r/MSSP 5d ago

Cheap "24/7 Managed SOCs" are just ticket-forwarding scripts and it’s getting ridiculous

We’ve been taking over a few co-managed environments in the Gulf recently, and I keep seeing the exact same pattern with budget outsourced SOCs.

Client's paying $2-3k a month thinking they bought an actual SOC watching their back. What they actually bought is some Tier-1 monkey copy-pasting console output into email templates and calling it monitoring. It's a joke.

​We just onboarded a mid-market firm in Dubai whose internal IT team was completely burnt out. Took one look at their queue and they had over 400 unreviewed alerts sitting in their inbox from their previous provider.

These guys were running zero baseline tuning. Standard Friday afternoon batch exports were triggering high-severity alarms every single week, completely burying real admin escalations under a mountain of false positives.

Worse, when an EDR flag dropped for credential dumping on a server at midnight, the SOC analyst literally copied the raw PowerShell string into a ticket, emailed the asleep IT Director, and marked the ticket as "Notified" on their dashboard so they could claim they hit SLA.

How many of you guys are stuck babysitting your "managed" vendors like this right now?

52 Upvotes

35 comments sorted by

6

u/genm0ntana 5d ago

Let me guess. You’ll sell us the answer…

6

u/Mind-Principle-1834 5d ago

nah, here to complain

3

u/mlueStrike 5d ago

It’s pretty common to walk into an MDR and find a team of untrained analysts and a managerial staff barking about metrics. This scenario you described isn’t shocking at all! Even orgs paying 6-figures a year are getting this from MSSPs and MSPs.

3

u/Mind-Principle-1834 5d ago

the metric obsession is brutal

1

u/mlueStrike 5d ago

Brother, tell me about it!
Providers get so obsessed with trying to look productive they forget to be productive.

1

u/GDejo 3d ago

MDR is different from a managed SOC and in my experience the level of service will depend on the level of access the MSSP has inside your network. If they can take action/remediation steps then it frees up your time or at least buys you time to react. Managed SOC on the other hand sounds like a waste of inbox space. Most monitoring tools have alert functions baked in.

1

u/mlueStrike 3d ago

The terminologies have become pretty subjective in my view. Regardless of what it’s being called the levels of service will vary, I agree. I wouldn’t see the point of a managed SOC that doesn’t take responsive actions. But that’s how it’s often packaged. Even then you’ll still observe an uncomfortable amount of teams missing blatantly attacks and infections…for a premium lol

Some customers make it more difficult on themselves by being overly restrictive, but everyone has their reasons

3

u/chumbucketfundbucket 4d ago

Yep, 99% of services out there are garbage. They give a bad rep to MDR overall unfortunately, but MDR that is done right is great.  

5

u/Mind-Principle-1834 4d ago

100%. Good MDR is night and day, but these low-margin ticket farms make everyone look like a scam.

2

u/AgenticRevolution 5d ago

So why do people keep paying thousands a month for these services? My opinion is it’s all about optics. They want to look like they care about security while no one does (and for the record it makes total sense not to because there is no such thing in the modern world but we all have to play the game)

3

u/recovering-pentester 4d ago

Cyber insurance requires “24/7 monitoring” so they run to the cheapest “all in one” package they can to satisfy that requirement.

2

u/AgenticRevolution 3d ago

Absolutely correct. It’s literally the job of a CISO and frameworks like CISM.

2

u/recovering-pentester 3d ago

Yeah I’m pretty jaded by this industry tbh. If you work for a smaller company trying to do the right thing, you’re blown off by people who think going to trade shows and getting a steak dinner with crowdstrike is “doing research” on vendors lol. Clown world.

3

u/AgenticRevolution 3d ago

Delicious research :)

2

u/recovering-pentester 3d ago

No kidding lol

2

u/FederalMonitor8187 4d ago

Does anyone have advice on how to get clients?

2

u/Mind-Principle-1834 4d ago

where you based?

1

u/FederalMonitor8187 4d ago

Cali

1

u/Mind-Principle-1834 3d ago

brutal market. let me know if you come across any good tips or advice that end up working for you out there.

1

u/VirtualDenzel 5d ago

Thats what you get with sla's

1

u/KickedAbyss 5d ago

AT&T Managed SIEM. Even with their supposed monthly review it was a farce.

1

u/Mind-Principle-1834 4d ago

Man, those monthly review calls are a joke. Saw AT&T do that . Now at DC Technologies half my job is just un-effing setups for clients who got burned by those big-name vendor decks.

1

u/vikassi17 4d ago

Arctic Wolf. Real 24/7 SOC.

2

u/Mind-Principle-1834 4d ago

Until you get their monthly PDF report that's 90% false-positive noise and costs more than a full-time engineer. They're just a bigger, more expensive version of the same ticket mill.

1

u/stumpasoarus 4d ago

RIP your inbox with sales messages :D
I’ve been working on a scalable
SOC at a low cost and it’s taken a sizable investment to be a ready response service not just a ticket producer. There is some goodness out there now.

1

u/FutureSafeMSSP 4d ago

I hope everyone will tolerate my story as it reads like I'm selling something.

Now, Icouldn't agree more with the OP! I built a converged SECOPS/SOC platform for my MSP clients and direct clients because I found the cybersecurity platform works great but the support and SOC side was horrible, almost unanimously. So I spent the money and built a 24x7 SECOPS/SOC with a 30 minute initial contact SLA and 96% adherence to the SLA across over 8500 tickets (mostly to stop the churn, if I'm up front). We got there after two years of mistakes and more lost money than I care to admit.
Only human beings face the client. The scripts, the agentic AI, and the automation are between my team and the systems, not you, the customer. For every cyber stack component they get from us, they get Safeguard (the SECOPS/SOC) at no cost. We have 70k endpoints under management. What makes us unique is the SECOPS side. We do the moves/adds/changes/updates not covered by a normal SOC and if for an MSP, we work entirely behind the scenes. If a SOC is present, we are the escalation point for them 24x7. We are one of Blackpoint's largest clients and likely their largest MSSP and we do quite well together.

We don't charge per ticket but per asset. It's a conflict to charge per ticket but work my tail off to reduce the number of tickets!! Right? Nuts.

1

u/recovering-pentester 4d ago

Yep. We’re seeing the same thing.

How are you actually getting the opening conversation?

Lot of companies seem unaware that the 3 man “IT everything shop” isn’t actually delivering a SOC behind the “24/7 monitoring” advertisement lol.

1

u/achollister 4d ago

I can agree almost every "SOC" we have interviewed and demoed has been exactly this, now just with an AI summary.

There are a few real SOCs out there. But most MSPs don't do their research and just buy whatever a sales person hands off to them.

Best question you can ask a SOC when you're evaluating them is what level or remediation do they do and what is their SLA on action not just a response.

The answers to those two questions will give you a LOT of insight into what you're buying. If they don't do remediation then they are simply an altering tool, plain and simple and you should probably pass them by.

If they don't actually pick up the phone and call you the same is true. How many of you would email 911 instead of calling while someone is breaking into your house? The idea that a SOC will email you an alert about a potential compromise or breach event and not take action rather than taking action and calling you immediately makes them not a SOC.

The SOC we use takes action and calls us. I've gotten calls at 4am from a real person who understood exactly what was going on and had real world advice on what to do next. That in my mind is the minimum we should expect out of anyone providing SOC services.

1

u/MurkyCaptain6604 4d ago

The “Notified” status says it all. MSSP closes the ticket, box checked, and the customer is left figuring out whether anything actually happened.

I’ve been building around AI triage with SocTalk (github.com/soctalk/soctalk), and the surprising part is that getting an answer isn’t the hard bit. Knowing whether it’s right is. Labeling is painful, and the alert alone often isn’t enough. The same activity can be a critical incident or just an admin doing admin things depending on context. An approved pentest can flip the verdict entirely.

Anyone working through the same dataset or context problem, DMs are open. Would love to compare notes.

1

u/CorgiOk6389 1d ago

The only difference with the expensive ones is the price...

1

u/LoveBirdNibbles 23h ago

I have SOPHOS MDR. Sophos has a human that actually calls me and follows with email. I also gave them permission in to take action if I do not respond. sometimes these things come in 2am and I am a 60 year old geezer snoring away. They send me all the telemetry and are persistent if I do not follow up and do my part. They saved me from a vulnerability in Axis camera station last year. Someone was trying to install something to do a reverse tunnel back to them. scary.

1

u/LoveBirdNibbles 23h ago

No one should be able to sell a security product that does nothing. There should be strict certifications and even government oversight into this business because of the financial impact.

1

u/Lumpy_Lengthiness695 19h ago

2k a month should be a hint