Flamingo Raises $4.5M Seed Round

Every MSP selling security hits the same wall: clients expect 24/7 threat monitoring, and a security operations center is the machinery that delivers it. Building one in-house runs $1.2 million to $3 million a year before the first client pays a dime. Buying SOC as a service starts around $8 per endpoint per month. That gap looks like an easy call, but it hides trade-offs in margin, control, and what happens at 3 a.m. when an alert fires. Here's the 2026 math for both paths, and the endpoint count where the answer flips.

TL;DR

  • Definition. SOC as a service is a subscription that delivers 24/7 threat monitoring, detection, and response from an external security operations center instead of an in-house team.
  • Buy cost. Published 2026 rates run $8 to $25 per endpoint per month.
  • Build cost. A minimum viable 24/7 SOC runs $1.2M to $3M a year, staffing 65-70% of it.
  • The call. Under 1,000 endpoints buy, 1,000 to 3,000 co-manage, past 3,000 model the build.

What Is SOC as a Service

SOC as a service (SOCaaS) is a subscription model where an external provider runs your security operations center: the people, the detection stack, and the response process. The provider ingests telemetry from your endpoints, networks, identities, and cloud workloads, then triages alerts, hunts threats, and either responds directly or escalates to your team. You pay monthly, usually per device or per user, instead of hiring analysts and licensing a SIEM yourself.

For an MSP the model has a second layer. You're not protecting one company's environment, you're deciding how to deliver security operations across every client you manage. That multiplies both the cost of building and the margin impact of buying. A managed SOC that costs you $11 per endpoint and bills out at $25 changes your P&L very differently than a $2M internal build you have to amortize across your client base.

The stakes keep rising. IBM's 2026 Cost of a Data Breach Report puts the global average breach at $4.99 million, up 12% year over year, and found that one in four malicious breaches is now AI-enabled, with those averaging $6 million. The number that should worry anyone selling monitoring: mean time to identify and contain a breach climbed to 247 days, reversing five straight years of improvement. Detection speed is a financial line item now, and a SOC, whoever runs it, is where detection speed lives.

The Real Cost of Building an In-House SOC

Start with people, because people are the budget. Round-the-clock coverage isn't three analysts working shifts. Once you account for nights, weekends, vacation, sick time, and training, each 24/7 seat needs five to six full-time analysts. A minimum viable SOC covering triage, investigation, and escalation across tiers needs 8 to 12 analysts. Glassdoor puts the average US SOC analyst near $100,000 a year as of mid-2026, with Tier 1 triage at $70,000 to $90,000 and Tier 2 investigators at $85,000 to $120,000. Salaries alone put you past $1 million before you've bought a single tool.

Then comes the stack: SIEM licensing, log storage that grows every time you onboard a client, EDR, SOAR tooling, threat intelligence feeds, and the engineering time to keep detections tuned. Published 2026 build-vs-buy models, including Cyflare's and Radicl's, converge on $1.2 million to $3 million per year for a functioning in-house SOC, with staffing at 65-70% of the total.

Hiring is the quieter problem. ISC2's last published workforce gap estimate, from its 2024 study, put it at 4.8 million unfilled roles. Its 2025 Cybersecurity Workforce Study stopped publishing a gap number and reported something more relevant to your P&L: 33% of organizations don't have the budget to staff their security teams adequately, and 29% can't afford people with the skills they need. Budget, not talent scarcity, is now the binding constraint. Attrition in Tier 1 roles compounds it, because alert triage burns people out and every departure restarts a 3-6 month hiring and training cycle.

The build path isn't irrational. It buys you full control of detection logic, data residency, and client experience, and it can become a product you sell at premium margin. But it's a seven-figure annual commitment with an 18-24 month road to maturity, and it only pencils out when enough endpoints are paying for it.

Talanos, an MSSP that sells the buy side, runs the same staffing arithmetic in two minutes. Worth watching for how quickly the headcount math stops being about salaries and starts being about coverage:

What Buying a SOC Looks Like in 2026

The buy side has matured fast, and the MSP channel is one of its main battlegrounds. Huntress built its business on a human-backed SOC sold through MSPs. Blackpoint Cyber sells MDR with active response aimed squarely at the channel. Arctic Wolf, eSentire, and a long tail of white-label providers round out the field. Published 2026 pricing research from NuHarbor and UnderDefense lands in the same band: $8 to $25 per endpoint per month for detection and response, with flat retainers running $1,000 to $10,000+ monthly depending on log volume, user count, and response depth. Bare alert forwarding sells for $3 to $9, and it's worth exactly that.

Pricing model matters more than sticker price. Per-device pricing scales cleanly with how MSPs bill, so you can bake SOC coverage into your per-seat price and protect margin as you grow. Log-volume pricing is harder to predict and spikes when a chatty client environment doubles its telemetry. Read the overage terms before you sign anything.

White-label deserves its own mention. A white-label SOC lets you sell 24/7 monitoring under your own brand while the provider's analysts do the work. Your clients see your name on the report, and you skip the seven-figure build. The trade-off is depth: you're reselling someone else's process, and when a real incident hits, your techs are coordinating with an external team they've never met. Ask any provider how escalation works at 3 a.m. on a Sunday, and ask for the SLA with the penalty clause attached, not the marketing version.

Build vs Buy: Side by Side

FactorBuild In-HouseBuy (SOCaaS)
Year-one cost$1.2M-$3M$12K-$120K+ per year, scales per device
Time to full coverage12-24 months2-8 weeks onboarding
Staffing burden8-12 analysts, 24/7 rotationZero analysts; vendor manages coverage
Control of detectionsFullLimited; tuning requests go through vendor
Data residencyYours entirelyLogs live in vendor infrastructure
Margin modelHigh margin at scale, loss before itPredictable spread on every endpoint
Exit costSunk build costContract term; telemetry re-pointing

The table understates one thing: risk concentration. When you build, a bad quarter of attrition can gut your night shift. When you buy, a vendor acquisition or price hike hits every client at once. Neither path removes risk, they just move it.

The Build Path: Wazuh and Open Source

If you build, the open-source route cuts licensing out of the equation. Wazuh gives you SIEM and XDR capabilities with no per-endpoint license fee, which is why it keeps showing up in MSP build stories. The software is free; the work isn't. Sizing indexers, building decoders for client-specific log sources, tuning out false positives, and keeping clusters healthy is real engineering time. Our Wazuh deployment guide for MSPs covers the sizing, clustering, and cost math in detail, including where the hidden hours go.

Alert fatigue is the failure mode to plan for. An untuned SIEM will bury two analysts in thousands of daily alerts, and fatigue is what turns a detection miss into a breach headline. Budget the first 90 days of any build almost entirely for tuning, not monitoring. Detection you can't triage isn't detection, it's noise with a dashboard.

The realistic open-source build for a small MSP looks like this: Wazuh for SIEM and endpoint telemetry, an EDR you already resell, a documented escalation runbook, and two to four security-focused techs providing business-hours coverage with an on-call rotation for nights. That's not a 24/7 SOC, and it shouldn't pretend to be one. It's a credible detection capability for $150K-$300K a year in payroll, and for some client bases that's the right product at the right price.

The Buy Path: How to Pick a Provider

Sorting providers starts with sorting acronyms, because vendors blur them on purpose. A SOCaaS provider runs monitoring and detection across your telemetry. An MSSP manages security tooling more broadly. MDR focuses on detection and response, usually anchored to a specific agent. The lines matter for what's in scope when something goes wrong; our breakdown of what MDR covers and how it differs from MSSP untangles the categories before you sit through a single demo.

Evaluate every provider on the same five questions:

  1. Response authority. Will they isolate a host or kill a session themselves, or just email you an alert? Alert forwarding at 2 a.m. is not response.
  2. Telemetry scope. Endpoints only, or identity, cloud, network, and SaaS too? Identity attacks dominated 2025-2026 breach data.
  3. MSP economics. Per-device pricing, monthly terms, multi-tenant console, white-label reporting. If the provider leads with three-year contracts, keep walking.
  4. Escalation clarity. Named contacts, documented severity tiers, SLA with penalties. Ask to see a real, redacted incident report, not a sample.
  5. Exit terms. How do you get your logs and detections out? Lock-in doesn't stop being lock-in because it's wearing a security badge.

Run a 30-day pilot with one mid-sized client before rolling anything out fleet-wide. Every provider demos well; the pilot tells you how they handle your ticket volume, your naming conventions, and your 3 a.m.

Watch how they handle false positives during that pilot, because that's the daily texture of the relationship. A SOC that pages you for every PowerShell execution will train your techs to ignore it within a month, and an ignored SOC is an expensive way to feel secure. The pilot should end with a tuning conversation where the provider shows you what they suppressed, what they escalated, and why. If they can't walk you through that reasoning client by client, the monitoring is a black box, and black boxes are what you were trying to stop paying for.

MSPs run this exact argument in public. One operator's client SOC caught malicious code execution at 2 a.m., sent the report at 6 a.m., had not remediated anything, and asked the MSP to decide whether it counted as an issue:

The Margin Math Nobody Shows You

Work one concrete example before any contract lands on your desk. Say you manage 1,500 endpoints across 40 clients. A per-device SOCaaS plan at $11 per endpoint costs you $16,500 a month, or $198,000 a year. Bill SOC coverage into your security package at $25 per endpoint and you gross $450,000, clearing roughly $250,000 a year on the spread while a vendor staffs the night shift. The same 1,500 endpoints trying to carry a $1.5M internal build would need you to bill $83 per endpoint per month just to break even on the SOC alone, before RMM, backup, licensing, or your techs' time.

That break-even line moves with scale, which is the whole decision in one sentence. At 5,000 endpoints, the same internal build drops to $25 per endpoint per month of cost, and owning the detection stack, the client experience, and the premium pricing starts to beat reselling someone else's SOC. Below the line, buying prints margin. Above it, building compounds. The mistake is deciding by instinct instead of running your own endpoint count through the math.

Two cautions on the model. Price the build at what it costs when hiring goes sideways, not at what it costs on paper: the $1.5M figure assumes you fill every seat the first time, and the ISC2 budget numbers say that's the optimistic case. Price the buy the same way: vendor per-device rates climb at renewal, and a $3 bump across 5,000 endpoints is $180,000 a year straight out of your margin. Model both paths at year three, not year one.

Co-Managed SOC: The Middle Ground

Co-managed splits the work: the provider carries 24/7 monitoring and Tier 1 triage, your team keeps escalation, remediation, and the client relationship. For MSPs with a couple of security-minded techs but no appetite for a night shift, it's often the strongest position. Your techs keep their hands on the tooling and build skills against real incidents, while the provider absorbs the part of the job that burns people out.

Pricing for co-managed arrangements usually lands between pure SOCaaS and a full internal build: expect $2,000 to $8,000 a month depending on endpoint count and how much Tier 2 work stays on your side. The contract detail that matters is the division of responsibility during an active incident. Get it in writing: who isolates the host, who talks to the client, who owns forensics, and who signs the breach notification if it comes to that. Ambiguity there is cheap to fix in a contract and ruinously expensive to discover mid-incident.

It also derisks a future build. MSPs that eventually stand up their own SOC usually get there through co-management: they learn the workflows, inherit tuned detections, and hire analysts gradually instead of fielding a 10-person team on day one. If your five-year plan includes a security practice as a flagship product, co-managed is the on-ramp that doesn't gamble the P&L on year one.

The Call for Your MSP

The short answer by size. Under roughly 1,000 managed endpoints, buy white-label SOCaaS and bake it into your per-seat price. Between 1,000 and 3,000 endpoints, co-manage, keep two security techs in-house, and revisit yearly. Past 3,000 endpoints with security as a named product line, model the build, and start with the open-source stack so licensing doesn't eat the case before staffing does.

Whichever way you go, the SOC decision sits inside a bigger stack decision. Monitoring feeds tickets, tickets feed techs, and the platform holding it together determines whether SOC alerts become fast fixes or swivel-chair chaos. That's the gap OpenFrame is built for: an open, AI-native infrastructure layer for IT and security, with the agents built into the infrastructure rather than bolted on top, so an alert, the ticket it opens, and the endpoint it came from all live in one place. Open source takes the software bill down, the agents take the hours down, and your data stays yours if you change course. Our guide to the full MSP security stack shows where SOC coverage plugs into the rest of the picture.

One more number for the road: IBM found that organizations running AI and automation across prevention, detection, investigation, and response closed breaches about two months faster and paid $1.93 million less per breach. The MSPs winning security deals in 2026 aren't the ones with the biggest SOC. They're the ones who made a clear-eyed build-or-buy call, wrote it down, and put the savings into response speed.

Your clients don't care who staffs the SOC. They care who answers at 3 a.m. Decide who that is on purpose.

Kristina Shkriabina

Content Marketing Lead

Ohayo! I'm Kristina, and I'm doing good things with content, SEO, social, and community at Flamingo. Before IT, I worked as a correspondent for Ukraine's Public Broadcasting Company and have a Master's in journalism.

Related Content

Blog Posts

Product Releases

Podcasts

Webinars

Case Studies

Events

Onboarding Guides

Frequently Asked Questions

MSP Security

SOC as a service is a subscription model where an external provider runs 24/7 security monitoring, threat detection, and response for your environment, replacing the analysts, SIEM licensing, and infrastructure an in-house security operations center would require.
Typical SOC as a service pricing runs $1,000 to $10,000+ per month depending on log volume, users, and response depth. Per-device plans start around $11 per endpoint monthly, which maps cleanly onto how MSPs bill clients.
Industry models in 2026 put a minimum viable in-house SOC at $1.2 million to $3 million per year. Staffing accounts for 65-70% of that, since 24/7 coverage requires 8 to 12 analysts across shift rotations.
SOC as a service delivers dedicated monitoring, detection, and response from an external security operations center. An MSSP manages security tooling more broadly, often including firewalls and compliance. SOCaaS is deeper on detection; MSSPs are wider on management.
Yes. White-label SOC providers let MSPs sell 24/7 monitoring under their own brand while the provider's analysts handle the work. MSPs keep the client relationship and margin spread, but should verify escalation paths and SLAs before committing.
Building starts making sense past roughly 3,000 managed endpoints with security as a named product line. At that scale, a $1.5 million internal build drops below outsourced per-endpoint costs and the MSP owns detections, data, and premium pricing.

About OpenFrame

Both. It's built for MSPs and MSSPs alike.
OpenFrame isn't built to plug into your stack. It replaces it. Instead of duct-taping a dozen tools together (RMM, MDM, SIEM, patching, remote access, each its own login and bill), we bundle it into one unified platform: RMM, MDM, monitoring, automation, remote access, patch management, security monitoring, and ticketing, plus built-in AI copilots. So "does it integrate with X?" usually means: you won't need X anymore.
Most platforms give you one piece and expect you to bolt the rest on. OpenFrame unifies the whole stack in one place, with AI copilots built in. Fewer logins, fewer bills, less duct tape.

MSP AI Agents

Yes. In production MSP shops today, 10% to 25% of tickets close before a human opens them. Thread alone has processed 173 million tickets across 750-plus MSP partners at 96% triage accuracy, handing back 490,000-plus technician hours. Agents own the low-risk, high-volume work (password resets, MFA enrollment, known installs, onboarding and offboarding) and flag anything that touches production data or needs judgment for a human to take.