ANOMAL consulting

Security consulting: architecture expertise from live SOC operations

ANOMAL security consulting provides engineering and architecture advisory from people who run a 24/7 SOC every day. We do not provide abstract strategy consulting. We work across four disciplines: Elastic and SIEM engineering, SOC build and consulting, IAM/PAM, and Zero-Trust and NIST audits. Engagements are time-boxed projects with a clear deliverable. We do not provide ongoing staffing or a fractional-CISO model. We scope every mandate individually and provide a dedicated quote.

All

Who this is for and typical triggers

Typical starting points include an existing SIEM generating too much noise or a planned SOC build. IAM/PAM may have evolved over time until nobody can trace all permission paths. A Zero-Trust initiative may need a reliable architecture beyond a slide deck. We serve internal IT and security teams in Switzerland that need concrete decisions and working configurations beyond a report. Teams seeking ongoing operations can find guidance on SOC as a Service Switzerland.

Customers can add occasional governance support, such as help with security strategy or board reporting, within a consulting mandate. ANOMAL does not offer an ongoing fractional-CISO role.

The four disciplines

DisciplineShort description
Elastic and SIEM engineeringData model, ingest architecture, detection engineering and migration for Elastic and Microsoft Sentinel.
SOC consulting and buildTarget operating model, processes and roles for a new or revised SOC, including the choice between managed, co-managed and in-house operations.
IAM and PAMIdentity and privileged-access architecture, review and cleanup of accumulated permission structures, integration with detection.
Zero-Trust and NIST auditsMaturity assessment against NIST frameworks, segmentation and Zero-Trust architecture with a concrete implementation path.

We welcome requests outside these four disciplines and scope them individually; not every topic fits a fixed template.

How an engagement runs

  1. Assessment: current-state review, interviews, technical stocktake (e.g. existing rules, permission structures, log sources).
  2. Design: target architecture, prioritised measures, documented decisions with rationale.
  3. Implementation support: we build configurations, rules or playbooks together with the internal team.
  4. Knowledge transfer: documentation and walkthroughs so the internal team can run the solution independently.
  5. Handover: clean close-out, either into internal operations or into a managed-service relationship with ANOMAL.

What the customer receives

  • Documented decisions with rationale, not just a slide strategy.
  • Working configurations (rules, policies, architecture artefacts) the team can adopt directly.
  • We base recommendations on customer needs and avoid vendor lock-in. ANOMAL operates Elastic, Microsoft Sentinel, CrowdStrike, Exeon and Halcyon in practice; we reference other platforms only as generic examples.

How this compares to neighbouring topics

ModelCharacterWhen it fits
Consulting (this offering)Time-boxed project with a defined deliverable.An architecture decision, migration, build or audit is due.
Managed servicesContinuous operations, 24/7 responsibility.Ongoing detection and response operations needed, see SOC as a Service Switzerland.
Audit onlyAssessment without implementation support.Only a maturity attestation for a regulator or insurer is needed.
StaffingPersonnel capacity billed by time, without responsibility for delivering a target operating model.A capacity gap, not a missing architectural outcome.

Placement in SOC operations

Consulting and operations complement each other: many mandates transition into an ongoing operating relationship after handover. SOC as a Service Switzerland and How a 24/7 SOC works explain how we organise 24/7 SOC operations.

Frequently asked questions

Does ANOMAL offer fractional-CISO services?

ANOMAL does not offer fractional-CISO services as a standalone offering. Occasional governance support can form part of a consulting mandate. ANOMAL provides engineering and architecture advisory and does not take on a permanent leadership role.

What does a consulting mandate cost?

There is no list price. Scope, discipline and duration differ per customer, so every mandate receives a dedicated quote after the scoping conversation. General SOC cost logic is on [SOC cost Switzerland](/en/soc/soc-cost-switzerland).

Does ANOMAL take over operations after consulting?

That is possible but not mandatory. Every mandate ends with a clean handover, either to the internal team or into a managed-service relationship.

Are topics outside the four disciplines possible?

Yes. The four disciplines are our core focus; we scope other requests individually if they fit our engineering focus.

Which platforms does ANOMAL work with in consulting?

Elastic, Microsoft Sentinel, CrowdStrike, Exeon and Halcyon are the platforms ANOMAL operates. We reference other technologies, such as common PAM platforms, only as generic examples; ANOMAL does not operate them.

Continue reading in this cluster
SOC as a Service in Switzerland: The Complete Guide
SOC as a Service is an externally operated Security Operations Center that monitors your environment around the clock, detects attacks and triggers the response. According to Mandiant M-Trends 2026, attackers went undetected for a median of 14 days in 2025. With a SOC that detects and assesses around the clock, typical detection time becomes much shorter.
What is a SOC? Definition, tasks and structure
A Security Operations Center (SOC) is a team of people, processes and technology. It monitors an organisation's IT and OT environment around the clock, detects attacks and coordinates the response. A SOC is not a piece of software; it is an operating unit.
SOC on Elastic Security: what ANOMAL delivers for existing customers
ANOMAL runs a 24/7 SOC for organisations already invested in Elastic Security. We manage detection engineering, response and threat hunting on your Elastic cluster. We correlate logs, endpoint, identity and cloud signals in one platform and handle documented response. Elastic is your platform, and ANOMAL is your operations team.
ISO 27001 and SOC: where the ISMS ends and operations begin
ISO 27001 requires a management system for information security with documented processes, risks and controls. A SOC complements the ISMS as its operational foundation. It puts controls A.5.24 to A.5.30 (incident management, continuity, readiness) and A.8.15 to A.8.16 (logging, monitoring) into practice. Without 24/7 detection, several Annex A controls remain operationally ineffective despite formal compliance.