We're a 15-person team developing billing software for the US healthcare sector. We store customer data on cloud servers and have stringent requirements like HIPAA compliance. Last week we met with an external cybersecurity consulting firm; they pitched us a 'Managed SOC' (managed security operations center) service priced at 3,500 dollars a month.
Looking over the proposal, I see a checklist of items like 24/7 log monitoring, threat hunting, SIEM integration, and immediate incident response. But for a core software team of 15 people, this scope feels a bit bloated and expensive.
What does this provider actually do in the middle of the night if there's a suspicious login or an attack attempt? Do they shut down the servers and intervene themselves, or do they just shoot us an email to wake us up? Is a managed SOC really a necessity for a company our size, or just unnecessary operational overhead?