Client support portal Pay invoice Sales(615) 555-0110 Support(615) 555-0111
Chartline Health IT
How we think  ·  27 May 2026  ·  6 min

Why we do not run our own 24/7 SOC

The arithmetic of covering one seat around the clock, and what we do with the money instead.

Prospects ask this, usually because a competitor has told them an in-house security operations centre is better. So here is the arithmetic.

What one seat around the clock costs

Covering a single seat 24/7/365 requires 4.2 full-time employees on paper. In practice it requires eight to twelve analysts once you load in weekends, holidays, paid time off, sick leave, training, and the fact that nobody can sustain permanent night shifts.

At $80,000 to $120,000 per skilled analyst, plus recruiting and certification, a minimum-viable 24/7 SOC runs over $1.5M a year in staffing. Before that there is $1M to $2M in stand-up, and six to eighteen months to reach full operational capability.

For a firm our size, that is more than half of revenue spent replicating something that has become a commodity — and doing it worse than vendors who have specialized in it for a decade and see telemetry from tens of thousands of organizations rather than thirty-five.

What we buy instead

Huntress Managed EDR on every client, Huntress Managed ITDR for identity, Blackpoint Cyber for our highest-risk clients where active containment matters most, and Blumira for SIEM with twelve-month retention. All of it is published on our security and trust page, including the subcontractor list and the BAA status for each.

What we spend our people on

The layer that cannot be bought. Knowing which alert matters in a clinic at 4pm on a Friday. Knowing that the imaging box that just did something strange has done that every Friday for two years because of a vendor's scheduled job. Knowing which practice administrator to call, on which number, and what to say to her so that the right thing happens in the next ten minutes rather than the next morning.

A generic SOC analyst looking at a healthcare alert queue does not have that context and cannot acquire it at scale. It is the whole reason a vertical-specialist provider exists.

The part worth being suspicious about

A provider our size claiming an in-house SOC is usually reselling somebody else's and has decided not to tell you whose. That is the thing to check. Ask who actually watches the queue at 3am, what their employer's name is, and where they are located.

Ours are on the table on the security and trust page, with a BAA against each name. Ask any provider you are evaluating for the same list.

Next step

See where you actually stand.

Fifteen questions, each mapped to a Security Rule citation. You get a scored result naming the specific §164 requirement behind every gap. No call required to see it.

Under attack right now? (615) 555-0119

Our incident line is answered 24/7/365 by a security engineer, not a queue. Clients and non-clients both. If you are mid-incident, call before you email.