- Best for
- Buyers that want to outsource most day-to-day SOC monitoring, triage and response workflow
They cover
- Endpoints
- Cloud Workloads
- Identity & Access
- Network
- SaaS Applications
- Data & DLP
Your team still owns
- Keeping the agreed log sources, cloud accounts, endpoint agents and business context current
- Defining which containment actions can run automatically and which need approval
- Owning internal IT remediation, recovery, user communication and business-owner decisions
- Maintaining any customer-owned SIEM, EDR, cloud or identity licenses outside the quoted service
- Separating base SOC scope from risk, protection, DFIR, advisory and managed administration add-ons
Pricing
| Line | Figure |
|---|---|
| Published price | G-Cloud examples from £30,664.70 to £297,154 per year |
| Billing model | Tiered, Custom |
| Contract | Not published |
| Onboarding | Not published |
Tradeoffs
Works well
- Clearer full-SOC fit than endpoint-only MDR because the offer spans defense, risk, protection, platform and SOC operations
- Public sources explain containment, SOAR, reporting, collaboration and regional SOC coverage in operational terms
- Works with buyer tooling or SecurityHQ-managed technology, which helps buyers avoiding a full stack replacement
- AWS Marketplace and G-Cloud provide procurement and pricing signals beyond the website
Watch out for
- Buyers need a detailed scope because SecurityHQ's portfolio includes many separately scoped services
- Pricing is quote-based outside public G-Cloud guidance examples
- Review volume is small compared with larger managed security providers
- A Run the SOC outcome depends on response authority, log coverage and managed administration being included in the contract
What buyers say
Alert noise
Not assessed
Transparency
Not assessed
Customers like
- Review excerpts mention monitoring, triage and threat hunting support
- Customers call out onboarding and communication customization
- Reddit discussion includes SecurityHQ as a managed SOC/MSSP recommendation, but with limited detail
Watch out for
- Gartner shows 4 public ratings, so review depth is limited
- One visible critique mentions defined procedures not always being followed
- Managed SOC Reddit threads repeatedly stress escalation paths and full-stack visibility, not only alert monitoring
Reputation reads from public reviews, not vendor-published numbers.
Ask before buying
- Which daily SOC tasks does SecurityHQ own versus notify or assign back to our team?
- Which containment playbooks can block IPs, suspend users or isolate machines without waiting for approval?
- Does the quote include SIEM management, SOAR playbooks, endpoint response, firewall or email administration, DFIR and log retention?
Integrations
Editorial notes
Why run the SOC
SecurityHQ's official material and AWS Marketplace listing describe 24/7 defense, risk and protection services, global SOCs, SIEM and SOAR workflow, triage, investigation, containment, reporting and customer collaboration. That supports Run the SOC when the contract covers the managed SOC bundle.
Scope boundary
SecurityHQ sells multiple service families. The public profile covers managed SOC and managed security services, not every risk, protection, advisory, offensive security or DFIR service unless it is included in the buyer's quote.
Response boundary
Public material supports containment playbooks, automated blocking, user suspension and machine isolation. Buyers still need rules of engagement because sensitive actions, restoration and business decisions can require internal approval.
Pricing boundary
The AWS Marketplace listing is private-offer only. The G-Cloud 14 pricing document gives useful annual examples for Managed SIEM and SOC, but it says those prices are guidance and final pricing depends on technical and commercial scope.