Arctic Wolf sells something specific: a named concierge security team, a platform you never touch, and the promise that somebody is watching at 3am. Teams leave for equally specific reasons. Multi-year contracts with per-user or per-sensor minimums that grow with headcount. A renewal conversation where you have no leverage, because the provider holds the operational knowledge of your own environment. And a slowly dawning realisation that after three years, your organisation has learned nothing about defending itself.
Leaving is therefore not a tooling migration. It is a hiring plan with a software project attached, and any business case that presents it the other way round is going to fail in month four.
Model the rota before you model anything else
Do this arithmetic first, honestly, and be prepared for it to end the project.
Covering a single seat continuously through a year, once you account for annual leave, sickness, training, public holidays, and normal turnover, takes roughly five to six full-time people. That buys you one analyst on shift at any given moment, with no depth, no second pair of eyes on a hard call, and no capacity for two simultaneous incidents. A rota that can handle a real incident at 4am without waking the entire team costs meaningfully more than that.
Then add what the analysts need around them: a detection engineer to write and maintain content, a platform engineer to keep the stack running, and a lead who owns the programme. Add recruitment cost and the reality that experienced security analysts are hard to hire and easy to lose.
Compare that total to the Arctic Wolf contract. If insourcing is more expensive, and for smaller organisations it usually is, then the right output of this exercise is a renegotiation backed by a credible alternative, not a migration. Walking into a renewal with a costed insourcing plan is itself worth doing, and it is worth doing regardless of which way you decide.
Consider the hybrid before the full exit
The rota arithmetic above is dominated almost entirely by out-of-hours coverage. Daytime coverage in one time zone is a normal team; overnight coverage is what multiplies the headcount.
That points at an option most organisations underweight: build the platform and the daytime team in-house, and contract only nights, weekends, and holidays. You get the institutional knowledge, the platform you control, the detection content you own, and the analysts who understand your business, while renting the specific thing that is genuinely uneconomic to build. The cost curve is far kinder and the capability curve is nearly as good.
Treat full insourcing as the goal only if you have the scale to fill a real rota, or a genuine requirement (sovereignty, classification, regulatory) that rules out a provider.
Extract everything while the relationship is still good
Whatever you decide, do this now rather than after notice.
Over the life of the contract, the provider has built something valuable and specific to you: detection rules tuned to your environment, exclusions for your noisy applications, an asset inventory, an understanding of what normal looks like on your network, and a history of closed investigations explaining what has actually happened to you. That accumulated knowledge is the real product, far more than the platform.
Request it explicitly and in writing: detection logic and tuning, exclusion lists, the asset and identity inventory the provider maintains, closed investigation and incident history, and any runbooks written for your environment. Check the contract for what you are actually entitled to, because it varies and the answer is rarely as generous as customers assume. Then ask anyway for anything beyond that, while you are still a renewing customer rather than a departing one.
Everything you fail to extract, you will rebuild from scratch, and the tuning exclusions in particular represent months of noise reduction you would otherwise repeat.
Building the stack
- Telemetry and detection: Wazuh for endpoint-plus-log coverage, or Graylog if your volume is dominated by network and application logs. This replaces the provider’s sensor and platform tier.
- Case management: TheHive, so alerts become cases with tasks, evidence, and a handover trail. Without this, a rota cannot hand over shifts coherently.
- Threat intel: MISP or OpenCTI for indicator management and enrichment.
- Automation: Shuffle or StackStorm for enrichment and containment, which is how a small team survives an alert volume built for a large one.
- Endpoint: whatever agent you keep. Note that MDR usually sits on top of an EDR you already license, so this may not change at all.
- On-call tooling: paging, escalation, and a documented severity matrix, which is the unglamorous part that decides whether 3am works.
The licences here total nearly nothing. The operating burden is a full-time platform role. Any business case built on the software being free has already gone wrong.
Order of operations
- Model the rota and the total staffing cost, and put it beside the contract. Decide full insourcing, hybrid, or renegotiate.
- Extract detections, tuning, inventory, and investigation history while the contract is live and the relationship is healthy.
- Map the notice deadline backwards: shadow quarter, hiring lead time, platform build, all ending before the decision point.
- Hire first, build second. A platform with nobody to watch it is worse than the contract you are leaving.
- Build the stack and onboard telemetry, starting with the sources the provider’s detections depend on.
- Rebuild detections from the extracted logic, and validate each against replayed events.
- Shadow for a full quarter: your team works every alert end to end, while the provider remains contractually responsible.
- Run a real out-of-hours exercise, unannounced, before you decide.
- Serve notice only after the shadow quarter demonstrably worked, not on the day it starts.
Clearing the bar before you serve notice
The rota is staffed and has run for a quarter with real people on real shifts, including a holiday period. Your analysts have handled genuine incidents end to end without provider intervention. Detection content is yours, tested, and documented. Escalation paths have been exercised out of hours by someone who was actually asleep beforehand. The platform has survived a peak day. And there is a written plan for what happens when the lead analyst resigns, because in a six-person rota that is a real, foreseeable event and not a hypothetical.
The short version
Leaving Arctic Wolf is an insourcing decision where the software is close to free and the people are close to everything. Model the rota honestly first, because for many organisations the correct answer is a hybrid or a renegotiation rather than a full exit, and reaching that conclusion with a costed plan in hand is a genuinely successful outcome. If you do go ahead, extract the provider’s accumulated tuning while you still can, hire before you build, and shadow for a full quarter before notice. The calculator above models illustrative per-endpoint economics; the number that actually decides this is the one with people in it.