Incident response within 72 hours
The outcome of a serious cyber incident is decided in the first hours. ANOMAL provides a Swiss incident response team that works within the 72-hour notification window of cyber insurance. It covers first analysis, containment, evidence preservation and communication with insurer, regulator and executive leadership. A retainer is not mandatory but recommended so the clock does not start with the first phone call.
Why the 72-hour window matters
Almost every Swiss cyber policy carries a first-notice duty within 72 hours of learning about an incident. Miss that window and a breach of duty clause usually reduces or excludes cover. In parallel, notification duties toward regulator and data subjects run. Losing the first hours without a structured process means negotiating later from a weak position.
The 72 hours run from the moment a responsible person becomes aware of the incident. See [Cyber insurance](/en/soc/soc-and-cyber-insurance-switzerland) for the requirements.
What the IR team does in the first hours
- Hour 0 to 2: intake call with the point of contact, fact capture, classification, communication lockdown.
- Hour 2 to 8: technical containment. Isolation of affected endpoints and accounts, disabling of compromised identities, forensic preservation of logs and memory images.
- Hour 8 to 24: threat and scope analysis. Reconstruction of attack paths, checks for persistence and lateral movement, first statement on data compromise.
- Hour 24 to 72: first notification to the insurer with a structured fact set, coordinated notification to regulator and data subjects, executive briefing.
- From hour 72 onward: eradication, recovery, lessons learned. Handover into regular SOC operations if such a service is in place.
An already running managed SOC service shortens each of these phases materially because log access, identity control and response authority are already in place. The SOC's operational targets (MTTR under 60 minutes for critical cases) refer to ongoing detection, not to IR without preparation. Details on those metrics on MTTD and MTTR in a SOC.
The 72-hour window is an insurance deadline. Regulated operators face additional, shorter deadlines in parallel. ISG requires notification to the National Cyber Security Centre (NCSC) within 24 hours of becoming aware of an incident (see [ISG reporting duty](/en/soc/soc-isg-24h-reporting)). FINMA requires notification within 24 hours of discovery (see [FINMA](/en/soc/soc-finma-requirements)). The shortest deadline takes priority.
Retainer or ad hoc?
Both are available but the starting conditions differ. The retainer clarifies access, points of contact, communication paths and legal counsel before an incident. Ad hoc means the same questions are answered while the clock is already ticking.
| Aspect | Retainer | Ad hoc |
|---|---|---|
| Response time | The team starts in minutes; access is already in place. | The team starts after contract and access arrangements are agreed, often taking several hours. |
| Cost | Annual retainer fee, reduced hourly rate on activation. | No fixed fee but full emergency hourly rate. |
| Insurance fit | Pre-documented IR process and named roles directly satisfy the insurer's requirement for a documented incident response plan with named roles. | The team improvises the IR process and roles during the incident, making it significantly harder to provide evidence to the insurer. |
| Evidence preservation | Playbook agreed with the customer; no log destruction in panic mode. | Depends on the state of the environment on arrival. |
For existing Halcyon customers, the licence already covers incident response for ransomware incidents. These customers do not need an additional retainer. See Halcyon.
How this compares to SOC, Halcyon and pentest
| Service | Timing | Purpose |
|---|---|---|
| Managed SOC | Continuous, 24/7 | Detect attacks early so they do not become an IR case in the first place. |
| Halcyon | At the moment of encryption | Ransomware-specific blocking and decryption, see Halcyon. |
| Incident Response 72h | After the incident becomes known | Structured response inside insurance and reporting deadlines. |
| Pentest | Before an incident | Uncover attack surfaces before attackers do. See Pentest Switzerland. |
Frequently asked questions
Can we call you without an existing ANOMAL contract?
Yes. Intake starts without a retainer. We need an authorised point of contact and your willingness to grant technical access in a controlled way. No IR team can help without access, regardless of the provider.
How does IR relate to the managed SOC?
A running SOC service reduces IR cases because attacks are stopped early. If an incident still escalates, the same team continues without handover losses. The frame sits on [SOC as a Service](/en/soc/soc-as-a-service-switzerland).
What role does legal counsel play?
Legal counsel plays a central role in notifications and communication. ANOMAL coordinates technical measures with the customer's designated legal counsel. Counsel has sole responsibility for notifications to the regulator and affected individuals. Customers without an existing legal contact should address this during retainer setup.
What happens to the evidence after the case?
We retain or hand over forensic artefacts according to customer instructions. A documented chain of custody is essential for insurance and possible criminal proceedings. The IR playbook includes this as standard.
Does the retainer cover unlimited hours?
No. The retainer covers on-call availability and a set number of preparation hours per year for the playbook, tabletop exercises and access checks. It also provides a reduced hourly rate during response work. We bill incident response hours separately to keep the retainer affordable.
Related terms
- Incident Response Incident Response is the structured process of containing, eradicating, and recovering from a security incident.
- Digital Forensics Digital forensics secures and investigates digital traces so an incident can be reconstructed and used as evidence.
- Playbook A playbook is a predefined procedure describing how a SOC responds to a specific type of security incident.
- Ransomware Ransomware is malicious software that encrypts data and demands a ransom for decryption.
- Malware Malware is the umbrella term for malicious software such as ransomware, Trojans or infostealers that damage systems or steal data.