received proposals from three well-known local cybersecurity firms. The monthly rates are pretty close to each other; they quoted 75,000 TL, 82,000 TL, and 90,000 TL respectively. However, digging into the technical specifications and annexes completely baffled us. Even though the prices look similar, the services they're pitching seem to belong to entirely different worlds.
One vendor's idea of 24/7 monitoring is literally just forwarding automated SIEM alerts, while another bundles 5 hours of monthly incident response (IR) support. One charges by log source, while another caps you by events per second (EPS). What line items should I include in a comparison matrix to present this to the board and make an apples-to-apples evaluation?