Home
Blog
SOC platform evaluation checklist for MSSPs: 4 questions to ask
Table of contents
12 min
H2 title on one or more lines.
Share
Copied !

SOC platform evaluation checklist for MSSPs: 4 questions to ask

Four questions MSSPs should ask about SOC platform costs, detection, context, and AI oversight before committing their margin and reputation.
cover image showing a flock of birds against a twilight sky

Key takeaways

An MSSP’s platform choice shapes customer trust. The right managed SOC provider should answer clearly on billing, detection, context, and AI decisions. Here's a SOC platform evaluation checklist for MSSPs.

  • Billing and pricing models: Confirm the billable unit, what changes with data volume, how long raw telemetry remains searchable, and whether pricing stays predictable.
  • Proactive threat detection: Ask which detections are written in-house against named, active adversaries rather than simply imported.
  • Context: Find out what threat intelligence and customer-specific knowledge are applied before an alert reaches analysts.
  • AI oversight: Require tool-call traces, controllable context, and autonomy settings at the workflow level.
  • Proof: Run the same log sources in parallel with your current platform and existing security tools before committing, and use that exercise to answer key questions about rapid service delivery, scalable client management, and key features.

If you run a managed security operations center (SOC), then your contract with your customer is fixed. Per endpoint, per seat, twelve months, signed. Your contract with the platform underneath it often isn't, it moves with how much data you send.

Most of the time that gap stays invisible in your cybersecurity defenses. Then a customer onboards a chatty log source, or a campaign runs for a week and produces a month of telemetry in four days. Your costs move. Your revenue doesn't. The difference is your margin (and the pressure on your in house security team) and you find out after the fact.

That gap is where this article lives, and it isn't only about price. A managed security service provider (MSSP) resells the platform under its own name, which means it inherits four things it didn't build: the bill, the detection content, the context on an alert, and the verdict at the end of it. Here are four questions you should ask every managed SOC provider.

Because remember, you're not buying a SOC platform. You're reselling one.

1. The bill that moves when your traffic does

You sell per endpoint. Ask what your platform counts as one.

Get the definition of the billable unit in writing, then ask for the list of what qualifies. Does a unique IP address count as one? Does an email alias? A distribution list? Does a cloud workload that scales to zero overnight and comes back in the morning with a new address count once, or twice?

Then ask the question underneath it: does that number move when log volume moves? It should stay predictable even during data spikes, which is why flexible consumption models matter. If it does, your worst operational week of the year is also your worst commercial one. An incident becomes a billing event, which directly affects managed security services margins, and you'll be explaining it to a customer who believes they bought a fixed price.

What does a bad month cost? Take an incident you actually handled last year and model the ingestion it produced? And how long the raw data lives, asked separately from how long the alert lives. Alerts and incidents are typically retained for a year; the logs underneath them frequently are not. You are the one holding the forensic and regulatory obligation when a customer asks for evidence from eight months ago.

Ask about data portability in the contract terms, especially around termination clauses. Also ask what operational evidence supports claims of fast response when it matters most.

2. The detection you didn't write

Custom means you wrote it. Imported means you downloaded it. Ask which one you're paying for. The onboarding process should cover deploying agents and tuning detection rules early, because setup directly shapes detection quality.

As above: everyone imports. The question isn't whether the public ruleset is in there. It's what sits on top of it.

Ask how many rules your platform's team wrote this quarter against a named, active adversary. Not techniques, adversaries. The difference lands on your analyst's screen. A generic rule tells you a MITRE technique fired somewhere in the estate and leaves your L2 to work out whether it matters. A rule written against an actor tells you who is in the estate, and what they tend to do next.

If done well during the onboarding timeline, tuning detection rules helps cut false positives, reduce alert noise, and improve detection quality.

Timely detection is commercial as much as technical. Detection is what your customer pays you to bring. If the detection layer is something they could download tonight, that's a hard position to hold at renewal, particularly against a competitor who can name what they wrote.

The best managed security services also support different vendors and tools. Advanced integration capabilities matter, because integration quality affects visibility and detection capabilities across customer environments.

Runbook from an alert in Sekoia.
Runbook from an alert in Sekoia.

3. The context nobody added

Agents are only as good as the context they can see. Ask what happens to an event between the moment it lands and the moment your analyst sees it.

If the answer is "it gets normalised and correlated," that's ingestion, not context. The question is whether anything is applied to it: who the infrastructure belongs to, whether the domain is already known, which campaign the hash appeared in last week, what the actor typically does after this step. Also ask whether the provider operates its own SIEM and how that gives it better control over enrichment and analysis.

If nothing is, that work still gets done. It gets done by hand, by your L1, on every alert. Price it properly, minutes per alert, times monthly volume, times the number of customers you run. Weak context and poor integrations also reduce client visibility and reporting value, making it harder to assess security posture and make informed decisions. It comes out in headcount rather than on the invoice, which is exactly why it rarely gets counted.

And ask who produces it. Not who licences it, who produces it. Those are different answers, and only one of them means someone is researching on your behalf. Ask, too, what vendor support exists, how ecosystem integration is handled, and how service capabilities are continuously reviewed against emerging threats.

Watch this clip to learn more about why this context is so important.

4. The verdict you can't inspect

This is the one that reaches you personally.

When an AI agent triages an alert and closes it, your customer doesn't call the vendor. They call you. You are the name on the contract and on the report, which makes you accountable for a conclusion you may not be able to reconstruct. Its automation should cut repetitive analyst work without creating too much noise or hiding the reasoning.

Three questions.

  • Can it show the queries it ran? Ask to see the tool-call trail for one live investigation. One is enough.
  • Can you tell it anything? An agent reasoning without knowing which server matters, who owns it, or which identities are privileged is reasoning about a generic network, not yours. Ask where that information goes in.
  • Who sets its autonomy, and at what granularity? Per workflow is a different product from a single switch.

A verdict you can't inspect isn't a decision. It's a recommendation you've agreed to sign, and that has direct implications for service quality, analyst fatigue, and MSSP margins.

Alert verdict in Sekoia.
Alert verdict in Sekoia.

How we answer the same four

Briefly, because you'll test it rather than take our word for it as key questions for a SOC partner.

  • We bill on assets, the estate you protect. That number doesn't move because a customer got noisy or because you had a bad Tuesday, which is what makes year-two cost knowable when you sign year one; that commercial clarity matters because SOC operations continue 24/7, 365 days a year. Threat intelligence is part of the platform, not a metered line beside it.
  • Our TDR team writes detections against named, active adversaries, and publishes the research behind them. Sekoia Intelligence is produced in-house and applied to every source at ingestion, so an alert opens already naming the adversary and carrying the TTPs. It's proactive threat hunting, right there in your dashboard, and a good evaluation should also test detection and response maturity against real cyber threats and the provider's response capabilities.
  • We keep all raw telemetry in the platform, accessible via search at anytime. Not only is it useful for hunting and audit purposes, but also vital context for agents performing investigations.
  • And our agents show their work: A full run trace on every action, a context field your analysts control, runbooks you can author, and autonomy you set per workflow (advisory, gated, or autonomous). The dial is safe to turn because the trace is there.

The difference we'd argue matters isn't the discount. It's the model.

list of verdicts in Sekoia
List of verdicts in Sekoia

Evaluation checklist: Take these to your vendor

A strong MSSP organization operates by asking the right questions.

  1. What counts as one billable unit, with the full list of what qualifies?
  2. How many detection rules did your team (or the vendors) write this quarter against a named adversary?
  3. Can the agent show the tool-call trail for one live investigation?
  4. Where do I tell it which of my assets are most important?

Ask for the answers in writing. A written answer is worth more than anything a vendor asserts on a call — ours included.

Run both

There's a simple way to determine whether Sekoia meets your industry standards.

Mirror the same log sources into Sekoia and run it in parallel with what you operate today, at no cost to you. Not a scripted demo on our data, yours, beside what you already run, judged by your own SOC.

If we win, the mirror becomes production. If we don't, nothing was owed.

See how we work with MSSP partners

Cyber Threat Intelligence Platform

Actionable cyber threat intelligence for security teams that need to understand threats faster, focus on what matters, and operationalize intelligence across hunting, detection, and investigation.

Abstract circular icon with a central human figure surrounded by six connecting nodes.