What a SOC is and why it is becoming essential
A SOC (Security Operations Center) is the function that centralizes the monitoring of an organization's security events: log collection, detection of abnormal behavior, alert qualification and triggering a response. In practice, a SOC continuously observes what happens on workstations, servers, network equipment and applications, looking for signals that indicate suspicious activity — an unusual connection, an abnormally large volume of exported data, an account attempting to access resources it never normally uses. As attacks diversify (phishing, ransomware, account takeover, exploitation of software vulnerabilities), having a detection capability is becoming an increasingly structural topic, including for mid-sized companies that historically considered this the preserve of large groups with substantial security budgets.
What building an in-house SOC really involves
Building a SOC in-house means recruiting and retaining several specialized profiles (SOC analysts, detection engineers, possibly a security lead overseeing the whole function), deploying and operating tools (SIEM, EDR, threat intelligence platforms), organizing hourly coverage suited to the business's needs, and keeping these skills up to date against threats that evolve rapidly from one year to the next. It is not a project that ends once the tools are installed: an in-house SOC requires continuous management, regular updates to detection rules, and constant monitoring of new attack techniques. It is an option that makes sense for organizations with enough activity to justify a full-time dedicated team, or specific regulatory and sector constraints that require full in-house control of this function. The main challenge is not only financial: it is also the availability of qualified profiles on the market, in a context where demand for these skills far outstrips supply.
The managed SOC: the principle and its limits
A managed SOC (SOC as a Service) consists of entrusting all or part of this monitoring function to a specialized external provider, who pools its teams and tools across several clients. The company gets a detection capability without bearing alone the cost of recruitment and tooling, which makes this function accessible to organizations that would not have the means to build a complete SOC in-house. It is not an instant universal solution: quality depends heavily on the integration achieved with existing systems, the scope actually covered (all systems or only part of them), and the agreed service level (response time, coverage hours, escalation channels) — elements that must be clearly defined for each engagement, rather than assumed by default or presumed identical from one provider to another.
Costs and talent scarcity: the core problem in Morocco
In Morocco as elsewhere, experienced cybersecurity profiles (SOC analysts, detection engineers) are scarce and in high demand, which makes recruitment slow and costly for an SME for which this is not the core business. Turnover in these roles is also a real issue: an analyst trained over several months can be poached by a larger organization, forcing the company to restart the recruitment and training cycle. Building a complete team capable of broad coverage has a significant fixed cost, regardless of the actual volume of incidents to handle — this cost exists whether the business faces an intrusion attempt every week or every quarter. It is this argument of scarcity and fixed cost that leads a large share of SMEs and mid-sized companies to see a managed SOC as a more realistic option to access detection capability without tying up several full-time positions on a function that is not their core business. This scarcity also affects intermediate profiles (security leads, architects) needed to oversee an in-house SOC team, which further complicates building a complete, self-sufficient team without at least some external support for the initial setup.
Decision criteria: how to choose
Several criteria help decide between the two options, or define the right balance between them. The size and complexity of the infrastructure: the larger and more heterogeneous the information system, the greater the value of continuous monitoring. Specific regulatory or sector constraints that may impose certain in-house control requirements depending on the industry. Existing internal maturity: an existing IT team, even a small one, greatly eases integrating a managed SOC by handling technical liaison and following up on recommendations. Available budget, keeping in mind that a full in-house SOC represents a significant recurring investment, while a managed SOC generally fits into a more predictable and scalable cost model. In practice, many organizations choose a hybrid model: a small internal team that manages the relationship with an external managed SOC, retains detailed business context knowledge, and makes final decisions, rather than a strictly binary choice between the two options. It is also worth revisiting this decision periodically: an SME that grows, changes industry, or migrates a significant part of its infrastructure to the cloud may see its needs evolve, which justifies reconsidering the balance between internal and external capabilities rather than treating the initial choice as final.