TL;DR: Security teams are discovering that SOC staffing, tooling, and alert volumes no longer fit sustainable in-house operating models, according to Expel, with turnover, false positives, and 24x7 coverage costs compounding the problem. Data-driven sizing and hybrid coverage now matter more than aspirational staffing plans.
NHIMG editorial — based on content published by Expel: SOC economics, staffing, and alert fatigue in modern security operations
By the numbers:
- Women represent only 22% of cybersecurity professionals globally, constraining the talent pool before hiring even begins.
- If analyst utilisation consistently exceeds 70%, the team is already operating in a burnout-prone zone rather than an efficient one.
Questions worth separating out
Q: How should security teams size a SOC for sustainable coverage?
A: Start with real alert volume, average handling time, and the amount of time analysts can spend at full effectiveness before quality drops.
Q: Why do overloaded SOCs miss identity abuse and privileged access anomalies?
A: Because identity events often look normal until they are correlated with other signals.
Q: What do security teams get wrong about automated SOC reporting?
A: They often treat report generation as a formatting task instead of a control point.
Practitioner guidance
- Measure true analyst capacity Calculate average handling time, daily alert volume, and target utilisation before requesting headcount or tool budget.
- Tighten detection tuning before expanding tooling Review default rules, remove low-value alerts, and retune detections around your own environment and business processes.
- Build identity telemetry into SOC triage Prioritise privileged account changes, service account misuse, and abnormal authentication events in the same workflow as other high-fidelity incidents.
What's in the full article
Expel's full article covers the operational detail this post intentionally leaves for the source:
- A worked SOC cost calculator that translates alert volume, handling time, and utilisation into headcount requirements.
- Detailed salary and tooling cost ranges for basic, intermediate, and advanced SOC operating models.
- The specific warning signs that indicate a SOC is already beyond sustainable capacity.
- Practical build-versus-buy guidance for organisations deciding between internal, hybrid, and managed coverage.
👉 Read Expel's analysis of SOC staffing, alert fatigue, and operational cost →
SOC staffing and burnout: what security leaders need to do?
Explore further
Alert volume is now a governance problem, not just an operations problem. When analysts cannot keep pace, the organisation has effectively accepted lower detection quality as a structural condition. That changes the risk model for IAM, PAM, and NHI telemetry because identity signals are only useful if they are reviewed in time. Security leaders should treat analyst capacity as part of control design, not as a back-office staffing issue.
A question worth separating out:
Q: Should organisations build, buy, or hybridise SOC operations?
A: The right answer depends on volume, talent access, and the need for continuous coverage. Build works when you can fund staffing, tuning, and retention over time. Buy or hybridise when the organisation needs immediate coverage, lower operational strain, or a better balance between internal expertise and managed triage.
👉 Read our full editorial: SOC economics are breaking the build-it-yourself model