Attackers don't work 9–5. They operate at night, on weekends, on holidays, precisely when no one is watching. A Security Operations Center (SOC) is the answer to that problem: continuous monitoring of your IT environment around the clock. But is it relevant for a Danish SMB, or is it reserved for the big players?
What a SOC actually is
A SOC is a function: a team of security analysts who continuously monitor logs, alerts, and events across your IT infrastructure. They use specialized systems such as SIEM (Security Information and Event Management) to aggregate and correlate data from all your systems, and they respond actively when anything suspicious is detected.
An in-house SOC typically requires:
- Minimum 4–6 analysts to cover 24/7 with shift rotation
- Specialized security platforms (SIEM, SOAR, EDR)
- Ongoing skills development in a rapidly evolving threat landscape
Realistically, that's an investment of 3–8 million DKK per year. Clearly not an option for most SMBs.
MDR: the outsourced alternative
Managed Detection and Response (MDR) is what most SMBs should consider instead. An MDR provider delivers SOC functionality as a service: it installs agents on your systems, monitors 24/7 from its SOC, and responds actively to incidents: either by isolating a device, blocking an attacker, or contacting you with a recommendation.
MDR pricing in a Danish SMB context: An MDR service typically starts from DKK 3,000–8,000 per month for a business with 20–50 devices. That includes endpoint monitoring, 24/7 SOC coverage, and incident response. Compared with the cost of a single successful attack, it is a sensible investment for many.
What 24/7 monitoring actually means
Attackers typically spend over 200 days moving around a network before striking. During that period, there are traces: unusual logins, strange network traffic, unexpected files. Without monitoring, no one sees these traces. With MDR, they're detected and acted upon while the attacker is still active, not only once the damage is done.
Who needs it?
That's a fair question. Not all SMBs need MDR. It typically makes the most sense if:
- You are subject to regulation (NIS2, financial sector, healthcare)
- You handle highly sensitive data: personal data, patient data, financial data
- You are a supplier to critical infrastructure or larger businesses
- You have previously experienced a security incident
- You have cyber liability insurance that requires active monitoring
For others, strong IT hygiene delivers the greatest security return for the money and should be prioritized first: MFA, updated software, backup and segmented networks.