Managed Detection and Response (MDR): Why a 24/7 SOC Is Becoming the New Baseline for UK SMEs, Not a Premium Extra

Home > Sentinel News > Managed Detection and Response (MDR): Why a 24/7 SOC Is Becoming the New Baseline for UK SMEs, Not a Premium Extra

For years the cyber security conversation with SMEs has followed a familiar script: get antivirus in place, put a firewall up, run some phishing awareness training, tick the box, move on. That approach was reasonable when the threat was mostly opportunistic and slow moving. It is no longer reasonable now, and the data backs that up more convincingly than most vendor pitches ever do.

This piece pulls together the most recent UK government statistics, the latest ransomware and breach research, and current cyber insurance underwriting practice, to make the case that Managed Detection and Response (MDR) backed by a 24/7 Security Operations Centre (SOC) is heading the same way antivirus and MFA did: from “nice to have” to “expected.”

A quick definition first, since the two terms get used loosely and interchangeably. MDR is a service in which a third party actively monitors your endpoints, network and identity systems for signs of compromise and takes action when something looks wrong, rather than simply alerting you and leaving you to work out what to do. A SOC is the team and infrastructure behind that service: the analysts, tooling and processes doing the actual watching, around the clock. In practice, most MDR is delivered through a managed SOC, and the two terms overlap far more in commercial reality than the marketing around either would suggest. The distinction that matters for an SME isn’t MDR versus SOC, it’s monitored versus unmonitored.

The Scale of the Problem, in the Government’s Own Numbers

The most authoritative source on this isn’t a vendor report, it’s the UK government’s own Cyber Security Breaches Survey 2025/2026, published jointly by the Department for Science, Innovation and Technology (DSIT) and the Home Office on 30 April 2026. It’s based on interviews with over 2,100 UK businesses and 1,000 charities.

The headline: 43% of UK businesses identified a cyber security breach or attack in the last 12 months, equivalent to roughly 612,000 businesses. Micro businesses sat at 42% and small businesses at 46%, both lower than medium (65%) and large (69%) businesses, but not by the margin many owners assume. Phishing remains overwhelmingly the most common route in, reported by 38% of businesses, and the survey’s qualitative interviews found a growing sense among business owners that phishing has simply become easier for attackers to pull off at scale.

The NCSC’s own guidance for small organisations puts it plainly: there are 5.5 million small organisations in the UK, and roughly 1 in 2 suffer a cyber incident every year. The NCSC’s point is not subtle. Businesses that assume they’re too small to be worth attacking are working from an outdated model of who gets targeted and why.

What the DSIT survey also shows, and this is the part that should worry SME owners more than the headline breach rate, is that basic cyber hygiene is going backwards for small businesses specifically. Compared with the previous year, small businesses saw declines in cyber security risk assessments (down to 41% from 48%), formal policies covering cyber risk (down to 52% from 59%), and business continuity plans that address cyber security (down to 44% from 53%). Only 19% of businesses overall ran any staff training on cyber security in the past year. Only 47% mandate two factor authentication. Only 5% hold Cyber Essentials certification, despite it being the government’s own recommended minimum standard.

In other words, the everyday reality inside most SMEs looks nothing like the tidy, well governed picture that “we have antivirus and a firewall” implies.

24/7 SOC Monitoring: Why Prevention Alone Keeps Failing

The traditional SME security stack, antivirus, firewall, email filtering, awareness training, still matters. None of it should be dropped. But it was built to stop attacks at the perimeter, and modern attacks increasingly don’t announce themselves at the perimeter at all. This is where continuous, 24/7 SOC monitoring earns its keep: it picks up the activity that happens after prevention has already failed, the same principle behind proactive IT monitoring generally, where catching an issue quickly is almost always cheaper and less disruptive than dealing with the fallout later.

Sophos’s State of Ransomware 2026 report, based on 2,158 IT and security leaders across 17 countries whose organisations had been hit by ransomware in the past year, found that identity based attacks (stolen or abused credentials, not malware signatures) now drive 79% of ransomware intrusions. Malicious email and phishing have overtaken exploited vulnerabilities as the top root cause for the first time in four years. Crucially, smaller organisations (100 to 250 employees) stopped only 34% of attacks before data was encrypted or stolen, compared with 46% for larger peers. Median ransom demands and payments both fell year on year in the 2026 report, but average recovery costs, the cost of getting systems and operations back to normal, separate from any ransom paid, climbed to roughly $1.7 million. Smaller firms are not just as likely to be attacked, they’re demonstrably worse at catching it in time, and the recovery bill has been rising even as ransom payments themselves have fallen.

That gap matters because of how long these things take to surface once prevention fails. IBM’s Cost of a Data Breach Report 2025 put the average breach lifecycle at 241 days, 181 days for an organisation to identify the breach and a further 60 to contain it, the lowest figure in nine years but still the best part of eight months of an attacker sitting inside a network before anyone notices. Breaches contained within 200 days cost organisations an average of $3.87 million; those that ran longer averaged $5.01 million.

Those dollar figures are worth a note of caution before quoting them to a UK SME client: IBM’s dataset is global and skewed heavily towards larger enterprises, so the pound figures a small UK business would actually face are lower. The DSIT survey itself found a median perceived cost of £0 for the most disruptive breach or attack, rising to only £4,000 at the 95th percentile for micro and small businesses, precisely because most reported incidents are low level phishing attempts that get caught quickly, not full blown breaches. The dwell time argument, not the headline cost figure, is the part of IBM’s data that applies squarely to SMEs: the longer an incident goes unnoticed, the more likely it is to escalate from a low cost nuisance into the kind of event that does show up in the higher percentiles, or in Sophos’s ransomware specific recovery figures, which is where the real financial exposure for a small business actually sits. The business case for detection speed, not just prevention, is what the combined data supports, not a claim that every SME breach costs millions.

This is the real argument for MDR and a SOC. Antivirus and a firewall answer the question “can we stop the obvious stuff?” A monitored, human led detection and response capability answers the much harder and much more relevant question: “if something gets past our defences, how long before we know, and how fast can we act?”

AI Is Making the “Spot It Yourself” Approach Worse, Not Better

There’s a reason the timing on this matters now specifically. The NCSC’s own assessment on the near-term impact of AI on the cyber threat concludes that AI will “almost certainly” increase the volume and impact of cyber attacks over the next two years, ransomware in particular. Its reasoning is worth taking seriously precisely because it’s specific, not speculative: AI removes the spelling and grammar mistakes that used to give phishing emails away, and it lets attackers sift through stolen data far faster to work out what’s actually valuable and who to target next. The NCSC is also clear that this lowers the skill bar. Attacks that used to require a capable operator are increasingly within reach of far less sophisticated criminals.

This lands hardest on exactly the layer of defence most SMEs still lean on most heavily: a member of staff spotting something that looks off. That’s precisely the tell AI is designed to remove. It doesn’t make firewalls or antivirus useless, but it does mean the human judgement backstop behind them is getting weaker at the same time as everything else is moving faster.

There’s also a gap opening up in how businesses are managing their own use of AI, not just attackers’ use of it. The DSIT Cyber Security Breaches Survey found that 31% of UK businesses are already using AI, in the process of adopting it, or actively considering it, but only 24% of that group have any cyber security practices or processes in place to manage the risks that come with it. Most SMEs adopting AI tools are not yet thinking about the new exposure that comes with them, on top of the AI enabled threats coming from the outside.

None of this changes the underlying argument, it sharpens it. The case for continuous, monitored detection was already strong on the numbers alone. AI closes the one gap that used to buy defenders a bit of time: the obviously fake email, the clumsy attempt, the thing a sharp eyed member of staff would catch. When that tell disappears, the only backstop left is something actually watching for the behaviour behind the message, not the message itself.

Managed SOC vs In-House SOC: The Build-versus-Buy Economics

The instinctive objection from SME owners is usually cost. It’s worth being precise about what the two options actually cost, because the comparison is not close.

Running genuine 24/7 in-house monitoring, not a single IT person checking a dashboard occasionally, but real round the clock coverage with shift rotation, holiday cover and someone senior enough to make containment decisions at 3am, requires a minimum of five to six analysts even at the smallest workable scale. UK SOC analyst salaries currently sit at roughly £45,000 to £60,000 for Tier 1 and £55,000 to £75,000 for Tier 2 staff, before recruitment costs, SIEM licensing, threat intelligence feeds and management overhead are added. Industry estimates for a credible in-house SOC for a UK SME or mid-market business land at £400,000 to £600,000 a year as a minimum, rising well beyond £1 million for anything more mature, plus £100,000 or more in first year setup and tooling costs.

By contrast, managed SOC and MDR services for UK SMEs typically run from roughly £1,500 to £3,500 a month for a smaller organisation, scaling with endpoint count and service depth, and generally sit well under £150,000 a year even for larger SME environments. The gap isn’t marginal. It’s the difference between a service most SMEs can budget for and a capability most SMEs will simply never be able to justify building themselves, regardless of how much they might want to own it outright.

That’s the practical reason a managed SOC exists as a category at all, and why the outsourced SOC route has become the default rather than the exception: it lets an SME buy access to a mature SOC’s shared capability rather than trying to replicate it alone with two or three stretched IT generalists who also have a help desk to run.

For most SMEs this sits alongside, not instead of, day to day IT Support: the two solve different problems, one keeps your systems running and your people unblocked, the other watches specifically for signs of compromise around the clock.

The Bar Is Being Raised for You, Whether You Act or Not

Even businesses inclined to leave this until “next year’s budget” are increasingly finding the decision made for them, from two directions.

Cyber insurance underwriting has hardened sharply. UK cyber insurers now routinely require evidence of MFA on all remote and email access, endpoint detection and response (EDR) rather than basic antivirus, tested and immutable backups, and increasingly a documented, monitored response capability. The direction of travel in the underwriting community is explicit: an EDR agent that only alerts someone during office hours is no longer considered sufficient by many carriers, because attacks now move in hours rather than the weeks organisations used to have to respond. MDR, precisely because it provides continuous monitoring and active response rather than a tool sitting idle overnight, is becoming the practical way SMEs satisfy that requirement without hiring a security team of their own. Firms that can’t evidence this are increasingly seeing declined applications, reduced cover, or claims disputes when the deployed reality (an agent installed but not properly monitored) doesn’t match what was declared on the proposal form.

Regulation is catching up too. The Cyber Security and Resilience Bill, which completed its Commons stages in June 2026 and is now progressing through the Lords, brings managed service providers into direct statutory scope for the first time, with an estimated 900 to 1,100 UK MSPs coming under ICO oversight, 24 hour initial incident reporting requirements, and fines of up to £17 million or 4% of global turnover for serious failures. Even businesses not directly regulated will feel this through their supply chain: larger clients and regulated organisations are already tightening what they expect from their own suppliers’ cyber security, and that pressure flows straight down to the SMEs supplying them.

Put together, the message from insurers and from government is converging on the same point the NCSC has been making for years through Cyber Essentials: basic technical hygiene is the floor, not the ceiling, and organisations are expected to be able to detect and respond, not just prevent.

What Managed EDR, MDR and a 24/7 SOC Actually Add

Stripped of the marketing language, a genuine MDR service, built on managed EDR and backed by a SOC, gives an SME four things that antivirus and a firewall, on their own, cannot:

  • Continuous human oversight. Someone is actually looking at the alerts, day and night, weekends and holidays included, rather than a tool quietly logging events nobody reviews until it’s too late.
  • Faster detection and containment. Directly against the 181 day identification and 60 day containment average from IBM’s data, and against the fact that smaller organisations currently stop barely a third of ransomware attacks before encryption.
  • Shared, senior expertise at a fraction of the cost of hiring it. The economics only work because the provider’s SOC serves many clients at once, spreading the cost of specialist analysts and tooling that no single SME could justify alone.
  • Evidence for insurers and regulators. A documented, monitored response capability with clear SLAs is increasingly the thing that keeps a cyber insurance claim valid and satisfies the direction of travel in UK cyber regulation.

Choosing an MDR Provider

Not every MDR provider offers the same depth of service, and the gap between them matters more than the marketing suggests. When comparing MDR providers, the questions worth asking are the same ones this article has already raised: is monitoring genuinely 24/7, or does it thin out overnight and at weekends? Are alerts reviewed and acted on by human analysts, or just forwarded on for someone else to interpret? Does the service extend to managed EDR on every endpoint, or only a subset? And critically, does the provider issue the kind of documented SLAs and incident evidence that insurers and, increasingly, regulators will ask to see? A provider that can’t answer these clearly is offering a tool, not a service.

The Conclusion the Data Points To

Ten years ago, antivirus was a discretionary purchase for a lot of small businesses. Today it’s assumed. Five years ago, MFA was best practice for the security conscious. Today insurers won’t quote without it. The evidence from DSIT, Sophos, IBM and the underwriting and legislative direction of travel in 2026 all point the same way for MDR and 24/7 SOC coverage: not as a premium add on for businesses that can afford to gold plate their security, but as the next control that moves from “advanced” to “expected” for any SME that wants to stay insurable, stay compliant with where supply chain expectations are heading, and, most importantly, actually catch an attacker before real damage is done.

The uncomfortable truth in the numbers is this: most SMEs are not being breached because they lack antivirus. They’re being breached, and taking months to notice, because nobody is watching what happens after the antivirus alert fires.

Sources

Note on the figures above: cost benchmarks for in-house SOC build and managed SOC/MDR pricing are drawn from multiple 2026 industry market guide sources rather than a single official study, and should be treated as indicative ranges rather than fixed prices. The DSIT, NCSC, Sophos and IBM statistics are drawn directly from their respective primary published reports.

Picture of Sentinel Data

Sentinel Data