Your security software just flagged something suspicious. But it’s 2am, your team’s asleep, and the office is closed. So what happens next? Most of the businesses I speak with assume that ‘somebody's already on it’. While that may be the case, there’s a lot more to the story.
I spend a lot of my working week with customers unpacking exactly this: what actually happens once an alert goes off; who's responsible for investigating and acting on it; and, (more often than not these days), what proper round-the-clock cover would cost them, whether they build that capability themselves or bring in outside help.
In this article, I'll walk through the whole chain: what an alert genuinely tells you, what needs to happen before the business opens the next morning, what “24/7 monitoring” has to include before the phrase means anything, and what it costs on both sides of building it yourself versus buying it in.
–
What this article covers:
- An alert is only the beginning
- What has to happen before the business opens again
- What does “24/7 monitoring” need to include?
- What it really costs to build this yourselves
- What it costs to bring in outside help
- Is building 24/7 cover in-house ever the right call?
- Three questions worth asking your provider tomorrow
An alert is only the beginning
An alert is the first warning sign, nothing more. It's the system telling you that something needs your attention, not confirming that a decision has already been made and handled. Think of it like a smoke alarm: its job is to make noise and get you out the door, not to tell you the fire's already out.
An alert is only the beginning
With these alerts constantly flooding in, it’s worth noting that not every single one carries the same weight. Some are a note for the record, like an unusual login at an odd hour that turns out to be someone trying to get some extra work done. Others sit much further up the scale: a genuine sign that someone who shouldn't be in your systems, is. Whether your team or your provider can tell the difference quickly enough usually comes down to one thing: do the people receiving that alert have the skills and the time to work it out properly, or are they relying on someone else to do that for them?
What has to happen before the business opens again
Say that serious alert comes in at 2am. Do you know where it would go, and can you be sure that someone's looking at it there and then?
The answer depends entirely on what's already in place. It might go to an automated system with nobody watching it in real time. It might go to whoever's on call from your own team, if you have one. Or it might go to a paid service whose job is to pick it up, investigate it and resolve it, with the only thing landing in your inbox the next morning being a summary of what happened and confirmation it's been dealt with.
The space between “receiving an alert” and “someone qualified deciding what it means” is where the real exposure sits. To be perfectly candid, it is unrealistic to expect a small internal IT team of one or two people to cover this properly, every night, every weekend, every holiday, on top of the day job. Even a genuinely strong team only has so many hours between them, and staying sharp on threat triage at 3am, night after night, is a different skill from being good at it during the day.
Once an alert does look credible, the investigation needs to establish what's happened, what it's affecting, and whether it's still ongoing, before anyone takes action. Once the impact has been established, containment is usually about limiting the damage rather than trying to solve everything at once. For example, isolating one account or device while the wider picture becomes clear, rather than assuming the worst across the whole business straight away.
This is exactly why I encourage every customer to agree on a plan before any of this happens, not in the middle of an incident. We call it a run book:
- Who's authorised to take action;
- What happens if nobody can reach the business to ask; and
- Where the line sits between protecting the business and disrupting it (a 24-hour production line and a nine-to-five office need very different answers to that question).
The 2am scenario
Communication matters just as much as the technical response. Whoever picks up that 2am alert needs to know who to tell, what to tell them, and whether anything's left over that could still affect the business once the doors open, so the right people aren't finding out for the first time at 9am and business can continue as usual.
What does “24/7 monitoring” need to include?
If a service tells you it offers 24/7 monitoring, the next question worth asking is: so what? If an alert reaches someone at 3am, what do they do with it? Notification, monitoring, investigation, containment, escalation and reporting are six different jobs that require many hats. This is sometimes shortened to MDR, or managed detection and response, but the acronym matters less than what's included underneath it. A service can offer some of these without offering all of them. Check which of them you're paying for, and which you'd still be covering yourself.
What it really costs to build this yourselves
Properly staffing round-the-clock cover isn't a headcount of one, or even two. Covering three shifts, plus holiday, sickness and weekends, typically means a team of five or six analysts once you account for realistic rota patterns. Cyber security professionals are in high demand, and for good reason. UK salaries for security analysts currently range from around £30,000 for an entry-level analyst up to £50,000 or more for someone more senior. This of course doesn’t include employer National Insurance, pensions, recruitment costs, ongoing certifications and the security tooling itself. Add it together, and genuinely 24/7 in-house cover for a smaller business tends to run well into six figures a year, before you've even accounted for the time it takes to build working playbooks, and a tested rota.
What it costs to bring in outside help
Buying this in is usually priced per user, per month. Current UK benchmarks put a fully-covered, 24/7 monitoring and response service at somewhere in the region of £15 to £35 per user, per month, with lighter tiers available below that for businesses who don't need full day and night response built in. For a 50-person business, that works out at roughly £750 to £1,750 a month: far less than building that capability internally. It's usually cheaper than people expect, whatever the size of the business.
Is building 24/7 cover in-house ever the right call?
None of this means outsourcing is automatically the right call for every business. A handful of larger organisations do have the scale and budget to employ every role this needs, and for them, building it in-house can make sense. However, for most small and medium-sized businesses, keeping specialists trained, certified and engaged enough to stay is its own ongoing cost, layered on top of the salary itself, in a field where good people are in short supply and everyone else wants them too.
How much cover you need also depends on how your business runs. An organisation that trades around the clock carries a different risk profile to one that closes its doors at five. But threats don't sleep or confine themselves to office hours: a quiet Friday evening, for instance, can buy an attacker three days before anyone's back online to notice. It's also not just your business you need to think about: a weaker link in your supply chain can expose you just as easily as a weak spot in your own systems. No business is the same so there isn’t a one-size-fits-all solution. The right level of coverage is worth a proper conversation, rather than an assumption based on the setup your peers or competitors have.
Three questions worth asking your provider tomorrow
This discussion doesn’t need to be technical. A few questions should help your current provider walk you through a scenario and tell you most of what you need to know.
- If a credible alert came in at 2am, what would happen, in plain terms?
- Is investigating, containing and resolving that alert included in what you already pay, or is it a separate cost?
- At what point does your current provider's responsibility for that alert end, and yours begin?
How your provider answers will tell you exactly where you stand.
Where to go from here
If you can't get clear answers to those three questions right now, that's not a mark against your existing tools or your provider, just the perfect place to start.
Having security tools installed and having someone actively watching, investigating and responding to what they flag are two very different things. It’s certainly worth knowing, before you need it, which one you have.
As a Strategic Account Director at Babble, having these conversations with businesses every day (practically and without fear tactics), is what I do most weeks. If any of this sounds familiar, we’d be glad to help you work through it.
Join our live webinar, Managed Cyber Security: What to Buy, and How to Buy It, on 22 September, to understand whether your current cyber model includes active monitoring, investigation and response.
