ANOMAL service

Penetration testing Switzerland: find attack surfaces before attackers do

A penetration test is a targeted attack simulation against defined systems, carried out by Swiss testers using a documented methodology. The test produces an auditable report with prioritised findings and recommendations that fit your environment. The report provides evidence for regulators and insurers. ANOMAL tests web, cloud, Active Directory, APIs and internal networks.

All

What a pentest is and what it is not

A pentest is a manual, targeted simulation of realistic attack paths against a defined scope. It is not the same as an automated vulnerability scan that lists known CVEs without assessing exploitability or chaining. Both have a place but answer different questions: the scan asks 'what is exposed?', the pentest asks 'what does an attacker reach with it?'

Evidence value, not just a tool dump

Cyber insurers routinely accept a pentest report as evidence of documented security maturity, not a scanner CSV. The insurance-side requirements sit on [Cyber insurance](/en/soc/soc-and-cyber-insurance-switzerland).

Typical scopes

ScopeMethodology referenceWhen it fits
Web applicationOWASP ASVS, OWASP Top 10Before go-live, on major releases or annually for exposed applications.
APIOWASP API Security Top 10For public or partner-exposed APIs with business logic.
Cloud (Azure, AWS, GCP)CIS Benchmarks, cloud-native threat modelAfter landing-zone rollout, before production customer go-live or for audits.
Active Directory / internal networksMITRE ATT&CK paths, PTESFor complex AD environments, hybrid with Entra ID.
Assumed breachTIBER elements, MITRE ATT&CKFor testing lateral movement after initial access.

How an ANOMAL pentest runs

  1. Scoping workshop: clear target systems, rules (time windows, blackout lists, data handling), success criteria.
  2. Threat modelling: which attacker goals are realistic for the tested application, which paths get priority.
  3. Testing phase: manual exploitation, chained attack paths, continuous contact with the customer point of contact on critical findings.
  4. Report: executive summary, technical detail per finding, CVSS and business impact, prioritised recommendations with effort ranges.
  5. Retest: no-cost verification of critical and high findings within a defined window after the initial report.

If the test phase surfaces actual compromise evidence, it moves into the same process as a real incident, see Incident Response 72h. This applies even for customers without an ANOMAL SOC.

How this compares to scanning, red teaming and audit

ActivityGoalOutcome
Vulnerability scanBroad, automated detection of known weaknesses.List of potential issues, without proven exploitability.
PentestDeep, manual test of a defined scope.Demonstrated attack paths with business impact and prioritisation.
Red teamGoal-based attack simulation without narrow scope boundaries.Statement on end-to-end detection and response capability including the SOC.
Audit / certificationCompliance check against standard or regulation.Certificate or attestation without an attacker's perspective.

A pentest does not replace SOC operations. It answers 'what could an attacker achieve?' at a point in time. The SOC answers 'what is happening in our environment right now?' continuously. See SOC as a Service Switzerland for context.

Frequently asked questions

How often should we pentest?

Test exposed applications and regulated areas annually, and after major architecture changes or the introduction of new external interfaces. Test internal networks and AD every 12 to 24 months, depending on the frequency of changes.

Does a pentest make sense without a managed SOC?

Yes, a pentest has value on its own, and a SOC increases that value. Without detection capability, the report remains a document. A SOC translates prioritised findings directly into detection rules and hardening measures.

Does a pentest satisfy cyber-insurance requirements?

A pentest is not a substitute for baseline controls such as MFA, EDR, backups and an IR plan. Insurers recognise it as evidence of documented maturity, and it often reduces premiums. The baseline requirements still apply. See [Cyber insurance](/en/soc/soc-and-cyber-insurance-switzerland) for an overview of requirements.

Do we get raw data or only the report?

We provide both, with the report as the primary deliverable. We supply test artefacts (screenshots, requests, payloads) according to customer instructions or delete them after the retest through a controlled process. We document the chain of custody.

Do you test production systems?

Yes, we test production systems. When test environments are not close to production, testing production is often the only meaningful option. We agree rules, time windows and abort criteria contractually during scoping.

Continue reading in this cluster
Incident response within 72 hours
The outcome of a serious cyber incident is decided in the first hours. ANOMAL provides a Swiss incident response team that works within the 72-hour notification window of cyber insurance. It covers first analysis, containment, evidence preservation and communication with insurer, regulator and executive leadership. A retainer is not mandatory but recommended so the clock does not start with the first phone call.
Halcyon Anti-Ransomware: the last line of defence
Halcyon is a dedicated anti-ransomware platform that steps in where EDR, XDR and backups fall short: at the moment of encryption. It detects ransomware behaviour at the kernel, blocks encryption in real time and restores affected files if an attacker still breaks through. ANOMAL runs Halcyon embedded in the SOC service, with 24/7 response and evidence artefacts that regulator and insurer accept.
Comparing SOC providers: the neutral selection checklist
Comparing SOC providers works via verifiable criteria, not logos: data scope, response authority inside the customer tenant, evidence artefacts, response times and contract wording. This page lists the questions used to line offers up side by side. Deliberately without vendor names, so the checklist holds up even when ANOMAL is not on the shortlist.
SOC and cyber insurance: what Swiss insurers require
Cyber insurers in Switzerland and the EU increasingly require applicants to evidence security controls. MFA, EDR, segregated backups, a documented incident response plan and a patch process appear on nearly every proposal form. Missing 24/7 detection via a managed SOC or MDR is rarely a formal exclusion. It is a strong premium driver and, in many policies, the only realistic way to meet short policy notification deadlines.