Skip to content
Ordinox
AI SOC Ordinox

Designing a SOC Rota: Coverage Models for 24/7 Security Operations

SOC Rota Design Is an Operational Problem, Not a Hiring Problem

Building a Security Operations Center is often framed as a technology decision: which SIEM, which EDR, which SOAR platform. But the decision that determines whether a SOC actually works at 3 AM on a Sunday is the rota. SOC rota coverage models define who is watching, when, for how long, and what happens when someone is sick, on leave, or burned out.

Get the rota wrong and you have a SOC that looks good on a diagram but has real coverage gaps. Analysts work unsustainable hours, alert fatigue sets in, and the people you spent months hiring start leaving.

The Math of 24/7 Coverage

A 24/7 operation requires 168 hours of coverage per week. A single analyst, working a standard 40-hour week, covers 24% of that. To maintain one analyst on shift at all times, you need a minimum of 4.2 full-time equivalents (FTEs), accounting for holidays, sick leave, and training time.

In practice, the number is closer to 5-6 FTEs per seat. A "seat" means one analyst position that must be occupied at all times. If your SOC requires two analysts on every shift (a common minimum for peer review and escalation coverage), you need 10-12 FTEs before you have a single manager, engineer, or threat hunter.

This is why SOC staffing discussions that start with "we will hire three analysts" are setting themselves up for failure. Three analysts cannot sustain 24/7 coverage. They can sustain business-hours coverage with an on-call arrangement, which is a valid model but a different one.

Coverage Models

Model 1: Business Hours + On-Call

Coverage: core hours (e.g. 08:00-18:00) with an on-call analyst outside hours.

Staffing: 2-3 analysts for daytime coverage, shared on-call rotation.

Best for: organisations in early SOC maturity where threat volume is manageable and overnight response within 30-60 minutes is acceptable.

The on-call model is honest about what most small SOCs actually need. Critical alerts trigger a page; the on-call analyst triages remotely. Non-critical alerts queue for the morning shift.

Risk: on-call burnout. If an analyst is paged multiple times per night, the model degrades fast. Tuning alert thresholds and automated triage (where AI-assisted SOC tooling adds real value) is essential to keep on-call sustainable.

Model 2: Extended Hours (16/7)

Coverage: two shifts covering 06:00-22:00, with on-call overnight.

Staffing: 4-6 analysts across two overlapping shifts.

Best for: organisations with business activity across time zones or elevated threat profiles that cannot accept business-hours-only coverage.

The overlap between shifts (typically 1-2 hours) is not wasted time. It is the handover window where the outgoing shift briefs the incoming shift on active incidents, pending investigations, and anything unusual. SOCs that skip structured handovers lose context between shifts.

Model 3: Full 24/7 (Three-Shift)

Coverage: three 8-hour shifts, continuous.

Staffing: 10-14 analysts minimum (2 per shift, 5-6 FTEs per seat).

Best for: critical infrastructure operators, MSSPs, financial services, government, and any organisation where a 30-minute response gap overnight is unacceptable.

The classic pattern is:

  • Day shift (06:00-14:00): highest staffing, handles most alert volume
  • Swing shift (14:00-22:00): moderate volume, often handles escalations from day
  • Night shift (22:00-06:00): lowest volume but highest individual responsibility per analyst

Night shift is the hardest to staff and sustain. Rotating night duty (e.g. one week nights, two weeks days) prevents permanent night workers but creates circadian disruption. Fixed night shifts avoid rotation stress but limit the pool of willing analysts.

There is no perfect night shift model. There is only the least-bad option for your team.

Model 4: Follow-the-Sun

Coverage: 24/7 by distributing shifts across time zones.

Staffing: 6-9 analysts across 2-3 geographic locations.

Best for: global organisations or MSSPs with teams in different regions.

Follow-the-sun eliminates the night shift problem entirely. Each location works business hours; coverage is continuous because the sun is always up somewhere. The challenge shifts from staffing to handover quality. Every transition between regions must transfer full incident context, and tooling must support shared visibility.

Model 5: Hybrid (Internal + MSSP)

Coverage: internal team during business hours, outsourced SOC-as-a-Service overnight.

Staffing: 2-4 internal analysts, MSSP contract for off-hours.

Best for: organisations that want internal control during the day but cannot justify the FTE count for 24/7 in-house coverage.

The hybrid model is increasingly common and pragmatic. The key design decision is the escalation boundary: what can the MSSP action autonomously (block an IP, isolate an endpoint) versus what must be escalated to the internal team? Get this boundary wrong and you either have an MSSP that pages you for everything (expensive on-call by proxy) or one that takes actions your internal team did not authorize.

Preventing Burnout

SOC analyst burnout is the single biggest operational risk in security operations. It is driven by:

  • Alert fatigue: too many low-fidelity alerts that require manual triage
  • Shift monotony: repetitive triage work without variety or growth
  • Inadequate staffing: being the only person on shift with no escalation path
  • Lack of rotation: permanent night shifts or permanent Tier 1 duty

Mitigation is structural, not motivational:

  • Tune detection rules aggressively. A SOC drowning in false positives is a SOC failing at engineering, not at analysis.
  • Rotate responsibilities: analysts should cycle between triage, investigation, threat hunting, and detection engineering. Nobody should be on Tier 1 triage permanently.
  • Staff for absence: build the rota assuming 20% absence at any time (leave, training, sick). If your rota breaks when one person is away, it is understaffed.
  • Invest in automation: AI-assisted triage, automated enrichment, and playbook-driven response reduce the cognitive load per alert. This is where AI SOC tooling pays for itself, not by replacing analysts but by reducing the per-alert cost of their attention.

Building the Rota

Start with these questions:

  1. What is your actual threat window? If 90% of your alerts arrive during business hours, 24/7 coverage may not be the first priority.
  2. What response time does your risk appetite require? A 15-minute SLA demands on-shift analysts. A 4-hour SLA can tolerate on-call.
  3. How many analysts can you hire and retain? Be honest about salary competitiveness and location constraints.
  4. What can automation handle? Automated alert triage, enrichment, and low-confidence closures reduce the human hours needed per shift.

Map answers to the coverage model that fits. Then staff it with the right FTE count, not the count your budget wishes were sufficient.

How Ordinox Designs SOC Rotas

At Ordinox, SOC design starts with the operating model, not the technology stack. We map threat windows, define response SLAs, build the rota with sustainable shift patterns, and design AI-assisted triage to keep alert volumes manageable per analyst.

The deliverable is a staffed operating model: roles, shift patterns, escalation paths, handover procedures, and the tooling baseline required to sustain it. Not a slide deck with a SOC diagram, but a working model your team can execute from day one.

If you are building a SOC or redesigning one that is not working, request an assessment and an Ordinox architect will scope it.

Need help with this? AI SOC is one of the services Ordinox delivers.

Request Assessment
Next step

Request a project assessment

Tell us the outcome you need. An architect scopes it - vendor-neutral, no obligation.