WhatsApp Image 2026 09 10 at 10.29.50 AM
Network Security

Staffing a 24/7 Security Operation Without Burning Out the Team

Por Cyber Lad Team·
WhatsApp Image 2026 09 10 at 10.25.18 AM


Image source

Every security leader reaches the same conclusion eventually. Attackers do not respect business hours, so monitoring cannot either.

The decision that follows is usually framed as a tooling question. It is a staffing question, and the staffing maths is harsher than most budgets assume.

The coverage maths nobody likes

Covering 168 hours a week is not three people working shifts. Allowing for holiday, sick leave, training days, and the fact that nobody works 52 weeks a year, continuous single-person coverage needs somewhere between five and six full-time analysts. If you want two people on at all times, which you do for anything beyond triage, double it.

For most mid-sized organisations,s that is an entire security budget spent on watching screens, before any tooling, incident response capability, ty or engineering work.

Coverage also has to survive one person being unavailable. A rota that works only when everybody is present is not a rota, and single-person night coverage means one resignation or one illness removes an entire shift. Whatever model you pick needs a documented answer for what happens when the person scheduled does not appear.

The second problem is human. Permanent night shifts have well-documented effects on health and retention, and the people who accept them tend to be junior, which means your quietest hours are covered by your least experienced staff. Alert fatigue compounds it. An analyst working through a queue of mostly false positives at four in the morning is not performing the task you think you are buying.

The stakes are worth stating plainly. IBM’s 2025 research put the mean time to identify and contain a breach at 241 days, split into 181 days to identify and 60 to contain. Detection speed is the variable security operations exist to improve, and it is the one most affected by whether the person watching is alert and competent.

Three ways to cover the clock

In-house shift rotation gives you full control and full cost. It works when the organisation is large enough to absorb ten or more analysts, and when you can offer people a path off nights before they leave.

Outsourced monitoring, whether an MDR provider or a managed SOC, converts the problem into a contract. Coverage arrives immediately, and expertise comes with it. The trade-offs are context and escalation. A provider knows security but not your environment, so tuning matters enormously, and the value you get depends more on how well you have defined escalation paths than on the provider’s brochure.

A detail worth checking in any outsourcing contract is what the provider is actually committing to. Time to acknowledge an alert is not the same as time to investigate it, and a fast acknowledgement service level costs far less to deliver than an investigation one. Read which of the two you are buying.

The third model is following the sun. Instead of asking one team to work through the night, you place analysts in regions where your night is their working day. Everyone works normal hours, which changes the retention picture completely.

Following the sun means employing people elsewhere

The appeal is obvious, and the practical implications get underestimated.

You need genuine coverage overlap rather than three isolated pods, a common toolset and runbook set across all regions, and consistent authority to act. An analyst in another region who cannot isolate a host without waking someone in headquarters has not extended your coverage, only your notification chain.

Then there is the employment structure. Security analysts are permanent, senior-adjacent staff, not project contractors, so treating them as freelancers is both a classification risk and a retention problem. Dublin is a common choice for European coverage given the concentration of security operations there, and companies employing analysts in Ireland typically either register a local entity or engage a provider that already holds one, since payroll, statutory notice, and benefits all follow Irish rules regardless of where the security function reports.

Time zone selection is worth doing deliberately rather than following where you happen to have contacts. Three roughly equal eight-hour blocks give the cleanest coverage, and the regions you choose should each have enough of a security labour market to replace someone within a reasonable window. A single analyst in a country where you will struggle to hire a second is a coverage gap waiting to happen.

Background screening deserves attention too. These people will hold privileged access, and what you can lawfully check varies by country. Build the vetting standard into the hiring process rather than discovering the limits after an offer.

Handover is where incidents get lost.

Distributed coverage introduces a failure mode that a single-site SOC does not have. Work crosses a boundary three times a day, and each crossing is an opportunity to drop something.

The classic version is an alert that looked low priority to the outgoing shift, mentioned briefly in a chat channel, and never picked up. Two days later it turns out to have been the first sign of something serious.

Teams that handle this well treat handover as a structured artefact rather than a conversation. Open investigations with their current state, anything deliberately deprioritised and why, changes made to detections during the shift, and anything the next team should watch for. Written down in the case management system, not in chat.

Tooling helps if it is set up for it. Case management that carries state across shifts, a shared timeline for each investigation, and a single queue everyone works from removes most of the friction. Handovers conducted in chat channels fail because chat has no state, only history, and nobody reads back far enough.

The test is whether the incoming shift can work without asking a question. If they routinely need to message someone who has just gone to bed, the handover format is the problem.

Skills decay faster in security than almost anywhere

Detection content ages. Attacker techniques change. The playbook that was accurate last year describes an environment you no longer run.

Analysts need continuous training as a condition of doing the job properly, not as a benefit. That means new detection logic, current threat intelligence, updated runbooks, and regular practice against realistic scenarios. Purple team exercises and tabletop drills are the most valuable version, because they surface the gaps between what the runbook says and what people actually do at three in the morning.

There is also the wider organisation to consider. Security awareness training for everyone outside the security team is where a large share of incidents is either prevented or created, and it needs to be assigned, refreshed, and recorded rather than delivered once at induction.

Certification adds a documentation requirement on top. ISO 27001 requires both competence and awareness for people whose work affects information security, along with evidence to support it, and auditors ask for records rather than assurances. Most teams past a handful of analysts end up running this through a learning management system, because when the auditor asks which analysts have completed the updated incident response procedure, you need to be able to show who is current.

The practical shape most teams settle on is a defined baseline everyone completes, role-specific material layered on top, and a short refresher whenever a procedure changes. Assigned automatically rather than announced in a channel, because announcements reach whoever happened to be online.

Distributed teams make this harder and more necessary at once. Three regions training separately drift apart within a year, and the drift shows up as inconsistent handling of the same alert type depending on who caught it.

Choosing the model

Match the model to your scale rather than your ambition.

Under roughly fifty staff, outsourced monitoring is almost always right, with one internal person owning the relationship and the escalation path. Between fifty and a few hundred, a hybrid works well: in-house analysts covering business hours where context matters most, a provider covering nights and weekends. Above that, following the sun becomes viable, and it is a better answer than permanent night shifts for both retention and quality.

Whichever you choose, three things determine whether it works. Escalation authority that lets whoever is on duty act. Handover discipline that survives the boundary. And training that keeps every region working from the same current playbook.

The tooling matters, but the tooling has never been the reason an alert sat unexamined for a weekend.

¿Listo para protegerse?

Comience su viaje de seguridad hoy

Obtenga una consulta gratuita con nuestros expertos en ciberseguridad. No se requiere compromiso.