Security consulting: architecture expertise from live SOC operations
ANOMAL security consulting provides engineering and architecture advisory from people who run a 24/7 SOC every day. We do not provide abstract strategy consulting. We work across four disciplines: Elastic and SIEM engineering, SOC build and consulting, IAM/PAM, and Zero-Trust and NIST audits. Engagements are time-boxed projects with a clear deliverable. We do not provide ongoing staffing or a fractional-CISO model. We scope every mandate individually and provide a dedicated quote.
Who this is for and typical triggers
Typical starting points include an existing SIEM generating too much noise or a planned SOC build. IAM/PAM may have evolved over time until nobody can trace all permission paths. A Zero-Trust initiative may need a reliable architecture beyond a slide deck. We serve internal IT and security teams in Switzerland that need concrete decisions and working configurations beyond a report. Teams seeking ongoing operations can find guidance on SOC as a Service Switzerland.
Customers can add occasional governance support, such as help with security strategy or board reporting, within a consulting mandate. ANOMAL does not offer an ongoing fractional-CISO role.
The four disciplines
| Discipline | Short description |
|---|---|
| Elastic and SIEM engineering | Data model, ingest architecture, detection engineering and migration for Elastic and Microsoft Sentinel. |
| SOC consulting and build | Target operating model, processes and roles for a new or revised SOC, including the choice between managed, co-managed and in-house operations. |
| IAM and PAM | Identity and privileged-access architecture, review and cleanup of accumulated permission structures, integration with detection. |
| Zero-Trust and NIST audits | Maturity assessment against NIST frameworks, segmentation and Zero-Trust architecture with a concrete implementation path. |
We welcome requests outside these four disciplines and scope them individually; not every topic fits a fixed template.
How an engagement runs
- Assessment: current-state review, interviews, technical stocktake (e.g. existing rules, permission structures, log sources).
- Design: target architecture, prioritised measures, documented decisions with rationale.
- Implementation support: we build configurations, rules or playbooks together with the internal team.
- Knowledge transfer: documentation and walkthroughs so the internal team can run the solution independently.
- Handover: clean close-out, either into internal operations or into a managed-service relationship with ANOMAL.
What the customer receives
- Documented decisions with rationale, not just a slide strategy.
- Working configurations (rules, policies, architecture artefacts) the team can adopt directly.
- We base recommendations on customer needs and avoid vendor lock-in. ANOMAL operates Elastic, Microsoft Sentinel, CrowdStrike, Exeon and Halcyon in practice; we reference other platforms only as generic examples.
How this compares to neighbouring topics
| Model | Character | When it fits |
|---|---|---|
| Consulting (this offering) | Time-boxed project with a defined deliverable. | An architecture decision, migration, build or audit is due. |
| Managed services | Continuous operations, 24/7 responsibility. | Ongoing detection and response operations needed, see SOC as a Service Switzerland. |
| Audit only | Assessment without implementation support. | Only a maturity attestation for a regulator or insurer is needed. |
| Staffing | Personnel capacity billed by time, without responsibility for delivering a target operating model. | A capacity gap, not a missing architectural outcome. |
Placement in SOC operations
Consulting and operations complement each other: many mandates transition into an ongoing operating relationship after handover. SOC as a Service Switzerland and How a 24/7 SOC works explain how we organise 24/7 SOC operations.
Frequently asked questions
Does ANOMAL offer fractional-CISO services?
ANOMAL does not offer fractional-CISO services as a standalone offering. Occasional governance support can form part of a consulting mandate. ANOMAL provides engineering and architecture advisory and does not take on a permanent leadership role.
What does a consulting mandate cost?
There is no list price. Scope, discipline and duration differ per customer, so every mandate receives a dedicated quote after the scoping conversation. General SOC cost logic is on [SOC cost Switzerland](/en/soc/soc-cost-switzerland).
Does ANOMAL take over operations after consulting?
That is possible but not mandatory. Every mandate ends with a clean handover, either to the internal team or into a managed-service relationship.
Are topics outside the four disciplines possible?
Yes. The four disciplines are our core focus; we scope other requests individually if they fit our engineering focus.
Which platforms does ANOMAL work with in consulting?
Elastic, Microsoft Sentinel, CrowdStrike, Exeon and Halcyon are the platforms ANOMAL operates. We reference other technologies, such as common PAM platforms, only as generic examples; ANOMAL does not operate them.
Related terms
- SOCaaS SOC as a Service (SOCaaS) is a SOC operated by an external provider and delivered as an ongoing service.
- ISO 27001 ISO 27001 is the international standard for information security management systems. Certification confirms that risks are managed systematically.
- SIEM A Security Information and Event Management (SIEM) system collects logs from many sources, makes them searchable and analyses them with detection rules.
- Hyper Automation Hyper Automation is the consistent, end-to-end automation of all recurring tasks in a Security Operations Center.