B BROCENT

Security Operations Center (SOC): What It Does and SOC-as-a-Service Cost in Asia (2026)

An explainer on the security operations center (SOC): what the function does day to day, how SIEM, EDR, MDR and XDR fit around it, the staffing arithmetic behind 24/7 coverage, how SOC-as-a-service is priced in Hong Kong, Singapore and Asia, eight questions to ask a provider, and what a regulated firm's board report should show.

Security analyst reviewing alerts on multiple monitors in a dark operations room
The short answer: A security operations center (SOC) is a team, process and toolset that watches security alerts 24/7, investigates them and acts within minutes. Staffing one seat around the clock takes about five analysts, so most firms under a few hundred staff buy SOC-as-a-service. Cost is quoted per endpoint, user or data volume, plus onboarding.

A security operations center is the function that answers one question: when an alert fires at 3 a.m., who looks at it, decides whether it is real and does something about it before the morning? Everything else — the SIEM, the EDR agents, the dashboards — is equipment. The SOC is the people and the procedures that turn that equipment into a response.

This guide explains what a SOC actually does, how the acronyms around it fit together (SIEM, EDR, MDR, XDR), why 24/7 coverage is a staffing problem before it is a technology problem, and how SOC-as-a-service is priced in Hong Kong, Singapore and the rest of Asia. If you already know you want an outsourced service, Brocent's Security Operations Center (SOC) service page sets out what our analysts monitor and the response targets we commit to, and the security services pricing page lists the security add-ons that carry published prices.

What is a security operations center (SOC)?

A security operations center is a dedicated capability — in-house, outsourced or a mix — that continuously monitors an organisation's IT environment for security threats, investigates suspicious activity, and contains and remediates confirmed incidents. The word "center" is historical. Many SOCs today are not a room with a wall of screens; they are a distributed team working from a shared platform and a shared rulebook.

A working SOC has three parts:

  • People: analysts who triage alerts (often called tier 1), investigators and incident responders (tier 2 and 3), and someone who owns detection rules and reporting.
  • Process: written runbooks for each alert type, a severity scheme with response times, an escalation path into your management, and a post-incident review.
  • Technology: a place where logs and alerts are collected and correlated (usually a SIEM), endpoint detection and response (EDR) agents on laptops and servers, and integrations with email, identity, firewall and cloud platforms.

Remove any one of the three and you do not have a SOC. Tools with nobody watching them produce alerts that sit in an inbox. People without process produce inconsistent decisions. People and process without telemetry are guessing.

What does a SOC actually do, day to day?

The daily work of a security operations center falls into five activities. When you evaluate a provider, ask them to show you each one.

1. Collect and normalise

Logs and events arrive from endpoints, servers, firewalls, Microsoft 365 or Google Workspace, identity platforms, VPNs and cloud workloads. The SOC makes sure each source is actually connected, that its clock and format are consistent, and that nothing has silently stopped sending. A source that stopped logging three weeks ago is a common and invisible gap.

2. Detect and triage

Correlation rules and analytics raise alerts: an impossible-travel sign-in, a mailbox rule that forwards invoices externally, a server running an unfamiliar encryption process. An analyst decides within minutes whether each alert is a false positive, benign but worth noting, or a probable incident. Good SOCs tune their rules continuously so that analysts are not drowning in noise; alert fatigue is how real attacks get missed.

3. Investigate

For anything that might be real, the analyst reconstructs what happened: which account, which device, what it touched, whether the same pattern appears elsewhere. This is where skill matters most and where a junior analyst working alone at night is weakest.

4. Contain and respond

A confirmed incident needs action: isolate the laptop from the network, disable the compromised account, revoke sessions, block a sender or a domain, and call the named contact at your firm. The single most important contract question is what the SOC is authorised to do on your systems without waking you up first. A SOC that can only email you a ticket is a monitoring service, not a response service.

5. Report and improve

After the incident, a root-cause write-up, rule changes and a monthly report that shows what was seen, what was escalated and how long each step took. This is the evidence you will need for auditors, insurers and your board.

SIEM, EDR, MDR, XDR and SOC: how do the terms fit together?

The vocabulary is confusing because vendors use it to sell overlapping products. Here is the plain version:

  • SIEM (security information and event management): the platform that collects and correlates logs from many sources. Microsoft Sentinel and Splunk are common examples. A SIEM is a tool; it does not respond to anything by itself. See our SIEM solutions page for how we deploy one.
  • EDR (endpoint detection and response): an agent on each laptop and server that records behaviour and can isolate the device. EDR is also a tool.
  • XDR (extended detection and response): a vendor's EDR extended to email, identity and cloud signals in one console. Still a tool.
  • MDR (managed detection and response): a service in which a provider's analysts watch and act on one vendor's detection stack, usually centred on endpoints. Our earlier article on MDR for a Singapore logistics company walks through what that looks like in practice.
  • SOC / SOC-as-a-service: the broader function — people, process and tools — covering every log source you connect, not only endpoints, with reporting and compliance evidence on top.

In short: SIEM and EDR are what a SOC looks through; MDR is a narrower, tool-centred version of what a SOC does; SOC-as-a-service is the whole function rented rather than built.

Why does 24/7 coverage need five or more analysts?

This is the arithmetic that decides most build-versus-buy conversations, so here it is with its assumptions shown.

  • A week has 168 hours (24 × 7).
  • Assume one analyst is contracted for 40 hours a week.
  • Assume about 15% of those hours are lost to annual leave, public holidays, sick days and training. That leaves roughly 34 productive hours per analyst per week.
  • 168 ÷ 34 ≈ 4.9 people to keep one seat filled every hour of the year.

So a single always-on seat needs about five analysts, before you add handover overlap between shifts, a second person at night so nobody investigates a live incident alone, a team lead, and someone who maintains detection rules. A realistic minimum for an in-house 24/7 SOC is therefore six to eight people, plus the SIEM and EDR licences and the engineering time to run them. Multiply that headcount by your own fully loaded cost per security analyst and you have the floor of an in-house budget.

That number is why firms with a few hundred staff or fewer rarely build a 24/7 SOC. They either accept a business-hours-only team (which leaves roughly three-quarters of the week unwatched — 168 hours minus a 45-hour office week is 123 hours) or they buy the function from a provider whose analysts are shared across many clients.

How much does SOC-as-a-service cost in Asia?

There is no honest single number, and you should be wary of any article that gives one. SOC-as-a-service providers in Hong Kong, Singapore and across Asia almost always quote per engagement, because cost depends on what you connect. Brocent's own SOC service is quoted the same way — it is listed as "custom quote" on our pricing pages — and we will not invent a figure here.

What we can tell you is how the price is built, so you can compare quotes on the same basis:

  • Pricing unit: per protected endpoint, per user, per log source, or per GB of log data ingested per day. Ask which one applies and what happens when you grow.
  • SIEM and EDR licences: included in the service fee, or billed separately on your own subscription? Cloud SIEMs such as Microsoft Sentinel are typically billed by data volume and the rate varies by Azure region, so check the vendor's own pricing calculator for your region rather than a figure in a blog post.
  • Log retention: how many days are searchable, and how long logs are archived. Longer retention costs more and may be what your regulator or insurer actually needs.
  • Onboarding: a one-off fee for connecting sources, tuning rules and writing runbooks, usually spread over the first four to twelve weeks.
  • Response scope: whether containment actions (isolation, account disablement) are included, or charged as incident-response hours.
  • Reporting and compliance evidence: monthly reports and audit-ready logs, included or extra.

For context, the security add-ons that Brocent does publish prices for — a Security Starter Bundle, vulnerability scanning, security awareness training and patch management — are listed with indicative USD rates on the security services pricing page, which always shows the current figures. SOC, MDR/EDR and vCISO are custom-quoted. Many small firms start with the bundle and patching, and add a SOC when their risk, regulator or insurer requires around-the-clock response.

In-house SOC vs SOC-as-a-service vs MDR: which fits?

Comparison: three ways to get 24/7 detection and response

  • In-house SOC — coverage: whatever you staff; 24/7 needs six to eight people. Cost shape: salaries plus tools plus engineering, largely fixed. Who acts: your own team, with full context of your business. Fits: large or highly regulated organisations with a security budget and the ability to recruit and retain analysts.
  • SOC-as-a-service — coverage: 24/7 across every log source you connect (endpoints, email, identity, firewall, cloud). Cost shape: onboarding fee plus a monthly fee per endpoint, user or data volume. Who acts: the provider's analysts, within the authority your contract gives them, escalating to your named contacts. Fits: firms of roughly 50 to a few hundred staff that need round-the-clock response and audit evidence without hiring a security team.
  • MDR — coverage: 24/7, centred on one vendor's endpoint or XDR stack. Cost shape: usually per endpoint, often bundled with the EDR licence. Who acts: the MDR provider, mainly on endpoints. Fits: firms whose main risk is ransomware and endpoint compromise and whose other logs matter less.
  • Hybrid (co-managed SOC): your internal IT or security lead handles business hours and context; the provider covers nights, weekends and holidays and the SIEM platform. A common step for firms that already have one or two security people.

Our earlier piece on how a Hong Kong retailer chose SOC as a service looks at the same decision from a multi-outlet retail angle.

Case study: A composite example. A Hong Kong wealth manager with about 120 staff and an SFC licence had EDR on every laptop, but its alerts went to a shared IT inbox read during office hours. After a peer firm's incident, the board asked, "Do we have a SOC?" The honest answer was "we have tools, not a SOC." The firm compared the arithmetic above with two service quotes, chose SOC-as-a-service with containment authority for laptops and Microsoft 365 accounts, and kept its IT manager as the daytime escalation contact. The first monthly report gave the board what it had asked for: who watched, what was found and how fast it was handled.

Does a regulated firm in Hong Kong need a SOC?

Regulators rarely say "you must have a SOC" in those words, and we will not claim a rule says so. What licensed and regulated firms are generally expected to show is that they manage cyber risk, detect and respond to incidents, keep records, and oversee any provider they outsource to. A SOC — in-house or outsourced — is one of the most direct ways to produce that evidence. Ask your compliance adviser to map your specific obligations; our financial services industry page covers how we support regulated firms more broadly.

One newer rule is worth knowing. Hong Kong's Protection of Critical Infrastructures (Computer Systems) Ordinance (Cap. 653) took effect on 1 January 2026. It applies only to operators formally designated under the Ordinance, not to every company, but designated operators must report serious computer-system security incidents within 12 hours of becoming aware of them and other incidents within 48 hours, with a written report to follow. If you are a designated operator, or a supplier whose contract flows those duties down to you, you need someone watching around the clock simply to know about an incident in time to report it.

The cost of not watching is also measurable. IBM's *Cost of a Data Breach Report 2025* put the global average time to identify and contain a breach at 241 days. Most of that is time in which nobody noticed. A SOC exists to shrink the first part of that number.

What should you ask a SOC provider? Eight questions

1. What are your response-time commitments by severity, and are they in the contract? Brocent's SOC targets under 15 minutes from alert confirmation to analyst action for critical (P1) incidents and under 30 minutes for high (P2); see our service levels page for how we define priorities.

2. What can your analysts do on our systems without calling us first? Get a written list: isolate a device, disable an account, revoke sessions, block a domain.

3. Which log sources are included in the price, and which cost extra? Microsoft 365, identity, firewall, VPN, servers and cloud should all be named.

4. Where are your analysts, and are they awake in our time zone? Ask who is on shift at 3 a.m. Hong Kong time.

5. Whose SIEM and EDR licences are we using, and who keeps the data if we leave? Exit terms matter as much as onboarding.

6. How long are logs searchable and archived? Match this to what your regulator, auditor and insurer ask for.

7. What does the monthly report contain? You want sources connected, alerts by severity, incidents, time to detect and respond, and open recommendations.

8. What evidence will you give us for an audit or a regulator's enquiry? Ask to see a redacted sample report and an incident timeline.

What should the board report show?

Boards do not need alert counts. They need a one-page answer to four questions, every month:

  • Coverage: which systems are monitored, and which are not yet connected.
  • Incidents: what happened, how serious it was, and whether any data or money was affected.
  • Speed: time to detect and time to contain, against the contracted targets.
  • Actions: open recommendations, who owns them and by when.

If your current setup cannot produce that page, that is the gap a SOC closes.

Frequently asked questions

What is a security operations center?

A security operations center (SOC) is a team, process and toolset that monitors an organisation's systems for security threats around the clock, investigates alerts and contains confirmed incidents. It can be in-house, outsourced as SOC-as-a-service, or a hybrid of both.

How much does a SOC cost?

An in-house 24/7 SOC needs roughly six to eight people plus SIEM and EDR licences, which puts it out of reach for most firms under a few hundred staff. SOC-as-a-service is usually quoted per endpoint, user or data volume plus an onboarding fee. Brocent's SOC service is custom-quoted; published security add-on prices are on our pricing page.

What is the difference between a SOC and MDR?

MDR is a managed service focused on one vendor's detection tools, usually endpoints. A SOC covers every log source you connect — email, identity, firewall, cloud and endpoints — and adds reporting and compliance evidence. Many SOC services include MDR-style endpoint response.

Does an SFC-licensed firm need a SOC?

We are not aware of a rule that requires a SOC by name, and you should confirm your obligations with your compliance adviser. Licensed firms are expected to manage cyber risk and to detect and respond to incidents, and a SOC is a direct way to evidence that.

Can a SOC act on our systems or only send alerts?

That depends on the contract. A good SOC-as-a-service agreement lists the containment actions analysts may take without prior approval, such as isolating a device or disabling an account, and the cases where they must call you first.

What should a monthly SOC report contain?

Sources connected, alerts by severity, confirmed incidents with timelines, time to detect and contain against targets, and open recommendations with owners.

How long does SOC onboarding take?

Typically four to twelve weeks, depending on the number of log sources, how much rule tuning is needed and whether a SIEM is already in place. Monitoring of the first sources can usually start before onboarding is complete.

Getting started

If your alerts go to an inbox that nobody reads at night, you have tools, not a security operations center. Start by listing what you would want to know about at 3 a.m., then decide whether you will staff that or buy it. Founded in 2007 and headquartered in Singapore since 2021, Brocent has run a permanent Hong Kong office since 2016. See what our SOC service covers and the published security services pricing, or explore our wider managed security services. To get a SOC quote based on your actual log sources, contact our team.

Share:

Ready to take action?

Turn these insights into a roadmap for your business.

Book a 15-minute no-obligation consultation with our APAC IT experts. We'll review your current setup and provide a tailored IT roadmap within 24 hours.

Explore all services
📋

Free Checklist

10 Critical Checks Before Expanding IT to Greater China

PIPL compliance, network segmentation, bilingual helpdesk setup, and more — everything your IT team needs before Day 1 in China.

Request the checklist →

📬 Monthly Asia IT Insights

China compliance updates, cybersecurity alerts, and IT tips for APAC teams — once a month.

No spam. Unsubscribe anytime.