Security Services · Swiss team

Everything
around
your SOC.

Proactive services that prevent what the SOC would otherwise have to detect. Pentesting, vulnerability management, awareness, hardening, consulting.

ISO 27001Swiss team · Zurich regionOne contract · one accountable team
What we deliver

Five services. One team.

No catalogue of ten interchangeable building blocks. Five services we deliver ourselves, in depth, from Switzerland and connected to our SOC.

TestFlagship

Penetration Testing

Penetration Testing Switzerland

Offensive tests by our experienced pentesters. External & internal networks, web apps, APIs, cloud, Active Directory.

  • External, internal, web, API, cloud, AD
  • Manual testing, no scanner-only reports
  • Retest included · English or German reporting
Read the deep dive
ReduceFlagship

Vulnerability Management

Managed Vulnerability Management

Continuous discovery, prioritisation and remediation steering. Not just CVSS. Prioritization by real exploitability, exposure and business context.

  • Continuous scanning · internal & external
  • Prioritization by EPSS, KEV & business context
  • Remediation tracking with your owners
Read the deep dive
Train

Security Awareness & Phishing

Managed Security Awareness & Phishing

Managed awareness programme: annual mandatory training plus role-specific modules, quarterly phishing simulations, quarterly report to the CISO.

  • Annual baseline training plus department modules, each with a knowledge test
  • Quarterly phishing campaigns: click rate, data entry, report rate
  • Quarterly CISO report incl. risk-score trend
Read the deep dive
Harden

Cloud & Identity Hardening

Microsoft 365, Entra ID, Azure & AWS Hardening

Configuration reviews and hardening along CIS and vendor guidelines. Conditional Access, privileged access, zero-trust design. Implementation hand in hand with your IT team.

  • M365 & Entra ID configuration review
  • Conditional Access design & review
  • Zero-trust architecture & roadmap
Read the deep dive
Advise

Security Consulting

Elastic & SIEM · SOC · IAM · Zero-Trust & NIST

Engineering and architecture consulting from the team that runs a 24/7 SOC every day. Detection engineering, SOC design, identity and privileged access, zero-trust and NIST assessments.

  • Elastic & SIEM engineering, detection-as-code
  • SOC design, target operating model, co-managed
  • IAM, zero-trust architecture, NIST audits
Read the deep dive
How we work

Assess. Implement. Operate.

No report that gathers dust in SharePoint after the final meeting. Every service feeds insights back into your SOC.

Assess

Kick-off, scope, threat model. We understand your environment, assets and regulatory context before we test or implement.

Implement

Test, hardening or campaign, executed by the same Swiss team that also runs your SOC. Clear deliverables, clear timeline.

Operate

Findings flow back into the SOC by default, even after a one-off pentest: as detections, playbooks or awareness triggers. A project becomes an ongoing loop.

SOC integration

Findings become detections.

A pentest finding describes an attack path. We turn it into a detection rule in the SOC. If someone clicks the link in a phishing simulation, our triage flags that person as higher risk. A cluster of vulnerabilities triggers a hardening sprint. That closes the loop.

How our SOC works
  • Penetration TestingNew detection rules in SIEM · playbook updates
  • Vulnerability ManagementPrioritized remediation · exposure-based alerting
  • Awareness & PhishingHigh-risk user signals for triage & scoring agents
  • Cloud & Identity HardeningConditional Access & detection baseline aligned
  • Security ConsultingRoadmap, board reporting, regulator evidence
Delivery

Three models. One team.

Retainer

Contractually guaranteed quota per quarter. Ideal for ongoing pentesting or vulnerability management.

Project

Clearly bounded scope, fixed price, defined end date. Ideal for one-off reviews, migrations or audit preparation.

Continuous

Fully managed and continuously operated, as part of your SOC contract. One team, one contract, one invoice.

Not sure which service fits?
30 minutes usually is enough.

Read next

Go deeper on the topics that matter.

All topics
Guide

SOC as a Service in Switzerland: The Complete Guide

SOC as a Service is an externally operated Security Operations Center that monitors your environment around the clock, detects attacks and triggers the response. According to Mandiant M-Trends 2026, attackers went undetected for a median of 14 days in 2025. With a SOC that detects and assesses around the clock, typical detection time becomes much shorter.

SOC topics
Article

What is a SOC? Definition, tasks and structure

A Security Operations Center (SOC) is a team of people, processes and technology. It monitors an organisation's IT and OT environment around the clock, detects attacks and coordinates the response. A SOC is not a piece of software; it is an operating unit.

SOC topics
Article

SOC for manufacturing: monitoring IT and OT together

During an incident, manufacturers lose production, not data. A SOC for manufacturing monitors the IT network and OT environment (PLC, HMI, legacy systems). It stops ransomware before the production line goes down. The core risk is not encryption; it is downtime.

SOC topics
Article

SOC, SIEM, EDR, XDR, MDR: the terms explained

SOC is the function; SIEM, EDR and XDR are tools; MDR is a service. The label matters less than whether response happens and in whose mandate. At ANOMAL, SOC as a Service covers detection and response and is often called MDR; a managed SIEM is part of the SOC with analysts and response in the mandate. Customers keep their existing tools.

SOC topics
Article

What is MDR? Managed Detection and Response explained

Managed Detection and Response (MDR) is the common name for a service that detects attacks, investigates them and responds, including isolating compromised systems. MDR is neither a tool nor a platform, but a contract with defined response duties. At ANOMAL, this service is part of SOC as a Service.

SOC topics
Article

What is XDR? Extended Detection and Response explained

Extended Detection and Response (XDR) is a detection platform that correlates telemetry from endpoint, identity, email, cloud and network in one data model. XDR replaces many functions of a classic SIEM, but it does not replace a team. Only combined with a SOC or MDR does it turn into security.

SOC topics