forumNew topic

Client requires a cybersecurity operations center, is this mandatory for a 20-person company?

NNuri K***Member
Job title
Product Manager
Sector
Real estate
Organization type
sole proprietorship
Joined
Apr 2023
Message
3
#1

We are a Riyadh-based e-commerce infrastructure and warehouse integration company with 20 employees in total. We are currently in technical talks to become a software vendor for a large semi-public retail chain in Saudi Arabia. In their vendor assessment form, their cybersecurity team asked if we have a 24/7 Security Operations Center (SOC) monitoring infrastructure and listed this as a contractual prerequisite.

We do not employ dedicated cybersecurity specialists in-house; two senior software engineers manage our cloud infrastructure and servers. Setting up an in-house 24/7 shift-based operations center would run up to several hundred thousand SAR annually, and it is simply impossible for a 20-person company to fund such an operation with internal staff.

What exactly does this requirement from enterprise clients cover, and is there a way to fulfill it at our scale without building an in-house center? Are outsourced monitoring services sufficient to meet this kind of enterprise prerequisite?

DDeniz K***ExpertCommunity member
Joined
Nov 2024
Message
154
Most Helpful#2

Short answer: A 20-person company is not required to build an in-house 24/7 cybersecurity operations center, and enterprise clients do not expect this from their vendors anyway. This requirement is typically met by contracting an outsourced Managed Detection and Response (MDR) or SOC-as-a-Service solution from a local security service provider.

Enterprise organizations implement this requirement to safeguard their own supply chains. Under Saudi Arabian National Cybersecurity Authority (NCA) regulations, critical infrastructures are mandated to ensure that logs from integrated software vendors are centrally monitored and that any suspicious activity is acted upon immediately.

Here are the steps you should take to fulfill this condition: 1) Instead of hiring internal staff, partner with an MSSP licensed in the local market. 2) Deploy monitoring agents to your servers, databases, and cloud access points, with logs streaming into the provider's central SIEM platform. 3) The provider monitors the logs on a 24/7 basis and executes incident response procedures whenever an anomaly or breach attempt occurs.

Replying on the vendor form with «No in-house SOC; 24/7 monitoring and incident response operations are handled via a contracted and licensed third-party SOC provider» and attaching the Service Level Agreement (SLA) you have in place is completely sufficient to pass the audit.

VVeli Y***MemberCommunity member
Joined
Feb 2024
Message
8
#3

Don't just check the «No» box on the vendor questionnaire. Put a preliminary agreement in place with an external managed security provider and fill out the form stating «Monitored 24/7 via third-party managed SOC infrastructure», otherwise your submission will be disqualified outright.

edit: typed from phone, sorry for typos.

AAhmet A***Member
Job title
Human Resources Specialist
Sector
Construction
Organization type
a company within a holding
Joined
Apr 2024
Message
320
#4

We bid on a similar public tender with a 22-person team. Building it internally would have cost us at least 400,000 SAR a year in payroll alone. We outsourced the SOC service instead; we pay about 4,800 SAR a month for 8 servers and 25 endpoints, and we passed the client audit without any issues.

KKemal S***Member
Job title
Content Editor
Sector
Sports and fitness
Organization type
a company within a holding
Joined
Jul 2022
Message
1
#5

Make sure that the outsourced operations center you choose stores all logs within the borders of Saudi Arabia. Under national data protection frameworks, transferring security logs outside the country can result in administrative penalties for vendors serving critical sectors.

MMerve Ö***MemberCommunity member
Joined
Feb 2026
Message
1
#6

Big enterprises send these vendor questionnaires out as standard templates to everyone. Most of the time they already know a small software shop can't afford that. If you sit down with them and explain that your API endpoints are monitored and you provide guaranteed log retention, they might ease up on the requirement.

SSelin T***Member
Job title
Intern
Sector
Logistics
Organization type
300-person organization
Joined
Sep 2022
Message
2

Doki · Corporate website · 2023

#7

anyone telling a 20-person company to set up an in-house soc has no clue about the market. you'd go broke just hiring three shifts of analysts. just get a shared tier from an mssp and show the contract to the client you'll be fine.

edit: I wrote something wrong above, sorry about that.

GGökhan C***Member
Job title
Studio Founder
Sector
Education
Organization type
chain store
Joined
Jan 2023
Message
64
#8

When evaluating quotes from external providers, check these three parameters: 1) Initial incident response SLA for critical security alerts (should be 15-30 minutes), 2) Log retention of at least 12 months, 3) Monthly incident reporting format that you can present to your client during audits.

IIrmak Ö***ExpertCommunity member
Joined
Aug 2023
Message
153
#9

Does the client's RFP explicitly reference NCA Essential Cybersecurity Controls (ECC) or Critical Systems Cybersecurity Controls (CCC)? If so, which compliance tier is being requested?

HHakan K***MemberCommunity member
Joined
Oct 2022
Message
84
#10

we just enabled security alerts and email notifications on our cloud provider, does that setup aolne not count as satisfying the operations center requirement?

OOnur Y***Member
Job title
Social media manager
Sector
Leather
Organization type
regional distributor
Joined
Aug 2025
Message
120
#11

You're right. Don't rely on a single measure; go layer by layer.

Payment information changes are never verified through the channel they came from. Good luck with that.

EEmine S***Veteran
Job title
Country Manager
Sector
Tourism
Organization type
chain store
Joined
Dec 2023
Message
1

Doki · Infrastructure migration · 2025

#12

I'll argue the opposite, don't get mad... An automated scan report is not the same as a penetration test.

Payment information changes are never verified through the channel they came from. This is my opinion Im not claiming its absolute truth.

PPolat A***MemberCommunity member
Joined
Apr 2023
Message
413
#13

let me summarize whats been said so far... honestly processes without records never improve, because you dont know what to fix.

having backups accessible on the same network and with the same identity makes them part of the targt then btw correct me if I'm wrong.

AAleyna A***Member
Job title
Field sales representative
Sector
Media and publishing
Organization type
120-person company
Joined
Apr 2025
Message
364
#14

Let me summarize what's been said so far. Start with a small trial; don't commit to everything at once.

Good luck with that.

OOnurExpert
Job title
Security developer
Joined
Oct 2023
Message
196
#15

You're right, I've been down that road too. Just because everyone does it doesn't mean it's right.

Taking notes for two weeks yields better results than a six-month estimate.

HHatice Ö***Member
Job title
Production Manager
Sector
Retail
Organization type
regional distributor
Joined
May 2022
Message
240

Doki · Log management setup · 2025

#16

The opposite happened to me, that's why I'm writing. The real issue isn't the number, but what it's based on.

Proven by experience.

RRıdvan Y***Expert
Job title
Software team lead
Joined
Sep 2023
Message
196

Doki · Interface design · 2023

#17

Absolutely. If I were to add anything: Just because everyone does it doesn't mean it's right.

Just leaving this note, it might be useful.

İİlknur Y***VeteranCommunity member
Joined
Jul 2022
Message
3
#18

I feel the same way. An untested backup is not a backup.

Hope this helps.

KKoray B***MemberCommunity member
Joined
Jul 2024
Message
87
#19

Exactly like that. If you don't write this down from the start, it leads to arguments later.

Proven by experience.

FFatma Y***ExpertCommunity member
Joined
Jan 2024
Message
287
#20

let's separate the concepts they're geting mixed up. forgotten test environments are more often the entry point than live systems.

Reply