forumNew topic

When we buy SOC services, is incident response included, or is it billed separately?

ÜÜlkü A***New memberCommunity member
Joined
Jul 2026
Message
70
#1

We are a mid-sized logistics company with about 45 servers and around 300 endpoints. Due to the recent uptick in ransomware and phishing incidents, we collected proposals from three different vendors for 24/7 outsourced security operations center (SOC) services. Our annual budget sits around the 450,000 TL to 600.000 TL range.

Reviewing the proposals, what confused us most was the Incident Response (IR) part. Two of the proposals broadly list incident detection, alert generation, and customer notification. However, if critical suspicious activity is detected or a ransomware attack kicks off in the middle of the night, whether their team actually logs into our environment and intervenes is left completely vague. Another vendor stated they charge by the hour, asking an extra 3,500 TL per hour of incident response.

For those using SOC services, how do you handle this process during a crisis? Does a baseline SOC package just raise alarms and make phone calls, or can containment actions like isolating a device from the network be included in the contract? How should we define the scope so we don't get hit with surprise invoices?

EEmre O***MemberCommunity member
Joined
Feb 2024
Message
104
Most Helpful#2

Short answer: A standard SOC service typically only covers monitoring, detection, and notification; actual hands-on incident response is almost always a separate discipline requiring an add-on contract. If active remediation authority and procedures aren't explicitly defined in your agreement, their team will merely call you at 2 AM to let you know an alert fired.

This distinction is often overlooked in the market. Tier 1 and Tier 2 monitoring analysts detect suspicious traffic or malware, generate an alert, and notify the customer's on-call sysadmin. Incident response, on the other hand, is a completely different ballgame: figuring out the attacker's initial access vector, removing persistence, running digital forensics, and safely restoring systems requires Tier 3 expertise.

When drafting the contract, clearly separate two distinct concepts. The first is containment authority. You can authorize the SOC team beforehand, through approved playbooks, to isolate a compromised machine via your endpoint agent or block a specific IP on the firewall. This is usually bundled into the monthly fixed fee.

The second is deep-dive incident response. This is usually handled by adding a prepaid 20- or 40-hour IR retainer to your annual contract. Calling in external emergency specialists mid-crisis costs significantly more, and it takes hours just for them to get familiar with your environment. Building a dedicated hourly response bucket into the master agreement is the safest approach.

YYavuz G***Member
Job title
Courier coordinator
Sector
Packaging
Organization type
family business
Joined
Jun 2025
Message
45

Doki · Log management setup · 2023

#3

If your endpoint security tool supports remote actions, define them as automation playbooks in the contract. Before calling you in the dead of night, the analyst should be able to isolate the infected client with one click. That isn't active remediation, that's basic initial response and shouldn't cost extra.

İİlker P***Member
Job title
Graphic Designer
Sector
Education
Organization type
early-stage startup
Joined
Nov 2022
Message
162
#4

During an attack we faced last year, the SOC provider called us in the middle of the night, said "there is unusual encryption activity on your server," and hung up. We had to bring in their response team, and they billed us for 18 hours at 4,000 TL an hour. Definitely get an included response bucket of at least 15-20 hours written into your contract.

DDilara T***Member
Job title
Social media manager
Sector
Logistics
Organization type
a company within a holding
Joined
Aug 2024
Message
333
#5

Put together a RACI matrix immediately. Spell out line by line who gets notified on an alert, who isolates the host, and who verifies the backups. Hand it over and ask, "which of these action items will you own?" Then attach their response as an appendix to the contract.

GGürkan U***Member
Job title
Technical service technician
Sector
Retail
Organization type
medium-sized business
Joined
Jan 2023
Message
2
#6

Be skeptical of budget providers claiming "we handle and fix everything." If an intern analyst working the night shift for minimum wage shuts down your accounting server, the fallout will be worse than the breach itself. Active response without clearly drawn boundaries is extremely risky.

LLevent K***MemberCommunity member
Joined
Jul 2024
Message
2
#7

same thing happened to us they emailed at 4 am saying there was suspicious activity. when we walked in at 8 am the entire file server was already encrypted. tbh if all they do is send alerts theres zero point in paying that money.

IIrmak Ö***ExpertCommunity member
Joined
Aug 2023
Message
153
#8

Do you have an on-call sysadmin internally who can jump on systems kill a server or restore from backups when an alert drops at night? If not, you have to outsource the incident response.

HHakanNew member
Job title
Real estate office
Joined
Sep 2024
Message
34
#9

Doesn't the EDR software automatically quarantine the threat on its own anyway? What's the practical difference between the SOC team doing that manually versus the software handling it?

HHüseyin T***MemberCommunity member
Joined
Nov 2023
Message
42
#10

Bottom line of this thread: Monitoring and alerting are baseline services, while deep IR gets billed extra. To keep costs predictable, write basic isolation actions into the standard package, and include a prepaid hourly response bucket upfront for deep analysis.

TTuğçe E***MemberCommunity member
Joined
Sep 2022
Message
343
#11

There's a trap here, let me mention it. When we decide without measuring we always end up in the same place.

When making decisions write down the worst-case scenario too, not just the best. That's all, sorry if I went on too long.

BBarışExpert
Job title
Chain supermarket
Organization type
regional distributor
Joined
Aug 2023
Message
148
#12

Let me share what happened to me; it might be useful. Forgotten test environments are more often the entry point than live systems.

If I were you, I'd go this route.

MMustafa E***MemberCommunity member
Joined
Feb 2024
Message
83
#13

There is something to watch out for. Security isn't absolute; it's about making attacks not worth the effort.

Just leaving this note, it might be useful.

KKadir G***MemberCommunity member
Joined
Sep 2022
Message
44
#14

Quick summary for newcomers: If you get three different answers on a topic, the question was asked wrong.

Good luck with that.

ÖÖzgür D***Member
Job title
Front office accounting
Sector
Automotive aftermarket
Organization type
20-person company
Joined
Oct 2022
Message
2
#15

My question might sound amateurish, sorry about that. When we decide without measuring, we always end up in the same place.

Most incidents start with a leaked password, not a vulnerability. Hope this helps.

HHakan U***MemberCommunity member
Joined
Apr 2024
Message
43
#16

My questions are cleared up, thanks. Everyone rushing into soc incident response included gets stuck at the same point.

Just leaving this note, it might be useful.

RRecep S***Member
Job title
Production planning
Sector
Retail
Organization type
sole proprietorship
Joined
Sep 2023
Message
103
#17

you're right, I've been down that road too and btw when making a decision first look at what data you have on hand.

taking notes for two weeks yields better results than a six-month estimate.

TTuğçe M***Member
Job title
Operations manager
Sector
Logistics
Organization type
two-branch business
Joined
Jan 2023
Message
362
#18

Let's separate the concepts, they're getting mixed up. If the notification path is long, notifications don't arrive; missing notifications mean delayed incident detection.

Proven by experience.

PPolat A***MemberCommunity member
Joined
Apr 2023
Message
413
#19

i completely agree but having backups accessible on the same network and with the same identtity makes them part of the target.

security isn't absolute; it's about making attacks not worth the effort... btw if you have questions write them; I'll answer as best I can.

TTaner A***Veteran
Job title
Intern
Sector
Advertising and promotion
Organization type
two-branch business
Joined
Mar 2025
Message
406
#20

I agree. If you scold false alarms, nobody will report again.

An untested backup is not a backup. That's all, sorry if I went on too long.

Reply