Do You Need a SOC for a 40-Person Company? The Truth About MDR

Sep 20, 2026

0 Comments

Do You Need a SOC for a 40-Person Company? The Truth About MDR

Managed detection and response security operations for a small business

If your company has 40 employees, you probably do not need to build a full, internal Security Operations Center (SOC).

You may still need the protection a SOC provides.

That is where managed detection and response (MDR) fits. MDR gives you continuous security monitoring, threat investigation, and incident response without requiring you to hire a round-the-clock security team.

The right answer depends on your data, customers, industry, technology environment, and risk tolerance. Headcount is only one factor.

FIRST, WHAT DOES “SOC” MEAN?

In this context, a SOC is a Security Operations Center. It is the people, processes, and technology responsible for monitoring your environment and responding to threats.

A SOC typically watches:

  • Employee laptops and servers
  • Cloud infrastructure
  • Microsoft 365, Google Workspace, or other SaaS platforms
  • Identity and access systems
  • Firewalls and network devices
  • Email security events
  • Suspicious logins, file changes, and data transfers

A SOC is not the same thing as SOC 2.

SOC 2 is an independent examination of security and related controls. It can help demonstrate trust to customers and partners. It does not automatically provide 24/7 monitoring or incident response.

According to Vanta’s SOC 2 guidance, SOC 2 uses five Trust Services Criteria: security, availability, confidentiality, processing integrity, and privacy. Security is required. The other criteria apply when relevant to your business.

You might need SOC 2 for a major customer contract. You might need a SOC to detect an attack. Those are related goals, but they are different requirements.

DO YOU NEED A FULL SOC WITH 40 EMPLOYEES?

For most 40-person companies, an internal SOC is too expensive and too difficult to staff.

A functional 24/7 SOC requires coverage across nights, weekends, vacations, and holidays. A small internal team cannot realistically provide that coverage without several analysts. You also need a security manager, detection tools, log management, threat intelligence, response playbooks, and ongoing training.

A managed SOC or MDR provider spreads those costs across many customers. You get access to specialized analysts and security tooling without building the entire operation yourself.

You should seriously consider MDR if you answer “yes” to one or more of these questions:

  1. Do you store sensitive customer, financial, healthcare, or proprietary data?
  2. Do you operate internet-facing applications or cloud workloads?
  3. Do enterprise customers ask for security monitoring or incident response details?
  4. Are you preparing for SOC 2, HIPAA, PCI DSS, or ISO 27001?
  5. Does your team lack after-hours security coverage?
  6. Would a ransomware incident create serious operational or financial damage?
  7. Do you need documented evidence of security events and response actions?

A 40-person company may be small by headcount but high-risk by responsibility. A healthcare practice, financial services firm, SaaS provider, or government contractor may need stronger monitoring than a larger company with less sensitive data.

WHAT MDR ACTUALLY PROVIDES

MDR stands for managed detection and response.

The provider monitors your environment, investigates suspicious activity, and helps contain confirmed threats. The goal is not to send you a stream of raw alerts. The goal is to identify what matters and act quickly.

A practical MDR service may include:

  • Endpoint detection and response (EDR)
  • Cloud and identity monitoring
  • Centralized security log collection
  • 24/7 alert triage
  • Threat investigation
  • Endpoint isolation
  • Credential or access revocation
  • Malicious IP and domain blocking
  • Incident escalation
  • Monthly security reporting
  • Threat hunting
  • Incident response coordination

The exact scope matters. Some providers only monitor endpoint alerts. Others monitor endpoints, identity, email, cloud infrastructure, and network devices.

Ask what is included before comparing prices.

Managed SOC and MDR pathways for an SMB security program

MDR VS. MANAGED SOC VS. MSSP

These terms overlap, but they are not identical.

MDR usually focuses on detecting and responding to threats. It often centers on endpoints, cloud workloads, and identity systems.

A managed SOC usually describes a broader outsourced security operations function. It may include MDR, SIEM management, log correlation, threat hunting, compliance reporting, and incident response.

An MSSP, or managed security services provider, may manage security infrastructure such as firewalls, VPNs, endpoint tools, vulnerability scanning, and monitoring. Some MSSPs provide strong detection and response. Others primarily forward alerts to your internal team.

The name matters less than the deliverables.

A good provider should clearly explain:

  • What systems are monitored
  • Who investigates alerts
  • What happens after a threat is confirmed
  • Which response actions the provider can take
  • How quickly critical alerts are escalated
  • Which services cost extra
  • What reports you receive
  • What your team must handle

If a provider cannot explain the workflow in plain English, keep looking.

REALISTIC MDR COSTS FOR A 40-PERSON COMPANY

MDR pricing varies based on endpoints, log volume, cloud complexity, response authority, and service-level agreements.

As a general planning range, a 40-person company with approximately 40 to 60 endpoints may budget:

  • Basic endpoint MDR: $1,000–$2,500 per month
  • MDR with identity and cloud monitoring: $2,000–$4,000 per month
  • Broader managed SOC coverage: $3,000–$7,500 per month
  • Advanced compliance, threat hunting, and response support: $5,000–$10,000+ per month

These are planning ranges, not a quote. Licensing, onboarding, SIEM data volume, cloud accounts, and incident response retainers may be billed separately.

A provider may also charge:

  • $5,000–$20,000 for onboarding and initial configuration
  • $10,000–$40,000 for a security assessment and remediation roadmap
  • $15,000–$50,000+ for a formal incident response engagement
  • $25,000–$80,000+ for a first-year SOC 2 readiness and audit program

You should receive a written scope and an all-in cost estimate before work begins.

THREE PRACTICAL SERVICE OPTIONS

You do not have to choose between “do nothing” and “build an enterprise SOC.”

OPTION 1: BASELINE SECURITY PROGRAM

This is the starting point for a lower-risk company.

Typical scope:

  • MFA deployment
  • Endpoint protection
  • Secure email configuration
  • Backup review
  • Access cleanup
  • Basic vulnerability scanning
  • Security awareness training
  • Incident response plan

Typical timeline:

  • Assessment: 1–2 weeks
  • Priority remediation: 30–60 days
  • Ongoing review: monthly or quarterly

This option improves your security foundation but may not provide true 24/7 monitoring.

OPTION 2: MDR FOR CRITICAL SYSTEMS

This is often the right fit for a 40-person company.

Typical scope:

  • EDR on employee devices and servers
  • Identity monitoring
  • Cloud log collection
  • 24/7 alert triage
  • Documented escalation process
  • Endpoint containment
  • Monthly executive reporting

Typical timeline:

  • Discovery and design: 1–2 weeks
  • Tool deployment: 1–3 weeks
  • Detection tuning: 2–4 weeks
  • Ongoing monitoring: continuous

This approach gives you stronger protection without paying for a complete enterprise SOC.

OPTION 3: CO-MANAGED SECURITY OPERATIONS

This works well when you already have an IT manager, internal administrator, or security lead.

The provider handles:

  • After-hours monitoring
  • Alert triage
  • Threat intelligence
  • Detection engineering
  • Specialized investigations
  • Incident response support

Your internal team handles:

  • Business decisions
  • User communication
  • Application ownership
  • Strategic risk acceptance
  • Internal remediation

Co-managed security combines internal knowledge with external security expertise. It is one of the clearest managed service provider benefits for small and mid-size companies: you extend your team without creating another full-time department.

24/7 managed detection and response monitoring across endpoints and cloud systems

HOW MDR SUPPORTS SOC 2 AND OTHER REQUIREMENTS

MDR does not make you SOC 2 compliant by itself.

It can support important control areas, including:

  • Continuous security monitoring
  • Alert investigation
  • Incident response
  • Access and endpoint visibility
  • Evidence collection
  • Security event documentation
  • Response testing and reporting

SOC 2 is risk-based. Your controls must fit your business and the systems within scope. The Vanta overview of SOC 2 requirements explains that each organization defines controls appropriate to its environment.

If a customer requires SOC 2, start with the requirement itself. Confirm whether they need a Type 1 or Type 2 report, which systems must be included, and when the report is due.

Do not purchase a large compliance program simply because another company told you that every business needs one.

WHAT TO ASK AN MDR PROVIDER

Before signing, ask these questions:

  1. What endpoints, cloud accounts, identities, and applications are monitored?
  2. Is monitoring 24/7/365, or only during business hours?
  3. Who investigates alerts?
  4. What is the response time for critical incidents?
  5. Can the provider isolate devices or disable compromised accounts?
  6. Will you receive raw alerts or investigated incidents?
  7. What tools and licenses are included?
  8. How long is data retained?
  9. What reports support audits and cyber insurance reviews?
  10. What happens if your environment changes?
  11. Is incident response included or billed separately?
  12. How does the provider transfer knowledge to your internal team?

A provider should be flexible as your business grows. Your security program should not become a black box that only one vendor understands.

THE BOTTOM LINE

A 40-person company usually does not need an in-house SOC.

It may need continuous security monitoring, fast threat investigation, and a dependable incident response process. MDR or a managed SOC can provide those capabilities at a realistic cost.

Start with your risk. Define the systems that matter. Build the minimum effective scope. Then expand as your customers, data, and operational complexity grow.

At Five 9, we begin with an honest assessment rather than a packaged answer. Our security services cover vulnerability management, compliance support, cloud and infrastructure security, monitoring, and incident response planning. Our consulting services can help you assess gaps, implement controls, and transfer knowledge to your team.

You can also review our broader services to determine whether you need targeted cybersecurity consulting, managed IT services for small business, or ongoing technology advisory support.

Schedule a no-pressure consultation. Tell us what you need to protect, what your customers expect, and what your budget allows. We will help you separate essential coverage from unnecessary complexity.

Secure cybersecurity foundation for a small business with monitoring, access control, and incident response

Five 9 Assistant

Automated · not a live person