REPORT
The high cost of low-quality L1 NOC outsourcing
New research from BigPanda reveals what enterprise IT leaders spend on outsourced L1 NOC support, what they get in return, and why organizations are rethinking the model.
1
Inside enterprise L1 operations: High-Volume, mission-critical, and fragmented
2
The rising costs of escalation
3
The 30% surcharge on outsourced L1 NOC
4
The automation opportunity
5
The status quo is running out of road
Enterprises spend $5.2M a year on outsourced L1 triage, and still misroute a third of their incidents.
The failures don’t stop at misrouting, either. Another 24% of L1 incidents are incorrectly resolved or reworked, requiring L2/L3 engineers to spend an average of 41 hours per month cleaning up lower-tier work.
And the contract price rarely holds. In addition to baseline spend, 90% of IT leaders report unplanned charges that add roughly 30% to annual costs.
Yet enterprise IT leaders estimate that 46% of L1 incidents are routine enough to automate.
While many organizations still assume people are the only scalable way to operate 24×7, the outsourced L1 operating model is buckling under the weight of modern infrastructure and becoming more expensive as complexity increases.
Agentic AI changes the economics, not just the tooling.
We surveyed 112 IT leaders at enterprises with 1,000+ employees about how they work with GSIs, the challenges that come with it, and the alternatives they’re weighing.
Inside enterprise L1 operations: High-Volume, mission-critical, and fragmented
“Centralizing our operations with BigPanda allowed us to have a much earlier MTTD (mean time to detection), which gave us a head start to resolve operational incidents.”

While L1 operational stats don’t typically make it into a board deck or quarterly earnings report, they keep the systems businesses rely on to drive revenue and growth running—and at the enterprise level, that takes significant resources.
On average, IT leaders say their orgs handle about 25,000 L1 incidents per month, with nearly a fifth (18%) reporting at least 50,000.
To surface all these incidents, enterprises leverage a fragmented stack comprising roughly 19 monitoring and observability tools. Worse, 23% reported using 25 or more different tools.
The most common ITSM platforms respondents use to process these incidents include:
Running these operations? About 115 full-time L1/NOC employees.
To get a clearer picture of third-party L1/NOC performance, we surveyed only IT leaders who use GSIs. Nine in 10 respondents take a hybrid approach to L1/NOC incident triage, using both internal employees and GSIs, while the remaining 10% completely outsource their operations.
Most companies aren’t relying on just one GSI, either. Almost eight in 10 IT leaders (79%) say their organizations work with more than one provider, averaging three each.
With tens of thousands of incidents each month, organizations are understandably overwhelmed. But dozens of tools and multiple providers aren’t the answer.
“Centralizing our operations with BigPanda allowed us to have a much earlier MTTD (mean time to detection), which gave us a head start to resolve operational incidents.”

The rising costs of escalation
You don’t have to dig deep into GSI performance metrics before you find significant quality issues. IT leaders’ responses suggest that the traditional, manual approach to L1 operations is struggling to keep pace with the sheer volume of incidents enterprises handle each month.
Organizations spend millions each year paying humans to spend an average of 34 minutes routing tickets. That’s more than half an hour of human attention on a single ticket before anyone even begins to work on the issue.
What’s more troubling than triage time, though, is the share of incidents that are incorrectly routed. According to respondents, just about one-third (34%) of incidents are misrouted or require reassignment before reaching the right team. Meanwhile, a quarter of IT leaders put that figure at 50% or more.
The outlook for resolution isn’t much better. IT leaders say nearly a quarter (24%) of L1 incidents are resolved incorrectly the first time, or must be reopened or reworked.
And when L1 can’t resolve an incident, the work moves up the chain. Enterprise IT leaders estimate that L2/L3 engineers spend an average of 41 hours per month on escalations that should have been resolved at L1. Every month, highly paid engineers spend another full workweek cleaning up failures that should never have escaped L1.
Given these quality issues, it may come as no surprise that SLA breaches are common—but we found they’re almost universal. Over nine in 10 IT leaders (94%) say slow or poor L1 outcomes have contributed to an SLA breach, with respondents reporting nearly four events (3.5) per year.
Altogether, these issues have a real impact. Nearly all (96%) IT leaders say misrouted, mishandled, or missed L1 incidents cost their business. Half describe the cost as “significant” or “severe.”
“I’m able to sleep at night because BigPanda is always watching my events.”

The greater the volume of incidents respondents face, the more these errors pile up.
To top it all off, organizations report paying an average of $5.36 million annually for these outcomes.
“I’m able to sleep at night because BigPanda is always watching my events.”

The 30% surcharge on outsourced L1 NOC
Many IT leaders end up spending more on L1 NOC triage than they originally planned, partly due to churn.
Respondents say new L1 team members are onboarded an average of six times per year. Paired with a ramp time of nearly four months (3.5), that means L1 NOC teams are virtually never working at full productivity. More than that, legacy knowledge is continually lost.
The upshot is that the price of a GSI contract often exceeds the agreed-upon amount. Roughly 90% of IT leaders say their organizations incur unplanned expansion, overage, or true-up charges three times per year. Those who face them say they add an average of 30% to their baseline contract price.
Organizations working with the worst-performing GSIs encounter even more unpredictable billing. Among those whose providers had the highest misrouting and resolution-error rates, unplanned charges added an average of 42% to annual contract value, compared with 30% across the full sample.
Another variable that affects costs: incident volume. Earlier, we saw that quality decreases with incident volume, but costs actually increase. So high-volume organizations aren’t just paying more, they’re getting less out of it.
That pressure is only building. Nearly three-quarters (74%) of respondents anticipate rising ticket volume over the next 12 months, with that group expecting a 27% increase.
Almost all (96%) of IT leaders say they’re concerned that growth in systems, environments, and alert volume will drive up their L1/GSI costs—and according to the data, their concern isn’t unfounded.
The automation opportunity
IT leaders know something needs to change: 92% are either open to, evaluating, or piloting alternatives to their current L1 NOC model.
Four in 10 respondents (41%) say their organizations plan to actively assess other solutions within the next twelve months. And with 83% of GSI contracts set to renew over the next two years, even more may join in the near future.
The top factors motivating change include:
IT leaders see agentic AI as capable of addressing all four. The areas where they say autonomous AI agents would deliver the most value include:
Amid rising ticket volume, costs, and errors, IT leaders face growing pressure to rethink L1 NOC operations. And with IT leaders saying nearly half (46%) of L1 NOC incidents are repeatable, rules-based, and, in principle, automatable, automating a defined share of L1NOC triage may be the logical next step.
The status quo is running out of road
“It’s really transformational and game-changing.”

For years, enterprises accepted an outsourced L1 NOC because there was no practical alternative. That assumption shaped staffing models, contracts, and budgets across the industry.
Our research suggests that assumption no longer holds.
When nearly half of L1 work is routine, organizations have an opportunity to stop scaling headcount with incident volume and instead scale intelligence.
The BigPanda Agentic ITOps platform transforms how enterprises detect, respond to, and prevent incidents. Agentic ITOps represents a new paradigm in which technology works alongside humans to scale IT capacity to meet the speed, complexity, and demands of modern enterprise IT environments.
Is your L1 NOC model due for a change? Request a demo to see what autonomous L1 triage can bring to your organization.
“It’s really transformational and game-changing.”
