Insights & research
CybersecurityDec 2025 10 min

A pragmatic SOC maturity model for African enterprises

Few mid-market organisations need a twenty-four-hour in-house security operations centre. Most need the four capabilities that determine whether an incident becomes a breach.

Digital Africa Practice
Cybersecurity
Key points
  • Detection coverage beats tooling count at every maturity level.
  • Mean time to contain is the metric that correlates with loss.
  • Hybrid models suit the regional talent market better than fully in-house teams.
  • Tabletop exercises expose more gaps per rand than any additional product.

Four levels, honestly assessed

Level one is reactive: alerts exist, nobody owns them outside business hours. Level two is monitored: coverage of critical systems with defined triage and escalation. Level three is responsive: playbooks, containment authority and measured response times. Level four is adaptive: threat-informed detection engineering and regular purple-team validation.

Most South African mid-market organisations sit between one and two while holding tooling licences appropriate to level three. The gap is process and staffing, not product.

Coverage before capability

Detection coverage — the percentage of critical assets and attack techniques with a functioning detection — is the single most useful figure to track. Map detections to a recognised technique framework and report coverage by tier. It converts a vague security conversation into a measurable programme with visible gaps.

Hybrid staffing reflects market reality

Skilled analysts are scarce and expensive across the region, and retention on night shift is poor. A hybrid model — in-house ownership of context, triage and response authority, outsourced coverage for after-hours monitoring — consistently outperforms fully in-house builds at mid-market scale, provided the escalation contract is specific about what the provider may and may not do.

  • In-house: asset context, containment authority, vulnerability ownership.
  • Outsourced: 24×7 monitoring, first-line triage, threat intelligence.
  • Shared: detection engineering backlog and quarterly tuning review.

Exercise the plan quarterly

A ransomware tabletop with the executive team surfaces decision bottlenecks that no technical assessment reaches: who declares an incident, who authorises taking production offline, who speaks to customers and regulators, and how the business operates while systems are down. Run it quarterly, rotate the scenario, and record the actions.

Let's discuss your next initiative.

Speak to our team about your digital infrastructure, cybersecurity, data or analytics requirements. We respond to every enquiry within one business day.