DEV Community

WhyCrew
WhyCrew

Posted on

Why We're Seeing More MSSPs Move Off Licensed SIEM (and Build Their Own)

If you've worked inside an MSSP's engineering team for more than a year, you've probably run this math yourself: your SIEM bill grew faster than your client count. Not because you're inefficient — because the pricing model was never built for a provider running dozens of tenants in the first place.

I want to walk through why this keeps happening, and why a growing number of MSSPs are choosing to build their own SIEM/SOAR stack instead of renting one.

The pricing model wasn't designed for multi-tenancy

Splunk, Microsoft Sentinel, IBM QRadar — most commercial SIEM platforms price per gigabyte ingested, somewhere in the €1–€4/GB/day range depending on vendor and tier. That's fine when you're a single enterprise monitoring your own environment.

It breaks down fast when you're an MSSP. Every new client adds their own log volume. Every new client adds their own retention requirements. The bill scales with client count, not with what you're able to charge for the underlying monitoring. Revenue and cost stop moving together right around the point where growth should start paying off.

True multi-tenant support is often bolted on as a higher tier, or missing from the core architecture entirely. In practice that means separate instances, separate licenses, separate operational overhead — the opposite of the economies of scale you'd expect as you onboard more clients.

Retention requirements make it worse

If you're serving EU clients, NIS2 and DORA are pushing retention windows longer. That's more data sitting in a storage tier you're paying for on top of ingestion. None of this shows up clearly on a vendor's pricing page — it shows up eighteen months later in a renewal quote that grew faster than your client base did.

"Just negotiate a better rate" doesn't fix the structure

I've seen teams treat this as a vendor-negotiation problem. Consolidate contracts, push for volume discounts, shop competing quotes. It helps at the margins. It doesn't change the fact that you're still paying per-GB, per-tenant, indefinitely, for a platform you don't own and can't fully reshape around your own detection logic.

If your MSSP's differentiation is genuinely better detection — faster time-to-alert, fewer false positives, tighter tuning — running the same licensed platform as everyone else in the market is a hard position to defend technically. The detection logic underneath is the vendor's, not yours.

What building your own actually looks like

A growing number of MSSPs are engaging engineering partners to build a SIEM (often with a SOAR layer) architected specifically for their multi-tenant environment, then taking full ownership of the resulting source code and infrastructure.

It's not fast — licensing gets you monitoring within weeks; building is a matter of months. But the economics flip once it's live. Instead of a bill that grows with every GB and every new client, you're left with infrastructure costs that stay largely fixed. The cost breakdown is worth working through for your own data volume, but the general pattern holds: the crossover point favors ownership once you're running enough tenants, or high enough data volume, to make per-GB licensing genuinely painful rather than just annoying.

This isn't universal advice. A provider running a handful of low-volume clients, without engineering capacity to maintain a custom platform, will likely still come out ahead licensing. The math shifts specifically once licensing costs start compounding faster than your business is actually growing — which, for a lot of MSSPs scaling past their first dozen clients, arrives sooner than most budget forecasts expect.

The multi-tenancy architecture question

If you do go this route, the hard engineering problem isn't "build a SIEM" — plenty of open-source and commercial building blocks exist for log ingestion and correlation. The hard problem is designing genuine multi-tenant isolation: separate data boundaries, separate access controls, separate reporting per client, without spinning up a fully separate stack for every tenant you add.

Get that part right and the economics actually scale with your business instead of against it.

Discussion

Curious how many other MSSP engineering teams have run into this specific wall — the point where a licensed SIEM's per-GB pricing stopped making sense relative to client growth. What did you end up doing about it?

Top comments (0)