SOC as a Service, Explained for Growing Teams
SOC as a service explained: the functions it delivers, the ones that stay yours, how it differs from MDR, what it costs, and when building in-house wins.

Published 3 September 2026. Figures are drawn from the 2026 SANS SOC Survey, MITRE’s 11 Strategies of a World-Class Cybersecurity Operations Center, IBM’s Cost of a Data Breach Report 2026, the 2026 Sophos Active Adversary Report, and UK government statistics from DSIT and the Home Office.
The security operations centre has an image problem. The phrase suggests a darkened room, a wall of screens, and a shift rota of specialists. Then you look at the data on what SOCs are actually staffed like.
SANS has surveyed security operations teams every year since 2017. In almost every edition, the most commonly reported SOC size has been between two and ten people. The 2026 survey, the tenth in the series, drew on 444 practitioners working in monitoring and security operations roles plus 69 senior security executives, and found a lack of skilled staff to be the single most-cited operational challenge. The small team is not an embarrassing exception to how security operations work. It is the ordinary case.
Which sets up the problem this article is about. A team of two to ten people is asked to cover an environment that generates signal continuously, on behalf of a business that increasingly has to prove that someone is looking. SOC as a service is one answer to that. This guide covers what it actually is, which parts of the job it takes on, which parts stay with you whatever the contract says, what it costs against the alternative, and the conditions under which building in-house is still the better decision.
Short answer: SOC as a service is the outsourced delivery of security operations: monitoring, triage, investigation and incident support, run by an external team on your telemetry, usually charged per user, per endpoint or per volume of data ingested. It differs from a product because you are buying operated capability rather than a console, and it differs from MDR mainly in breadth and in where the contractual commitment sits. It does not outsource accountability, business context or remediation, and those three are the reason the model succeeds or disappoints.
What is a SOC, and what is SOC as a service?
A security operations centre is a set of functions, not a place or a headcount, and SOC as a service is those functions delivered under contract by somebody else. MITRE makes the functional framing explicit in 11 Strategies of a World-Class Cybersecurity Operations Center, the 2022 second edition by Kathryn Knerler, Ingrid Parker and Carson Zimmerman: a SOC meets its constituency’s needs by performing a defined set of functions for that constituency, centred on monitoring, detecting, analysing, responding to and recovering from attacks.
That definition is more useful than the room-with-screens picture, because it is the only version that lets you answer the buying question sensibly. If a SOC is a place, the question is whether you can afford one. If a SOC is a set of functions, the question becomes which functions you need, which you can perform yourself, and which you should rent. Those are different conversations, and only the second one has a good answer for a team of six.
SOC as a service, sometimes written SOCaaS and sold as a managed SOC or an outsourced SOC, is the subscription delivery of those functions. A provider connects to your telemetry, applies its own detection content and process, staffs the hours, and returns triaged and investigated findings along with the evidence trail. You keep the environment. They operate the watching of it.
The eleven functions a SOC actually performs
Breaking the job into functions is the single most useful thing you can do before talking to a provider, because no contract covers all eleven and the gaps are rarely volunteered. The list below is a working decomposition rather than a standard, but every item in it corresponds to work somebody has to do, whoever employs them.
| Function | What it produces | What its absence looks like |
|---|---|---|
| Telemetry collection | The logs, sensor data and identity signal that everything else depends on | Investigations that end at “we cannot tell” |
| Detection engineering | The rules and analytics that turn raw data into candidate alerts | You only detect what shipped in the box |
| Monitoring | Coverage of the hours in which alerts actually fire | A queue that gets read the next working morning |
| Triage | A decision on which signals deserve a human | Everything is investigated, or nothing is |
| Investigation | Scope: which accounts, which hosts, how far it went | You know a machine alerted, not what happened |
| Threat hunting | Findings no existing rule was looking for | Blind to anything your detections do not already model |
| Containment | An isolated host, a disabled account, a revoked session | A notification, and a wait |
| Remediation | The patch, the config change, the removed access | The same incident, again, next quarter |
| Threat intelligence | Context on who is doing this and what they do next | Every alert treated as a first encounter |
| Reporting and evidence | Proof for an insurer, auditor, customer or regulator | An honest answer you cannot substantiate |
| Continuous improvement | Tuning, coverage review, lessons applied | Alert volume rises and precision falls |
Read the table as a procurement instrument. Take it into a vendor call and ask, function by function, who owns it. The useful providers answer quickly and specifically. The answer you should worry about is a confident yes to all eleven.
What SOC as a service delivers, and what stays yours
Three functions cannot meaningfully be transferred, and every disappointing SOC-as-a-service engagement traces back to somebody assuming they had been. Remediation, business context and accountability stay on your side of the line no matter what the service description says.

| Function | Typically transferred | Why the boundary sits there |
|---|---|---|
| Monitoring and triage | Yes, fully | The clearest win. Hours are the thing you are actually short of. |
| Detection engineering | Mostly | Providers bring content built across many customers, which is usually better than what a small team writes alone. |
| Investigation | Mostly | Depth varies sharply between providers. This is where price differences hide. |
| Threat hunting | Sometimes | Often a premium tier, or a fixed number of hours per quarter. Check. |
| Containment | Partly, and negotiated | Requires you to grant a third party permission to act in your tenant. Some organisations will not, which is a legitimate position with a cost. |
| Telemetry collection | Shared | They specify the sources. You deploy, licence and pay for them. |
| Remediation | No | Patching, configuration, identity hygiene and access removal touch systems the business owns and depends on. |
| Business context | No | Nobody outside your organisation knows that the finance director travels in August or that the odd-looking service account runs payroll. |
| Accountability | No | Under Article 20 of NIS2, responsibility for managing cybersecurity risk sits with the entity and its management body. A regulator asks you. |
The third row from the bottom deserves particular attention, because it is where most of the residual work lives. A provider can tell you at 03:00 that a legacy authentication protocol is being abused against three accounts. Turning that protocol off, and absorbing whatever breaks when you do, remains an internal project with an internal owner. Budget for that owner. Engagements fail more often from an unstaffed remediation queue than from bad detection.
Fully outsourced, co-managed, or hybrid
The same label covers three quite different operating models, and picking the wrong one is more expensive than picking the wrong provider. The distinction is not how much you pay. It is who holds the platform and who holds the process.
- Fully outsourced. The provider brings the platform, the detection content and the people. You connect sources and receive findings. Fastest to stand up, lowest internal load, least visibility into how decisions were reached, and the hardest to unwind. Suits organisations with no security specialist at all.
- Co-managed. You own the platform, typically a SIEM or an extended detection stack you already licence, and the provider operates it alongside your team, often covering nights and weekends while you cover business hours. You keep the data and the detection content. Requires someone internal who can hold a technical conversation. This is the model most growing teams should look at first.
- Hybrid, sometimes sold as a virtual SOC. Functions are split individually rather than by clock. The provider might take triage and hunting while you retain investigation and all containment. Most flexible, most demanding to govern, and the model most likely to develop gaps at the seams if the runbook is vague.
One practical test separates these quickly. Ask where the data lands and who holds the tenancy. If the answer is the provider’s platform, you are buying fully outsourced whatever the proposal calls it, and you should read the exit terms before anything else.
SOC as a service vs MDR, MSSP and SIEM as a service
These four categories overlap heavily, and the honest way to tell them apart is by scope and ownership rather than by capability claims. Every vendor in all four boxes will tell you they detect threats and respond to them.
| Model | Scope | Who owns the platform and data | Typical commitment |
|---|---|---|---|
| SIEM as a service | Log collection, storage, correlation and search | Provider hosts, you generally retain the data | Availability and retention, not outcomes |
| MSSP | Broad: device management, patching, monitoring across a mixed estate | Usually yours, managed by them | Service levels on tickets and uptime |
| SOC as a service | The security operations function, frequently on tooling you already own | Either, and this is the question that matters | Coverage hours, triage and investigation |
| MDR | Narrower and deeper: detection through investigation to containment | Usually provider tooling, or yours in mature offerings | A contracted response, ending in action |
The cleanest way to see the difference between the middle two is to ask what happens after the finding. SOC as a service is scoped by breadth: it aims to operate your security function across whatever you feed it. MDR is scoped by outcome: it aims to contain a specific class of threat within an agreed time. Neither is superior. They answer different questions, and plenty of organisations buy both without realising it.
If your immediate problem is that nobody is watching between 18:00 and 08:00 and you want someone contractually obliged to act rather than notify, our guide to what MDR is and when a business needs it covers that decision in detail, including the seven triggers that make it urgent. If your problem is broader, that you have no security operations function at all and need one assembled, keep reading here.
The arithmetic that decides this for most growing teams
A week contains 168 hours and a full-time analyst covers roughly 40 of them, so continuous cover of a single position needs 4.2 people before anyone takes a day off. That number is the whole argument, and it is worth working through properly rather than accepting a vendor’s version of it.
Start with the leave floor. Article 7 of Directive 2003/88/EC entitles every worker in the EU to at least four weeks of paid annual leave, and it is not among the provisions member states may derogate from. UK statutory entitlement is 5.6 weeks including bank holidays. Add sickness, training days, handover time and the fact that a rota with no slack collapses the first time two people are unavailable at once, and the realistic figure per continuously staffed position lands between five and six people.
Then decide how many people are on shift at once. One is common in proposals and poor in practice, because the moment that person starts investigating something real, nobody is watching anything else. Two is the honest minimum.
| Model input | Value used | Basis |
|---|---|---|
| Hours per week requiring cover | 168 | Arithmetic |
| Contracted hours per analyst per week | 40 | Common full-time norm |
| People per position, before absence | 4.2 | 168 divided by 40 |
| Minimum paid annual leave | 4 weeks EU floor, 5.6 weeks UK | Directive 2003/88/EC Article 7; UK statutory entitlement |
| People per position, after leave and absence | 5 to 6 | Assumption, stated so you can vary it |
| Median advertised salary, core cyber role | £55,000 | DSIT analysis of UK job postings, 2024 |
| Employer on-cost multiplier | 1.25 | Assumption covering national insurance, pension, equipment and training |
Run those inputs through three coverage choices and the decision usually makes itself.
| Coverage you want | Analysts required | Annual people cost |
|---|---|---|
| Business hours only, no nights or weekends | 2 to 3 | £138,000 to £206,000 |
| Continuous, one analyst on shift | 5 to 6 | £344,000 to £413,000 |
| Continuous, two analysts on shift | 10 to 12 | £688,000 to £825,000 |
Three things about those figures. They are people costs only, before the SIEM, the ingestion charges, the recruitment fees and the tooling. They assume you can hire, which the DSIT labour market research suggests is easier than it was, with the estimated annual UK workforce shortfall falling to 3,800 in 2024 from 11,100 the year before, but still not instant. And they assume nobody leaves, when SANS has consistently found three to five years to be the most common tenure in a SOC role.
The direction of travel makes this harder rather than easier. DSIT’s cyber security sectoral analysis for 2026 found the average security team shrinking, from 31 staff to 27, and from 204 to 180 in large enterprises, with sector employment up only 3%, the slowest growth since the series began in 2018. Teams are being asked to cover more with fewer people, not more.
This is the real reason SOC as a service exists, and it is a more honest one than the skills-shortage story that usually gets told. For a company of eighty people, continuous coverage is not a line item that got cut. It is a line item roughly the size of the entire IT budget.
Where the in-house case becomes real again
Buying stops being obvious at the point where you would be paying for the same capability twice, and the crossover is a calculation you can do with your own quote. Divide your loaded in-house estimate by the annual per-user price you have been offered. The result is the user count at which building becomes cheaper than buying.
Do not stop at that number, though, because four conditions move the answer more than price does.
- You already employ the people for other reasons. Regulated firms, organisations shipping their own software, and anyone running an internal risk function often have most of a security team already. Adding coverage to an existing team is much cheaper than creating one.
- Your environment is unusual. Operational technology, bespoke line-of-business applications and heavily customised estates all reduce the value of detection content built across a general customer base.
- Your data cannot leave. Sovereignty requirements, classified material or contractual restrictions can rule out models where telemetry lands in a provider’s platform. Co-managed exists largely for this case.
- You need context more than you need hours. If your incidents are being missed because nobody understands the application, not because nobody was awake, external analysts will not fix it.
There is also a partial answer worth considering before the full one. Covering business hours in-house and buying nights, weekends and holidays is the most common co-managed arrangement for a reason: it targets spend at exactly the window where the risk concentrates. Sophos, analysing 661 incident response and managed detection cases handled between November 2024 and October 2025 across 70 countries, found ransomware activity peaking outside standard business hours, and recommends continuous monitoring on that basis.
The numbers you will be shown, and how much weight they carry
Most alert-volume statistics in this market come from vendor-sponsored surveys in which practitioners estimate their own team’s coverage, and they should be read as sentiment rather than measurement. That does not make them worthless. It makes them a different kind of evidence than they are usually presented as.
The most widely quoted current figure comes from Vectra AI’s 2026 State of Threat Detection and Response report, published on 10 February 2026 and based on 1,450 security practitioners and decision-makers. It reports an average of 2,992 alerts per day, down from 3,832 the previous year, with 63% still going unaddressed. It also found 69% of respondents running more than ten detection and response tools, and close to 40% running more than twenty.
Two cautions. The 63% is self-reported estimation, not instrumented data, and the research is published by a company selling the remedy. Competing surveys put the same figure nearer 40%, and the gap between the two is mostly a definitional argument about what counts as addressing an alert. Treat the direction as reliable and the decimal places as decoration.
The SANS 2026 survey is a better guide to where the work actually is, because it asks practitioners about their own operations rather than about the industry. It found endpoint security generating 86% of day-to-day responses against 78% from SIEM, while SIEM skills were the most sought-after in hiring by roughly double the demand for endpoint skills. It also recorded 79% of respondents using AI or machine learning tools, but only 36% having built them into a defined workflow.
That last split is the one to carry into a vendor conversation. Nearly everyone has AI in the SOC. Barely a third have decided what it is allowed to conclude on its own.
What breaks when you leave
Exit terms are the most consequential and least examined part of a SOC-as-a-service contract, because two years of tuned detection content and historical telemetry are assets you may not own. This gets discovered at renewal, which is the worst possible negotiating position.
Four things need to be settled in writing at signature.
- Historical log data. How far back does retention go, in what format can you extract it, and what does extraction cost? Retention is where providers quietly manage their own margins.
- Detection content. Rules tuned to your environment over two years are genuinely valuable. Establish whether they are yours, theirs, or licensed to you only while you pay.
- Case history. Investigation records are the evidence base for your next audit and your next insurance renewal. Confirm you can export them.
- Tenancy. If the platform is in their tenant, migration is a project. If it is in yours, it is a permissions change.
Retention deserves a specific warning, because the failure is common and silent. Sophos reported that cases with missing telemetry doubled year on year in its 2026 dataset, driven substantially by firewall appliances shipping with default retention of only seven days, and in some cases twenty four hours. No provider, internal or external, can investigate what was never recorded. Before you evaluate anyone’s analysts, check what your own devices are keeping. This is foundation work that belongs underneath the detection layer, and it is cheaper than any service.
What to ask before you sign
Six questions expose the difference between an operated security function and a monitoring product with a service-shaped price. All six are answerable on a first call.
| Ask this | What a weak answer reveals |
|---|---|
| Which of the eleven functions are you contracting to perform? | A yes to all of them means the boundary has not been thought about, and you will find it during an incident. |
| What does “24/7” mean in this contract? | Continuous monitoring, continuous triage and continuous investigation are three different commitments with three different prices. |
| Are you permitted to contain, and what specifically may you do? | If containment needs your approval, your response time is your availability, not theirs. |
| Whose tenant holds the data, and what leaves with me? | Vagueness here is the single strongest predictor of a painful exit. |
| What is the escalation path, and who is the named human? | A shared mailbox at 03:00 on a Sunday is not an escalation path. |
| What evidence do I receive for an auditor, insurer or regulator? | Reporting is the deliverable you will use most and evaluate least. |
The first question is the one that does the most work, which is why the function table earlier in this article is worth printing out.
How SOC as a service is priced
Four pricing bases dominate, and the same organisation can receive quotes that differ by a factor of three purely because of which unit was chosen. Model your own numbers against each rather than comparing headline rates.
| Pricing basis | Works well when | Bill rises unexpectedly when |
|---|---|---|
| Per user or per identity | Headcount is stable and devices per person are high | You hire quickly, or take on contractors and seasonal staff |
| Per endpoint or per device | Device count is well understood and controlled | Servers, virtual machines and cloud workloads get counted the same as laptops |
| Per gigabyte ingested | Log volume is predictable | An incident, a new source, or a verbose application. Volumes spike precisely when you cannot negotiate. |
| Flat tier or per seat covered | You want budget certainty | Growth pushes you into the next tier mid-year |
Three costs sit outside the headline in almost every proposal. Onboarding and tuning are usually charged separately, and cover the period in which the service is least effective. Incident response with hands on keyboard during a major event is often a separate retainer rather than an inclusion, and the difference matters enormously on the worst day of your year. And the telemetry itself, the licences and ingestion that feed the service, remains yours to pay for. Ask for a worked example using your own user, device and volume counts, and compare that against the coverage arithmetic above. Our pricing page sets out how per-user pricing works in practice against those variables.
SOC as a service, NIS2 and the accountability that does not move
Outsourcing the operation of security does not outsource responsibility for it, and NIS2 is explicit on the point. Article 20 places the duty to manage cybersecurity risk on the entity and its management body, including approving the measures and overseeing implementation. Article 23 requires an early warning to a competent authority within 24 hours of becoming aware of a significant incident, and a fuller notification within 72 hours.
There is a subtlety worth getting right. The 24-hour clock starts on awareness, so slow detection does not by itself breach the deadline. What it does is worse. It extends the period an attacker operates unobserved, and it leaves you assembling a 72-hour notification out of telemetry that has already rolled off retention. Coverage and retention are therefore reporting controls as much as detection controls.
If you are unsure whether these duties reach you, our two-minute NIS2 applicability check settles it quickly, and Who does NIS2 cover, and what you actually have to do sets out the obligations that follow. The NIS2 overview maps the directive onto the controls involved.
The commercial pressure often arrives before the regulatory one. UK government research illustrates how thin the foundations still are: the Cyber Security Breaches Survey 2025/2026, run for DSIT and the Home Office with fieldwork between August and December 2025, found formal incident response plans in only 25% of businesses, rising to 57% of medium-sized and 76% of large ones. Meanwhile 44% of micro businesses now use an external cyber security provider, up from 39%. Buying the capability is running ahead of documenting it, which is the wrong order when someone asks for evidence rather than assurance.
SOC as a service in a Microsoft environment
If you run Microsoft 365, you are already generating most of the telemetry a SOC needs, and quite possibly paying for it without operating it. Defender for Endpoint, Defender for Office 365, Defender for Identity, Entra ID Protection and Microsoft Sentinel produce the identity, endpoint and email signal where intrusions surface first.
That has a direct bearing on which delivery model suits you. When the telemetry and the platform are already in your tenant, co-managed is usually the better shape: the provider brings analysts and detection content to a stack you keep, and the exit conversation stays simple because the data never moved. Fully outsourced models that duplicate ingestion into a provider platform mean paying twice for the same events, and the second copy is the one you lose at the end of the contract.
The gap worth naming is between owning the signal and operating it. A licence produces alerts. It does not produce anyone reading them at 02:00. Closing that gap is what a layer across Sentinel, Defender, Intune and Entra ID is for, and the detection and response platform applies it to an existing estate without replacing it. The security architecture behind that is worth reviewing alongside any provider’s.
Why shared defence changes the arithmetic
The strongest argument for renting security operations is not cost, it is that the same tradecraft hits many organisations in sequence, so the second target can be defended with what the first one already revealed. An in-house SOC of six people sees only what happens to six people’s worth of environment.

IBM’s Cost of a Data Breach Report 2026, covering more than 600 breached organisations across incidents between March 2025 and February 2026, put the global average cost at $4.99 million and mean time to identify and contain at 247 days, 183 to identify and 64 to contain. That reversed five consecutive years of improvement. Breaches running past 200 days averaged $5.65 million against $4.32 million for those resolved sooner. The gap between those two figures is what detection speed is worth, and detection speed is largely a function of having seen the technique before.
That is the reasoning behind UnifiedONE’s shared defence intelligence: an attack investigated once in one member environment becomes a validated detection for every other member. The weekly account of what attackers actually did to Microsoft environments is published openly in The Repeat, and the same reasoning underpins how ransomware is contained, covered in our guide to what ransomware is and how to prevent it.
How this is packaged depends on who carries the operational load: managed service providers running many tenants, smaller organisations with no dedicated security team, or enterprises that already run a SOC and need coverage rather than replacement.
Frequently asked questions
What is SOC as a service?
SOC as a service is the subscription delivery of security operations by an external provider: monitoring your telemetry, triaging alerts, investigating what matters and supporting incident response, charged per user, per device or per volume of data. You keep the environment and the accountability. The provider supplies the analysts, the process and usually the detection content.
What does a security operations centre do?
A security operations centre, written security operations center in US usage, performs the functions that turn raw telemetry into decisions: collection, detection engineering, monitoring, triage, investigation, hunting, containment, threat intelligence, reporting and continuous improvement. MITRE frames a SOC as a set of functions performed for a constituency rather than as a physical room, which is the framing that makes the build-or-buy question answerable.
What is the difference between SOC as a service and MDR?
Scope and commitment. SOC as a service is broad: it operates your security function across whatever telemetry you provide, and is measured on coverage, triage and investigation. MDR is narrower and deeper: it commits contractually to detect and contain specific threats within an agreed time. Many providers sell both, and the category names overlap enough that you should judge the contracted commitment rather than the label.
How much does SOC as a service cost?
Published prices vary by more than an order of magnitude, so the useful comparison is against the alternative. Continuous in-house cover needs 4.2 analysts per position before any absence, realistically five to six, or ten to twelve if two people are on shift at once. At a UK median core cyber salary of £55,000 plus employer costs, that is roughly £344,000 to £825,000 a year in people alone, before tooling.
Can a small business use SOC as a service?
Yes, and small organisations are the clearest case for it, because the coverage arithmetic does not scale down. A company of forty people faces the same ransomware affiliates as one of four thousand but cannot staff a rota. The prerequisites are the same at any size: know what you own, enforce multi-factor authentication, and retain logs long enough to investigate with.
How do you evaluate SOC as a service providers?
Start with the function list and make the provider state which ones they contract to perform. Then establish what “24/7” covers, whether they may contain without waiting for you, whose tenant holds the data, who the named escalation contact is, and what evidence you receive. Ask for a worked price using your own user and volume counts, and read the exit terms before the feature list.
Will AI replace the SOC?
Not on current evidence. The 2026 SANS SOC Survey found 79% of respondents using AI or machine learning tools but only 36% having integrated them into a defined workflow, and staffing remained the top-cited challenge. AI is changing what triage costs, not whether investigation, containment and remediation need an accountable human. Ask providers what their automation is permitted to conclude without review.
In short
- A SOC is a set of functions, not a room. Decompose the eleven and ask a provider which ones they are contracting to perform. A confident yes to all of them is the answer to worry about.
- Remediation, business context and accountability do not transfer. Under NIS2 Article 20 the duty stays with the entity and its management body.
- The arithmetic drives the decision: 168 hours divided by a 40-hour week is 4.2 people per position before any leave, five to six after it, and ten to twelve for two analysts on shift. That is £344,000 to £825,000 a year in people alone.
- Co-managed suits most growing teams: you keep the platform and the data, the provider covers the hours you cannot, and the exit stays simple.
- Alert-volume statistics are mostly vendor-sponsored self-reporting. Vectra’s 63% unaddressed and the competing 40% differ mainly on what counts as addressed. Read the direction, not the decimals.
- Settle retention, detection-content ownership, case history and tenancy in writing at signature. Sophos found missing-telemetry cases doubled year on year, driven by seven-day default log retention.
- Small SOCs are the norm, not the exception. SANS has found two to ten people to be the most common size in almost every year since 2017.
Sources
- SANS Institute, 2026 SANS SOC Survey Insights: A Decade of Evolution in Cyber Defense, Christopher Crowley, 2026, based on 444 security operations practitioners and 69 senior security executives. Retrieved 28 August 2026.
- Kathryn Knerler, Ingrid Parker and Carson Zimmerman, 11 Strategies of a World-Class Cybersecurity Operations Center, MITRE, second edition 2022. Retrieved 28 August 2026.
- IBM Security, Cost of a Data Breach Report 2026, July 2026, based on more than 600 breached organisations, incidents between March 2025 and February 2026. Retrieved 28 August 2026.
- Sophos X-Ops, Nowhere, man: The 2026 Active Adversary Report, February 2026, based on 661 incident response and managed detection cases handled between 1 November 2024 and 31 October 2025 across 70 countries. Retrieved 28 August 2026.
- Department for Science, Innovation and Technology, Cyber security skills in the UK labour market 2025, published 2 February 2026, delivered by Ipsos and Perspective Economics. Retrieved 28 August 2026.
- Department for Science, Innovation and Technology and Home Office, Cyber Security Breaches Survey 2025/2026, published 30 April 2026, fieldwork August to December 2025. Retrieved 28 August 2026.
- Department for Science, Innovation and Technology, Cyber security sectoral analysis 2026, May 2026. Retrieved 28 August 2026.
- Vectra AI, 2026 State of Threat Detection and Response Report, 10 February 2026, based on 1,450 security practitioners and decision-makers. Vendor-sponsored research based on self-reported estimates. Retrieved 28 August 2026.
- European Union, Directive 2003/88/EC concerning certain aspects of the organisation of working time, Article 7. Retrieved 28 August 2026.
- European Union, Directive (EU) 2022/2555 (NIS2), Articles 20 and 23. Retrieved 28 August 2026.
Written by
Sher Khatak
UnifiedONE



