Every South African CISO faces the same question at some point: should we build our own Security Operations Centre, outsource to an MSSP, or find some hybrid middle ground? The answer is less straightforward than either camp admits.
By Neil Beulecke, Managing Director — Layer7 Networking
The Numbers, Honestly
Let's start with what an internal SOC actually costs in South Africa in 2026.
A minimum viable 24/7 SOC requires at least eight analysts to cover three shifts with redundancy, plus a SOC manager, plus a threat intelligence analyst. At current South African market rates, you're looking at:
- 8 x SOC Analysts (L1/L2): R450,000 - R750,000 each per annum
- 2 x Senior Analysts (L3): R850,000 - R1,200,000 each
- 1 x SOC Manager: R1,000,000 - R1,500,000
- 1 x Threat Intelligence Analyst: R750,000 - R1,100,000
That's R7.5 - R12.5 million in salaries alone — before you add SIEM licensing (R1.5 - R4 million), SOAR tooling, threat intelligence feeds, training, and the physical or virtual infrastructure to run it all. A realistic fully loaded cost for an internal SOC is R12 - R20 million per year.
And that's if you can actually hire. South Africa's cybersecurity skills gap is well documented — we have roughly 12,000 qualified cybersecurity professionals against an estimated demand of 40,000+. Your analysts will be recruited away constantly, and each departure costs six months of productivity.
When to Build Internal
Despite the costs, an internal SOC makes sense in specific circumstances:
Highly regulated industries where regulatory requirements mandate direct control over security operations — certain banking and financial services requirements fall into this category.
Organisations with unique threat profiles that require deep, specialised knowledge of proprietary systems. Mining operations with complex OT environments, for example, may need analysts who understand SCADA protocols intimately.
Very large organisations (5,000+ employees) where the cost per user of an internal SOC approaches the cost of outsourcing, and the organisation has the brand recognition to attract and retain talent.
When to Outsource
Outsourcing to a managed security services provider makes sense when:
Speed to capability matters. An MSSP can have you monitored within weeks. Building an internal SOC takes 12-18 months to reach operational maturity. If you have an immediate compliance deadline or have recently experienced an incident, outsourcing buys time.
Budget constraints are real. A managed SOC service typically costs R150,000 - R400,000 per month, depending on scope — significantly less than the internal alternative for most mid-market organisations.
Your core business isn't cybersecurity. A retail chain, a logistics company, a manufacturing firm — their competitive advantage isn't in security operations. Outsourcing frees leadership attention for core business activities.
The Hybrid Model
The most effective approach for most South African organisations is a hybrid model, and this is what we increasingly recommend:
Internal: Governance, risk, and strategic security. Keep your CISO, your security architect, and a small team focused on policy, risk assessment, vendor management, and strategic direction. These roles require deep organisational knowledge that an MSSP can't replicate.
External: Operational security monitoring and response. Let a specialist handle the 24/7 grind of log analysis, alert triage, threat hunting, and incident response. They have the scale, the tools, and the talent pipeline to do this efficiently.
Shared: Incident response and threat intelligence. Major incidents require collaboration between the internal team (who understands the business context) and the external SOC (who has the technical depth and 24/7 coverage). Joint runbooks and regular exercises keep this interface smooth.
Questions to Ask Your MSSP
If you're evaluating managed SOC providers, these questions separate the serious from the marketing:
- What's your analyst-to-client ratio? Anything above 1:15 means your alerts are competing for attention with too many other clients.
- Where are your analysts located? Time zone alignment matters for incident response. A SOC in a different hemisphere introduces communication delays at the worst possible moment.
- What's your mean time to detect and mean time to respond? Get contractual SLAs, not marketing numbers. And ask how they measure these metrics.
- How do you handle false positives? A SOC that forwards every alert to your team isn't providing a service — it's providing noise. Ask about their tuning process and false positive rate.
- Can I see your incident reports from the last quarter? Redacted, of course. But the quality and depth of their reporting tells you everything about their analytical capability.
The Bottom Line
There's no universally correct answer to build versus buy. But there is a wrong answer: doing neither. Operating without continuous security monitoring in 2026 isn't a risk acceptance — it's negligence. Whether you build, buy, or blend, get coverage in place. The threat landscape doesn't wait for budget approval cycles.
Layer7 Networking provides managed security services tailored to the South African market. We're not the cheapest option — we're the one that answers the phone at 2 AM on a Sunday when you're dealing with ransomware.