ANOMAL service

Incident response within 72 hours

The outcome of a serious cyber incident is decided in the first hours. ANOMAL provides a Swiss incident response team that works within the 72-hour notification window of cyber insurance. It covers first analysis, containment, evidence preservation and communication with insurer, regulator and executive leadership. A retainer is not mandatory but recommended so the clock does not start with the first phone call.

All

Why the 72-hour window matters

Almost every Swiss cyber policy carries a first-notice duty within 72 hours of learning about an incident. Miss that window and a breach of duty clause usually reduces or excludes cover. In parallel, notification duties toward regulator and data subjects run. Losing the first hours without a structured process means negotiating later from a weak position.

The clock starts when you learn of the incident

The 72 hours run from the moment a responsible person becomes aware of the incident. See [Cyber insurance](/en/soc/soc-and-cyber-insurance-switzerland) for the requirements.

What the IR team does in the first hours

  1. Hour 0 to 2: intake call with the point of contact, fact capture, classification, communication lockdown.
  2. Hour 2 to 8: technical containment. Isolation of affected endpoints and accounts, disabling of compromised identities, forensic preservation of logs and memory images.
  3. Hour 8 to 24: threat and scope analysis. Reconstruction of attack paths, checks for persistence and lateral movement, first statement on data compromise.
  4. Hour 24 to 72: first notification to the insurer with a structured fact set, coordinated notification to regulator and data subjects, executive briefing.
  5. From hour 72 onward: eradication, recovery, lessons learned. Handover into regular SOC operations if such a service is in place.

An already running managed SOC service shortens each of these phases materially because log access, identity control and response authority are already in place. The SOC's operational targets (MTTR under 60 minutes for critical cases) refer to ongoing detection, not to IR without preparation. Details on those metrics on MTTD and MTTR in a SOC.

Parallel reporting deadlines for regulated sectors

The 72-hour window is an insurance deadline. Regulated operators face additional, shorter deadlines in parallel. ISG requires notification to the National Cyber Security Centre (NCSC) within 24 hours of becoming aware of an incident (see [ISG reporting duty](/en/soc/soc-isg-24h-reporting)). FINMA requires notification within 24 hours of discovery (see [FINMA](/en/soc/soc-finma-requirements)). The shortest deadline takes priority.

Retainer or ad hoc?

Both are available but the starting conditions differ. The retainer clarifies access, points of contact, communication paths and legal counsel before an incident. Ad hoc means the same questions are answered while the clock is already ticking.

AspectRetainerAd hoc
Response timeThe team starts in minutes; access is already in place.The team starts after contract and access arrangements are agreed, often taking several hours.
CostAnnual retainer fee, reduced hourly rate on activation.No fixed fee but full emergency hourly rate.
Insurance fitPre-documented IR process and named roles directly satisfy the insurer's requirement for a documented incident response plan with named roles.The team improvises the IR process and roles during the incident, making it significantly harder to provide evidence to the insurer.
Evidence preservationPlaybook agreed with the customer; no log destruction in panic mode.Depends on the state of the environment on arrival.

For existing Halcyon customers, the licence already covers incident response for ransomware incidents. These customers do not need an additional retainer. See Halcyon.

How this compares to SOC, Halcyon and pentest

ServiceTimingPurpose
Managed SOCContinuous, 24/7Detect attacks early so they do not become an IR case in the first place.
HalcyonAt the moment of encryptionRansomware-specific blocking and decryption, see Halcyon.
Incident Response 72hAfter the incident becomes knownStructured response inside insurance and reporting deadlines.
PentestBefore an incidentUncover attack surfaces before attackers do. See Pentest Switzerland.

Frequently asked questions

Can we call you without an existing ANOMAL contract?

Yes. Intake starts without a retainer. We need an authorised point of contact and your willingness to grant technical access in a controlled way. No IR team can help without access, regardless of the provider.

How does IR relate to the managed SOC?

A running SOC service reduces IR cases because attacks are stopped early. If an incident still escalates, the same team continues without handover losses. The frame sits on [SOC as a Service](/en/soc/soc-as-a-service-switzerland).

What role does legal counsel play?

Legal counsel plays a central role in notifications and communication. ANOMAL coordinates technical measures with the customer's designated legal counsel. Counsel has sole responsibility for notifications to the regulator and affected individuals. Customers without an existing legal contact should address this during retainer setup.

What happens to the evidence after the case?

We retain or hand over forensic artefacts according to customer instructions. A documented chain of custody is essential for insurance and possible criminal proceedings. The IR playbook includes this as standard.

Does the retainer cover unlimited hours?

No. The retainer covers on-call availability and a set number of preparation hours per year for the playbook, tabletop exercises and access checks. It also provides a reduced hourly rate during response work. We bill incident response hours separately to keep the retainer affordable.

Continue reading in this cluster
Halcyon Anti-Ransomware: the last line of defence
Halcyon is a dedicated anti-ransomware platform that steps in where EDR, XDR and backups fall short: at the moment of encryption. It detects ransomware behaviour at the kernel, blocks encryption in real time and restores affected files if an attacker still breaks through. ANOMAL runs Halcyon embedded in the SOC service, with 24/7 response and evidence artefacts that regulator and insurer accept.
SOC and cyber insurance: what Swiss insurers require
Cyber insurers in Switzerland and the EU increasingly require applicants to evidence security controls. MFA, EDR, segregated backups, a documented incident response plan and a patch process appear on nearly every proposal form. Missing 24/7 detection via a managed SOC or MDR is rarely a formal exclusion. It is a strong premium driver and, in many policies, the only realistic way to meet short policy notification deadlines.
SOC as a Service in Switzerland: The Complete Guide
SOC as a Service is an externally operated Security Operations Center that monitors your environment around the clock, detects attacks and triggers the response. According to Mandiant M-Trends 2026, attackers went undetected for a median of 14 days in 2025. With a SOC that detects and assesses around the clock, typical detection time becomes much shorter.
MTTD and MTTR: the two SOC KPIs that count
Mean Time to Detect (MTTD) measures how fast a SOC spots an attack. Mean Time to Respond or Contain (MTTR, MTTC) measures how fast it is stopped. Together they are the only credible evidence that a SOC is working, not just running.