Everything
around
your SOC.
Proactive services that prevent what the SOC would otherwise have to detect. Pentesting, vulnerability management, awareness, hardening, consulting.
Five services. One team.
No catalogue of ten interchangeable building blocks. Five services we deliver ourselves, in depth, from Switzerland and connected to our SOC.
Penetration Testing
Penetration Testing Switzerland
Offensive tests by our experienced pentesters. External & internal networks, web apps, APIs, cloud, Active Directory.
- External, internal, web, API, cloud, AD
- Manual testing, no scanner-only reports
- Retest included · English or German reporting
Vulnerability Management
Managed Vulnerability Management
Continuous discovery, prioritisation and remediation steering. Not just CVSS. Prioritization by real exploitability, exposure and business context.
- Continuous scanning · internal & external
- Prioritization by EPSS, KEV & business context
- Remediation tracking with your owners
Security Awareness & Phishing
Managed Security Awareness & Phishing
Managed awareness programme: annual mandatory training plus role-specific modules, quarterly phishing simulations, quarterly report to the CISO.
- Annual baseline training plus department modules, each with a knowledge test
- Quarterly phishing campaigns: click rate, data entry, report rate
- Quarterly CISO report incl. risk-score trend
Cloud & Identity Hardening
Microsoft 365, Entra ID, Azure & AWS Hardening
Configuration reviews and hardening along CIS and vendor guidelines. Conditional Access, privileged access, zero-trust design. Implementation hand in hand with your IT team.
- M365 & Entra ID configuration review
- Conditional Access design & review
- Zero-trust architecture & roadmap
Security Consulting
Elastic & SIEM · SOC · IAM · Zero-Trust & NIST
Engineering and architecture consulting from the team that runs a 24/7 SOC every day. Detection engineering, SOC design, identity and privileged access, zero-trust and NIST assessments.
- Elastic & SIEM engineering, detection-as-code
- SOC design, target operating model, co-managed
- IAM, zero-trust architecture, NIST audits
Assess. Implement. Operate.
No report that gathers dust in SharePoint after the final meeting. Every service feeds insights back into your SOC.
Assess
Kick-off, scope, threat model. We understand your environment, assets and regulatory context before we test or implement.
Implement
Test, hardening or campaign, executed by the same Swiss team that also runs your SOC. Clear deliverables, clear timeline.
Operate
Findings flow back into the SOC by default, even after a one-off pentest: as detections, playbooks or awareness triggers. A project becomes an ongoing loop.
Findings become detections.
A pentest finding describes an attack path. We turn it into a detection rule in the SOC. If someone clicks the link in a phishing simulation, our triage flags that person as higher risk. A cluster of vulnerabilities triggers a hardening sprint. That closes the loop.
How our SOC works- Penetration TestingNew detection rules in SIEM · playbook updates
- Vulnerability ManagementPrioritized remediation · exposure-based alerting
- Awareness & PhishingHigh-risk user signals for triage & scoring agents
- Cloud & Identity HardeningConditional Access & detection baseline aligned
- Security ConsultingRoadmap, board reporting, regulator evidence
Three models. One team.
Retainer
Contractually guaranteed quota per quarter. Ideal for ongoing pentesting or vulnerability management.
Project
Clearly bounded scope, fixed price, defined end date. Ideal for one-off reviews, migrations or audit preparation.
Continuous
Fully managed and continuously operated, as part of your SOC contract. One team, one contract, one invoice.
Not sure which service fits?
30 minutes usually is enough.
Go deeper on the topics that matter.
SOC as a Service in Switzerland: The Complete Guide
SOC as a Service is an externally operated Security Operations Center that monitors your environment around the clock, detects attacks and triggers the response. According to Mandiant M-Trends 2026, attackers went undetected for a median of 14 days in 2025. With a SOC that detects and assesses around the clock, typical detection time becomes much shorter.
What is a SOC? Definition, tasks and structure
A Security Operations Center (SOC) is a team of people, processes and technology. It monitors an organisation's IT and OT environment around the clock, detects attacks and coordinates the response. A SOC is not a piece of software; it is an operating unit.
SOC for manufacturing: monitoring IT and OT together
During an incident, manufacturers lose production, not data. A SOC for manufacturing monitors the IT network and OT environment (PLC, HMI, legacy systems). It stops ransomware before the production line goes down. The core risk is not encryption; it is downtime.
SOC, SIEM, EDR, XDR, MDR: the terms explained
SOC is the function; SIEM, EDR and XDR are tools; MDR is a service. The label matters less than whether response happens and in whose mandate. At ANOMAL, SOC as a Service covers detection and response and is often called MDR; a managed SIEM is part of the SOC with analysts and response in the mandate. Customers keep their existing tools.
What is MDR? Managed Detection and Response explained
Managed Detection and Response (MDR) is the common name for a service that detects attacks, investigates them and responds, including isolating compromised systems. MDR is neither a tool nor a platform, but a contract with defined response duties. At ANOMAL, this service is part of SOC as a Service.
What is XDR? Extended Detection and Response explained
Extended Detection and Response (XDR) is a detection platform that correlates telemetry from endpoint, identity, email, cloud and network in one data model. XDR replaces many functions of a classic SIEM, but it does not replace a team. Only combined with a SOC or MDR does it turn into security.