White-label SOC for MSPs, MSSPs and resellers: how the model actually works
A white-label SOC means an outside team runs security monitoring for your customers under your brand: your logo on the report, your name on the ticket, your account manager on the call, and an operator behind you who never appears. Partners look for this because the arithmetic of hiring is brutal: round-the-clock coverage is not four analysts, it is closer to eight once leave, attrition and a real shift roster are accounted for — and because customers keep asking for something the partner cannot yet sell. It is a good model. It is not a free one, and this page is about both halves.
- Last checked
- Compared with
- building your own SOC
- How we sell
- Only through partners
Where the two models differ
The dimensions that decide which one a partner should buy, including the ones where we come off worse.
| Dimension | Cyber Defense | building your own SOC | Edge |
|---|---|---|---|
| Time to your first customer | Weeks. The lines that install nothing — exposure management, leak detection — can be live in the week you sell them. | A year or more before 24/7 coverage is real, and longer before the runbooks behind it are worth anything. | OURS |
| What round-the-clock really costs | A monthly unit per customer with a floor, so your cost is known before you quote and it moves with the customers you win. | A payroll line that exists whether or not you sold anything this quarter, plus tooling, plus the recruiting to replace whoever leaves. | OURS |
| Control over quality | You inherit somebody else's methodology and mostly see it through reports. Ask for the escalation path and a sample report before you sign, not after. | Yours end to end. You can change a playbook on Monday because you decided to on Sunday. | THEIRS |
| Who owns the customer | You do — provided the operator has no direct sales motion. Check that before you believe it, because it is the whole basis of the arrangement. | You do, with nobody else in the room at all. | EVEN |
| Where the knowledge accumulates | Detection engineering lives with the operator. If you leave, the tuning does not follow you unless your contract says it does — so make it say so. | Everything the team learns stays inside your company and compounds there. | THEIRS |
| Margin structure | Fixed unit cost in, your own price out. Margin improves as you add customers rather than as you add staff. | Margin only appears once utilisation clears the fixed cost of the team, which is why sub-scale SOCs lose money quietly for years. | OURS |
| Liability and notification duty | Delegated work is not delegated responsibility. The contract with the end customer is yours, and so is the breach-notification duty. | Identical, with fewer parties in the chain to coordinate when it happens. | EVEN |
When you should choose building your own SOC instead
If one of these is your situation, take it seriously and buy the other thing. We would rather lose the deal than be the wrong line on your price list.
- Security operations is the product you sell, not an attachment to an IT service. If the SOC is the thing customers are buying, owning it is the business.
- You already have three or more analysts and enough case volume to keep them busy. Past that point an operator is a cost rather than a capability.
- A contract, a regulator or a public-sector tender requires your own staff, your own facility, or in-country processing that a third party cannot satisfy.
- You have one customer large enough to fund a team on their own, which changes the arithmetic completely.
- Your differentiation is a detection approach you invented and do not want to hand to anyone else to operate.
What a partner should actually do
A white-label SOC is the right shape for a partner whose customers keep asking for security and whose own business is not security operations. It turns a hiring problem into a unit cost and lets you sell next month instead of next year. It is the wrong shape if you want to own the craft, if you have already passed the volume where a team pays for itself, or if you cannot get comfortable judging quality through reports rather than over someone's shoulder. Two things to insist on before you sign anyone: an operator with no direct sales motion — otherwise your customer list is somebody's prospect list — and a written escalation path with names and times on it. Cyber Defense sells only through partners, which is why we can state the first one plainly.
Questions partners ask before they commit
What does white-label SOC mean?
An arrangement where an outside security operations team monitors, triages and escalates for your customers, but everything the customer sees carries your brand. The operator has no relationship with the end customer, does not appear on the ticket and does not sign the contract.
How is a white-label SOC different from MDR?
MDR is normally bought as a vendor-branded service — the customer knows the vendor's name and often logs into their console. A white-label SOC is a delivery arrangement behind your own service. The work can look similar; the difference is whose brand is on it and who owns the relationship.
Will my customer find out who is really behind the SOC?
Not from the reporting, if the operator is genuinely white-label. The place arrangements get exposed is a live incident, when someone needs to be on a bridge call at 3am. Ask any operator you evaluate exactly how that call is handled, in writing, before you sign.
What does a white-label SOC cost?
It is normally priced per unit rather than per hour — per customer per month for monitoring, per domain for exposure and leak detection, per site for OT. The number that matters is the floor, because that is the cost you carry on a customer who has a quiet month.
Can I keep the SIEM I already own?
It depends entirely on the operator, and it is the question that decides most evaluations. Ours runs managed SOC on zcr, so that line means moving telemetry; our detection engineering line works against the platform you already have. Get a straight answer on this early — it is expensive to discover late.
How quickly can I start selling?
The services that install nothing move fastest. Exposure management and leak detection need no agent and no credentials, so a customer can be live in a week and you have something to sell while the monitoring deployment is still being scheduled.