{"nav":{"soc":"SOC","securityServices":"Security Services","company":"Company","bookDemo":"Talk to us","talkToSocEngineer":"Talk to us","openMenu":"Open menu","closeMenu":"Close menu","toggleTheme":"Toggle theme","commandPalette":"Open command palette","learn":"Learn","learnMenu":{"basics":"Basics","guides":"Guides","guidesDesc":"Guides and comparisons on SOC and security.","glossary":"Glossary","glossaryDesc":"SOC, detection and compliance terms explained in brief."},"companyMenu":{"who":"Who we are","trustGroup":"Trust","about":"About us","aboutDesc":"Who we are and how our SOC works.","careers":"Careers","careersDesc":"Open roles in our SOC team.","references":"Examples","referencesDesc":"Anonymised examples from our SOC operations.","trust":"Trust Center","trustDesc":"Certification, data residency and sub-processors."},"homeLink":"ANOMAL home","primaryNav":"Main navigation","contactAnomal":"Talk to us"},"hero":{"eyebrow":"SOC as a Service from Switzerland","titleLine1":"Your SOC as a Service","titleLine2":"from Switzerland.","titleLine3":"24/7 in operation.","sub":"Automation, Agentic AI and our analysts work as one team. <1>Hyper Automation</1> filters out the noise and prepares every case with full context. People make the decisions. Automated response only runs where you have approved it in advance.","ctaPrimary":"Talk to us","ctaSecondary":"See how our SOC works","trustLead":"Trusted by Swiss enterprises","trust":{"iso":"ISO 27001","hosted":"Data in Switzerland and the EU","always":"24/7 · 365","eu":"Swiss & EU data residency","regs":"FIRST member"}},"operatingModel":{"eyebrow":"How our SOC works","titleA":"Machines prepare.","titleB":"People decide.","lead":"Every alert goes through the same five stages: triage, investigation, scoring, response and improvement. Each stage has a clear division of labour. Deterministic playbooks handle everything that must run the same way every time. Agentic AI steps in where judgement is needed. Our analysts make the decisions. Every step is logged and traceable.","metrics":{"mttr":"mean time to respond","auto":"cases auto-resolved within mandate","cold":"cold starts for analysts"},"outcomeLabel":"Outcome","outcomeBody":"When an analyst takes over, the case is already enriched, investigated and scored.","noColdStarts":"Nobody starts from scratch.","deepDive":"Learn more","layerLabel":"Layer","layers":{"triage":{"name":"Triage","tag":"Enrich","l1":"Deterministic dedupe, correlation, normalisation across every source","l2":"Automated enrichment · TI · VirusTotal · MISP · AbuseIPDB","l3":"Agentic AI steps in only where reasoning is needed, for example the triage summary."},"investigation":{"name":"Investigation","tag":"Reason","l1":"Agentic AI analyses the enriched evidence","l2":"Deterministic playbooks fetch the data the agents need","l3":"Full reasoning trace attached to every case"},"scoring":{"name":"Scoring","tag":"Decide","l1":"Scoring based on your past cases and your environment (RAG)","l2":"Risk signals · user, device, environment","l3":"The verdict decides which of your mandates applies"},"response":{"name":"Response","tag":"Act","l1":"Deterministic actions inside your approved mandate","l2":"Low-impact and reversible first (revoke before isolate)","l3":"Handoff to our analyst with full context"},"feedback":{"name":"Improvement","tag":"Learn","l1":"Every analyst decision reduces noise at the source","l2":"Baselines and playbooks tuned per tenant","l3":"The model becomes measurably more accurate over time"}}},"outcomes":{"values":{"Hours":"Hours","Minutes":"Minutes","Manual":"Manual","always":"always"},"eyebrow":"Outcomes","titleA":"What a tiered SOC","titleB":"can't deliver.","lead":"The classic tiering model with L1, L2 and L3 queues does not scale with today's alert volume. Every handover between tiers costs time and context, L1 analysts burn out on repetitive triage, and attackers now move faster than any escalation chain. That is why we use a model where automation does the groundwork and analysts decide directly.","trailingLabel":"","legacy":"Legacy tiered SOC","anomal":"ANOMAL Operating Model","delta":{"faster":"→ faster","zero":"→ 0"},"metrics":{"mttd":{"label":"Mean time to decision","context":"From alert ingest to a scored, contextualised decision."},"noise":{"label":"Noise removed","context":"Deduplication, correlation and normalisation before an analyst sees the alert."},"autoclose":{"label":"Cases auto-closed","context":"Benign, duplicate and low-risk cases resolved by agents with full audit trail."},"coldstart":{"label":"Analyst cold starts","context":"Every analyst-tagged event lands in the IMS with playbook trace, scoring rationale and pre-drafted response actions."}},"footerLabel":"Bottom line","footerBody":"When an analyst takes over, the case is already investigated, scored and documented.","footerAccent":"Our analysts never start from zero.","deepDive":"Learn more"},"caseAnatomy":{"eyebrow":"Anatomy of a case","titleA":"From alert to containment","titleB":"in minutes, not hours.","sub":"A real trace through the five stages of our operating model, from the first EDR alert to a contained session. Each step is scored, documented and handed to the analyst with full context.","totalTime":"Containment in minutes, not hours","autoAdvance":"Plays automatically · click to jump","compareLabel":"Total time to containment","compareBody":"compared with much longer response times in a legacy tiered SOC","cta":"Learn more about our SOC","steps":{"alert":{"name":"Alert","body":"Detection signal from any source, including EDR, SIEM, NDR, Cloud and Identity. A case is created, normalised and pushed into the hot triage queue."},"triage":{"name":"Triage","body":"The triage agent enriches: threat intel (VirusTotal, MISP, AbuseIPDB), user and device risk, processes, logons, geo. 14 signals condensed."},"investigation":{"name":"Investigation","body":"Playbook agent for known patterns, freeform agent for the unknown. Reasoning trace and evidence artefacts attached to the case."},"scoring":{"name":"Scoring","body":"Confidence score from triage + investigation, RAG lookup against historical cases, risk signals. Verdict: true positive · severity high."},"response":{"name":"Response","body":"Session revoke, MFA reset, host isolation. Handoff to our analyst with playbook trace, rationale and pre-drafted actions."}}},"legacyVs":{"eyebrow":"Legacy vs. ANOMAL","titleA":"The tiered SOC is a","titleB":"2010 org chart.","sub":"Legacy MSSPs still bill you for L1 analysts who move alerts through queues and L2 analysts who triage them again. We replace that routine work with Hyper Automation: deterministic where possible, Agentic AI where judgement is needed. That leaves our analysts free for the decisions that matter.","headMeta":"side by side","legacyLabel":"Legacy tiered SOC","anomalLabel":"ANOMAL Operating Model","footerLabel":"Bottom line","footerBody":"Same tools, same regulator, a different result.","footerAccent":"Switch providers, keep your tools.","cta":"Discuss switching providers","rows":{"triage":{"label":"Triage depth","legacy":"Basic dedup · L1 tags & escalates","anomal":"Full context · TI, risk, geo, MITRE stage","delta":"12× more context"},"investigation":{"label":"Investigation time","legacy":"Analyst starts from scratch","anomal":"Deterministic playbooks and AI reasoning, no wait time","delta":"Minutes, not hours"},"handoffs":{"label":"Handoffs per case","legacy":"L1 → L2 → L3 · 3 handoffs per case","anomal":"No tiers · no handoffs","delta":"3 → 0"},"load":{"label":"Analyst load","legacy":"Analysts triage 50+ alerts per shift","anomal":"Analysts make decisions instead of sifting noise","delta":"Signal, not queue"},"autoclose":{"label":"Auto-close rate","legacy":"8% auto-closed · rest queued","anomal":"78% auto-closed within mandate · full audit trail","delta":"Higher auto-close share"}},"badge":"Human-led · Tier-less"},"bento":{"eyebrow":"What you get as a customer","titleA":"One service.","titleB":"Everything included.","sub":"One contract with our SOC. Coverage around the clock from Switzerland, Hyper Automation for routine triage, Agentic AI in investigations and analysts who make every decision. One flat fee per year, no hidden items.","includedLabel":"Included in every mandate","priceLabel":"Pricing","priceLine":"FLAT FEE PER YEAR","footerLine":"One contract · one bill · one accountable team","footerMeta":"Halcyon with Ransomware Warranty as optional add-on","included":{"detection":"Detection engineering","response":"Incident response","tuning":"Threat Hunting","playbooks":"Custom playbooks","threatIntel":"Threat intelligence","reporting":"SOC KPI reporting"},"tiles":{"socaas":{"title":"SOC as a Service · flat fee","body":"One contract. Everything included: 24/7 detection, response, tuning, playbooks, threat intel and executive reporting. Halcyon with its Ransomware Warranty available as an optional add-on.","tag":"Core offering"},"agents":{"title":"Hyper Automation","body":"Deterministic workflows for triage, enrichment and mandated response, reliable and auditable. Agentic AI inside investigation and scoring, where judgement is needed, running privately in Switzerland with no customer data used for model training.","tag":"How it runs"},"halcyon":{"title":"Halcyon Add-on","body":"Extra protection with Halcyon's Ransomware Warranty. Halcyon stops encryption, captures the attackers' encryption key and blocks data exfiltration during a live attack. Operated by our SOC.","tag":"Warranty"},"anoview":{"title":"ANOVIEW","body":"Customer portal with reporting and a live view into our SOC. You see every case the way our team sees it.","tag":"Portal"},"sources":{"title":"Every detection source","body":"EDR (Elastic, Defender, CrowdStrike), SIEM, NDR, cloud, email and identity. Keep what you already run. We connect, normalise and operate it.","tag":"Integrations"},"delivery":{"title":"SOC Delivery","body":"24/7/365 from Switzerland. Contractual SLAs and onboarding completed within weeks.","tag":"Operations"}}},"social":{"eyebrow":"Sectors we serve","title":"Built for Swiss organisations.","cta":"Talk to us","stats":{},"sectors":{"finance":"Public sector","insurance":"Blue light organisations","industry":"Industry","energy":"Energy & critical infrastructure","health":"Healthcare","legal":"IT service providers"}},"ecosystem":{"eyebrow":"Our partners","title":"Our partners.","titleItalic":"Selected, certified, operated by us.","lead":"We work closely with these vendors and operate their solutions inside our SOC. What counts for you is the result, not the licence.","note":"Which telemetry sources and tools we can connect in your environment is described on the platform page.","cta":"Learn more about our SOC","first":{"eyebrow":"FIRST member","title":"We are a FIRST member.","body":"ANOMAL is a member of FIRST, the global Forum of Incident Response and Security Teams. Membership is vetted, so our incident response practice is peer-reviewed and connected to the trusted network other CERTs and SOC teams rely on.","points":{"p1":"Trusted channels to CERTs, vendors and other response teams worldwide","p2":"Early, verified intelligence on active campaigns before it becomes public","p3":"Incident response that follows internationally recognised practice","p4":"Faster escalation paths when your case needs external help"}}},"halcyonTeaser":{"eyebrow":"Add-on · Anti-Ransomware","title":"Halcyon on top.","titleItalic":"Recovery, not wishful thinking.","body":"Every SOCaaS subscription can be extended with Halcyon, including Halcyon's Ransomware Warranty. Prevention, key capture and resiliency in one package.","bullets":{"b1":"Anti-ransomware engine on every endpoint","b2":"Encryption-key capture for rapid recovery","b3":"Ransomware Incident Response","b4":"Fully operated inside the ANOMAL SOC"},"cta":"Discuss ransomware protection"},"cta":{"eyebrow":"Two ways to work with us","titleA":"Your SOC,\ndelivered as a service.","titleB":"Or build your own, with us.","button":"Talk to us","buttonSecondary":"We'll help you build","meta":"30-MINUTE INTRO · NO SLIDES"},"newsletter":{"eyebrow":"Newsletter by our founder","title":"SOC Rewritten","pitch":"Notes on how modern SOCs should work. Hyper Automation, agentic automation, analyst craft and the quiet failure modes nobody puts on a slide.","cta":"Subscribe on LinkedIn","meta":"Weekly · Personal newsletter · LinkedIn"},"footer":{"tagline":"SOC as a Service from Switzerland. Automated where possible, led by people where it matters.","cols":{"soc":"SOC","securityServices":"Security Services","company":"Company","learn":"Learn","topics":"Topics"},"links":{"operatingModel":"Operating Model","agentStack":"Agent Stack","anoview":"ANOVIEW","halcyon":"Halcyon Add-on","socDelivery":"SOC Delivery","cyberDefense":"Cyber Defense","consulting":"Consulting","offensive":"Offensive Security","training":"Training","about":"About","careers":"Careers","certs":"Certifications","press":"Press","contact":"Contact","glossary":"Glossary","caseStudies":"Examples","trust":"Trust Center","socAsAService":"SOC as a Service","whatIsSoc":"What is a SOC?","socTerms":"SOC, SIEM, EDR, XDR, MDR","socManufacturing":"SOC for manufacturing","guides":"Guides"},"legal":{"privacy":"Privacy","imprint":"Imprint","terms":"Terms","editorial":"Editorial principles"},"rights":"UEBERLANDSTRASSE 1 · DÜBENDORF · SWITZERLAND"},"careers":{"meta":{"title":"Careers at ANOMAL | Join our team","description":"Open roles at ANOMAL AG in the Zurich region. A small, senior team building a Swiss SOC without tiers, highly automated and led by people.","ogTitle":"Careers | ANOMAL","ogDescription":"Open roles in the Zurich region. Cyber Defense Engineer & Analyst. Shape your career with us."},"hero":{"eyebrow":"Careers · ANOMAL AG","titleLead":"Join our mission","titleAccent":"shape your career.","subtitle":"We're building a Swiss SOC without tiers, highly automated and led by people. A small, senior team, real ownership, and five streams that hold our SOC together.","cta":"See open roles"},"streams":{"label":"SOC Streams · 5","teaserLead":"J.A.R.V.I.S · GUARDIANS · HYPERDRIVE · ILLUMINATI · JUSTICE LEAGUE.","teaserQuestion":"Curious what sits behind these names? Open a stream.","details":[{"name":"J.A.R.V.I.S","body":"Agentic AI and deterministic automation. The stream that prepares cases end-to-end before a human looks at them."},{"name":"GUARDIANS","body":"24/7 monitoring and case ownership. Every alert from low to critical gets a verdict, not a queue position."},{"name":"HYPERDRIVE","body":"Sales and go to market. The stream that brings new customers on board and translates security needs into a clear SOC scope."},{"name":"ILLUMINATI","body":"Strategy stream of the founders. Company direction, service portfolio, partnerships and where ANOMAL goes next."},{"name":"JUSTICE LEAGUE","body":"Engineering stream. Continuous development of the SOC, monitoring and customer onboarding into the platform."}],"reveal":"Reveal","close":"Close"},"principles":{"label":"How we work","items":[{"n":"01","title":"Small. Senior. Swiss.","body":"Direct access to experts. Seniority over headcount."},{"n":"02","title":"Automate the routine work.","body":"If a step is deterministic, it belongs in automation. Human time is for decisions, not for ticket handling."},{"n":"03","title":"Governed autonomy.","body":"Agentic AI drafts, humans decide. Autonomous action only within customer-approved mandates. Every action reversible, every action auditable."}]},"roles":{"label":"Open roles · 2","applyCta":"Apply now","byId":{"cyber-defense-analyst":{"number":"01","title":"Cyber Defense Analyst","tagline":"You make the calls. The agents prep them.","team":"SOC Operations","type":"Full-time","location":"Zurich region · hybrid","bullets":["Own the true-positive decisions on cases that Agentic AI has prepared end to end","Shape response mandates with customers instead of crunching tickets","Detection tuning and feedback loop directly into automation"]},"cyber-defense-engineer":{"number":"02","title":"Cyber Defense Engineer","tagline":"Build the automation that solves 78% of cases without a human.","team":"Engineering","type":"Full-time","location":"Zurich region · hybrid","bullets":["Deterministic workflows in Tines & Python, triage, enrichment, mandated response","Detection engineering across Defender, CrowdStrike, Elastic, Identity","Own reliability, your automation runs 24/7 in production"]}}},"culture":{"label":"Culture","titleLead":"How we work and","titleAccent":"how we grow.","items":[{"title":"Flexibility","body":"We know life is more than work. Flexible schedules, hybrid setup, fair shift planning."},{"title":"Growth","body":"Certifications, conferences, dedicated learning time. You grow as fast as you want."},{"title":"Ownership","body":"Small teams, short paths. Your work has direct impact on real customer environments."},{"title":"Swiss First","body":"Local standards and location. Salaries and conditions at market level."}]},"final":{"eyebrow":"Nothing quite right?","titleLead":"Introduce yourself","titleAccent":"anyway.","titleTail":"","body":"If you're strong in SOC operations, detection engineering or automation, we want to hear from you, even without an open role.","mailCta":"personal@anomal.xyz","contactCta":"Contact form"},"apply":{"cancel":"Cancel","back":"Back","next":"Next","submit":"Send application","sending":"Sending…","done":"Done","applicationFor":"Application · {{title}}","genericError":"Something went wrong.","intro":{"badgePrefix":"Application ·","titleLead":"Let's start.","titleAccent":"A few questions.","titleTail":"8 minutes.","body":"Basics, motivation, personality, one tech question and a small challenge, plus your CV at the end. Progress is stored locally. Questions rotate on each new attempt.","tags":["Basics","Motivation","Value","Personality","Tech","Challenge","CV"]},"questionNo":"Question {{n}}","funNo":"Fun Question · {{n}}","tipTag":"Tip","counterMinInfo":"{{n}} / 2000 · min. 200","counterMin":"{{n}} · min. {{min}}","counterOfMin":"{{n}} / {{min}}","steps":{"name":{"q":"What's your name?","ph":"Your full name"},"email":{"q":"Your email.","ph":"you@example.com"},"found":{"q":"How did you find us?","options":{"linkedin":"LinkedIn","referral":"Referral","event":"Event / conference","other":"Other"}},"why":{"q":"Why ANOMAL?","sub":"Briefly, what draws you in. Min. 40 characters.","ph":"Because…"},"motivation":{"q":"Motivation letter.","sub":"Who you are, what drives you in cybersecurity, what you want to make happen with us. 200–2000 characters.","ph":"I'm applying because…","tip":"Tip: concrete examples beat buzzwords."},"value":{"q":"Where would you bring the biggest value at ANOMAL, and why?","sub":"Min. 120 characters. Optional: mark your core areas.","ph":"I bring the biggest value in …, because …","tags":["Detection Engineering","Threat Hunting","Incident Response","SOAR & Automation","Cloud Security","Identity & IAM","Endpoint / EDR","Network / NDR","Purple Teaming","SIEM / KQL"]},"hero":{"q":"If you were a superhero, which one?","sub":"Don't worry, this isn't part of the standard process.","options":{"batman":"Batman","ironman":"Iron Man","spiderman":"Spider-Man","strange":"Doctor Strange","other":"Other"}},"hero_why":{"q":"And why that one exactly?","ph":"Because…"},"coffee":{"q":"Coffee level on an incident day?","sub":"Scale 0 (zen) to 10 (espresso turbine).","labels":["Zen master","Herbal tea","One cup","Second cup","Solid dose","Barista mode","Double espresso","Triple shot","Espresso turbine","I am coffee","Legend"],"scaleMin":"Zen master","scaleMax":"Legend"},"shift":{"q":"Your preferred SOC shift?","options":{"early":"Early shift","late":"Late shift","night":"Night shift","rotation":"Rotation"}},"tech":{"label":"Tech check · 11","correct":"Solid. Moving on.","incorrect":"No worries, we'll look at the right answer together in the interview. You still move on."},"challenge":{"label":"Challenge · 12 · Gatekeeper","placeholder":"Your answer","check":"Check","solvedBtn":"Solved ✓","attempts":"Attempts: {{n}}","showHint":"Show hint","hideHint":"Hide hint","wrong":"❌ Not yet. Try again.","solved":"Nice. You're through."},"cv":{"label":"CV · Question 13","title":"Upload your CV.","sub":"PDF or DOCX · max. 10 MB. A human reads it, not a bot.","drop":"Drop file here or click.","formats":"PDF · DOCX","replace":"{{size}} MB · Click to replace","remove":"Remove","tooBig":"File > 10 MB.","badFormat":"Only PDF or DOCX."},"linkedin":{"q":"LinkedIn or portfolio?","sub":"Optional. One link is enough.","ph":"https://linkedin.com/in/your-profile"},"review":{"label":"Almost done","title":"Review & send.","sub":"Quick check. Everything editable.","change":"Edit","rowLabels":{"name":"Name","email":"Email","found":"Found via","why":"Why ANOMAL","motivation":"Motivation","value":"Value area","hero":"Superhero","hero_why":"…and why","coffee":"Coffee level","shift":"Preferred shift","tech":"Tech question","challenge":"Challenge","cv":"CV","linkedin":"LinkedIn"},"challengeOpen":"Open","challengeSolved":"Solved ✓"},"success":{"thanks":"Thanks, {{name}}.","thanksAccent":"We'll be in touch.","fallbackName":"candidate","body":"Your application is with us. A human, not a bot, will look at it within the next 5 working days and reach out by email from personal@anomal.xyz.","backCareers":"Back to careers","backHome":"To homepage"}},"hints":{"name":"Please enter your first and last name (at least 2 characters).","email":"Please enter a valid email address.","found":"Please pick an option.","why":"Please write at least 40 characters.","motivation":"Please write at least 200 characters (maximum 2000).","value":"Please write at least 120 characters.","hero":"Please pick an option.","hero_why":"Please write at least 10 characters.","coffee":"Please pick an option.","shift":"Please pick an option.","tech":"Please pick an option.","challenge":"Please solve the challenge first.","cv":"Please upload your CV.","generic":"Please complete this step."}}},"contact":{"eyebrow":"30 min · no slides","titleLine1":"See the SOC","titleLine2":"live.","lead":"See the Operating Model live. Watch a real case flow through Triage, Investigation, Scoring and Response inside ANOVIEW, with real telemetry.","contactBullets":{"phone":"· Zurich region · +41 44 537 85 80","email":"· hello@anomal.xyz","hubspot":""},"form":{"label":"Contact form","successTitle":"Message received.","success":"Thanks. We'll be in touch within one business day.","fields":{"firstname":"First name","lastname":"Last name","email":"Email","company":"Company","phone":"Phone (optional)","message":"Message"},"consentPre":"I agree to the processing of my data according to the ","consentLink":"privacy policy","consentPost":".","captchaMissing":"Please complete the security check.","captchaError":"Security check failed. Please refresh and try again.","sending":"Sending…","submit":"Send message","privacy":"Spam protection by Cloudflare Turnstile.","errors":{"required":"Please fill in this field.","email":"Please enter a valid email address.","messageMin":"Please write at least 10 characters.","consent":"Please confirm your consent."},"optional":"optional","preferCall":"Prefer a call?","preferCallCta":"Talk to us"}},"trust":{"eyebrow":"Company · Trust Center","titleLine1":"Swiss standards.","titleLine2":"Documented.","lead":"This page is maintained by ANOMAL AG. It answers common questions about security, privacy and operations of our SOC and describes our current controls and practices. It is not an independent certification.","foundation":"Foundation","practices":"Practices","practicesHeading":"How we handle your data.","subprocessors":"Sub-processors","subprocessorsHeading":"Who has access to your data.","subprocessorsLead":"Parties to which ANOMAL AG transfers personal data as controller or processor for the operation of anomal.xyz and its business systems. Customer-specific variations are defined in the Data Processing Agreement.","tableProvider":"Provider","tablePurpose":"Purpose","tableRegion":"Region","contactSectionLabel":"Contact","contactHeading":"Security & privacy contact.","contactBody":"Report a security concern, request our DPA, or ask for the ISO 27001 statement of applicability. We reply within one business day.","contactForm":"Contact form","pillars":{"cert":{"tag":"Certification","title":"ISO 27001 certified","body":"ANOMAL operates an ISO/IEC 27001:2022 certified Information Security Management System. Full statement of applicability available on request under mutual NDA."},"residency":{"tag":"Data residency","title":"Switzerland & EU only","body":"Customer telemetry and case data are stored and processed in Swiss or EU regions only. Some website and marketing tools are US-based; they never receive customer telemetry or case data."},"ops":{"tag":"Operations","title":"24/7 from the Zurich region","body":"The SOC is staffed and operated from the Zurich region, 24/7/365. Analysts work as one team."}},"practiceItems":{"access":{"title":"Access & authentication","body":"Role-based access, phishing-resistant MFA for all staff, Just-In-Time elevation for production access. All administrative access is session-recorded."},"crypto":{"title":"Encryption","body":"TLS 1.2+ in transit, AES-256 at rest across managed backends. Customer-scoped keys where the backend supports them."},"retention":{"title":"Retention & deletion","body":"Case data retention is contractually defined per customer. Deletion is executed on request and on contract termination, with written confirmation."},"mandates":{"title":"Response mandates","body":"Autonomous response only within customer-approved mandates. Every mandate is versioned, reversible, and visible in ANOVIEW."}},"subprocessorItems":{"hubspot":{"name":"HubSpot, Inc.","purpose":"CRM, lead and marketing data","region":"EU (Germany)","transfer":"EU SCC + Swiss FDPIC addendum"},"cloudflare":{"name":"Cloudflare, Inc.","purpose":"Edge delivery, DNS, Turnstile bot protection","region":"Global","transfer":"EU SCC + Swiss FDPIC addendum"},"web-hosting":{"name":"Website hosting","purpose":"Website hosting","region":"EU","transfer":"EU SCC"},"database":{"name":"Website database","purpose":"Website database (enquiries, bookings, applications), data centre in Zurich, Switzerland","region":"CH","transfer":"EU SCC + Swiss FDPIC addendum"},"google":{"name":"Google Ireland Ltd.","purpose":"Web analytics (Google Analytics), only after consent","region":"EU, possible transfer to the US","transfer":"EU SCC + Swiss addendum"},"google-ads":{"name":"Google Ireland Ltd. (Google Ads)","purpose":"Conversion measurement (Google Ads), only with «Marketing» consent","region":"EU, possible transfer to the US","transfer":"EU SCC + Swiss addendum"}},"tableTransfer":"Transfer","badges":{"iso":"ISO 27001:2022 certified","swiss":"Swiss Made","sla":"24/7 SOC in the Zurich region"},"customerTechHeading":"Customer-tenant technology","customerTechLead":"Detection and response technology deployed inside the customer’s own cloud tenant. Customer remains data controller. ANOMAL operates the stack under the Master Service Agreement. These are not ANOMAL sub-processors.","customerTechItems":{"ms":{"name":"Microsoft Sentinel / Defender / Entra","purpose":"SIEM, XDR, identity in customer tenant","region":"Switzerland North / West Europe","transfer":"Customer-controlled"},"elastic":{"name":"Elastic (Elastic Security / SIEM)","purpose":"SIEM and detection in customer tenant","region":"Switzerland / EU","transfer":"Customer-controlled"},"exeon":{"name":"Exeon Analytics","purpose":"ML-based NDR in customer network","region":"Switzerland","transfer":"Customer-controlled"},"edr":{"name":"Microsoft Defender or CrowdStrike","purpose":"EDR options per customer choice","region":"EU","transfer":"Customer-controlled"},"halcyon":{"name":"Halcyon","purpose":"Optional anti-ransomware runtime with Ransomware Warranty","region":"EU","transfer":"Customer-controlled"}}},"references":{"breadcrumbAnomal":"ANOMAL","breadcrumbResources":"Company","breadcrumbLedger":"Deployment patterns","titleLine1":"Anonymised examples.","titleLine2":"No borrowed logos.","lead":"Illustrative deployment patterns for the ANOMAL Operating Model: what a mandate typically replaces, how long onboarding takes, what changes in day-to-day operations.","aggregate":{"autoClosed":"Cases auto-closed","noiseRemoved":"Noise removed","coverage":"Swiss coverage"},"filterLabel":"Filter by sector","industries":{"all":"All","financial":"Financial services","industrial":"Industrial","healthcare":"Healthcare"},"entrySingular":"entry","entryPlural":"entries","featured":"Pattern","more":"More examples","moreCount":"{{count}} of {{total}}","problem":"Situation","solution":"Solution","empty":"No entries under this sector.","ndaLabel":"Our reference policy","ndaTitle1":"We do not promise named references upfront.","ndaTitle2":"We show you the operating model instead.","ndaBody":"In a qualified procurement process we walk you through the operating model, the mandate logic and ANOVIEW with live data from your own detection sources during the shadow-run. Whether a reference call happens is decided case by case, and only with that customer's explicit consent.","requestCta":"Talk to us","footerLeft":"{{count}} entries","footerRight":"ANOMAL","cases":{"REF_01":{"title":"From backlog to real-time handling","problem":"Swiss asset manager routed every EDR alert through an outsourced T1/T2 provider. Backlog averaged 40 hours. Analysts saw the same tickets twice. Regulator was asking questions.","solution":"Replaced the outsourced tiers with the ANOMAL Operating Model. Deterministic enrichment and Agentic AI absorbed triage and investigation. Our analysts saw only fully-prepared cases, under mandates the customer set."},"REF_02":{"title":"OT + IT under one operating model","problem":"Manufacturing group ran plant-floor telemetry and corporate SIEM as two disconnected worlds. Cross-domain incidents took days to correlate. Nobody owned the seam between OT and IT.","solution":"Unified plant-floor and corporate signal into ANOVIEW. One case model, one response playbook, mandates set per-site by the customer's OT security lead. Our analysts cover 24/7. Local plant owners keep the kill switch."},"REF_03":{"title":"Ransomware contained the same day","problem":"Regional healthcare provider hit by ransomware payload landing on a clinical endpoint outside working hours. Clinical workflow can't tolerate downtime.","solution":"Halcyon runtime blocked the encryption stage. ANOMAL deterministic response isolated the endpoint under the customer's pre-approved mandate. Our on-call analyst validated the containment and communicated with clinical ops in parallel."}},"disclaimer":"These are modelled scenarios based on our operating model and Swiss market reality, not published customer case studies. We do not name customers and we do not publish customer quotes.","scenarioBadge":"Modelled scenario"},"whySwiss":{"eyebrow":"Why Swiss","titleLine1":"Sovereign by design.","titleLine2":"Precise by nature.","lead":"For us, data sovereignty is part of the architecture, not an item on a compliance list. Every case, every agent log and every decision stays in Switzerland or the EU.","points":{"hosted":{"title":"Data in Switzerland and the EU","body":"Customer case data, control plane and analysts stay in Swiss or EU regions."},"iso":{"title":"ISO 27001 certified","body":"Independently audited security management system covering the full SOC delivery."},"regs":{"title":"FINMA · DORA · NIS2 aligned","body":"Ready for regulated industries. Evidence packages available to auditors on demand."},"team":{"title":"Human analysts on call in Switzerland","body":"Our team is based in Switzerland and reachable around the clock. No global handoffs."},"stack":{"title":"Own the entire stack","body":"We build the agents, the operating model and ANOVIEW ourselves. We are not a reseller."},"pricing":{"title":"Flat fee","body":"One yearly price. Response inside your mandate is included, incident response for major incidents is billed separately.\nHalcyon ransomware add-on optional."}},"migrationTitle":"Migrate from your existing MSSP.","migrationBody":"30 days of parallel operation. We take over use-cases, playbooks and evidence. You stay in control.","migrationCta":"Discuss switching providers"},"about":{"eyebrowLocation":"About · Zurich region, CH","titleLine1":"Swiss cyber security.","titleLine2":"Built for what's next.","lead":"ANOMAL AG is a Swiss cyber security company from the Zurich region. We operate a modern Security Operations Center built on an AI-driven, tier-less operating model. Every service around it follows the standards we apply to our own platform.","meta":{"founded":"Operating since 2021","byOperators":"Founded by security practitioners","independent":"Independent"},"stats":{"hq":{"k":"Zurich region","v":"headquartered","note":"Ueberlandstrasse 1 · 8600 Dübendorf"},"iso":{"k":"ISO 27001","v":"certified","note":"ISO/IEC 27001:2022 · full ISMS"},"residency":{"k":"CH / EU","v":"data residency","note":"Managed in Switzerland"},"ops":{"k":"24/7","v":"SOC operations","note":"365 days · our analysts"}},"belief":"Our belief","quotePre":"We believe the future of SOC is","quoteAccent":"fully automated, AI-driven and tier-less.","quoteAttr":"ANOMAL · Founding principle · 2021","location":"Where we are","hqName":"ANOMAL AG","hqSub":"Headquarters · Zurich region, CH","address":"Address","email":"Email","socHours":"SOC hours","socHoursValue":"24/7 · 365 days","contactUs":"Talk to us","hqLive":"Headquarters","nowOpen":"Available 24/7","ctaTitle1":"Talk to one of our SOC engineers.","ctaTitle2":"No slides.","ctaCta":"See the SOC live","faqHeading":"Frequently asked questions about ANOMAL","write":{"eyebrow":"No meeting needed yet?","titleA":"Just","titleB":"write to us.","body":"A short message is enough. We reply from the Zurich region within one working day, with no autoresponder and no sales sequence."}},"soc":{"hero":{"eyebrow":"THE ANOMAL SOC","titleA":"What a Swiss Managed SOC","titleB":"should be.","lead":"An inside look at how we operate, not a product pitch. Automation handles the routine triage work, Agentic AI analyses the context during investigation, and our analysts decide. For you, that means protection around the clock, from Switzerland.","kpis":{"mttr":"Noise removed","autoResolved":"cases auto-resolved","coldStarts":"cold starts for analysts","swiss":"Operated from Switzerland"}},"layerMatrix":{"eyebrow":"Operating Model · Who does what","titleA":"Who does","titleB":"what?","lead":"Every alert goes through the same five stages: triage, investigation, scoring, response and improvement. Each stage has a clear division of labour. Deterministic playbooks handle everything that must run the same way every time. Agentic AI steps in where judgement is needed. Our analysts make the decisions. Every step is logged and traceable.","headers":{"layer":"Layer","det":"Automation","agents":"Agentic AI","humans":"Our analysts"},"rows":{"triage":{"layer":"Triage","tag":"Enrich","det":"Dedupe, correlate, normalise across every source. Enrichment via our Threat Intelligence.","agent":"Agentic AI steps in only where reasoning is needed, for example the triage summary.","human":"No human here. Raw alerts never reach analysts."},"investigation":{"layer":"Investigation","tag":"Reason","det":"Playbooks fetch the evidence the agents need, deterministic and auditable.","agent":"Agentic AI analyses the enriched evidence. Every step is recorded as a reasoning trace.","human":"No analyst yet. The case reaches an analyst only after scoring."},"scoring":{"layer":"Scoring","tag":"Decide","det":"Risk signals for user, device and environment feed the score deterministically.","agent":"Scoring based on your past cases and your environment (RAG). Agentic AI proposes a verdict.","human":"No analyst here either. Agentic AI derives which customer mandate applies from the verdict."},"response":{"layer":"Response","tag":"Act","det":"Actions execute deterministically inside your approved mandate, low-impact and reversible first (revoke before isolate).","agent":"Agents draft the action set. Nothing runs outside the mandate.","human":"The analyst is accountable for every decision and acts as the final guardrail."},"improvement":{"layer":"Improvement","tag":"Learn","det":"Baselines, playbooks and detections tuned per tenant.","agent":"RAG index and reasoning updated from every closed case.","human":"Analyst decisions are the benchmark the system learns from. That is how noise disappears at the source."}}},"capabilities":{"title":"Everything else that makes it a SOC.","items":{"portal":{"title":"ANOVIEW customer portal","body":"A live view of your SOC: cases, agent reasoning, scoring and response. The same view our team works with.","tag":"Customer view"},"halcyon":{"title":"Halcyon Ransomware Warranty","body":"Optional add-on: anti-ransomware protection including Halcyon's Ransomware Warranty. Everything else is covered by the flat fee.","tag":"Add-on"},"delivery":{"title":"SOC delivery","body":"Onboarding within weeks. Documented delivery model, playbooks per customer and quarterly business reviews.","tag":"Delivery"},"tierless":{"title":"Tier-less operations","body":"No L1 queue and nobody starts from scratch. Automation and Agentic AI prepares every case with full context, and our analysts make the decisions that matter.","tag":"Model"}}},"delivery":{"eyebrow":"Delivery Models","titleA":"Three ways.","titleB":"One operating model.","lead":"Not everyone needs the same thing. We deliver the operating model in the mode that fits your organisation and maturity. Switching modes is possible as your setup evolves.","flagship":"Flagship","fitLabel":"Fit","footerBody":"Not sure which model fits? A 30-minute chat is usually enough to figure it out. No slide decks, we show ANOVIEW live.","footerCta":"Discuss delivery model","models":{"full":{"tag":"Model 01","title":"Fully Managed SOC","tagline":"We run everything.","body":"Complete SOC operation on our platform. Detection, response, tuning, reporting, compliance. You get the outcomes, we carry the ops load.","bullets":["Full operation on the ANOMAL platform","24/7 detection & response included","Multi-week onboarding phase","One contact, one contract, one price"],"fit":"Ideal for teams without a dedicated SOC or with a legacy MSSP."},"co":{"tag":"Model 02","title":"Co-Managed SOC","tagline":"We operate on your platform.","body":"You already have SIEM, EDR, SOAR. We take over operations where you are. Content engineering, detection, response, all in your environment.","bullets":["Operation on your SIEM/XDR/SOAR","Analysts work in your console","Playbooks and runbooks stay with you","Knowledge transfer included, no vendor lock-in"],"fit":"For organisations that have already invested in their own tools."},"hybrid":{"tag":"Model 03","title":"Hybrid 24/7","tagline":"Daytime you. Nights and weekends us.","body":"Your team works business hours, we cover nights, weekends and holidays. Clean handovers, shared case context, no double work.","bullets":["Off-hours coverage: nights, weekends and public holidays","Shared case queue with clear handoffs","Escalation matrix per shift","Reduces analyst burnout and the risk of losing staff"],"fit":"Ideal for teams with their own SOC but without 24/7 capacity."}}},"advanced":{"eyebrow":"Advanced Services · Included","title":"Beyond monitoring.","lead":"Threat hunting, threat intelligence and automated response within your mandate are part of the flat fee. No packages and no surcharges for the basics. What others sell as extras is standard here.","includedBadge":"Included","items":{"hunting":{"tag":"Included","title":"Threat Hunting","body":"Hypothesis-driven. Human expertise combined with automated queries against the full telemetry lake: process interrogation, persistence mechanisms, lateral movement traces, driver profiling. Findings feed directly back into detection rules and playbooks.","points":["Process interrogation","Persistence anomalies","Lateral movement traces","Driver profiling"]},"intel":{"tag":"Included","title":"Threat Intelligence","body":"Curated intelligence, integrated in real time. Automated reputation checks on every suspicious artefact. IoCs pushed straight into detection so alerts fire faster on emerging campaigns.","points":["Curated community feeds","Automated reputation checks","Real-time IoC push","Continuous playbook tuning"]},"ir":{"tag":"Included","title":"Automated Incident Response","body":"Automated data enrichment from internal and external sources. Playbook-driven workflows. Every case created with full context and a clear audit trail. Contain actions (host isolation, account disable) fire only against use cases you approve.","points":["Data enrichment","Playbook workflows","Automated case creation","Approved contain actions"]}}},"human":{"eyebrow":"Human layer","titleA":"Our analysts.","titleB":"Always reachable.","lead":"Every SOC talks about AI. Regulators, boards and CISOs still ask the same question: who decides, who is accountable, who picks up the phone. Our answer: a Swiss team, based in the Zurich region, operating 24/7. Agentic AI does the work. Our analysts make the decisions.","doTitle":"What our analysts do","dontTitle":"What they don't","do":["Decide on scored cases with full context","Approve contain actions on high-impact assets","Own quarterly business reviews and detection strategy","Escalate to the customer CISO on critical cases, 24/7"],"dont":["Triage alert queues by hand","Copy-paste between SIEM, EDR, ticketing","Start from zero on every case","Wait for L2 to pick up an escalation"]},"slaSection":{"eyebrow":"SLA & Coverage","titleA":"What you can","titleB":"expect from us.","lead":"Typical service parameters for a new tenant. Concrete SLAs are defined in your mandate, adjusted to your regulatory footprint and business criticality. No small print: what the flat fee includes is set out in your mandate.","rows":{"coverage":{"k":"Coverage","v":"24/7 / 365 · Swiss-operated"},"critical":{"k":"Response · Critical","v":"Contractual < 60 min · typical < 15 min"},"high":{"k":"Response · High","v":"Typical <30 min"},"medlow":{"k":"Response · Medium / Low","v":"Same business day"},"onboarding":{"k":"Onboarding","v":"Multi-week onboarding phase to first live coverage"},"reporting":{"k":"Reporting","v":"Live in ANOVIEW · monthly SOC report · quarterly business review"},"ir":{"k":"IR bridge line","v":"24/7 encrypted channel for SEV-1"}}},"compliance":{"eyebrow":"Compliance"},"cta":{"eyebrow":"Two ways to work with us","titleA":"Your SOC, delivered as a service.","titleB":"Or build your own, with us.","primary":"Talk to us","secondary":"Building your own SOC? We can help.","note":"30 min intro · live ANOVIEW · real cases, no slides"},"faqHeading":"Frequently asked questions about the ANOMAL SOC","coverage":{"eyebrow":"Coverage · What we manage","titleA":"Every detection source.","titleB":"One SOC.","lead":"We are vendor-agnostic. Bring your existing detection landscape, or let us assemble the right one. Every surface is normalised and runs through the same operating model.","hint":"","more":"Learn more →","sheet":{"slas":"SLAs","scopeIn":"Included","scopeOut":"Not included","process":"Process","vendors":"Vendor Coverage","deliverables":"Deliverables","standards":"Standards & Frameworks","faq":"FAQ","ctaTitle":"Let's talk about {{title}}.","ctaBody":"30 minutes with our SOC team. You describe your situation, we tell you clearly whether and how we can help.","ctaCta":"Talk to us","telemetry":"Telemetry & signal sources","detections":"Typical detections","responseActions":"Response actions within mandate","limits":"Limits of this service","baseline":"Included in every ANOMAL managed service","pairsWith":"Pairs well with"},"items":{"siem":{"title":"Managed SIEM","body":"We run your SIEM and keep it sharp: we connect new log sources, build detection rules and maintain them.","intro":["Managed SIEM is our platform scope: log source onboarding, parsing and normalisation, detection engineering, rule lifecycle, retention tiering and platform operations. Example stacks are Elastic Security, Microsoft Sentinel or CrowdStrike.","What sets this service apart: the detection pipeline itself is part of the deliverable. We build and maintain use cases and playbooks, keep MITRE ATT&CK coverage traceable and report data gaps openly."],"telemetry":["Log sources across every domain: endpoint, identity, network, cloud, SaaS, applications","Syslog, CEF, NetFlow and API-based collectors","Custom parsers for in-house and line-of-business applications","Audit and compliance logs with defined retention tiering"],"detections":["Cross-source correlation rules, prioritised against MITRE ATT&CK gaps","Tampering with, disabling or truncating audit logs","Silent log sources and ingest failures as a detection of their own","Suspicious admin activity on systems without an EDR agent","Access to regulated data and other compliance-relevant events","Anomalies in legacy and line-of-business applications without standard telemetry"],"responseActions":["SIEM is the detection and evidence layer: the actual action runs through connected tools (EDR, identity, firewall) per mandate","Immediate deployment of new detections and parser fixes during a live incident","Evidence package with timeline and raw logs for IR, insurers and regulators","Query and hunting support for your IT team or an external IR partner"],"limits":["Without connected response tools, SIEM stays detection without action, that needs Managed EDR or Managed IDR","Detection quality is capped by data quality, missing sources are reported as gaps","No substitute for behavioural visibility at segment level, that is Managed NDR"],"scopeIn":["Use case and playbook development and management: use cases, correlation rules and playbooks are built, versioned and tuned","Log source integration and management: onboarding, parsing, normalisation, retention tiering and ingest monitoring","Detection coverage management against MITRE ATT&CK including a prioritised gap backlog"],"scopeOut":["Platform and agent licences (yours, or passed through at cost)","Anti-ransomware (e.g. Halcyon) as a separate add-on module","Eradication and recovery inside your systems, executed by your IT with our coordination","On-prem hardware, collectors and network taps"],"process":[{"title":"Assess","body":"Log source inventory, coverage gap analysis against MITRE ATT&CK, platform and retention health check."},{"title":"Integrate","body":"Priority-based log onboarding with out-of-the-box integrations and custom parsers, baseline detections live within the onboarding phase."},{"title":"Automate","body":"Playbook per detection, SOAR enrichment and automated queries, response actions pre-authorised in the mandate matrix."}],"deliverables":["Use case and playbook catalogue with documented analysis steps","Log source inventory with retention and data quality status","MITRE ATT&CK coverage board with a prioritised detection backlog"],"faqs":[{"q":"Can we keep our existing SIEM?","a":"Yes, we are vendor-agnostic and work on your platform. If none exists yet, we propose one based on log volume, retention needs and budget, for example Elastic Security hosted in Switzerland."},{"q":"What happens to our existing rules?","a":"We inventory them, measure hit quality and keep what works. Rules with no signal or a chronic false positive rate get tuned or replaced, documented in the detection backlog."}]},"edr":{"title":"Managed EDR","body":"We monitor your endpoints around the clock and step in immediately during an attack. It works with all leading EDR platforms.","intro":["Managed EDR is our endpoint scope: policy and prevention tuning, behavioural detections at process and memory level, endpoint hunting and active response up to isolation. Examples are CrowdStrike Falcon, Microsoft Defender for Endpoint or Elastic Defend.","What sets this service apart: this is where the fastest response levers live. A host can be taken off the network in minutes, a process killed, a file rolled back. That is exactly why the mandate matrix matters most here."],"telemetry":["Process tree, command lines and parent-child relationships","Memory and injection activity","File and registry changes","Script interpreters such as PowerShell, WMI and WScript","Persistence mechanisms: scheduled tasks, services, run keys","Outbound connections per process"],"detections":["Abuse of legitimate system tools (LOLBins)","Ransomware precursors: shadow copy deletion, mass encryption, backup sabotage","Credential dumping directly on the host","Persistence established right after initial access","EDR tampering and sensor deactivation","Hands-on-keyboard activity following initial access"],"responseActions":["Host isolation within minutes","Process kill and file quarantine","Rollback where the platform supports it","Blocklisting of hashes and binaries","Example mandate: auto isolation on critical verdicts for standard clients, analyst-in-the-loop for servers and OT-adjacent systems"],"limits":["Managed endpoints with an agent only, OT, IoT, printers and BYOD stay invisible, that is Managed NDR","No view of the cloud control plane or identity layer, that is Managed IDR or Managed XDR","Without a SIEM scope there is no long-term retention and no custom parsing of your own applications"],"scopeIn":["Policy and prevention tuning on the endpoint platform, including hardening against known bypass techniques","Custom behavioural detections on endpoint telemetry plus targeted endpoint hunting","Agent coverage management: deployment gaps, outdated sensors, tamper protection status"],"scopeOut":["Platform and agent licences (yours, or passed through at cost)","Anti-ransomware (e.g. Halcyon) as a separate add-on module","Eradication and recovery inside your systems, executed by your IT with our coordination","Use case/playbook development and log source integration, those come with a Managed SIEM or Managed NDR scope"],"process":[{"title":"Assess","body":"Deployment coverage, policy review, prevention baseline against known bypass techniques."},{"title":"Integrate","body":"Rollout to remaining endpoints, policy hardening, custom behavioural detections, connection to the SOC pipeline."},{"title":"Automate","body":"Isolation and process kill pre-authorised by asset criticality, playbook per detection, SOAR enrichment."}],"deliverables":["Endpoint coverage report: agent distribution, gaps, sensor health","Policy and prevention hardening report with open recommendations","Root cause analysis per true positive including kill chain"],"faqs":[{"q":"Do you isolate endpoints without asking?","a":"Only within the mandate you define. Asset criticality and pre-authorised actions are agreed during onboarding, for example automatic isolation on critical verdicts for standard clients and analyst-in-the-loop for servers."},{"q":"Do you work with our existing EDR licence?","a":"Yes. We take over the existing platform, review coverage and policy maturity and say openly when a switch delivers more value than further tuning."}]},"ndr":{"title":"Managed NDR","body":"We monitor traffic inside your network and detect lateral movement and connections to attacker infrastructure. The signals flow straight into our cases.","intro":["Managed NDR is our network scope: sensor and flow planning, behavioural baselines per segment, detection on metadata and normalisation of signals into the case flow. Examples are Exeon, Corelight, Darktrace or Vectra AI.","What sets this service apart: NDR sees what carries no agent. Unmanaged devices, OT and IoT, legacy systems, lateral movement between zones and C2 in encrypted channels. Because NDR brings its own pipeline, use case and playbook development and log source integration are part of the scope here."],"telemetry":["Flow metadata from firewalls, switches and routers","DNS queries and responses","TLS and JA3 fingerprints, without packet payloads","Proxy, VPN and NAC logs","East-west traffic at segment and zone boundaries","Asset discovery straight from network traffic"],"detections":["Lateral movement across zone boundaries","C2 beaconing in encrypted channels","DNS tunnelling and data exfiltration","Unauthorised access from IT zones into OT zones","New or unknown assets without an agent","Internal scanning and reconnaissance"],"responseActions":["Network isolation via firewall, NAC or switch port per mandate","Blocklisting of domains, IPs and destinations","Segment-specific blocking without intervening on the host","Example mandate: auto block in client zones, approval required in OT and production zones"],"limits":["No process or file forensics on the host, that is Managed EDR","Packet payloads are not captured, analysis runs on metadata","Detection quality depends on sensor and flow coverage per segment"],"scopeIn":["Use case and playbook development and management: network use cases and playbooks are built, versioned and tuned","Log source integration and management: flows, DNS, proxy and sensor onboarding including health monitoring","Segment baselining per zone with documented drift control"],"scopeOut":["Platform and sensor licences (yours, or passed through at cost)","Anti-ransomware (e.g. Halcyon) as a separate add-on module","Eradication and recovery inside your systems, executed by your IT with our coordination","On-prem hardware, collectors and network taps"],"process":[{"title":"Assess","body":"Network topology, critical segments, blind spots, sensor and flow placement plan."},{"title":"Integrate","body":"Onboarding of existing flow sources, baseline over the first weeks, enrichment with asset context."},{"title":"Automate","body":"Playbook per detection, block and isolation actions pre-authorised per zone, SOAR enrichment."}],"deliverables":["Network coverage map with sensor and flow coverage per segment","Baseline report and drift overview per zone","Asset list from a network perspective, including devices without an agent"],"faqs":[{"q":"Do you need decrypted traffic?","a":"No. Detection works on metadata, TLS fingerprints and behavioural patterns. If you run SSL inspection we use it, but it is not a requirement."},{"q":"Does this work in OT zones as well?","a":"Yes, and that is where the value is highest. We work passively on metadata, without an agent and without touching control systems. Response actions in OT zones require approval by default."}]},"xdr":{"title":"Managed XDR","body":"We correlate signals from endpoint, identity, cloud, email and network. Everything lands in one case with one response path.","intro":["Managed XDR is our correlation scope: endpoint, identity, cloud, email and network in one data model, from a single platform or cross-vendor. Examples are Elastic Security, Microsoft Defender XDR or CrowdStrike Falcon.","What sets this service apart: a case is built across domain boundaries, with one timeline and one response path. Attacks that look like three harmless alerts in separate tools become visible as one chain."],"telemetry":["Endpoint telemetry from the EDR platform","Identity signals from Entra ID, Active Directory or Okta","Cloud workloads and control plane logs","Email and collaboration signals (M365, Google Workspace)","Network signals and SaaS audit logs"],"detections":["Attack paths across domain boundaries","Phishing to token theft to endpoint execution as one chain","Cloud persistence after identity compromise","Mailbox rules and consent grants correlated with endpoint activity","BEC chains across mail, identity and cloud","Multi-stage campaigns spanning days or weeks"],"responseActions":["Coordinated response in one playbook: session revoke, host isolation, mail purge and blocklisting in a single step","One case, one timeline, one mandate check across all affected domains","Example mandate: automated combined response on critical verdicts for standard assets, approval for tier-0"],"limits":["Detection depth depends on the integration depth of each individual source","Compliance retention and custom parsing usually run through Managed SIEM","Without network onboarding there is no visibility into agentless zones, that is Managed NDR"],"scopeIn":["Cross-domain correlation and case building across endpoint, identity, cloud, email and network","Cross-domain response playbooks with one shared mandate check","Attack path review and coverage reconciliation per domain"],"scopeOut":["Platform and agent licences (yours, or passed through at cost)","Anti-ransomware (e.g. Halcyon) as a separate add-on module","Eradication and recovery inside your systems, executed by your IT with our coordination","Use case/playbook development and log source integration, those come with a Managed SIEM or Managed NDR scope"],"process":[{"title":"Assess","body":"Domain inventory across endpoint, identity, cloud, email and network, integration paths and API availability."},{"title":"Integrate","body":"Connect all signal sources into a normalised schema, build and test cross-domain correlation cases."},{"title":"Automate","body":"Combined response playbooks across several domains, pre-authorised in the mandate matrix."}],"deliverables":["Cross-domain coverage matrix per connected domain","Attack path review with prioritised hardening recommendations","Case timelines across domain boundaries, documented per incident"],"faqs":[{"q":"Single vendor or best of breed?","a":"Both work. Single-vendor XDR integrates faster, best of breed gives more detection depth. We base our recommendation on your existing landscape."},{"q":"Do we still need a SIEM alongside it?","a":"For detection and response often not. For compliance retention, custom parsing of your own applications and long-term forensic search, many customers add Managed SIEM or a data lake."}]},"idr":{"title":"Managed IDR","body":"We protect your accounts in Entra ID, Okta and Active Directory. We detect suspicious sign-ins and stolen credentials early and revoke affected sessions automatically.","intro":["Managed IDR is our identity scope: cloud and on-prem, human and non-human. Examples are Microsoft Defender for Identity and Entra ID Protection.","What sets this service apart: identity is the attack surface that needs no malware. A stolen token, one approved consent, one MFA push too many. Response here means session revoke and account control, not host isolation."],"telemetry":["Entra ID sign-in and audit logs","Active Directory: Kerberos, LDAP, replication events","Okta or other IdP logs","Consent grants and app registrations","Token and session events","MFA and conditional access outcomes"],"detections":["Token theft and session hijacking","Consent phishing and abuse of OAuth apps","Impossible travel and implausible device combinations","MFA fatigue and push bombing","Kerberoasting and DCSync on on-prem AD","Changes to tier-0 groups and privileged roles"],"responseActions":["Session revoke across all active tokens","Forced password and MFA reset","Account disable and temporary lockout","Revoking risky app consents and service principal permissions","Example mandate: auto revoke for standard accounts, approval required for privileged and tier-0 accounts"],"limits":["No host forensics and no process visibility, that is Managed EDR","No network visibility at segment level, that is Managed NDR","On-prem coverage depends on domain controller logging and sensor deployment"],"scopeIn":["Identity detection tuning against legitimate business patterns such as travel, contractors and automation","Monitoring of conditional access, privileged roles and tier-0 groups","Coverage for non-human identities: service principals, managed identities, OAuth apps"],"scopeOut":["Platform and licence cost of the IdP (yours, or passed through at cost)","Anti-ransomware (e.g. Halcyon) as a separate add-on module","Implementation of IAM governance, role models and recertification","Use case/playbook development and log source integration, those come with a Managed SIEM or Managed NDR scope"],"process":[{"title":"Assess","body":"Identity inventory, privileged and tier-0 accounts, existing conditional access policies, non-human identities."},{"title":"Integrate","body":"Identity detections rolled out, baseline over the first weeks, tuning against legitimate business patterns."},{"title":"Automate","body":"Session revoke and MFA reset pre-authorised by account class, playbook per detection, SOAR enrichment."}],"deliverables":["Identity attack surface report including non-human identities","Conditional access baseline with deviations and recommendations","Overview of privileged and tier-0 accounts with change history"],"faqs":[{"q":"Does this cover non-human identities?","a":"Yes. Service principals, managed identities, OAuth apps and workload identities are in scope, that is exactly where consent grants and app impersonation happen."},{"q":"Do you also disable executive accounts automatically?","a":"Only if you mandate it that way. As a rule, privileged and tier-0 accounts require approval: we revoke the session, document the finding and escalate along your defined path."}]}},"seo":{"scopeIn":"Included","scopeOut":"Not included","process":"Process","deliverables":"Deliverables","vendors":"Vendor Coverage","standards":"Standards"},"baseline":{"items":["24/7 threat monitoring: every alert is picked up, enriched with context and documented in the ticket system","Incident triage on every severity from low to critical, classified as false positive, benign true positive or true positive","Further analysis on every suspected true positive, including log, telemetry and asset context","Incident response along NIST: containment and first response within your mandate. A full IR engagement for a major incident is billed separately.","SOC platform operations: backend, updates and health monitoring of the SOC stack","Automated incident response: SOAR enrichment, automated queries, pre-authorised response actions per mandate","Threat hunting and threat intelligence (e.g. MISP plus external feeds) feeding back into detections","Effectiveness testing once a year, e.g. together with an external purple team","Service management: monthly service efficiency report, quarterly optimisation meeting, live view in ANOVIEW","Ongoing operations: continuous tuning, detection maintenance and quarterly service optimisation"],"sla":{"label":"Critical incident response time (contractual)","value":"< 60 min (24/7)"},"note":"Scope, service level (e.g. business hours for low to high, 24/7 for critical) and volumes differ per environment. That is why there is no list price: every customer gets a dedicated quote with defined scope, service level and response mandate. With Managed SIEM and Managed NDR the scope additionally covers use case and playbook development as well as log source integration and management."}},"anoview":{"eyebrow":"ANOVIEW · Customer Portal","titleA":"Full visibility.","titleB":"Your SOC, live.","lead":"ANOVIEW is the customer portal included with your SOCaaS. Click through the sections below. This is exactly what your team sees when logged in. Real dashboards, real case flow, no black box.","hint":"↓ Interactive preview with anonymised sample data. Click sidebar & tabs","footer":"Multi-tenant isolated. Every customer sees only their own data. Reports exportable as PDF or PPTX. All KPIs, including SLA, MTTFR, MTTR and MITRE ATT&CK coverage, are configurable per tenant. Figures shown are anonymised sample data.","portalLabel":"Portal","topbar":{"period":"Last 30 days","reportIncident":"Report incident","tenant":"Sample Customer Ltd","user":"Analyst view"},"live":"Live","liveTitle":"Live Insights","liveSub":"Real-time security operations · Last 30 days","nav":{"home":{"label":"Home","sub":"Executive Dashboard"},"live":{"label":"Live Insights","sub":"SLA · Cases · MITRE"},"case":{"label":"Case Command","sub":"Central Case Management"},"status":{"label":"Service Status","sub":"Health Monitoring"},"reporting":{"label":"Reporting","sub":"PDF / PPTX Reports"},"ir":{"label":"IR Communication","sub":"Contacts & Procedures"}},"tabs":{"sla":"SLA","cases":"Cases","mitre":"MITRE ATT&CK","autonomous":"Autonomous","handling":"24/7 Handling","sources":"Detection Sources"},"home":{"title":"Executive Dashboard","sub":"Board-ready overview · Q3 2026","kpi":{"sla":"SLA (90d)","auto":"Auto-resolved","tp":"True positives","sev1":"Incidents SEV-1"},"posture":"Posture Summary","rows":{"mitre":"Detection coverage · MITRE","endpoints":"Endpoints protected","halcyon":"Halcyon anti-ransomware","active":"Active","nextReview":"Next business review"}},"case":{"title":"Case Command","sub":"Central case management · Filters · SLA timers","panel":"Open cases","sev":{"low":"Low","medium":"Medium","high":"High"},"status":{"contained":"Contained","autoClosed":"Auto-closed","review":"Analyst review","investigating":"Investigating"},"cases":["Suspicious PowerShell on endpoint WKS-0417","M365 atypical travel for user-4821","Entra ID unusual device sign-in","DNS anomaly with outbound 445 KB","Vulnerable driver load · rwdrv.sys"]},"status":{"title":"Service Status","sub":"Health monitoring · Uptime 99.9% · 30d","panel":"Components","operational":"Operational","degraded":"Degraded","components":["Elastic SIEM · ingestion","Microsoft Defender · Switzerland North","Microsoft Defender · Switzerland West","Jira Service Management","Tines SOAR"]},"reporting":{"title":"Reporting","sub":"PDF / PPTX · Scheduled & on-demand","panel":"Latest reports","download":"Download","reports":[{"t":"Monthly SOC Report, September 2026","f":"PDF · 24 pages"},{"t":"Quarterly Business Review, Q3 2026","f":"PPTX · 18 slides"},{"t":"MITRE ATT&CK Coverage Snapshot","f":"PDF · 12 pages"},{"t":"Executive Summary for Board","f":"PDF · 4 pages"},{"t":"Threat Hunting Findings, Aug 2026","f":"PDF · 9 pages"}]},"ir":{"title":"IR Communication","sub":"Incident contacts · Escalation procedures","panelEsc":"Escalation matrix","panelCh":"Communication channels","escRows":{"sev1p":"SEV-1 · Primary","sev1s":"SEV-1 · Secondary","sev2":"SEV-2","legal":"Legal / DPO"},"chRows":{"primary":"Primary","primaryVal":"Signal group · verified","secondary":"Secondary","secondaryVal":"Encrypted email (PGP)","bridge":"Bridge line · 24/7"},"vals":{"ciso":"CISO · +41 44 xxx xx xx","headit":"Head of IT · +41 44 xxx xx xx","soclead":"SOC Lead · soc@customer.ch","dpo":"dpo@customer.ch","phone":"+41 44 xxx xx xx"}}},"differentiators":{"eyebrow":"Why ANOMAL · Six positions","titleA":"We don't just","titleB":"forward alerts.","titleC":"We are your SOC.","lead":"These are the points where we break with the traditional MSSP model, and where our customers notice the difference every day.","meta":"Legacy MSSP vs. ANOMAL","count":"6 positions","legacyLabel":"Legacy MSSP","usLabel":"ANOMAL","footerLabel":"Bottom line","footerA":"Same regulator. Same attack surface.","footerB":"Different operating model.","cta":"Talk to us","items":{"coverage":{"tag":"Coverage","legacy":"Only Critical and High cases get looked at. Low and Medium are out of scope.","us":"We work every case from Low to Critical, 24/7."},"communication":{"tag":"Direct line","legacy":"Email ticket via a service manager, reply in a few hours. The provider stays outside.","us":"Teams, Slack or your channel, directly with the analyst on the case. Response within minutes.\nWe work as part of your team, not as an external ticket desk."},"licenses":{"tag":"Licenses & tools","legacy":"The MSSP locks you into its stack. Rip and replace or nothing.","us":"Buy licences through us or we operate inside your own SIEM, EDR, XDR. Your choice, no vendor lock-in."},"baseline":{"tag":"Baseline & silence","legacy":"Ten “Can you check this?” requests a day. Alert fatigue lands on the customer.","us":"A clean baselining phase. After that you only hear from us when something matters. No noise pushed to you."},"access":{"tag":"Access","legacy":"You talk to the service manager. He talks to the analyst. Sometimes.","us":"You reach our analysts directly in your own communication channels, Teams, Slack or email. Any time, with no service manager in between."},"integration":{"tag":"Integration","legacy":"External vendor with a monthly report. Stays outside.","us":"We become a fixed part of your team. After a short time, most people forget we are external."},"response":{"tag":"Response","legacy":"MTTR measured in hours. SLA measured in business days.","us":"Hyper Automation, Agentic AI and our analysts work as one unit.\nThat cuts response from hours to minutes."},"price":{"tag":"Pricing","legacy":"Surcharges per alert and per investigation, plus a fresh quote for every incident.","us":"Flat fee per year. Response and containment inside your mandate are included. An incident response engagement for a major incident is billed separately, and the Halcyon add-on covers ransomware financially."},"positioning":{"tag":"Positioning","legacy":"Managed Detection and Response, a 2015 model.","us":"A SOC that works differently from day one. Customers notice it immediately."},"documentation":{"tag":"Documentation","legacy":"One line in the ticket, case closed. No auditable trail.","us":"Every case is documented in full detail. You see everything, and your knowledge of your own environment grows every day."}}}},"securityServices":{"hero":{"eyebrow":"Security Services · Swiss team","title1":"Everything","title2":"around","title3":"your SOC.","lead":"Proactive services that prevent what the SOC would otherwise have to detect. Pentesting, vulnerability management, awareness, hardening, consulting.","chips":{"iso":"ISO 27001","team":"Swiss team · Zurich region","contract":"One contract · one accountable team"}},"grid":{"eyebrow":"What we deliver","title1":"Five services.","title2":"One team.","lead":"No catalogue of ten interchangeable building blocks. Five services we deliver ourselves, in depth, from Switzerland and connected to our SOC.","flagship":"Flagship","details":"Details →","more":"Learn more","openAria":"Open details for {{title}}","deepDive":"Read the deep dive"},"process":{"eyebrow":"How we work","title1":"Assess. Implement.","title2":"Operate.","lead":"No report that gathers dust in SharePoint after the final meeting. Every service feeds insights back into your SOC.","items":[{"step":"01","title":"Assess","body":"Kick-off, scope, threat model. We understand your environment, assets and regulatory context before we test or implement.","accent":"danger"},{"step":"02","title":"Implement","body":"Test, hardening or campaign, executed by the same Swiss team that also runs your SOC. Clear deliverables, clear timeline.","accent":"warn"},{"step":"03","title":"Operate","body":"Findings flow back into the SOC by default, even after a one-off pentest: as detections, playbooks or awareness triggers. A project becomes an ongoing loop.","accent":"ok"}]},"integration":{"eyebrow":"SOC integration","title1":"Findings become","title2":"detections.","lead":"A pentest finding describes an attack path. We turn it into a detection rule in the SOC. If someone clicks the link in a phishing simulation, our triage flags that person as higher risk. A cluster of vulnerabilities triggers a hardening sprint. That closes the loop.","cta":"How our SOC works","rows":[{"from":"Penetration Testing","to":"New detection rules in SIEM · playbook updates","accent":"danger"},{"from":"Vulnerability Management","to":"Prioritized remediation · exposure-based alerting","accent":"warn"},{"from":"Awareness & Phishing","to":"High-risk user signals for triage & scoring agents","accent":"link"},{"from":"Cloud & Identity Hardening","to":"Conditional Access & detection baseline aligned","accent":"ok"},{"from":"Security Consulting","to":"Roadmap, board reporting, regulator evidence","accent":"lavender"}]},"delivery":{"eyebrow":"Delivery","title1":"Three models.","title2":"One team.","items":[{"title":"Retainer","body":"Contractually guaranteed quota per quarter. Ideal for ongoing pentesting or vulnerability management.","accent":"link"},{"title":"Project","body":"Clearly bounded scope, fixed price, defined end date. Ideal for one-off reviews, migrations or audit preparation.","accent":"lavender"},{"title":"Continuous","body":"Fully managed and continuously operated, as part of your SOC contract. One team, one contract, one invoice.","accent":"ok"}]},"ctaBand":{"title":"Not sure which service fits? 30 minutes usually is enough.","button":"Talk to us"},"faqHeading":"Frequently asked questions about Security Services","sheet":{"scopeIn":"Included","scopeOut":"Not included","process":"Process","deliverables":"Deliverables","standards":"Standards & frameworks","faq":"FAQ","ctaTitle":"Let's talk about {{title}}.","ctaBody":"30 minutes with our team. You describe your situation, we tell you clearly whether and how we can help.","ctaButton":"Talk to us"},"seo":{"scope":"Scope","scopeOut":"Not included","process":"Process","deliverables":"Deliverables","standards":"Standards & frameworks"},"services":[{"id":"pentest","tag":"Test","title":"Penetration Testing","subhead":"Penetration Testing Switzerland","body":"Offensive tests by our experienced pentesters. External & internal networks, web apps, APIs, cloud, Active Directory.","outcomes":["External, internal, web, API, cloud, AD","Manual testing, no scanner-only reports","Retest included · English or German reporting"],"flagship":true,"accent":"danger","detail":{"intro":["A penetration test at ANOMAL is not a scanner dump in PDF format. Our experienced pentesters simulate targeted attacks, from external recon to lateral movement in Active Directory, and document every step so that your team can reproduce and close it.","The core difference: every confirmed finding is translated into a detection rule or playbook in the SOC. An attack path that worked once will be detected on the next attempt."],"scopeIn":["External perimeter tests (IP ranges, web, DNS, cloud)","Internal network pentests incl. Active Directory","Web applications & REST/GraphQL APIs (OWASP-based)","Cloud configuration: Azure, AWS, GCP, M365","Red-team-light: assumed-breach & phishing combos","Reporting in English or German with executive summary"],"scopeOut":["No pure vulnerability scanning without validation","No physical red-team without a separate scope","No DoS tests on productive systems"],"process":[{"title":"Scoping","body":"Threat model, goals, rules of engagement, emergency contacts."},{"title":"Execution","body":"1–3 weeks of active testing by dedicated consultants."},{"title":"Reporting","body":"Findings with impact, PoC, CVSS and concrete remediation."},{"title":"Debrief","body":"Technical walkthrough plus executive session for management."},{"title":"Retest","body":"Free retest of all critical and high findings."}],"deliverables":["Executive summary (board-ready, EN or DE)","Technical report with reproducible PoCs","Prioritized remediation roadmap","SOC detection rules from verified findings","Retest report as formal evidence"],"standards":["OWASP Top 10 / ASVS","MITRE ATT&CK","PTES","NIST SP 800-115","OSSTMM"],"faqs":[{"q":"How long does a pentest take?","a":"A typical external/web assessment 5–10 working days, an internal AD pentest 8–15. We scope precisely before the contract is signed."},{"q":"Do you test on production?","a":"Yes, in a controlled way with clear rules of engagement. For destructive tests we use staging or defined maintenance windows."}]}},{"id":"vulnmgmt","tag":"Reduce","title":"Vulnerability Management","subhead":"Managed Vulnerability Management","body":"Continuous discovery, prioritisation and remediation steering. Not just CVSS. Prioritization by real exploitability, exposure and business context.","outcomes":["Continuous scanning · internal & external","Prioritization by EPSS, KEV & business context","Remediation tracking with your owners"],"flagship":true,"accent":"warn","detail":{"intro":["Vulnerability management rarely fails at scanning. It fails at prioritising and following through. We take over the whole loop: continuous discovery, contextualisation with threat intelligence, assignment to owners, and reporting until the ticket is closed.","Prioritization is not by CVSS ranking but by EPSS exploitation probability, the CISA KEV catalogue, exposure and your business context. So your admins work on the 10 things that matter, not the 10,000 in the report."],"scopeIn":["External attack surface monitoring (domains, IPs, certificates)","Internal authenticated scans (servers, workstations, network gear)","Cloud configuration & container images (CSPM/CIEM light)","Microsoft 365 / Entra ID posture assessment","Prioritization with EPSS, KEV, Exploit-DB, MITRE context","Monthly steering with your IT and business owners"],"scopeOut":["No patching on your systems without a separate contract","No code scanning (SAST/DAST), see pentest service"],"process":[{"title":"Onboarding","body":"Asset inventory, scan access, scope confirmation."},{"title":"Baseline","body":"First full scan cycle, false positive cleanup."},{"title":"Continuous","body":"Rolling scans, daily reassessment after new CVEs."},{"title":"Steering","body":"Monthly owner meeting, KPIs, escalations."}],"deliverables":["Live dashboard with prioritised backlog","Monthly management report (trend, SLA, top risks)","Ticket integration in Jira, ServiceNow or Azure DevOps","Ad-hoc advisories for zero-days and KEV entries"],"standards":["EPSS","CISA KEV","CVSS 3.1 / 4.0","ISO 27001 A.8.8","NIS2 Art. 21"],"faqs":[{"q":"Which scanners do you use?","a":"Best of breed: we are scanner-agnostic and choose per customer. Usually a combination of attack surface, network and cloud posture tooling."},{"q":"Who patches in the end?","a":"By default your IT team, we steer and track. Fully managed including patching is available as an extension."}]}},{"id":"awareness","tag":"Train","title":"Security Awareness & Phishing","subhead":"Managed Security Awareness & Phishing","body":"Managed awareness programme: annual mandatory training plus role-specific modules, quarterly phishing simulations, quarterly report to the CISO.","outcomes":["Annual baseline training plus department modules, each with a knowledge test","Quarterly phishing campaigns: click rate, data entry, report rate","Quarterly CISO report incl. risk-score trend"],"flagship":false,"accent":"link","detail":{"intro":["Awareness is a managed programme, not a once-a-year e-learning slot. Every employee completes an annual baseline training with a knowledge test, departments get additional modules, and phishing campaigns run quarterly across the contract term.","The platform is interchangeable, the service is not. Examples are KnowBe4, Proofpoint Security Awareness, SoSafe, Hoxhunt or Microsoft Attack Simulation Training. We take over an existing platform or recommend one based on languages, seat count and Microsoft 365 integration."],"scopeIn":["Annual mandatory training for all employees, with knowledge test and documented completion","Department modules (finance and HR, IT, executives) plus custom content on request","Quarterly phishing campaigns over the contract term, DE and EN as standard","Onboarding gate: initial training as a prerequisite for system access, reconciled with your HR process","Report button in Outlook / M365 with SOC integration","Quarterly report to the CISO: training status, test results, phishing results, risk-score trend"],"scopeOut":["Per-seat platform licence, listed separately and not part of the managed fee","Additional languages beyond DE and EN unless ordered","Enforcement of the access rule in your HR and IT onboarding process","No public rating of individual employees"],"process":[{"title":"Baseline","body":"Unannounced first campaign for positioning, target group and department mapping."},{"title":"Programme","body":"Annual baseline training plus department modules, each with a knowledge test."},{"title":"Campaigns","body":"Quarterly phishing campaigns with rising difficulty, report button into SOC triage."},{"title":"Report","body":"Quarterly CISO report: training status, test results, phishing results, risk-score trend."}],"deliverables":["Training plan with modules per department and completion status","Quarterly phishing results: click rate, data entry, report rate","Quarterly CISO report with risk-score trend","Compliance evidence (ISO 27001, NIS2, DORA) and insurer evidence"],"standards":["ISO 27001 A.6.3","NIS2 Art. 21","NIST SP 800-50","ENISA Awareness Framework"],"faqs":[{"q":"Is the platform licence included?","a":"No. The managed fee covers programme design, modules, campaigns, reporting and steering. The per-seat licence is listed separately in the same quote."},{"q":"Which languages are standard?","a":"Training content is available in every language our training platform offers."},{"q":"Are you tied to one platform?","a":"No. We run the programme on your existing awareness platform, or recommend one based on languages, seat count and M365 integration. The service stays the same."}]}},{"id":"hardening","tag":"Harden","title":"Cloud & Identity Hardening","subhead":"Microsoft 365, Entra ID, Azure & AWS Hardening","body":"Configuration reviews and hardening along CIS and vendor guidelines. Conditional Access, privileged access, zero-trust design. Implementation hand in hand with your IT team.","outcomes":["M365 & Entra ID configuration review","Conditional Access design & review","Zero-trust architecture & roadmap"],"flagship":false,"accent":"ok","detail":{"intro":["In modern environments the attacker finds the open door in identity and cloud configuration, not in the firewall. We check your M365, Entra ID, Azure and AWS tenants against CIS benchmarks and vendor baselines, prioritise the gaps by risk, and implement together with your IT team.","Focus is identity-first: Conditional Access, privileged access management, MFA hardening, session controls. The outcome becomes a detection baseline for the SOC so that deviations stand out."],"scopeIn":["M365 & Entra ID configuration review","Conditional Access policy design & test","Privileged access & PIM/PAM setup","Azure & AWS landing zone hardening per CIS","Zero-trust architecture & roadmap","SOC detection baseline for identity anomalies"],"scopeOut":["No pure lift-and-shift migration","No operation of your tenants, we design and accompany"],"process":[{"title":"Assess","body":"Read-only assessment via delegated rights, findings report."},{"title":"Design","body":"Target architecture, policy set, exceptions and migration path."},{"title":"Implement","body":"Implementation hand in hand with your IT team, change windows."},{"title":"Verify","body":"Attack simulation against the new policies, detection baseline in the SOC."}],"deliverables":["Assessment report with CIS mapping","Conditional Access & PIM policy set (production-ready)","Zero-trust roadmap (12–24 months)","SOC detection rules for identity abuse"],"standards":["CIS Benchmarks M365 / Azure / AWS","Microsoft Zero Trust","NIST SP 800-207","ISO 27001"],"faqs":[{"q":"Do you need global admin rights?","a":"No, not for the assessment, we work with read-only roles. For implementation we get time-limited, logged access via your PIM process."}]}},{"id":"consulting","tag":"Advise","title":"Security Consulting","subhead":"Elastic & SIEM · SOC · IAM · Zero-Trust & NIST","body":"Engineering and architecture consulting from the team that runs a 24/7 SOC every day. Detection engineering, SOC design, identity and privileged access, zero-trust and NIST assessments.","outcomes":["Elastic & SIEM engineering, detection-as-code","SOC design, target operating model, co-managed","IAM, zero-trust architecture, NIST audits"],"flagship":false,"accent":"lavender","detail":{"intro":["We advise where we work every day ourselves: running a SOC around the clock. Our engineers build and optimise SIEM platforms on Elastic, develop detection rules as code and design SOC structures that work in day-to-day operations.","On the regulatory side we cleanly map your requirements to ISO 27001, NIS2, FINMA circulars and DORA, under Swiss law and without copied US templates. You get a roadmap that stands up to auditors and that your IT can implement."],"scopeIn":["Elastic and SIEM engineering: architecture, log source onboarding, performance and cost","Detection-as-code: detection rules versioned, tested and rolled out automatically","SOC design and target operating model, including co-managed models","IAM and PAM: role models and privileged access, implemented with your team","Zero trust architecture and roadmap","Assessments against NIST CSF 2.0 and ISO 27001"],"scopeOut":["No certification audit (separation of consulting and audit)","No concept papers without implementation"],"process":[{"title":"Discovery","body":"Starting point, existing architecture, goals and regulatory requirements."},{"title":"Design","body":"Target architecture, priorities and effort estimate."},{"title":"Build","body":"Engineering together with your team, with ongoing knowledge transfer."},{"title":"Handover","body":"Documentation and handover into your operations or into our SOC."}],"deliverables":["Target architecture and implementation plan","Detection rules and pipelines as code in your repository","Assessment report with prioritised measures (NIST, ISO 27001, zero trust)","Operations documentation and knowledge transfer to your team"],"standards":["NIST CSF 2.0","NIST SP 800-207","ISO 27001","MITRE ATT&CK","CIS Controls"],"faqs":[{"q":"Do you only work with Elastic?","a":"No. Elastic is our focus and we are an Elastic Premier Partner. We also advise on Microsoft Sentinel, Splunk and other SIEM platforms."},{"q":"Do you implement, or only advise?","a":"We implement. Our engineers work directly in your environment together with your team and hand everything over, documented, into operations."}]}}]},"glossary":{"eyebrow":"Learn · Glossary","titleLead":"The","titleAccent":"vocabulary","titleTail":"of a modern SOC.","intro":"{{count}} terms across SOC, detection, threat, identity, cloud, compliance and AI, defined by practitioners. Each term has its own dedicated page with an extended explanation.","all":"All","searchPlaceholder":"Search: SIEM, XDR, ATT&CK…","searchAria":"Search glossary","readMore":"Read more →","noResults":"No matching terms.","termNotFound":"Term not found","termNotFoundBody":"This term is not (yet) in the ANOMAL glossary.","backToGlossary":"Back to glossary","breadcrumb":"Learn · Glossary","howAnomal":"How ANOMAL implements this","previous":"Previous","next":"Next","relatedTerms":"Related terms","noRelated":"No related terms.","allTerms":"All terms →"},"command":{"placeholder":"Search pages, actions, glossary…","empty":"No results.","esc":"esc","navigate":"Navigate","actions":"Actions","footer":"ANOMAL · Command","hintUpDown":"↑↓ navigate","hintEnter":"↵ select","rows":{"home":"Home","soc":"SOC · Security Operations Center","services":"Security Services","about":"About us","careers":"Careers","glossary":"Learn · Glossary","references":"Examples","trust":"Trust Center","contact":"Contact · See the SOC live","bookWalkthrough":"See the SOC live","bookWalkthroughHint":"30 min · no slides","toggleTheme":"Toggle theme","toggleThemeHint":"dark / light","switchEn":"Switch to English","switchDe":"Auf Deutsch wechseln","guides":"Learn · Guides"}},"milestones":{"eyebrow":"Milestones","titleLead":"Five years,","titleAccent":"five","titleTail":"milestones.","intro":"Five years of Swiss security operations, one operating model, and a legal form that followed the business.","items":[{"year":"2021","title":"Founded as Authentix Switzerland GmbH","body":"Started in Switzerland by operators with 15+ years in Swiss security operations, engineering detection and response for Swiss customers."},{"year":"2024","title":"Renamed to Anomal GmbH","body":"The tier-less, highly automated operating model becomes the core of the business, so the name follows the product."},{"year":"2025","title":"ISO 27001 certified","body":"Full ISMS audit passed. Data storage in Switzerland or the EU, SOC operations in Switzerland."},{"year":"2025","title":"Converted into ANOMAL AG","body":"Conversion into a Swiss stock corporation on 23 December 2025, UID CHE-213.937.621."},{"year":"2026","title":"Halcyon partnership","body":"Halcyon's Ransomware Warranty on top of the ANOMAL SOC: after a successful attack it provides incident response and recovery services."}]},"principlesManifesto":{"eyebrow":"Principles · four, no more","items":[{"keyword":"Swiss","title":"Swiss by default.","body":"Data, operations, ownership: all Swiss. Managed by our team. Full jurisdictional clarity."},{"keyword":"Transparent","title":"Transparent by design.","body":"ANOVIEW gives customers the same view we have. Every agent decision, every reasoning trace, every score."},{"keyword":"Human-commanded","title":"AI-driven, human-commanded.","body":"Agents do the routine work. Analysts make the decisions that matter. Never the other way round."},{"keyword":"Flat fee","title":"Flat fee, no drama.","body":"SOCaaS is a flat fee per year. Only an incident response engagement for a major incident is billed separately, and Halcyon covers ransomware financially."}]},"leadership":{"eyebrow":"Leadership","meta":"Zurich region · CH · 2 founders","people":[{"name":"Zoran Savic","initials":"ZS","role":"Founder","linkedin":"https://www.linkedin.com/in/zosa-a13164192/","quote":"A SOC that wakes analysts at 3am to click through a SIEM isn't a service. That's the model we retired."},{"name":"Marc Lori","initials":"ML","role":"Co-Founder","linkedin":"https://www.linkedin.com/in/marclori/","quote":"Every agent decision, every score, every response, visible in ANOVIEW. Transparency isn't a feature, it's the contract."}]},"alertAnatomy":{"eyebrow":"Anatomy of an alert","stages":[{"n":"00","label":"INGEST","title":"Vendor-agnostic ingest.","body":"EDR, SIEM, NDR and Identity flow into one normalised event stream. Vendor-agnostic, no rip and replace."},{"n":"01","label":"TRIAGE","title":"The noise falls away.\nAgents find what matters.","body":"The triage layer creates a case for each alert, collects all necessary alert information, checks every IOC against Threat Intel and enriches the case with general context such as last logons or running processes. The result is presented as behaviour observations."},{"n":"02","label":"INVESTIGATE","title":"Use case driven playbooks.","body":"The Investigation agent is connected to the necessary tools. It runs SIEM queries and live responses and correlates across the security stack. Always based on the dedicated playbook for the detection rule that fired."},{"n":"03","label":"SCORE","title":"One score.\nOne recommended action.","body":"The Scoring agent receives information from the triage, investigation and RAG (knowledge) layer. A confidence score is generated and a response is recommended."},{"n":"04","label":"RESPOND","title":"Your mandate decides,\nnot our agents.","body":"The Response agent takes the recommendation from the scoring layer and checks it against your mandate and asset criticality list: what may be executed, where, and how far. Clear cases are auto-closed with full documentation, low-impact actions like session revoking run instantly, and everything beyond your mandate keeps the case open for one of our analysts who owns it from there."},{"n":"05","label":"IMPROVE","title":"Improvement loop.","body":"Analyst verdicts feed back into the RAG store. Tomorrow's scoring agent is measurably better than today's. A closed loop."}]},"operatingFlow":{"mttdQualitative":"Minutes, not hours","header":"anomal · operating model · live","ingesting":"ingesting","sources":"Telemetry Sources","streams":"streams","ims":"ANOMAL IMS","outcome":"outcome","autoClosed":"Auto-closed","autoClosedBody":"Benign / duplicate / low-risk. Full audit trail retained.","analystTagged":"Analyst-tagged event","analystTaggedBody":"Response drafted per mandate. The analyst makes the call.","preAuth":"pre-auth","mttd":"Mean Time to Decision · 30d","stage":"stage","stages":[{"id":"filter","label":"Filter","n":"00","desc":"Deterministic dedupe, correlate, normalise. Noise dropped before it ever hits a queue.","kpi":"Less noise","kpiLabel":"removed before the queue"},{"id":"triage","label":"Triage","n":"01","desc":"Deterministic enrichment and classification. Agentic AI only where the call is ambiguous.","kpi":"Automatic","kpiLabel":"enrichment"},{"id":"invest","label":"Investigation","n":"02","desc":"Agentic AI analyses the enriched data. Deterministic playbooks fetch what the agents need.","kpi":"PB-047","kpiLabel":"active playbook"},{"id":"score","label":"Scoring","n":"03","desc":"Scoring based on your past cases and your environment (RAG). True positive, false positive or benign, with evidence.","kpi":"0.87","kpiLabel":"TP confidence"},{"id":"resp","label":"Response","n":"04","desc":"Deterministic actions inside your approved mandate. Low-impact and reversible first. Isolate, revoke, block, notify.","kpi":"Minutes","kpiLabel":"to containment"}],"mobileLoopLabel":"Improvement Loop","mobileLoopBody":"Every closed case → Feedback · Baselining · Tuning · case memory → IMS."},"pageFaq":{"heading":"Frequently Asked Questions"},"applyRole":{"notFoundTitle":"Role not found","notFoundBody":"This position is not currently open.","back":"Back to careers","errorTitle":"Something went wrong"},"learn":{"hub":{"eyebrow":"ANOMAL Learn","title":"Everything you need to know about a modern SOC.","lead":"Guides, comparisons and deep dives written by our SOC analysts. Clear answers to practical questions.","count":"{{count}} entries","glossaryTitle":"Glossary","glossaryLead":"Terms from SOC, detection, identity, cloud and compliance, each explained in brief. Search for a term or open the full overview.","glossarySearch":"Search a term","glossaryNoMatch":"No matching term found.","glossaryAll":"Open the full glossary","jumpGlossary":"Glossary","jumpLabel":"On this page","startTitle":"Start here","guidesTitle":"All guides","searchLabel":"Search guides","searchPlaceholder":"Search guides","results_one":"{{count}} guide found","results_other":"{{count}} guides found","filterLabel":"Filter by topic","filterAll":"All","sortLabel":"Sort order","sortRecommended":"Recommended","sortAz":"A–Z","noResults":"No guide matches this selection. Try another term or topic.","reset":"Reset filters","minutes":"{{count}} min read","guideCount_one":"{{count}} guide","guideCount_other":"{{count}} guides","editorial":"Editorial principles: who is responsible for our content and how figures are sourced"},"categories":{"soc":"SOC topics","services":"Security Services","glossary":"Glossary"},"badges":{"pillar":"Guide","cluster":"Article","glossary":"Glossary"},"readMore":{"eyebrow":"Read next","title":"Go deeper on the topics that matter.","allTopics":"All topics"}},"faq":{"eyebrow":"Frequently asked questions","titleA":"Direct answers.","titleB":"To the questions we hear most.","sub":"The questions CISOs, procurement and legal teams ask us before every mandate.","stillLabel":"Still open?","stillBody":"We answer every question, usually within one business day.","cta":"Still have questions?"},"formErrors":{"verification_failed":"The security check failed. Please reload the page and try again.","verification_unavailable":"The security check is currently unavailable. Please try again in a few minutes.","rate_limited":"Too many requests came from your connection in a short time. Please try again later.","submission_failed":"We could not send your request. Please try again or email hello@anomal.xyz.","cv_invalid_type":"Your CV must be a valid PDF or DOCX file.","cv_too_large":"Your CV must not be larger than 10 MB.","cv_upload_failed":"We could not upload your CV. Please try again.","config_error":"The form is currently unavailable. Please email hello@anomal.xyz.","cv_unsafe":"The file contains active content (for example scripts, macros or embedded files) and cannot be accepted. Please save your CV as a plain PDF and upload it again.","invalid_input":"Please check your details.","generic":"Something went wrong. Please try again or email hello@anomal.xyz."},"formErrorsApply":{"verification_failed":"The security check failed. Please reload the page and try again.","verification_unavailable":"The security check is currently unavailable. Please try again in a few minutes.","rate_limited":"Too many applications came from your connection in a short time. Please try again later.","submission_failed":"We could not save your application. Please try again or email personal@anomal.xyz.","cv_invalid_type":"Your CV must be a valid PDF or DOCX file.","cv_too_large":"Your CV must not be larger than 10 MB.","cv_upload_failed":"We could not upload your CV. Please try again.","config_error":"The form is currently unavailable. Please email personal@anomal.xyz.","cv_unsafe":"The file contains active content (for example scripts, macros or embedded files) and cannot be accepted. Please save your CV as a plain PDF and upload it again.","invalid_input":"Please check your details.","generic":"Something went wrong. Please try again or email personal@anomal.xyz."},"stickyCta":{"badge":"24/7 · SOC from the Zurich region","label":"Talk to us","dismiss":"Close"}}