ANOMAL Learn

Everything you need to know about a modern SOC.

Guides, comparisons and deep dives written by our SOC analysts. Clear answers to practical questions.

Start here

SOC operations3 min read

SOC as a Service in Switzerland: The Complete Guide

SOC as a Service is an externally operated Security Operations Center that monitors your environment around the clock, detects attacks and triggers the response. According to Mandiant M-Trends 2026, attackers went undetected for a median of 14 days in 2025. With a SOC that detects and assesses around the clock, typical detection time becomes much shorter.

SOC operations2 min read

What is a SOC? Definition, tasks and structure

A Security Operations Center (SOC) is a team of people, processes and technology. It monitors an organisation's IT and OT environment around the clock, detects attacks and coordinates the response. A SOC is not a piece of software; it is an operating unit.

Choosing and comparing4 min read

What a SOC costs: cost drivers, pricing models, in-house or service

SOC costs arise from the response scope first, not the platform licence. What counts are endpoint and identity counts, log sources and data volume, the response scope you choose, onboarding and licences. Swiss providers rarely publish prices; offers differ widely by scope. Your own calculation starts by holding the cost drivers against your organisation.

Choosing and comparing4 min read

Comparing SOC providers: the neutral selection checklist

Comparing SOC providers works via verifiable criteria, not logos: data scope, response authority inside the customer tenant, evidence artefacts, response times and contract wording. This page lists the questions used to line offers up side by side. Deliberately without vendor names, so the checklist holds up even when ANOMAL is not on the shortlist.

Regulation5 min read

Reporting obligations in Switzerland: ISG, FINMA, revFADP, DORA and NIS2

One incident can trigger several reporting duties at once: ISG to the National Cyber Security Centre (NCSC) within 24 hours of discovery, FINMA within 24 hours of discovery, revFADP (revised Federal Act on Data Protection) to the FDPIC as soon as possible where a high risk to the persons concerned is likely, plus DORA and NIS2 with their own deadlines for EU entities. The regimes differ in addressee, deadline and content. A single classification that serves all duties in parallel is what matters.

All guides

59 guides found

SOC operations

9 guides
SOC operations3 min read

SOC as a Service in Switzerland: The Complete Guide

SOC as a Service is an externally operated Security Operations Center that monitors your environment around the clock, detects attacks and triggers the response. According to Mandiant M-Trends 2026, attackers went undetected for a median of 14 days in 2025. With a SOC that detects and assesses around the clock, typical detection time becomes much shorter.

SOC operations2 min read

What is a SOC? Definition, tasks and structure

A Security Operations Center (SOC) is a team of people, processes and technology. It monitors an organisation's IT and OT environment around the clock, detects attacks and coordinates the response. A SOC is not a piece of software; it is an operating unit.

SOC operations2 min read

MTTD and MTTR: the two SOC KPIs that count

Mean Time to Detect (MTTD) measures how fast a SOC spots an attack. Mean Time to Respond or Contain (MTTR, MTTC) measures how fast it is stopped. Together they are the only credible evidence that a SOC is working, not just running.

SOC operations3 min read

SOC onboarding in Switzerland: process, roles, realistic timeline

A clean SOC onboarding typically takes 5 to 8 weeks. It has five phases: discovery and scoping, log ingestion with EDR, rule tuning, playbook handover with go-live, and a 30-day steady-state review. Vendors promising faster onboarding usually skip rule tuning. The result: alert fatigue within weeks and a SOC that fails to make decisions when it matters.

SOC operations3 min read

Co-Managed SOC: contract model and responsibility matrix, not a black box

Co-managed SOC is a contract model where the internal security team and an external SOC provider share the same tenant. They split responsibility per alert type and function in a RACI matrix. Hybrid splits responsibility by time: the internal team covers daytime, and the provider covers off-hours. Co-managed splits responsibility by function within the same tenant, 24/7. It fits organisations that want to keep their existing security team and extend it with 24/7 capability.

SOC operations3 min read

How a 24/7 SOC works in practice

A 24/7 SOC runs in overlapping analyst shifts with clear tiers, playbooks and an escalation matrix up to executive level. Alerts flow from EDR, identity, cloud and network into a central SIEM or XDR. They are triaged on L1, investigated on L2/L3 and never parked outside the customer tenant. Targets for critical cases: MTTR up to 60 minutes, MTTC between 1 and 4 hours.

SOC operations4 min read

Creating an incident response plan: template, roles, notification chains

An incident response plan defines who decides, who receives notifications and the order for shutting down, isolating and restoring systems before a crisis. It references the five core controls cyber insurers require: MFA, EDR, segregated backups, a patch process and the documented IR plan itself. It also assigns binding notification deadlines under revFADP (revised Federal Act on Data Protection), ISG, FINMA and DORA to specific roles and response times. Without this plan, teams improvise the 72-hour response, and insurers can contest the payout.

SOC operations4 min read

Threat hunting in Switzerland: when detection rules stop being enough

Threat hunting is the hypothesis-driven search for adversaries that slip past existing detection rules. It complements SIEM and EDR alerts, it does not replace them. The goal is to structurally reduce how long adversaries stay undetected; Mandiant M-Trends 2026 reports a median of 14 days. Analysts actively search for tactics, techniques and procedures (TTPs) before an alert fires.

SOC operations4 min read

AI in the SOC: where it helps, where it hurts, and where the marketing ends

AI in the SOC supports analysts, who remain responsible for their work. The real value lies in alert triage, correlation across data sources, summarising forensic raw data and suggesting response steps. AI causes harm through unattended auto-response without analyst sign-off and hallucinated links in reports. Assuming an AI module can replace a detection-engineering process also creates risk. ANOMAL uses AI where its output is deterministically verifiable and keeps the analyst as decision-maker.

Industries

6 guides
Industries2 min read

SOC for manufacturing: monitoring IT and OT together

During an incident, manufacturers lose production, not data. A SOC for manufacturing monitors the IT network and OT environment (PLC, HMI, legacy systems). It stops ransomware before the production line goes down. The core risk is not encryption; it is downtime.

Industries4 min read

SOC for SMEs in Switzerland: what is realistic, what it costs, what makes sense

For Swiss SMEs between 50 and 500 endpoints, managed SOC is almost always the right answer. An in-house SOC rarely pays off at that size: one 24/7 seat covers 8,760 hours, which requires at least 5 to 6 full-time roles and a capable platform. Managed SOC delivers 24/7 detection, documented response and regulatory evidence for revFADP (revised Federal Act on Data Protection), ISG and customer contracts.

Industries3 min read

SOC for healthcare: patient data, EPR and operational safety

Hospitals, clinics and practices lose more than data during an incident; they lose the ability to treat patients. A SOC for Swiss healthcare monitors clinical IT (HIS, RIS, PACS), administrative IT and medical device networks together. It reports incidents promptly to the FDPIC and, for critical infrastructures, to the National Cyber Security Centre (NCSC). The core risk is loss of patient care. See [SOC as a Service Switzerland](/en/soc/soc-as-a-service-switzerland) for details of the framework and operating model.

Industries3 min read

SOC for energy providers and critical infrastructures

Energy providers, water utilities and grid operators carry a double responsibility: data protection under revFADP (revised Federal Act on Data Protection) and supply continuity under StromVG and ISG. A SOC for critical infrastructure monitors IT and OT (control systems, SCADA, remote control) and reports cyber incidents to the National Cyber Security Centre (NCSC) within 24 hours. The core risk is loss of supply. See [SOC as a Service Switzerland](/en/soc/soc-as-a-service-switzerland) for details of the framework and operating model.

Industries3 min read

SOC for law firms: professional secrecy, client data, M365

Law firms are attractive targets because a single client can unlock M&A details, litigation strategy or compliance investigations. A SOC for law firms monitors M365, DMS platforms (iManage, NetDocuments), identity and endpoints. It prevents data leaks that would breach both professional secrecy (SCC Art. 321) and revFADP. See [SOC as a Service Switzerland](/en/soc/soc-as-a-service-switzerland) for details of the framework and operating model.

Industries4 min read

SOC for banks in Switzerland: FINMA, DORA and bank-specific detection

A Swiss bank operates under two regulatory regimes: FINMA Guidance 05/2020 and 03/2024 for Swiss supervision and DORA when EU subsidiaries or EU customers are involved. FINMA requires an initial notification of material cyber attacks within 24 hours of discovery and a full report within 72 hours. DORA requires a 4/24-hour initial notification, a 72-hour intermediate report and a 1-month final report. A SOC for banks must meet both regimes' requirements within a single operation and cover bank-specific use cases. These include SWIFT, e-banking and card-channel abuse, insider activity in core banking systems, account takeover and payment anomalies. Banks that do not consolidate these functions in one SOC run three separate structures with three times the effort.

Choosing and comparing

6 guides
Choosing and comparing4 min read

What a SOC costs: cost drivers, pricing models, in-house or service

SOC costs arise from the response scope first, not the platform licence. What counts are endpoint and identity counts, log sources and data volume, the response scope you choose, onboarding and licences. Swiss providers rarely publish prices; offers differ widely by scope. Your own calculation starts by holding the cost drivers against your organisation.

Choosing and comparing4 min read

Comparing SOC providers: the neutral selection checklist

Comparing SOC providers works via verifiable criteria, not logos: data scope, response authority inside the customer tenant, evidence artefacts, response times and contract wording. This page lists the questions used to line offers up side by side. Deliberately without vendor names, so the checklist holds up even when ANOMAL is not on the shortlist.

Choosing and comparing4 min read

SOC, SIEM, EDR, XDR, MDR: the terms explained

SOC is the function; SIEM, EDR and XDR are tools; MDR is a service. The label matters less than whether response happens and in whose mandate. At ANOMAL, SOC as a Service covers detection and response and is often called MDR; a managed SIEM is part of the SOC with analysts and response in the mandate. Customers keep their existing tools.

Choosing and comparing4 min read

Switching SOC provider: how the transition works without a gap

A provider switch succeeds through preparation rather than parallel worlds: clarify contract and notice period, hand over use cases and playbooks, document log sources, then run 30 days in parallel, with the new provider detecting and responding before the old one ends. Your existing tools stay in place. ANOMAL offers 30 days of parallel operation for this transition.

Choosing and comparing4 min read

SOC and cyber insurance: what Swiss insurers require

Cyber insurers in Switzerland and the EU increasingly require applicants to evidence security controls. MFA, EDR, segregated backups, a documented incident response plan and a patch process appear on nearly every proposal form. Missing 24/7 detection via a managed SOC or MDR is rarely a formal exclusion. It is a strong premium driver and, in many policies, the only realistic way to meet short policy notification deadlines.

Choosing and comparing3 min read

Managed vs in-house SOC: which model pays off in Switzerland, and when

An in-house 24/7 SOC needs 8,760 hours of cover per seat; at roughly 1,700 productive hours per full-time role, that means at least 5 to 6 roles, plus platform and training. Economically, running your own SOC only pays off with a large environment and a dedicated team, when regulation, data sovereignty or OT proximity demand it.

Regulation

9 guides
Regulation5 min read

Reporting obligations in Switzerland: ISG, FINMA, revFADP, DORA and NIS2

One incident can trigger several reporting duties at once: ISG to the National Cyber Security Centre (NCSC) within 24 hours of discovery, FINMA within 24 hours of discovery, revFADP (revised Federal Act on Data Protection) to the FDPIC as soon as possible where a high risk to the persons concerned is likely, plus DORA and NIS2 with their own deadlines for EU entities. The regimes differ in addressee, deadline and content. A single classification that serves all duties in parallel is what matters.

Regulation4 min read

SOC & ISG: The 24-hour cyber-incident reporting duty in Switzerland

Since 1 April 2025, the Swiss Information Security Act (ISG, SR 128, Art. 74a-74f) imposes a cyberattack reporting duty on critical infrastructure operators. Operators must report cyberattacks to the National Cyber Security Centre (NCSC) within 24 hours of detection. Operators need 24/7 detection and documented response processes to meet this deadline reliably. A SOC delivers these two building blocks.

Regulation4 min read

SOC & FINMA: What a Swiss financial institution needs to satisfy the supervisor

FINMA requires supervised institutions to document detection and response capabilities and demonstrate operational resilience. Institutions must report material cyber incidents within 24 hours of assessment. FINMA Circular 2023/1 Operational Risks and Resilience is the authoritative reference. It has been in force since 1 Jan 2024 and replaced Circular 2008/21. A SOC delivers 24/7 detection, a ticket and evidence trail and audit-ready evidence. Institutions need all three to meet the requirements reliably.

Regulation4 min read

revFADP (revised Federal Act on Data Protection) and SOC: what the revised Swiss data-protection act requires from security operations

The revFADP (revised Federal Act on Data Protection, in force since 1 Sep 2023) requires appropriate technical and organisational measures. Controllers must document these measures and notify the FDPIC as soon as possible of data security breaches likely to result in a high risk to the persons concerned. A SOC delivers the detection, documented response and evidence trail needed for a credible FDPIC notification and for informing data subjects.

Regulation4 min read

NIS2 for Swiss subsidiaries: when the EU directive lands in Switzerland

The EU NIS2 directive (transposition deadline was 17 Oct 2024, implemented nationally by member states) does not apply directly in Switzerland. It bites through two channels: first, EU subsidiaries of Swiss groups fall directly under national NIS2 implementations. Second, Swiss providers of essential services to regulated EU customers inherit obligations contractually. A SOC is the operational building block for detection, notification and evidence in both cases.

Regulation5 min read

DORA requirements for the SOC: what the Digital Operational Resilience Act means in operations

The Digital Operational Resilience Act (Regulation (EU) 2022/2554) requires EU financial entities to maintain a continuous ICT risk and resilience framework. It has applied since 17 January 2025. For Swiss groups, DORA applies directly through EU subsidiaries and indirectly through contracts with EU financial customers. These subsidiaries include banks, insurers, payment institutions, crypto-asset service providers, CSDs, CCPs and trading venues. A SOC delivers four DORA cornerstones. It provides continuous ICT detection and classified incident notification to the competent authority under the 24-hour / 72-hour / 1-month cascade. It also provides the evidence trail for supervisory review and the operational foundation for threat-led penetration testing (TLPT).

Regulation4 min read

ISO 27001 and SOC: where the ISMS ends and operations begin

ISO 27001 requires a management system for information security with documented processes, risks and controls. A SOC complements the ISMS as its operational foundation. It puts controls A.5.24 to A.5.30 (incident management, continuity, readiness) and A.8.15 to A.8.16 (logging, monitoring) into practice. Without 24/7 detection, several Annex A controls remain operationally ineffective despite formal compliance.

Regulation4 min read

Cyber Resilience Act: when Swiss manufacturers are in scope

The EU Cyber Resilience Act (Regulation (EU) 2024/2847) has been in force since 10 Dec 2024. It requires manufacturers, importers and distributors of products with digital elements to implement security-by-design, vulnerability management across the product lifecycle and reporting processes. It does not apply directly in Switzerland. It affects every Swiss manufacturer whose products enter the EU market. A SOC is the operational foundation for the active reporting and vulnerability-management duties.

Regulation4 min read

AI Governance: how Swiss organisations govern AI use securely

AI Governance is the framework of policies, roles, controls and evidence with which an organisation runs AI usage safely, legally and auditably. In Switzerland, revFADP (revised Federal Act on Data Protection), sector regulation (FINMA, ISG) and the EU AI Act (for providers with EU exposure) meet. This page describes how governance decisions (which models, which data classes, which approvals) translate into technical controls and SOC detection. For the operational detection of unapproved AI use see [Shadow AI detection](/en/soc/shadow-ai-detection).

Threats

7 guides
Threats4 min read

Detecting and stopping Business Email Compromise in Microsoft 365

Business Email Compromise (BEC) in Microsoft 365 rarely involves malware. The attack chain involves phishing, session or token theft, inbox rules and OAuth consent abuse. A SOC detects BEC by correlating signals from Entra ID, Exchange Online and Defender for Cloud Apps. The email body alone is insufficient for detection. Responders revoke sessions, remove inbox rules, withdraw OAuth consents and enforce MFA again. They document these actions in line with ISG and insurance requirements.

Threats3 min read

Detecting and stopping token theft and session hijacking

Token theft means attackers steal the session or refresh token of an already authenticated user and use it to bypass MFA. The classic path is reverse-proxy phishing (adversary-in-the-middle), increasingly also endpoint info-stealers. A SOC detects this from token usage outside the user context, not from the login itself. Defence means phishing-resistant MFA, Continuous Access Evaluation, token binding and detection on refresh-token replay.

Threats5 min read

Ransomware backup strategy: immutable, tested, recoverable

Backups are the last reliable lifeline against ransomware. They must be immutable, tested regularly and segregated from the production network. Cyber insurers list 'segregated backups' among the five core controls; missing evidence in a claim eliminates cover. A ransomware recovery layer such as [Halcyon Anti-Ransomware](/en/services/halcyon-anti-ransomware) complements backups. It addresses the encryption attempt itself and shortens recovery time.

Threats4 min read

AI-driven cyber attacks: what changes, and what is marketing

Generative AI changes cyber attacks in scale, language quality and personalisation. The underlying techniques remain unchanged. Phishing in flawless Swiss German, deepfake vishing against the finance team, auto-generated malware code and LLM-driven reconnaissance are today's reality. The kill chain, detection logic and the importance of fast response remain unchanged. Attack volume, quality and the ability to bypass security controls based on linguistic or behavioural anomalies are changing.

Threats4 min read

Deepfake vishing: detect and stop AI voice attacks on Swiss organisations

Deepfake vishing combines AI-generated voices with voice phishing. Attackers clone the voice of a CEO, CFO or IT admin from a few seconds of public audio. They then call employees to trigger payments, password resets or MFA approvals. For Swiss organisations the vector is dangerous because classical email filters, MFA and EDR do not see it. Effective defence requires process controls (call-back, second channel) and awareness with realistic voice samples. It also requires a SOC that correlates accompanying signals in M365 and Entra ID.

Threats4 min read

Supply-chain attacks: when the supplier becomes the entry point

Supply-chain attacks do not target the organisation directly but a service provider, a software update or a library in the supply chain. Cases such as SolarWinds, 3CX or XZ-Utils show that attacks often take effect weeks to months later, simultaneously across many target environments. For Swiss organisations, detection in their own SOC matters most, alongside prevention through vendor risk management, SBOM and signature verification. The SOC detects suspicious activity from legitimate software and segments third-party access. During an incident, it identifies which impacts trigger notification duties under revFADP (revised Federal Act on Data Protection), FINMA and ISG.

Threats4 min read

Shadow AI detection: when staff use AI outside policy

Shadow AI describes AI use outside approved processes. Examples include private ChatGPT accounts at work, browser extensions with LLM integration and unapproved AI features in SaaS products. Customer data, source code or confidential documents can flow uncontrollably to a vendor without a contract or documentation. Swiss organisations need technical detection at network, endpoint and identity levels to make shadow AI visible and bring it back under governance. For the policy framework, see [AI Governance](/en/soc/ai-governance-security).

Technologies

8 guides
Technologies2 min read

What is MDR? Managed Detection and Response explained

Managed Detection and Response (MDR) is the common name for a service that detects attacks, investigates them and responds, including isolating compromised systems. MDR is neither a tool nor a platform, but a contract with defined response duties. At ANOMAL, this service is part of SOC as a Service.

Technologies2 min read

What is XDR? Extended Detection and Response explained

Extended Detection and Response (XDR) is a detection platform that correlates telemetry from endpoint, identity, email, cloud and network in one data model. XDR replaces many functions of a classic SIEM, but it does not replace a team. Only combined with a SOC or MDR does it turn into security.

Technologies3 min read

SOC for Microsoft 365 and Sentinel: what matters

A SOC for Microsoft 365 and Sentinel environments correlates signals from Entra ID, Defender XDR, Exchange Online and Azure in one detection layer. It responds 24/7. Analysts, playbooks and documented response provide the operational value beyond the licence.

Technologies4 min read

SOC on CrowdStrike Falcon: what ANOMAL delivers for existing customers

ANOMAL runs a 24/7 SOC for organisations already invested in CrowdStrike Falcon. We orchestrate detection engineering, response and threat hunting on your Falcon console, correlate signals with identity and cloud, and take over documented response. Falcon is your platform, ANOMAL is your operations team.

Technologies4 min read

SOC on Elastic Security: what ANOMAL delivers for existing customers

ANOMAL runs a 24/7 SOC for organisations already invested in Elastic Security. We manage detection engineering, response and threat hunting on your Elastic cluster. We correlate logs, endpoint, identity and cloud signals in one platform and handle documented response. Elastic is your platform, and ANOMAL is your operations team.

Technologies4 min read

Attack surface management: what is visible outside your perimeter

Attack surface management (ASM) is the continuous discovery, classification and assessment of every internet-facing asset an organisation exposes. The goal is to find exposed systems, forgotten subdomains, vulnerable services and leaked credentials before attackers exploit them. ASM complements vulnerability management (known assets, deep scanning) with the outside-in view: what attackers learn about you when they start from a blank page.

Technologies4 min read

ITDR: Identity Threat Detection and Response for Switzerland

ITDR (Identity Threat Detection and Response) detects attacks on the identity itself, not just endpoints or networks. Targets are accounts, tokens, sessions, permissions and identity providers such as Entra ID or Okta. ITDR extends EDR and SIEM with signals only visible in the identity layer. These include impossible travel, consent phishing, refresh-token abuse, role abuse and attacks on federation and directory objects. For Swiss organisations running M365, Entra ID and regulated processes, ITDR today is as important as EDR was five years ago.

Technologies3 min read

Zero Trust and SOC: from principle to effective detection

Zero Trust is an architecture principle, not a product category. No network, device or account is trusted implicitly, and every request is continuously authenticated and authorised. For the principle to work you need a SOC that correlates identity, device and network signals and detects violations of the defined policies. Without detection Zero Trust stays a diagram; without a Zero Trust foundation the SOC runs in circles. Frame and operating model in detail on [SOC as a Service Switzerland](/en/soc/soc-as-a-service-switzerland).

Services and consulting

14 guides
Services and consulting4 min read

Halcyon Anti-Ransomware: the last line of defence

Halcyon is a dedicated anti-ransomware platform that steps in where EDR, XDR and backups fall short: at the moment of encryption. It detects ransomware behaviour at the kernel, blocks encryption in real time and restores affected files if an attacker still breaks through. ANOMAL runs Halcyon embedded in the SOC service, with 24/7 response and evidence artefacts that regulator and insurer accept.

Services and consulting4 min read

Incident response within 72 hours

The outcome of a serious cyber incident is decided in the first hours. ANOMAL provides a Swiss incident response team that works within the 72-hour notification window of cyber insurance. It covers first analysis, containment, evidence preservation and communication with insurer, regulator and executive leadership. A retainer is not mandatory but recommended so the clock does not start with the first phone call.

Services and consulting3 min read

Penetration testing Switzerland: find attack surfaces before attackers do

A penetration test is a targeted attack simulation against defined systems, carried out by Swiss testers using a documented methodology. The test produces an auditable report with prioritised findings and recommendations that fit your environment. The report provides evidence for regulators and insurers. ANOMAL tests web, cloud, Active Directory, APIs and internal networks.

Services and consulting4 min read

Red team assessment: detection and response under realistic load

A red team assessment is a goal-based, multi-week attack simulation against the entire detection and response chain, not against a narrow scope. The output is not a vulnerability list but an evidence-backed statement about what SOC, EDR, identity and cloud controls stop together. ANOMAL runs red team engagements using MITRE ATT&CK with a methodology based on TIBER-EU. For systemically important institutions, FINMA considers red-teaming exercises a required part of cyber exercises (supervisory notice 03/2024) and names frameworks such as TIBER-EU and CBEST.

Services and consulting4 min read

Security awareness training: turning click risk into reporting behaviour

Security awareness training is a measurable behavioural process, beyond a mandatory e-learning module. The target is not a zero click rate but a reporting rate for suspicious mail in the 40 to 50 percent target band before the SOC escalates. ANOMAL combines short role-specific modules, realistic phishing simulations and a reporting interface in Microsoft 365 so awareness becomes a detection source. The 'Regular security awareness training with phishing simulations' requirement of most Swiss cyber insurers is documented in the process.

Services and consulting3 min read

ISG 30-day programme: reporting-ready in four weeks

The ISG 30-day programme helps Swiss critical-infrastructure operators and other organisations subject to ISG prepare for incident reporting in four weeks. They can then report notifiable cyber incidents to the National Cyber Security Centre (NCSC) within the statutory 24-hour window. The programme focuses on roles, reporting paths, playbooks and evidence, not tool procurement. It delivers a rehearsed process with a documented first notification, an escalation matrix and named responsible people.

Services and consulting3 min read

Exeon NDR Managed: network visibility without sensor sprawl

ANOMAL runs Exeon NDR as a managed service for Swiss environments. It centrally analyses network metadata from existing sources (firewalls, switch flows, proxies) without additional inline sensors. The service focuses on threats invisible to endpoints, particularly in OT, IoT and BYOD zones. The ANOMAL SOC handles detections 24/7 with clear response playbooks and Swiss data sovereignty.

Services and consulting3 min read

Managed vulnerability management: from scan list to closed gap

ANOMAL runs vulnerability management as an ongoing service with continuous internal and external scanning. We prioritise by real exploitability rather than raw CVSS scores. We coordinate remediation with the responsible teams, including ticket ownership and SLAs, and verify remediation through re-scans. Monthly reporting delivers evidence for ISO 27001, FINMA and ISG. We quote scope and scan cadence per customer.

Services and consulting3 min read

Cloud and identity hardening: closing the most common misconfigurations

ANOMAL reviews Microsoft 365, Entra ID, Azure and AWS against CIS benchmarks and vendor baselines, focusing on identity. The review covers Conditional Access, MFA, privileged access, session and token controls, and legacy auth. Findings become a prioritised remediation plan we implement together with your IT. The hardened baseline then becomes the detection baseline for the SOC, so deviations turn into alerts.

Services and consulting3 min read

Security consulting: architecture expertise from live SOC operations

ANOMAL security consulting provides engineering and architecture advisory from people who run a 24/7 SOC every day. We do not provide abstract strategy consulting. We work across four disciplines: Elastic and SIEM engineering, SOC build and consulting, IAM/PAM, and Zero-Trust and NIST audits. Engagements are time-boxed projects with a clear deliverable. We do not provide ongoing staffing or a fractional-CISO model. We scope every mandate individually and provide a dedicated quote.

Services and consulting3 min read

Elastic and SIEM consulting: data model, detection and migration

ANOMAL advises on building, migrating and tuning SIEM environments, primarily on Elastic and Microsoft Sentinel. The mandate covers data model and ingest architecture, onboarding of new log sources, detection engineering with version control, and playbook and automation development. Outcomes are measurable, such as coverage per MITRE tactic and fewer noisy rules, not just a concept paper. Every mandate is scoped individually and gets a dedicated quote.

Services and consulting4 min read

SOC consulting: target picture, operating model and decision before build

ANOMAL consulting assesses an organisation's SOC maturity and derives a target operating model. The assessment covers visibility, detection coverage per MITRE tactic, process and escalation readiness, and evidence readiness. The core decision concerns in-house operations, managed SOC or co-managed SOC. The design centres on a tierless, highly automated SOC that replaces classic tier-1 queues. The resulting operating design defines shift and coverage planning, an escalation matrix and mandate, metrics and a clear transition plan into operations. ANOMAL scopes every engagement individually and provides a dedicated quote per customer.

Services and consulting4 min read

IAM and PAM consulting: identity architecture that also supports detection

ANOMAL consulting designs identity architecture covering directories, federation, external and guest identities, and service and workload identities. We also design authorisation models based on least privilege and segregation of duties, alongside joiner-mover-leaver automation. Privileged access consulting covers admin account tiering, just-in-time elevation, session recording and break-glass procedures. It also covers secrets and service account hygiene. Well-designed identity architecture also provides the telemetry foundation for ITDR and the SOC. We scope every engagement individually and provide a dedicated quote per customer.

Services and consulting4 min read

Zero-Trust and NIST consulting: a baseline, not a product purchase

ANOMAL evaluates Zero-Trust maturity and NIST CSF coverage through interviews, configuration checks and architecture reviews, not a product list. The output is a prioritised measure list with effort classes, architecture decisions and a board-ready summary. Segmentation, conditional access and application access are developed as a roadmap with measurable milestones. Effort and depth depend on the environment and target state and are quoted per customer.

Glossary

Terms from SOC, detection, identity, cloud and compliance, each explained in brief. Search for a term or open the full overview.

Open the full glossary

Editorial principles: who is responsible for our content and how figures are sourced