Why we do not run our own 24/7 SOC
The arithmetic of covering one seat around the clock, and what we do with the money instead.
Prospects ask this, usually because a competitor has told them an in-house security operations centre is better. So here is the arithmetic.
What one seat around the clock costs
Covering a single seat 24/7/365 requires 4.2 full-time employees on paper. In practice it requires eight to twelve analysts once you load in weekends, holidays, paid time off, sick leave, training, and the fact that nobody can sustain permanent night shifts.
At $80,000 to $120,000 per skilled analyst, plus recruiting and certification, a minimum-viable 24/7 SOC runs over $1.5M a year in staffing. Before that there is $1M to $2M in stand-up, and six to eighteen months to reach full operational capability.
For a firm our size, that is more than half of revenue spent replicating something that has become a commodity — and doing it worse than vendors who have specialized in it for a decade and see telemetry from tens of thousands of organizations rather than thirty-five.
What we buy instead
Huntress Managed EDR on every client, Huntress Managed ITDR for identity, Blackpoint Cyber for our highest-risk clients where active containment matters most, and Blumira for SIEM with twelve-month retention. All of it is published on our security and trust page, including the subcontractor list and the BAA status for each.
What we spend our people on
The layer that cannot be bought. Knowing which alert matters in a clinic at 4pm on a Friday. Knowing that the imaging box that just did something strange has done that every Friday for two years because of a vendor's scheduled job. Knowing which practice administrator to call, on which number, and what to say to her so that the right thing happens in the next ten minutes rather than the next morning.
A generic SOC analyst looking at a healthcare alert queue does not have that context and cannot acquire it at scale. It is the whole reason a vertical-specialist provider exists.
The part worth being suspicious about
A provider our size claiming an in-house SOC is usually reselling somebody else's and has decided not to tell you whose. That is the thing to check. Ask who actually watches the queue at 3am, what their employer's name is, and where they are located.
Ours are on the table on the security and trust page, with a BAA against each name. Ask any provider you are evaluating for the same list.
Eaglesoft, dba, and sql
A practice management system that shipped with hardcoded database credentials, and what to actually do about it in a live operatory.
Read it Behavioral health · 13 May 202642 CFR Part 2 stopped being a paper rule in February
Civil enforcement began February 16, 2026. Almost no generalist IT provider has heard of it, and it sits on top of HIPAA rather than instead of it.
Read it