Attacks do not keep office hours. Most security teams do. Round-the-clock monitoring means trained analysts on every shift, and those analysts are scarce, expensive, and quick to burn out.
The math is the hard part. A week has 168 hours. One analyst covers maybe 40 of them. Keeping a single seat filled at all times, once you count leave, sick days, and training, takes close to five full-time hires.
Most mid-sized teams have two or three people total, for everything. So many stopped trying to build a SOC and started renting one.
That is managed detection and response: a provider runs the monitoring, triage, and first response from its own SOC, for companies that cannot run their own. It is less a product than a way to buy SOC capacity.
Build, rent, or split
MDR is not one thing. In a full model, the provider is the whole SOC, which suits a company with no security staff at all. In a co-managed model, the provider extends an in-house team, usually taking nights, weekends, and first-pass triage, and escalating only validated, high-severity incidents.
Much of the small-business market gets MDR through the managed-service provider that already runs its IT. Which model fits comes down mostly to how many people you already have: none, a team that just needs nights and weekends covered, or a small business whose IT provider runs everything.
What this year's winners are building
The 2026 Cybersecurity Stars Awards map across that spread. ArmorPoint won for a single managed platform across endpoint, network, and cloud, built for a company that has no security team of its own.
Ontinue won in the co-managed lane, with a model built to extend an in-house team rather than replace it: it takes nights and weekends and escalates only what an analyst has already validated.
The harder part of the market is the small business that gets attacked with no one in-house to absorb it, and that coverage usually reaches it through the IT provider already running its systems. Guardz won here for a platform built for the MSPs that protect hundreds of small customers at once. ThreatDown won for MDR that does more than detect: it acts, so a lean team is not left holding the alert alone.
Strip away the platforms, and an MDR provider is a room of analysts working the three-in-the-morning shift. Huntress was named SOC Team of the Year for a 24/7, AI-assisted operations center. Automation clears the noise; a human still makes the call.
What to do now
Renting a SOC is not the same as handing one over. Before you sign:
- Write down who does what at 3 a.m. Use a responsibility matrix. Can the provider isolate a host, disable a compromised account, or block a port on its own, or must it wake your team first? Decide it in advance, not mid-incident.
- Demand response-time commitments, not best effort. First, pin down what "respond" means: acknowledging an alert, triaging it, and acting on it are three different clocks. Get the one that matters, a human acting on a high-severity alert, written into the contract with a number attached.
- Check the integration depth. A provider is only as good as the data it sees. Confirm it connects to your endpoint, cloud, and identity systems at the API level, not just forwarded logs, because if it cannot see the signal or act on it, you have bought blind spots.
- Keep your own visibility. Insist on read-only access to the underlying console so your team can verify the provider's work and hunt independently, rather than seeing only a curated report.
- Run a joint tabletop in the first month. Simulate a serious incident and test the handoff: did they reach the right on-call engineer, did they contain the fire correctly? Find the gaps in peacetime.
For a security leader, the question is no longer whether a SOC earns its keep. It is whether to build one, rent one, or split the work, and how much control to give up: what a provider may isolate on its own, when it escalates, and how much you still see.
The winners answer that last part differently. What they share is the premise underneath it: you do not have to run the SOC yourself to have one.
Part of The Stars Briefing, our editorial series on the trends behind the 2026 Cybersecurity Stars Awards, a program The Hacker News runs. This piece analyzes where the field is moving and uses the winners as examples. It is not a product review. The complete list of 2026 winners is live at awards.thehackernews.com/winners/2026.
