SOC as a Service from Switzerland

Your SOC as a Servicefrom Switzerland.24/7 in operation.

Automation, Agentic AI and our analysts work as one team. Hyper Automation filters out the noise and prepares every case with full context. People make the decisions. Automated response only runs where you have approved it in advance.

See how our SOC works
ISO 27001 certified
anomal · operating model · live
ingesting
Telemetry Sources5× streams
RAG
Improvement Loop

Every closed case → Feedback · Baselining · Tuning · case memory → IMS.

ANOMAL IMSoutcome
Auto-closed78 %

Benign / duplicate / low-risk. Full audit trail retained.

Analyst-tagged event22 %

Response drafted per mandate. The analyst makes the call.

isolate endpointpre-auth
revoke sessionpre-auth
block IOCspre-auth
Mean Time to Decision · 30d
Minutes, not hours
stage 00 · FilterDeterministic dedupe, correlate, normalise. Noise dropped before it ever hits a queue.removed before the queueLess noise
What you get as a customer

One service.
Everything included.

One contract with our SOC. Coverage around the clock from Switzerland, Hyper Automation for routine triage, Agentic AI in investigations and analysts who make every decision. One flat fee per year, no hidden items.

Core offering

SOC as a Service · flat fee

One contract. Everything included: 24/7 detection, response, tuning, playbooks, threat intel and executive reporting. Halcyon with its Ransomware Warranty available as an optional add-on.

Learn more
Included in every mandate
  • Detection engineering
  • Incident response
  • Threat Hunting
  • Custom playbooks
  • Threat intelligence
  • SOC KPI reporting
How it runs

Hyper Automation

Deterministic workflows for triage, enrichment and mandated response, reliable and auditable. Agentic AI inside investigation and scoring, where judgement is needed, running privately in Switzerland with no customer data used for model training.

Learn more
Operations

SOC Delivery

24/7/365 from Switzerland. Contractual SLAs and onboarding completed within weeks.

Learn more
Portal

ANOVIEW

Customer portal with reporting and a live view into our SOC. You see every case the way our team sees it.

Learn more
Integrations

Every detection source

EDR (Elastic, Defender, CrowdStrike), SIEM, NDR, cloud, email and identity. Keep what you already run. We connect, normalise and operate it.

Learn more
Warranty

Halcyon Add-on

Extra protection with Halcyon's Ransomware Warranty. Halcyon stops encryption, captures the attackers' encryption key and blocks data exfiltration during a live attack. Operated by our SOC.

Learn more

What a tiered SOC
can't deliver.

The classic tiering model with L1, L2 and L3 queues does not scale with today's alert volume. Every handover between tiers costs time and context, L1 analysts burn out on repetitive triage, and attackers now move faster than any escalation chain. That is why we use a model where automation does the groundwork and analysts decide directly.

Mean time to decision→ faster
100ANOMAL
Legacy tiered SOCHours
ANOMAL Operating ModelMinutes

From alert ingest to a scored, contextualised decision.

Analyst cold starts→ 0
100ANOMAL
Legacy tiered SOCalways
ANOMAL Operating Model0

Every analyst-tagged event lands in the IMS with playbook trace, scoring rationale and pre-drafted response actions.

Bottom line

When an analyst takes over, the case is already investigated, scored and documented. Our analysts never start from zero.

Our partners

Our partners.
Selected, certified, operated by us.

We work closely with these vendors and operate their solutions inside our SOC. What counts for you is the result, not the licence.

  • Elastic Logo, SIEM-Plattform im ANOMAL SOC
  • CrowdStrike Logo, EDR-Partner von ANOMAL
  • Microsoft Logo, Microsoft Defender und Entra-ID-Telemetrie
  • Exeon Logo, Schweizer Network Detection and Response
  • Tines Logo, Automation Engine im ANOMAL SOC
  • Halcyon Logo, Anti-Ransomware-Partner von ANOMAL
  • CyberArk Logo, Identity Security Partner
  • Tenable Logo, Vulnerability Management Partner
  • KnowBe4 Logo, Security Awareness Training Partner
  • Netskope Logo, Security Service Edge Partner
FIRST member

We are a FIRST member.

ANOMAL is a member of FIRST, the global Forum of Incident Response and Security Teams. Membership is vetted, so our incident response practice is peer-reviewed and connected to the trusted network other CERTs and SOC teams rely on.

  • Trusted channels to CERTs, vendors and other response teams worldwide
  • Early, verified intelligence on active campaigns before it becomes public
  • Incident response that follows internationally recognised practice
  • Faster escalation paths when your case needs external help
Sectors we serve

Built for Swiss organisations.

Public sector
Blue light organisations
Industry
Energy & critical infrastructure
Healthcare
IT service providers
Public sector
Blue light organisations
Industry
Energy & critical infrastructure
Healthcare
IT service providers
Public sector
Blue light organisations
Industry
Energy & critical infrastructure
Healthcare
IT service providers
Why Swiss

Sovereign by design.
Precise by nature.

For us, data sovereignty is part of the architecture, not an item on a compliance list. Every case, every agent log and every decision stays in Switzerland or the EU.

  • Data in Switzerland and the EU

    Customer case data, control plane and analysts stay in Swiss or EU regions.

  • FINMA · DORA · NIS2 aligned

    Ready for regulated industries. Evidence packages available to auditors on demand.

  • Human analysts on call in Switzerland

    Our team is based in Switzerland and reachable around the clock. No global handoffs.

Migrate from your existing MSSP.

30 days of parallel operation. We take over use-cases, playbooks and evidence. You stay in control.

Two ways to work with us

Your SOC, delivered as a service.
Or build your own, with us.

Frequently asked questions

Direct answers.
To the questions we hear most.

The questions CISOs, procurement and legal teams ask us before every mandate.

A Swiss SOC as a Service without tiers, operated 24/7 from the Zurich region. You get one contract, one flat fee per year and a team that works your cases instead of a queue that forwards them. No raw alerts ever reach a human. Benign, duplicate and low-risk cases are auto-closed inside your mandate with a full audit trail. Every case that needs a decision is validated by an analyst before it closes.

Still open?

We answer every question, usually within one business day.

Still have questions?