From an underperforming provider to an in-house SOC — in four weeks


From an underperforming provider to an in-house SOC — in four weeks
Case Study — SOC Insourcing with Splunk | Small Robot

Customer Case Study · Security Operations

From an underperforming provider
to an in-house SOC — in four weeks

How Small Robot helped a national retailer replace an underperforming incumbent security provider with its own Splunk-based detection and response capability — reaching parity with the outgoing service in two days.

Client name, logo and incumbent provider identity withheld at the customer's request
Client
National retailer
(name withheld)
Sector
Retail — electronics & technology
Engagement
SOC insourcing — detection & response build
Duration
Four calendar weeks
Technology
Splunk Enterprise Security & Splunk SOAR

The starting point

A national retailer, an underperforming security provider, and a decision to bring it in-house.

The client is a national retailer with the scale, brand exposure and customer data holdings that make it a genuine target — the kind of business where a security incident is a headline, not just an internal issue. Security monitoring and response had been outsourced to a third-party provider, the model many retailers of this size start with.

That incumbent provider was not performing to the standard the business needed. Rather than switch to another external provider and risk the same outcome, the client made a different call: build the capability internally, on a platform it would own and control. That decision — not a security incident — is what set the engagement in motion.

The challenge

Replace an external provider without a gap in coverage, and do it on a platform the client would run itself.

An underperforming incumbent

The existing third-party security provider was not delivering the coverage or responsiveness the business expected — the trigger for the client's decision to stop outsourcing the function altogether.

No coverage gap allowed

Moving from an external provider to an in-house capability had to happen without a period of reduced protection. The new capability needed to match — not eventually approach — what the incumbent was meant to be providing, and do it fast.

Why the timeline mattered

Every day running two security models at once — winding down a provider while a new capability comes online — is a day of ambiguity about who is actually watching the environment. The brief was not just "build an in-house SOC." It was "build one fast enough that the gap is never real."

What Small Robot did

Platform, detection and response — built and owned in-house from day one.

  • Deployed Splunk Enterprise Security. The platform was configured for the client's own environment, not carried over from the incumbent's tooling.
  • Developed detection analytics. Built the detection content the retailer's environment needed, engineered to reach and exceed what the incumbent was covering.
  • Developed response playbooks. Documented the response steps for each detection, so response no longer depended on an external provider's own runbooks.
  • Implemented the playbooks in Splunk SOAR. Converted those documented steps into orchestrated, repeatable automation the client's own team could execute.

Four weeks, three phases

Enterprise Security and detections first, then playbooks, then automation.

WEEKS 1–2 Deploy Splunk Enterprise Security & build detections WEEK 3 Develop response playbooks WEEK 4 Implement playbooks in Splunk SOAR Day 2: parity reached NO GAP IN COVERAGE. FULL CAPABILITY IN-HOUSE.

The results

Parity with the outgoing provider in days, full capability in weeks.

2 daysto reach parity with the incumbent provider's coverage — confirmed by the client
4 weeksfrom kick-off to a fully implemented, in-house SOC capability
In-housedetection and response now owned and operated by the client's own team
AreaBeforeAfter
Security coverage Outsourced to a third-party provider not meeting expectations Matched incumbent coverage within two days; now exceeded via purpose-built detections
Detection capability Dependent on the incumbent's own detection content Splunk Enterprise Security deployed with detections built for this environment specifically
Response capability Response processes owned and run by the external provider Documented playbooks implemented as automation in Splunk SOAR, owned by the client
Ownership & control Security operations sat with a third party Security operations brought fully in-house, on a platform the client controls

A note on the two-day figure

The client confirmed parity with the incumbent's detection coverage was reached within two days.

In their words

“Your team work fast and we love the result. Thank you for the collaboration and knowledge transfer to get us up to speed quickly.”

Cyber Defence Lead — Cybersecurity

Where things stand today

The client's own team now runs Splunk Enterprise Security and Splunk SOAR, using the detections and playbooks built during the engagement. Security operations sit fully in-house, on a platform the business controls end to end — the outcome the original decision to insource was aiming for.