ANOMAL consulting

SOC consulting: target picture, operating model and decision before build

ANOMAL consulting assesses an organisation's SOC maturity and derives a target operating model. The assessment covers visibility, detection coverage per MITRE tactic, process and escalation readiness, and evidence readiness. The core decision concerns in-house operations, managed SOC or co-managed SOC. The design centres on a tierless, highly automated SOC that replaces classic tier-1 queues. The resulting operating design defines shift and coverage planning, an escalation matrix and mandate, metrics and a clear transition plan into operations. ANOMAL scopes every engagement individually and provides a dedicated quote per customer.

All

SOC maturity assessment

Organisations need an objective baseline before discussing operating models. The assessment covers four dimensions. First, it examines current visibility across log sources, endpoints and networks. Second, it reviews detection coverage per MITRE ATT&CK tactic. Third, it assesses the reliability of escalation processes and accountabilities. Fourth, it checks whether evidence exists for customers, insurers or regulators during an incident. What is a SOC describes what a SOC fundamentally needs to deliver.

  • Visibility coverage: which systems, clouds and identities deliver telemetry and where gaps exist.
  • Detection coverage per tactic: from initial access to exfiltration, with prioritised gaps and assessment beyond checklist completion.
  • Process and escalation readiness: are roles, contact paths and decision authority clear in a real incident?
  • Evidence readiness: do logging, retention and documentation suffice for audit, insurance and reporting duties?

Target operating model: tierless instead of tier-1 queue

Classic tier-1/tier-2/tier-3 models create queues, handover losses and long delays for simple alerts. ANOMAL consulting designs a tierless operating model. Automation and enrichment handle pre-filtering, and experienced analysts retain ownership of cases from start to finish. This reduces friction at interfaces and shortens decision paths without diluting competence. How a 24/7 SOC works shows how a 24/7 operation works in practice.

Build, buy or co-managed: decision basis

The consulting delivers the decision basis, not a pre-baked sales pitch. It includes a structured comparison of in-house and managed SOC (see Managed vs in-house SOC). It also defines the role split in a co-managed SOC. SOC cost in Switzerland provides context for the cost drivers and effort involved. ANOMAL names concrete figures only during individual scoping; every engagement gets a dedicated quote.

Shift and coverage design, escalation matrix and mandate

  • 24/7 coverage: shift model, handovers and cover arrangements, aligned with actual alert volumes.
  • Escalation matrix: who is informed at which severity and when, with clear time windows.
  • Mandate and asset criticality: the mandate defines and authorises response powers upfront. This avoids debates during incidents about permission to isolate or block.
  • Criticality classes for systems and accounts as the basis for prioritised response times.

A pre-defined mandate is the difference between a response in minutes and a response that only starts after internal back-and-forth. MTTD and MTTR explains how this affects detection and response times.

Metrics, reporting and transition into operations

The target model needs measurable figures: detection coverage per tactic, response times per criticality class, automatically closed case rates and audit evidence density. The consulting ends with a guided transition into live operations. This covers in-house operations, an ANOMAL managed SOC or a co-managed arrangement. For regulatory evidence, ISO 27001 and SOC and FINMA requirements are relevant follow-on topics.

How this compares to neighbouring topics

OfferingFocusWhere it stops
SOC consultingMaturity, target operating model, build-vs-buy decision, escalation matrix and transition into operations.Does not run ongoing operations itself; ends with the handover.
Managed SOC operations24/7 detection, triage and response in day-to-day operations.Assumes an already defined target picture and mandate, otherwise the basis for priorities is missing.
SIEM engineering consultingTechnical implementation of use cases, parsing and rules on a concrete platform.Does not answer how shifts, escalation or mandate should be organised.
Compliance auditChecks the current state against a control framework and identifies deviations.Limited to identifying gaps; excludes operating model design.

Placement in SOC operations

SOC consulting provides the path to operations; SOC as a Service Switzerland describes the ongoing operations afterwards. IAM and PAM consulting complements the target model where identity and access topics shape it. Security consulting Switzerland provides an overview of all consulting services.

Frequently asked questions

How long does a SOC maturity assessment take?

Effort depends on the number of systems, locations and existing documentation. ANOMAL scopes every assessment individually and provides a dedicated quote per customer.

Does a tierless SOC make sense for every company size?

The principle scales up and down as long as automation and enrichment grow with it. For very small environments, a leaner model is often more suitable; the assessment also examines this.

Does ANOMAL still consult if we do not end up choosing ANOMAL as managed SOC?

Yes. The consulting delivers the decision basis for build, buy or co-managed, independent of who ends up operating it.

What happens to the mandate when asset criticality changes?

ANOMAL creates the escalation matrix and mandate as living documents. Reviews at agreed intervals keep response authority aligned with the current system landscape.

How does SOC consulting relate to ISO 27001 or FINMA?

A cleanly documented target operating model with escalation matrix and mandate produces directly usable audit evidence. [ISO 27001 and SOC](/en/soc/iso-27001-and-soc) and [FINMA requirements](/en/soc/soc-finma-requirements) provide details.

Continue reading in this cluster
SOC as a Service in Switzerland: The Complete Guide
SOC as a Service is an externally operated Security Operations Center that monitors your environment around the clock, detects attacks and triggers the response. According to Mandiant M-Trends 2026, attackers went undetected for a median of 14 days in 2025. With a SOC that detects and assesses around the clock, typical detection time becomes much shorter.
Managed vs in-house SOC: which model pays off in Switzerland, and when
An in-house 24/7 SOC needs 8,760 hours of cover per seat; at roughly 1,700 productive hours per full-time role, that means at least 5 to 6 roles, plus platform and training. Economically, running your own SOC only pays off with a large environment and a dedicated team, when regulation, data sovereignty or OT proximity demand it.
Co-Managed SOC: contract model and responsibility matrix, not a black box
Co-managed SOC is a contract model where the internal security team and an external SOC provider share the same tenant. They split responsibility per alert type and function in a RACI matrix. Hybrid splits responsibility by time: the internal team covers daytime, and the provider covers off-hours. Co-managed splits responsibility by function within the same tenant, 24/7. It fits organisations that want to keep their existing security team and extend it with 24/7 capability.
What a SOC costs: cost drivers, pricing models, in-house or service
SOC costs arise from the response scope first, not the platform licence. What counts are endpoint and identity counts, log sources and data volume, the response scope you choose, onboarding and licences. Swiss providers rarely publish prices; offers differ widely by scope. Your own calculation starts by holding the cost drivers against your organisation.
IAM and PAM consulting: identity architecture that also supports detection
ANOMAL consulting designs identity architecture covering directories, federation, external and guest identities, and service and workload identities. We also design authorisation models based on least privilege and segregation of duties, alongside joiner-mover-leaver automation. Privileged access consulting covers admin account tiering, just-in-time elevation, session recording and break-glass procedures. It also covers secrets and service account hygiene. Well-designed identity architecture also provides the telemetry foundation for ITDR and the SOC. We scope every engagement individually and provide a dedicated quote per customer.
ISO 27001 and SOC: where the ISMS ends and operations begin
ISO 27001 requires a management system for information security with documented processes, risks and controls. A SOC complements the ISMS as its operational foundation. It puts controls A.5.24 to A.5.30 (incident management, continuity, readiness) and A.8.15 to A.8.16 (logging, monitoring) into practice. Without 24/7 detection, several Annex A controls remain operationally ineffective despite formal compliance.
SOC & FINMA: What a Swiss financial institution needs to satisfy the supervisor
FINMA requires supervised institutions to document detection and response capabilities and demonstrate operational resilience. Institutions must report material cyber incidents within 24 hours of assessment. FINMA Circular 2023/1 Operational Risks and Resilience is the authoritative reference. It has been in force since 1 Jan 2024 and replaced Circular 2008/21. A SOC delivers 24/7 detection, a ticket and evidence trail and audit-ready evidence. Institutions need all three to meet the requirements reliably.