forumNew topic

The SOC quote itemizes licensing and monitoring fees separately — is this normal?

ÜÜmit K***Member
Job title
Operations manager
Sector
Jewelry
Organization type
a company within a holding
Joined
May 2022
Message
406
#1

We are a manufacturing and distribution company with 85 employees. Our network consists of 120 endpoints and 6 mission-critical servers. To mitigate potential ransomware and data breach risks, we've begun discussions with a Security Operations Center (SOC) provider for 24/7 monitoring.

The proposal we received breaks down into two distinct line items: The first is 42,000 TL for 'Monthly SOC Monitoring and Analysis Fee', and the second is 1,900 USD per quarter for 'Centralized Security Software and EDR Licensing Fee'. For all our previous IT services, we've always been used to a single flat monthly package rate.

Is it standard practice to separate software licensing from the service fee like this? Does having the license in USD while monitoring is in TL expose us to financial risk over the contract term? And if we decide to switch service providers down the road, who actually retains ownership of these licenses?

GGökhan C***Member
Job title
Purchasing manager
Sector
Printing
Organization type
medium-sized business
Joined
Jun 2022
Message
181
Most Helpful#2

Short answer: Yes, itemizing technology licensing costs separately from human-driven monitoring and analysis fees is standard industry practice in SOC proposals, and at an enterprise scale, it actually works in your favor. This breakdown provides full transparency by separating the direct software overhead from the ongoing effort of 24/7 analyst surveillance and incident response.

There are two main reasons behind this model: First, the backend tools—such as SIEM, EDR, and log collectors—are globally developed platforms priced in foreign currency by the vendor, typically charged per user or log volume (EPS / GB). Rather than absorbing currency fluctuations into their service margins, the provider passes these vendor costs through directly. Conversely, the monitoring fee covers the operational labor of shift-based cybersecurity specialists here in Turkey, which is why it is rightfully billed in TL.

The most crucial detail to watch during contract negotiations is license ownership. You need explicit clarification on whether the management tenant is provisioned directly in your company's name or hosted within the provider's multi-tenant pool. If the license is registered directly to your organization, you retain the freedom to terminate the monitoring agreement without losing your deployed agents or historical log data, allowing for a seamless transition to another SOC vendor.

You also need to keep a close eye on the licensing metrics. Is the quoted license strictly capped at 120 endpoints, or is there an ingest limit where intraday log spikes could trigger overage charges? I strongly advise stipulating in the contract that unit costs remain fixed in the event of any overage.

OOkan F***Expert
Job title
Fintech product manager
Organization type
chain store
Joined
Aug 2023
Message
146
#3

Splitting them up is definitely the right approach because EDR is billed per agent, while SIEM/logging is priced per events per second (EPS). Monitoring, on the other hand, is the shift labor cost of the Tier 1 and Tier 2 analysts triaging those alerts. Vendors bundling everything into a single flat rate often throttle your log limits, leaving you completely blind during an actual breach.

ÖÖmer B***MemberCommunity member
Joined
Dec 2022
Message
55
#4

Make sure to verify these points before signing: 1) Are the licenses issued directly to your corporate legal entity? 2) Are there penalty fees if daily log GB or EPS thresholds are exceeded? 3) Is there a contractual guarantee for log archive export upon service termination? 4) Do monitoring SLA breaches trigger service credits or fee reductions?

FFurkan U***MemberCommunity member
Joined
Dec 2024
Message
266
#5

We run a similar setup across 140 endpoints. We pay 48,000 TL monthly for monitoring services and 6,800 USD annually for software licensing. Last year, a vendor offered us an all-inclusive single rate, only to attempt a unilateral price hike four months in because we exceeded our log quota. A transparent, two-line breakdown is always the safer bet.

BBurcu Ö***New member
Job title
Store associate
Sector
Media and publishing
Organization type
40-person manufacturing company
Joined
Sep 2026
Message
2

Doki · Server maintenance contract · 2026

#6

The real trap here is the provider tacking on their own markup and selling the license above MSRP. Call the Turkish distributor for that security software directly and get a ballpark quote for 120 agents. See if the provider is pocketing hidden margins on the licensing side.

JJülide A***Member
Job title
Accounting Manager
Sector
Jewelry
Organization type
20-person company
Joined
May 2024
Message
103

Doki · Vulnerability scanning · 2026

#7

pay close attention to who owns the console. the primary admin account has to stay with you, the msp should just get an analyst role. if things go south tomorrow you don't wanna get locked out of your own systems.

Correction: I misremembered the figure, it was a bit lower.

OOya E***Member
Job title
Human Resources Specialist
Sector
Insurance
Organization type
chain store
Joined
Mar 2024
Message
118
#8

Where software license fees are denominated in foreign currency, the contract must explicitly stipulate that payments will be converted at the Central Bank foreign exchange selling rate on the date of transaction, with invoicing dates strictly scheduled on a quarterly basis.

UUfuk B***MemberCommunity member
Joined
Feb 2024
Message
1
#9

Two years ago we went with a provider that billed everything on a single invoice. When service went downhill and we tried to walk away we discovered all our agents were tied to their shared tenant. It took us two weeks to manually rip the agents off every machine and deploy new ones bringing operations to a standstill. Keeping them completely separated from day one is hands down the best move.

OOrhan E***Member
Job title
Export manager
Sector
Law
Organization type
chain store
Joined
Dec 2025
Message
91

Doki · Vulnerability scanning · 2023

#10

I think differently. Most incidents start with a leaked password, not a vulnerability.

Most time waste accumulates in tasks waiting for approval.

FFerhat A***Member
Job title
Board member
Sector
Advertising and promotion
Organization type
20-person company
Joined
Jun 2024
Message
155
#11

Don't miss this: Taking measures without an inventory leaves doors you haven't seen open.

Good luck with that.

FFatih Z***Member
Job title
Software developer
Sector
Glass
Organization type
regional distributor
Joined
Nov 2025
Message
187
#12

You're right. Having backups accessible on the same network and with the same identity makes them part of the target.

LLeyla K***Expert
Job title
Store associate
Sector
Energy
Organization type
20-person company
Joined
Dec 2024
Message
29
#13

Let me share my experience. Just because everyone does it doesn't mean it's right.

If you have questions, write them; I'll answer as best I can.

AAycan D***MemberCommunity member
Joined
Jul 2023
Message
10
#14

Correct in theory, but it doesn't work that way in practice. Taking notes for two weeks yields better results than a six-month estimate.

This is my opinion, I'm not claiming it's absolute truth.

SSena K***Member
Job title
Accounting clerk
Sector
Media and publishing
Organization type
boutique agency
Joined
Feb 2025
Message
2
#15

This thread is archived.

ÜÜlkü Y***Member
Job title
Logistics planning
Sector
Food wholesale
Organization type
a company within a holding
Joined
Nov 2024
Message
84
#16

Correct. Trying to do this alone is the most expensive way.

When making decisions, write down the worst-case scenario too, not just the best.

MMustafa M***Member
Job title
Quality control inspector
Sector
Food wholesale
Organization type
regional distributor
Joined
Feb 2024
Message
106
#17

I was thinking the same thing. Everything goes well for the first three months; problems arise in the fourth.

DDoruk K***Expert
Job title
Quality Assurance Manager
Sector
Construction
Organization type
20-person company
Joined
Feb 2024
Message
28
#18

There is something to watch out for. The harder it is to reverse a decision, the slower you should make it.

This is my opinion, I'm not claiming it's absolute truth.

ŞŞerife K***Veteran
Job title
Clinic manager
Sector
Electrical-electronics
Organization type
early-stage startup
Joined
Dec 2023
Message
128
#19

Good call starting this thread.

BBeren C***Expert
Job title
Information Security Specialist
Sector
Logistics
Organization type
early-stage startup
Joined
Jul 2023
Message
227
#20

I'd appreciate it if you shared the outcome.

Reply