Global Healthcare Organization · Operations
A 24x7 SOC that didn’t hollow out the team
Any organization can buy round-the-clock monitoring. The failure mode is subtle: two years later the provider knows your environment better than you do, your analysts have stopped developing, and you have outsourced the judgment along with the alerts. That was the design constraint.
- Organization
- Leading global healthcare organization — academic medical system, $16B+ revenue, 76,000 employees
- Role
- Director of Information Security
- Scope
- 100-person security organization — operations, threat management, IAM, GRC, engineering, architecture, cloud security
- Outcome
- 24x7 SOC on a hybrid MSSP model with detection engineering and IR retained in-house
The situation
An academic medical center is an unusually difficult monitoring environment. Clinical systems that cannot be taken offline sit alongside research computing that behaves like a university, connected medical devices with long lifecycles and limited patchability, and a large administrative estate. Add HIPAA, GDPR, and CCPA obligations and a threat environment where healthcare is a priority target, and the requirement for continuous coverage is not really debatable.
The staffing math, however, is brutal. Genuine 24x7 in-house coverage requires enough analysts to staff overnight and weekend rotations sustainably. Those shifts are where burnout and attrition concentrate, and they are the hardest roles to keep filled with people who are actually good. Meanwhile the overnight work is mostly triage — important, repetitive, and not where a strong analyst develops.
The obvious answer is to outsource the SOC. The obvious answer has a well-documented failure mode: the provider accumulates the environmental knowledge, detection content stops evolving because nobody internal owns it, and when a serious incident arrives the organization discovers it has retained accountability without retaining capability.
What I did
Split on capability, not on hours
The design divided the work by what kind of judgment it required rather than by what time of day it happened. Tier 1 monitoring and triage — high-volume, well-specified, procedure-driven — went to the MSSP. Escalation, detection engineering, and incident response stayed in-house, permanently and by design.
That boundary is the whole thing. It means the provider handles volume, and the organization retains everything that requires knowing what these systems are for, which anomalies matter in a clinical context, and what the consequences of a given action would be at 3am on a hospital floor.
Kept detection engineering internal on purpose
Detection content is where environmental knowledge lives. If the provider writes the detections, the provider owns the understanding, and the internal team gradually becomes a ticket-routing function. Keeping detection engineering in-house meant the team stayed technically current, kept building institutional knowledge of the estate, and continued to improve what the MSSP was executing against.
It also inverts the usual dependency. The provider was executing against content the organization owned, which made the relationship replaceable — commercially valuable, and a genuine resilience property.
Retained incident command internally
I served as executive incident commander for major security events, owning technical resolution alongside executive and legal communications, regulator coordination, and post-incident improvement. In a healthcare environment those threads cannot be separated. Decisions about containment are simultaneously clinical decisions, legal decisions, and communication decisions, and they have to be made by someone with the authority and the context to make all three at once.
No provider can hold that role. Structuring the SOC so escalation lands on an internal team that was already deep in the environment is what made incident command work when it mattered.
Wired it into everything else
The SOC was not built as a standalone capability. It connected to vulnerability management, threat intelligence, IAM, endpoint protection, and the secure SDLC and DevSecOps practices we had embedded with engineering — OWASP-aligned review, WAF, DDoS protection. Detection improved because the rest of the program fed it, and the rest of the program improved because detection told it what was actually being attempted.
Outcome
- Sustainable 24x7 coverage without the attrition cost of fully in-house overnight rotations.
- Detection engineering, escalation, and incident response retained and strengthened in-house.
- Executive incident command capability that held up across major security events, including regulator and legal coordination.
- A provider relationship that stayed replaceable, because the organization owned the detection content.
- Security operations integrated with vulnerability management, threat intelligence, IAM, and secure delivery rather than running beside them.
What transfers
The question to ask about any managed security service is not “what does this cost?” but “what capability will we no longer have in two years?” Outsource volume. Never outsource the judgment layer or the detection content. If the provider is writing your detections, you are renting your security program rather than running it.
Related
- Standing up security for a $6.5B retailer from zero — the same build problem at an earlier stage.
- Turning vulnerability counts into $46M of risk removed
- Operating philosophy — build for the organization that stays.