In our latest contract with a major enterprise client, there's a requirement for external SOC integration. We need to forward our server network device, and app logs to a center that monitors 24/7, and respond to incoming security alerts.
We are a 35-person B2B software company. We don't have a dedicated in-house cybersecurity team. Our infrastructure and office network are managed by a 2-person sysadmin team and we have an 8-person dev team on the software side. Management wants to dump this entirely on the sysadmins, but with their current workload they don't want to take on this responsibility alone.
For a company of our size, who should actually own log ingestion, alert triage, and coordination with the SOC vendor? Should we handle this internally with our current staff, or bring in outside consulting?