In-House, DIY, or Managed Security: The Honest Math

One analyst covers 40 of the week's 168 hours. The honest comparison of in-house teams, DIY tooling, and managed security — and when each one wins.

Illustration of a seven-by-twenty-four grid of hour cells with only business hours lit in sunset gradient

At some size, every growing company asks the question: do we hire a security person, buy tools and run them ourselves, or bring in a managed security partner? Like the managed-versus-hire question on the AI side, it deserves math instead of reflex — including the scenarios where hiring is right.

What the hire costs — and covers

A capable security analyst runs $100K–$140K base; a security engineer or manager, meaningfully more. Fully loaded, the first hire is a $150K+ commitment — for one person, awake eight hours a day, five days a week. Here's the structural problem: attacks don't keep business hours, and one human covers 40 of the week's 168 hours. True 24/7 monitoring requires roughly five people once you account for shifts, weekends, vacations, and turnover — a half-million-dollar function. That's why "we have a security guy" and "we have security coverage" are different sentences.

The DIY tooling trap

The tempting middle path: buy the tools (EDR, email security, a SIEM) and have IT run them. The tools are genuinely good now. But tools generate alerts, not security — and an unwatched alert queue is where incidents hide in plain sight. The pattern is so common it's a cliché: post-incident review finds the detection fired weeks earlier and nobody was looking, because watching was everyone's ninth priority. Alert fatigue isn't a discipline problem; it's what happens when monitoring is a side duty instead of a job.

What managed security actually buys

A managed security partner sells the thing that's structurally impossible to build small: coverage. Monitoring that doesn't sleep, response that starts in minutes, tooling amortized across many clients, and pattern recognition from seeing hundreds of environments instead of one. Layer on the evidence discipline — the reporting your insurer and enterprise customers now demand — and the comparison isn't partner-versus-salary; it's partner-versus-a-team-you-can't-yet-justify.

When building in-house is right

Honesty requires this section. Build internal security when you're large enough that a full team pencils out — typically north of 750–1,000 employees or under regulatory regimes that demand it. Build it when security is the product. And even then, the pattern that works is hybrid: internal leadership setting strategy, a managed partner running the 24/7 floor. That leadership layer, incidentally, doesn't require a full-time executive either — it's exactly what a vCISO seat provides.

The decision, simplified

Count your real coverage hours, price your real alert-watching capacity, and compare against a fixed monthly number — ours are published, because everything we sell is. Two decades of running IT and security operations taught us most growing companies don't have a tools problem; they have a coverage problem. Book a conversation and we'll run your math honestly — including if the answer is that you're ready to build.