Request an exact quote
Cybersecurity · MDR, MSSP & SOC-as-a-Service migration path

From Arctic Wolf to In-house SOC (open stack)

Ending a concierge MDR contract is a staffing decision before it is a tooling one: modelling the real cost of a 24x7 rota, extracting tuned detections while the contract is live, building the open stack, and shadowing the provider for a full quarter.

Effort
High
Est. timeline
~21 wks
In-house SOC (open stack) model
Staff + infrastructure only
Open source
Yes
▶ Model your savings in the interactive calculator

Arctic Wolf sells something specific: a named concierge security team, a platform you never touch, and the promise that somebody is watching at 3am. Teams leave for equally specific reasons. Multi-year contracts with per-user or per-sensor minimums that grow with headcount. A renewal conversation where you have no leverage, because the provider holds the operational knowledge of your own environment. And a slowly dawning realisation that after three years, your organisation has learned nothing about defending itself.

Leaving is therefore not a tooling migration. It is a hiring plan with a software project attached, and any business case that presents it the other way round is going to fail in month four.

Model the rota before you model anything else

Do this arithmetic first, honestly, and be prepared for it to end the project.

Covering a single seat continuously through a year, once you account for annual leave, sickness, training, public holidays, and normal turnover, takes roughly five to six full-time people. That buys you one analyst on shift at any given moment, with no depth, no second pair of eyes on a hard call, and no capacity for two simultaneous incidents. A rota that can handle a real incident at 4am without waking the entire team costs meaningfully more than that.

Then add what the analysts need around them: a detection engineer to write and maintain content, a platform engineer to keep the stack running, and a lead who owns the programme. Add recruitment cost and the reality that experienced security analysts are hard to hire and easy to lose.

Compare that total to the Arctic Wolf contract. If insourcing is more expensive, and for smaller organisations it usually is, then the right output of this exercise is a renegotiation backed by a credible alternative, not a migration. Walking into a renewal with a costed insourcing plan is itself worth doing, and it is worth doing regardless of which way you decide.

Consider the hybrid before the full exit

The rota arithmetic above is dominated almost entirely by out-of-hours coverage. Daytime coverage in one time zone is a normal team; overnight coverage is what multiplies the headcount.

That points at an option most organisations underweight: build the platform and the daytime team in-house, and contract only nights, weekends, and holidays. You get the institutional knowledge, the platform you control, the detection content you own, and the analysts who understand your business, while renting the specific thing that is genuinely uneconomic to build. The cost curve is far kinder and the capability curve is nearly as good.

Treat full insourcing as the goal only if you have the scale to fill a real rota, or a genuine requirement (sovereignty, classification, regulatory) that rules out a provider.

Extract everything while the relationship is still good

Whatever you decide, do this now rather than after notice.

Over the life of the contract, the provider has built something valuable and specific to you: detection rules tuned to your environment, exclusions for your noisy applications, an asset inventory, an understanding of what normal looks like on your network, and a history of closed investigations explaining what has actually happened to you. That accumulated knowledge is the real product, far more than the platform.

Request it explicitly and in writing: detection logic and tuning, exclusion lists, the asset and identity inventory the provider maintains, closed investigation and incident history, and any runbooks written for your environment. Check the contract for what you are actually entitled to, because it varies and the answer is rarely as generous as customers assume. Then ask anyway for anything beyond that, while you are still a renewing customer rather than a departing one.

Everything you fail to extract, you will rebuild from scratch, and the tuning exclusions in particular represent months of noise reduction you would otherwise repeat.

Building the stack

  • Telemetry and detection: Wazuh for endpoint-plus-log coverage, or Graylog if your volume is dominated by network and application logs. This replaces the provider’s sensor and platform tier.
  • Case management: TheHive, so alerts become cases with tasks, evidence, and a handover trail. Without this, a rota cannot hand over shifts coherently.
  • Threat intel: MISP or OpenCTI for indicator management and enrichment.
  • Automation: Shuffle or StackStorm for enrichment and containment, which is how a small team survives an alert volume built for a large one.
  • Endpoint: whatever agent you keep. Note that MDR usually sits on top of an EDR you already license, so this may not change at all.
  • On-call tooling: paging, escalation, and a documented severity matrix, which is the unglamorous part that decides whether 3am works.

The licences here total nearly nothing. The operating burden is a full-time platform role. Any business case built on the software being free has already gone wrong.

Order of operations

  1. Model the rota and the total staffing cost, and put it beside the contract. Decide full insourcing, hybrid, or renegotiate.
  2. Extract detections, tuning, inventory, and investigation history while the contract is live and the relationship is healthy.
  3. Map the notice deadline backwards: shadow quarter, hiring lead time, platform build, all ending before the decision point.
  4. Hire first, build second. A platform with nobody to watch it is worse than the contract you are leaving.
  5. Build the stack and onboard telemetry, starting with the sources the provider’s detections depend on.
  6. Rebuild detections from the extracted logic, and validate each against replayed events.
  7. Shadow for a full quarter: your team works every alert end to end, while the provider remains contractually responsible.
  8. Run a real out-of-hours exercise, unannounced, before you decide.
  9. Serve notice only after the shadow quarter demonstrably worked, not on the day it starts.

Clearing the bar before you serve notice

The rota is staffed and has run for a quarter with real people on real shifts, including a holiday period. Your analysts have handled genuine incidents end to end without provider intervention. Detection content is yours, tested, and documented. Escalation paths have been exercised out of hours by someone who was actually asleep beforehand. The platform has survived a peak day. And there is a written plan for what happens when the lead analyst resigns, because in a six-person rota that is a real, foreseeable event and not a hypothetical.

The short version

Leaving Arctic Wolf is an insourcing decision where the software is close to free and the people are close to everything. Model the rota honestly first, because for many organisations the correct answer is a hybrid or a renegotiation rather than a full exit, and reaching that conclusion with a costed plan in hand is a genuinely successful outcome. If you do go ahead, extract the provider’s accumulated tuning while you still can, hire before you build, and shadow for a full quarter before notice. The calculator above models illustrative per-endpoint economics; the number that actually decides this is the one with people in it.

Tooling & automation for this path

Treat this as insourcing, not a tool swap: stand up your own telemetry pipeline and detection platform (Wazuh or Graylog plus TheHive for cases), request an export of concierge-tuned detections and open investigations while the contract is live, hire or contract 24x7 coverage, and shadow the provider for a full quarter before the renewal date.

Frequently asked questions

How many analysts does a genuine 24x7 rota need?

The arithmetic is unforgiving and it is the first thing to model. Covering one seat continuously across a year, allowing for leave, sickness, training, and turnover, takes roughly five to six full-time people. That is one person on shift at any moment, not a team. A rota with any depth, or one that can handle two incidents at once, needs more. This is why MDR exists commercially: the provider amortises that rota across many customers and you cannot. If the modelled staffing cost exceeds the contract, the honest conclusion is to renegotiate rather than insource, and that is a legitimate outcome of this exercise.

Can we get our tuned detections and investigation history out?

Ask early, in writing, and while the relationship is good. Concierge providers tune detections specifically for your environment over the life of the contract, and that tuning is genuinely valuable institutional knowledge about your estate. What is contractually yours varies, so check the agreement rather than assuming. Request an export of detection logic, tuning exclusions, the asset inventory the provider built, and closed investigation history, and do it months before notice, because a request made after notice is served rarely gets an enthusiastic response.

Is a hybrid model, in-house during business hours and a provider overnight, a real option?

Yes, and it is frequently the right answer rather than a compromise. The staffing arithmetic that makes full insourcing expensive is dominated by out-of-hours coverage; daytime coverage in a single time zone is comparatively cheap. Building the platform and the daytime team in-house while contracting only nights and weekends captures most of the cost saving and most of the capability building, at a fraction of the rota burden. Many organisations that set out to leave MDR entirely end up here deliberately.

What does the open stack actually consist of?

At minimum: a detection and log platform (Wazuh or Graylog), a case-management system (TheHive), threat-intel handling (MISP or OpenCTI), automation (Shuffle or StackStorm), and whatever endpoint agent you keep or replace. That collection is free to license and substantial to operate, so budget a platform engineer alongside the analysts. The software is genuinely the cheap part of this decision, and any business case that treats the licence saving as the headline number is measuring the wrong thing.

How long should we shadow the provider before serving notice?

A full quarter of your own team handling real alerts end to end, with the provider still contractually responsible, is the realistic minimum. Shorter than that and you have not seen a patch Tuesday, a month-end, a holiday period with a thin rota, or a genuine incident at an inconvenient hour. Work backwards from the contract's notice deadline so the shadow period ends before the decision point, not after it.

Model your 3-year cost

Pre-filled for Arctic Wolf → In-house SOC (open stack); adjust every figure with your own numbers. Estimates are illustrative, not vendor quotes, see our methodology.

Sized at 500 GB ingested/day, cost is computed on this.
Stay on Arctic Wolf (3yr)
$2,250,000
Move to In-house SOC (open stack) (3yr + migration)
$684,000
Projected savings
$1,566,000 (70%)
Payback period
1.8 mo
Build a decision report from these numbers:

How this is licensed: Security is the category where the billing unit changes per segment: EDR/XDR bills per endpoint or per protected asset; SIEM bills by ingest volume (GB/day) or events per second; MDR, MSSP, and SOC-as-a-Service bill per endpoint or per asset for endpoint-centric services but per GB ingested for co-managed SIEM and SOC-as-a-Service; SOAR bills per analyst seat or per automation run; and vulnerability management bills per scanned asset. The calculator normalizes everything to protected endpoints so segments stay comparable; if you are modelling a SIEM or an ingest-priced SOC-as-a-Service specifically, treat one endpoint as roughly one asset generating logs and sanity-check the total against your GB/day contract.

Illustrative, editable figures, not vendor pricing (defaults reviewed May 2026).

Request a vendor-accurate In-house SOC (open stack) quote

A guided builder that turns your estimates into a requirements report (RFQ) you can send to a vendor, partner, or distributor for a binding quote, then feed the real prices back into the calculator above. How our estimates work.

  1. 1Size it
  2. 2Requirements
  3. 3Your details
  4. 4Channels & export

How big is your Arctic Wolf estate?

Every device that needs the agent installed. Not sure? Enter rough numbers, the distributor confirms exact counts later.

1,000 endpoints
Default mid-size assumption (1,000 endpoints)