
24/7 SOC Coverage Models for a Crypto Exchange
Co-managed, follow-the-sun, or an in-house night shift — how to pick the staffing model that actually delivers 24/7 SOC coverage for a crypto exchange.
The short answer
There are three ways to actually staff round-the-clock SOC coverage for a crypto exchange: a follow-the-sun handoff across time zones so nobody works nights, an in-house night shift that rotates your own analysts through overnight hours, and a co-managed setup where your team keeps authority over the most sensitive systems while an outsourced team covers first-line triage and the hours you can't staff. The right one depends less on budget alone and more on how much custody and withdrawal-pipeline context an outside team needs before it can act without waking someone up.
Who this is for
This is written for a CISO, Head of Security, or Head of Infrastructure at a regulated crypto exchange who has already decided they need continuous detection and response coverage and is now deciding how that coverage gets staffed — not whether to buy monitoring at all. If you're still deciding between an in-house team, a SIEM you operate yourself, or an outsourced MDR/Managed SOC in the first place, that's the upstream operating-model decision, covered in SOC vs MDR vs SIEM for iGaming. If you've already decided to buy and need the detection content and on-call structure itself, see building a SOC for a crypto exchange from scratch — this post is one layer above that: it's about which staffing model you run underneath whichever detection stack you choose.
The three coverage models
The terms get used loosely enough in vendor conversations that it's worth defining them precisely before comparing:
- Follow-the-sun. Coverage passes between teams in different time zones as each region's business hours end, so the team on shift is always the team that's awake. This requires either a genuinely global outsourced provider or your own presence (or a partner's) in at least two, ideally three, time zones. The failure mode isn't staffing — it's the handoff: anything lost or garbled at the shift boundary is a gap the next team inherits without context.
- In-house night shift. A local team covers 24 hours through rotating shifts — commonly three 8-hour rotations or two 12-hour ones. This keeps everyone in one time zone and one organizational culture, but it concentrates fatigue: someone is always working overnight, and a small team covering this alone is perpetually one resignation or one bout of PTO away from a coverage gap.
- Co-managed SOC. This isn't a time-zone model at all — it's an authority model. Your own analysts retain context and response authority over the systems where that context matters most (custody operations, the withdrawal pipeline, privileged admin actions), while an outsourced team handles first-line triage and covers the hours your in-house team physically can't. Co-managed can run on top of either a follow-the-sun or a night-shift schedule underneath it.
Which model fits, and why exchanges tip the decision earlier than other industries
A generic SaaS company can often get by with a lean in-house night shift for years. A crypto exchange usually can't, for the same structural reasons detection coverage itself can't wait for business hours: the withdrawal pipeline and custody operations never stop, alert-response gaps are exposure gaps on live funds, and the detection content that matters most — wallet-drainer bundle tampering, unscheduled cold-to-hot replenishment, withdrawal-address-change-then-cashout patterns — needs someone who can act, not just page someone, the moment it fires.
| Situation | Best-fit model | Why |
|---|---|---|
| Small security team (1–2 engineers), no existing time-zone presence | Fully outsourced follow-the-sun | You don't have the headcount to staff any rotation yourself, in-house or hybrid; the provider's follow-the-sun coverage has to carry the whole clock |
| Small-to-mid team with 2–3 engineers who understand the custody architecture | Co-managed, on top of the provider's follow-the-sun coverage | First-line triage and off-hours coverage go to the outsourced side; your team keeps authority over custody and withdrawal-pipeline actions that need institutional context |
| Established team large enough that a 24/7 rota is a small fraction of total headcount | In-house night shift, or in-house follow-the-sun across your own regional offices if you have them | Full operational control is affordable at this scale, and institutional knowledge of proprietary systems (custody infrastructure, trading engine) outweighs the staffing cost |
| Team of any size currently running a single-region night shift and losing people to attrition | Move to follow-the-sun (own regional presence or outsourced) | Night-shift-specific attrition is a staffing-model problem, not a hiring problem — the fix is removing the permanent overnight rotation, not hiring faster into it |
Most exchanges land on the second row without framing it that way: they already have a handful of security engineers who know the custody stack, and the real decision isn't "outsource or don't" — it's which alert categories that team keeps authority over versus which ones get triaged externally first.
What actually breaks each model
The failure modes are different enough that they deserve separate answers, not a single "coverage gap" bucket:
- Follow-the-sun breaks at the handoff. An alert opened by the outgoing region and not resolved before the boundary needs a documented handoff briefing, not a silent drop. The tell that a provider's follow-the-sun coverage is real rather than marketing: they can show you the handoff runbook, not just describe the model.
- In-house night shift breaks on attrition. A team of five covering 24/7 alone is not five people's worth of coverage once rotation, PTO, and burnout are accounted for — and unlike a hiring gap, this one gets worse over time as the same people keep absorbing the same overnight hours.
- Co-managed breaks on an undefined authority boundary. If it isn't written down per alert category which side can act without the other's sign-off, the boundary gets discovered live, mid-incident, which is the worst time to negotiate it.
What our follow-the-sun coverage looks like
Our own Managed SOC retainer runs on a follow-the-sun model — EDR/SIEM-agnostic, so it tunes to whatever you already run rather than forcing a stack migration before monitoring starts, and it covers up to 250 endpoints in the base tier (with a fixed per-endpoint rate above that). It includes incident-response hours inside the base retainer each month, with additional hours billed at a pre-agreed rate rather than negotiated mid-incident. Standard onboarding runs about ten business days for SIEM connector setup and detection-content baselining; an active-incident onboarding can start the same day with narrower initial coverage. For an exchange running the co-managed model above it, the scoping conversation is the same one described in Managed SOC for iGaming — which log sources feed the SIEM, which alert categories are ours to act on versus yours, and where SOC monitoring ends and an Incident Response retainer begins.
Limitations
None of the three staffing models changes what the underlying detection content actually catches — that's a separate question, covered by the exchange-specific detection layers in building a SOC for a crypto exchange from scratch. And no coverage model, however staffed, replaces finding exploitable weaknesses before an attacker does — that's a penetration test, a point-in-time offensive engagement, not continuous monitoring; see scoping a penetration test for a crypto exchange if that hasn't happened yet. A confirmed incident, regardless of which staffing model caught it, still needs an Incident Response retainer with the legal and forensic authority to run containment and disclosure.
How to decide
Answer three questions before evaluating a vendor or a hiring plan: how many in-house engineers already understand the custody and withdrawal architecture well enough to hold response authority over it; whether your current team, if any, is already showing attrition signs from a single-region night rotation; and whether your budget supports full in-house 24/7 staffing or needs to lean on an outsourced follow-the-sun team for some or all of the clock. Tell us your current team size and setup and we'll map it against a co-managed or fully outsourced follow-the-sun structure before you commit to a staffing plan.
Sources and review
Coverage-model definitions and failure-mode reasoning reflect general industry practice for follow-the-sun, in-house shift, and co-managed SOC staffing. Retainer scope, pricing tier, and onboarding timeline are AnySec's own published Managed SOC service terms; no third-party vendor pricing or performance statistic is cited as fact. Author: AnySec Engineering. Published 2026-08-17; last reviewed 2026-08-17.
Related reading
- SOC vs MDR vs SIEM for iGaming — the upstream operating-model decision (tool, in-house team, or outsourced) this post assumes is already made.
- Building a SOC for a crypto exchange from scratch — the detection content and on-call structure to run underneath whichever staffing model you choose.
- Managed SOC for iGaming — the log-source and response-boundary scoping conversation for a co-managed or fully outsourced engagement.
- Scoping a penetration test for a crypto exchange — finding the gaps a SOC, however staffed, is built to detect against.
Rather not learn this in production.
Talk to the engineers behind these write-ups — thirty minutes, no sales script, a straight read on where you stand.
Book a call
