Tier 1-3
Analyst tier model used by 78% of enterprise SOCs
4.2 FTEs
Minimum for true 24x7 single-shift coverage with vacation buffer
1:8
Recommended SOC manager to analyst span of control
68%
Of SOC analysts report burnout from alert volume per SANS 2025

SponsoredRetool

Retool's new app builder is where AI-generated code ships safely

Building apps with AI is easy. Getting them to production safely is another story.

Start building for free today

SOC staffing models fail in two directions: too thin produces missed incidents and analyst burnout from alert volume; too bloated produces expensive teams doing work that SIEM automation or MDR services should handle. The right model depends on three variables: your alert volume and complexity, your coverage hours requirement (business hours only vs. 24x7x365), and the maturity of your detection and automation stack.

This guide provides the staffing math and tier model that practitioners use to build or justify SOC headcount. It is written for security managers sizing a new SOC, for CISOs evaluating build-vs-buy, and for analysts who want to understand how their role fits the organizational model.

The three-tier analyst model: role definitions and responsibilities

Tier 1 Analyst (Alert Triage Analyst): Tier 1 is the first responder for incoming SIEM alerts and security tool notifications. Responsibilities: review and classify alerts from SIEM, EDR, DLP, email gateway, and other security tools; determine whether an alert is a true positive, false positive, or requires escalation; perform initial enrichment (IOC lookup, asset classification, user context); escalate confirmed or suspected true positives to Tier 2 within defined SLA (typically 15 to 30 minutes); document findings in the ticketing system. Tier 1 analysts typically have 1 to 3 years of experience, hold or are pursuing CompTIA Security+ and CySA+, and handle 20 to 40 alerts per shift depending on SIEM noise level.

Tier 2 Analyst (Incident Investigator): Tier 2 handles escalated incidents requiring deeper investigation. Responsibilities: scope the incident by determining affected systems, user accounts, and data; review endpoint forensics (process trees, file system activity, memory), network logs (firewall, proxy, DNS), and identity logs (authentication, privilege use); contain the incident by isolating affected systems and disabling compromised accounts; coordinate with IT operations for remediation; document the incident timeline and root cause; contribute to post-incident review. Tier 2 analysts have 3 to 5 years of experience, hold SANS GCIA or GCIH, and handle 3 to 8 incidents per shift depending on complexity.

Tier 3 Analyst (Threat Hunter and Senior Investigator): Tier 3 handles the most complex incidents, proactive threat hunting, and detection engineering. Responsibilities: investigate incidents where Tier 2 cannot determine scope or root cause; conduct proactive threat hunts based on threat intelligence (looking for attacker presence without a triggering alert); develop and tune SIEM detection rules; perform malware analysis and digital forensics on complex incidents; mentor Tier 1 and Tier 2 analysts. Tier 3 analysts have 5 or more years of experience, hold SANS GCFE, GCFA, or GREM, and often work irregular hours driven by incident severity rather than shift schedules.

Headcount formulas: alert volume to FTE

The most reliable SOC headcount formula starts with your SIEM alert volume and works backward through analyst capacity:

Tier 1 capacity: One Tier 1 analyst can handle 20 to 35 actionable alerts per 8-hour shift in a mature environment with good SIEM tuning. A high-noise environment with poor tuning drops this to 10 to 15 actionable alerts per shift. If your SIEM fires 200 alerts per 24-hour period (approximately 8.3 per hour) and each requires 15 minutes of Tier 1 attention, you need 200 x 15/60 = 50 analyst-hours of Tier 1 time per day, or 6.25 FTEs for 24x7 coverage (before absence buffering).

24x7 coverage math: Covering a single seat (one analyst on shift) 24 hours a day, 365 days a year requires approximately 4.2 FTEs when accounting for vacation (15 days), sick leave (10 days), training (10 days), and holidays (10 days). Most organizations budget 5 FTEs per 24x7 seat to cover all absence scenarios without overtime.

Tier 2 to Tier 1 ratio: Industry benchmarks range from 1:3 to 1:5 (one Tier 2 for every 3 to 5 Tier 1 analysts). A 1:4 ratio is the most common starting point. In a high-detection-quality environment with effective SIEM tuning, the ratio can be as high as 1:6.

Tier 3 to Tier 2 ratio: 1:3 to 1:4 is typical for organizations with active threat hunting programs. Tier 3 roles are often filled by senior Tier 2 analysts who grow into the role, and many smaller SOCs handle Tier 3 functions through retainer agreements with IR firms or MDR service providers.

Sample model for a 24x7 SOC with 150 SIEM alerts per day: 4 to 5 Tier 1 FTEs (covering 2 shifts plus on-call), 1 to 2 Tier 2 FTEs (business hours primary plus on-call for overnight escalations), and 1 Tier 3 FTE (business hours, on-call for major incidents). SOC Manager covering this team of 6 to 8 analysts falls within the 1:8 span of control guideline.

Free daily briefing

Briefings like this, every morning before 9am.

Threat intel, active CVEs, and campaign alerts, distilled for practitioners. 50,000+ subscribers. No noise.

Shift coverage models and the on-call vs. overnight trade-off

SOC coverage models range from business-hours-only to true 24x7x365 staffing. The right model depends on your risk tolerance for overnight incident detection latency and your budget.

Business hours only (8 to 12 hours, 5 days): The lowest-cost model. After-hours incidents are handled via on-call analyst rotation. Alert queue is reviewed at shift start. The risk: a ransomware deployment that begins at 2am Friday is not detected until 8am Monday, giving attackers a 54-hour dwell window in the worst case. Acceptable for low-risk organizations; unacceptable for those in sectors targeted by ransomware or nation-state actors.

Follow-the-sun (two 12-hour shifts, weekdays; reduced coverage weekends): Covers most business-hours risk across time zones. On-call or reduced staff covers nights and weekends. Commonly used by organizations with SOC staff in multiple geographies (US + UK, US + Asia-Pacific). Requires clear shift handover procedures to prevent incident context loss between shifts.

True 24x7 (three 8-hour shifts or two 12-hour shifts, all 7 days): Provides minimum latency for incident detection and response at all hours. Requires 4.2 to 5 FTEs per staffed seat. Shift handover, alert fatigue management on overnight shifts, and maintaining Tier 2 escalation coverage for overnight incidents are the primary operational challenges.

MDR augmentation model: Many organizations use a Managed Detection and Response (MDR) service for 24x7 Tier 1 coverage and maintain an internal Tier 2/3 team for investigation and response. MDR services handle alert triage and initial escalation; internal analysts handle incident scoping, remediation, and threat hunting. This model is cost-effective for organizations that cannot staff a full internal 24x7 team.

Justifying SOC headcount to leadership

SOC headcount justification requires connecting analyst capacity to business risk in terms leadership understands. Three frameworks work consistently:

Alert volume to incident detection latency: Present your current alert volume, the analyst capacity required to process it at target SLA (15 to 30 minute Tier 1 response time), and the headcount gap. Translate the headcount gap into detection latency impact: 'At current staffing, our Tier 1 queue builds to 4-hour backlog by end of shift, meaning incidents that begin at shift start may not be detected until the following shift.' Leadership understands the 4-hour dwell time risk better than the abstract headcount number.

MDR vs. in-house cost comparison: Build the 5-year TCO for internal 24x7 staffing (salary, benefits, training, tooling, turnover cost) versus an MDR service contract covering equivalent coverage hours. For organizations needing 24x7 Tier 1 coverage without Tier 2/3 depth, MDR is frequently more cost-effective and the comparison justifies either investment.

Incident cost basis: Reference Ponemon and IBM research showing that mean time to detect (MTTD) is the strongest predictor of breach cost. Each additional hour of undetected attacker access costs an estimated $100,000 to $500,000 depending on industry and data sensitivity. SOC headcount that reduces MTTD by 8 hours per major incident justifies significant investment at these rates.

The bottom line

Right-sizing a SOC starts with alert volume and coverage hours, not with benchmarking peer organizations. The tier model (1 triage, 2 investigation, 3 hunting) provides the role framework; the 4.2 to 5 FTEs per 24x7 seat provides the coverage math. For organizations that cannot staff a full 24x7 internal team, MDR augmentation for overnight Tier 1 coverage combined with an internal Tier 2/3 team is consistently more cost-effective and operationally sustainable than a fully internal model.

Frequently asked questions

How many analysts do I need for a 24x7 SOC?

A minimum of 4.2 FTEs are required to staff a single seat (one analyst on duty) 24 hours a day, 7 days a week, when accounting for vacation (15 days per year), sick leave (10 days), training (10 days), and holidays (10 days). Most organizations budget 5 FTEs per 24x7 seat to cover all absence scenarios without requiring overtime. If your SOC needs two analysts on shift simultaneously for coverage or workload reasons, multiply accordingly: 10 FTEs for two simultaneous 24x7 seats.

What is the difference between a Tier 1 and Tier 2 SOC analyst?

Tier 1 analysts triage incoming SIEM alerts, classify them as true or false positives, perform initial enrichment (IOC lookup, asset identification), and escalate confirmed incidents to Tier 2 within the defined SLA. Tier 2 analysts investigate escalated incidents: determining scope (which systems are affected), performing forensic analysis, containing the threat, and coordinating remediation. Tier 1 focuses on volume and speed; Tier 2 focuses on depth and accuracy. Tier 1 typically handles 20 to 40 alerts per shift; Tier 2 handles 3 to 8 incidents.

Should I build an in-house SOC or use an MSSP or MDR service?

The build-vs-buy decision depends on three factors: whether you need dedicated analyst attention to your specific environment (in-house advantage), whether you can staff 24x7 coverage cost-effectively (MSSP/MDR advantage for smaller teams), and whether your incident response complexity requires deep familiarity with your specific infrastructure (in-house advantage for complex environments). A hybrid model, MDR for 24x7 Tier 1 coverage and internal Tier 2/3 for investigation and response, is the most cost-effective structure for mid-market organizations that need 24x7 coverage but cannot staff a full internal team.

What certifications should SOC analysts have?

Tier 1 analysts: CompTIA Security+ (baseline), CompTIA CySA+ (intermediate), and Blue Team Labs Online or TryHackMe SOC Analyst learning path for hands-on skills. Tier 2 analysts: SANS GCIA (Certified Intrusion Analyst) for network-focused SOCs, SANS GCIH (Certified Incident Handler) for incident response, and EC-Council CHFI for digital forensics track. Tier 3 analysts: SANS GCFE (Forensic Examiner), GCFA (Forensic Analyst), or GREM (Reverse Engineering Malware) depending on specialization. OSCP is valuable for Tier 3 analysts involved in adversary simulation and red-team-informed detection development.

What is alert fatigue and how do I prevent it in my SOC?

Alert fatigue occurs when analysts receive more alerts than they can meaningfully investigate, causing them to ignore, dismiss, or speed through alerts without adequate analysis, increasing the risk of a missed true positive. Prevention requires: SIEM tuning to reduce false positive rates below 10 percent (target: below 5 percent), alert correlation that groups related events into single incidents rather than generating dozens of individual alerts, automated enrichment that provides context before the analyst sees the alert (reducing time-per-alert), and analyst capacity management that matches staffing to alert volume rather than creating chronic queue backlogs. SANS data shows 68 percent of SOC analysts report burnout related to alert volume, making tuning and staffing a retention issue.

How do I measure SOC performance?

The five core SOC performance metrics are: Mean Time to Detect (MTTD), the average time from the start of an attack to when the SOC generates an alert; Mean Time to Respond (MTTR), the average time from alert generation to incident containment; False Positive Rate, the percentage of alerts classified as true positives that turn out to be false positives (target below 10 percent); Escalation Rate, the percentage of Tier 1 alerts escalated to Tier 2 (calibrates whether Tier 1 training is adequate); and SLA Compliance Rate, the percentage of alerts receiving Tier 1 response within the defined SLA window. Report all five monthly to SOC leadership and quarterly to CISO.

Sources & references

  1. SANS 2025 SOC Survey Report
  2. Exabeam State of the SOC 2025
  3. NIST SP 800-61: Computer Security Incident Handling Guide

Free resources

25
Free download

Critical CVE Reference Card 2025–2026

25 actively exploited vulnerabilities with CVSS scores, exploit status, and patch availability. Print it, pin it, share it with your SOC team.

No spam. Unsubscribe anytime.

Free download

Ransomware Incident Response Playbook

Step-by-step 24-hour IR checklist covering detection, containment, eradication, and recovery. Built for SOC teams, IR leads, and CISOs.

No spam. Unsubscribe anytime.

Free newsletter

Get threat intel before your inbox does.

50,000+ security professionals read Decryption Digest for early warnings on zero-days, ransomware, and nation-state campaigns. Free, daily, no spam.

Unsubscribe anytime. We never sell your data.

Eric Bang
Author

Founder & Cybersecurity Evangelist, Decryption Digest

Cybersecurity professional with expertise in threat intelligence, vulnerability research, and enterprise security. Covers zero-days, ransomware, and nation-state operations for 50,000+ security professionals every morning.

Black Hat Giveaway

Win a $2,495 Black Hat pass.

Full-access to Black Hat USA 2026 in Las Vegas. Subscribe free to enter.

Joins Decryption Digest daily briefing. Unsubscribe anytime.

Giveaway: Black Hat USA 2026 Full-Access Pass ($2,495 value)

Details →
Daily Briefing

Subscribe to enter the giveaway

Every subscriber is automatically entered. You also get daily threat intel every morning: zero-days, ransomware, and nation-state campaigns. Free. No spam.

Already subscribed? You're already entered.

Giveaway

Win a $2,495 Black Hat USA 2026 pass.