SOC consulting: target picture, operating model and decision before build
ANOMAL consulting assesses an organisation's SOC maturity and derives a target operating model. The assessment covers visibility, detection coverage per MITRE tactic, process and escalation readiness, and evidence readiness. The core decision concerns in-house operations, managed SOC or co-managed SOC. The design centres on a tierless, highly automated SOC that replaces classic tier-1 queues. The resulting operating design defines shift and coverage planning, an escalation matrix and mandate, metrics and a clear transition plan into operations. ANOMAL scopes every engagement individually and provides a dedicated quote per customer.
SOC maturity assessment
Organisations need an objective baseline before discussing operating models. The assessment covers four dimensions. First, it examines current visibility across log sources, endpoints and networks. Second, it reviews detection coverage per MITRE ATT&CK tactic. Third, it assesses the reliability of escalation processes and accountabilities. Fourth, it checks whether evidence exists for customers, insurers or regulators during an incident. What is a SOC describes what a SOC fundamentally needs to deliver.
- Visibility coverage: which systems, clouds and identities deliver telemetry and where gaps exist.
- Detection coverage per tactic: from initial access to exfiltration, with prioritised gaps and assessment beyond checklist completion.
- Process and escalation readiness: are roles, contact paths and decision authority clear in a real incident?
- Evidence readiness: do logging, retention and documentation suffice for audit, insurance and reporting duties?
Target operating model: tierless instead of tier-1 queue
Classic tier-1/tier-2/tier-3 models create queues, handover losses and long delays for simple alerts. ANOMAL consulting designs a tierless operating model. Automation and enrichment handle pre-filtering, and experienced analysts retain ownership of cases from start to finish. This reduces friction at interfaces and shortens decision paths without diluting competence. How a 24/7 SOC works shows how a 24/7 operation works in practice.
Build, buy or co-managed: decision basis
The consulting delivers the decision basis, not a pre-baked sales pitch. It includes a structured comparison of in-house and managed SOC (see Managed vs in-house SOC). It also defines the role split in a co-managed SOC. SOC cost in Switzerland provides context for the cost drivers and effort involved. ANOMAL names concrete figures only during individual scoping; every engagement gets a dedicated quote.
Shift and coverage design, escalation matrix and mandate
- 24/7 coverage: shift model, handovers and cover arrangements, aligned with actual alert volumes.
- Escalation matrix: who is informed at which severity and when, with clear time windows.
- Mandate and asset criticality: the mandate defines and authorises response powers upfront. This avoids debates during incidents about permission to isolate or block.
- Criticality classes for systems and accounts as the basis for prioritised response times.
A pre-defined mandate is the difference between a response in minutes and a response that only starts after internal back-and-forth. MTTD and MTTR explains how this affects detection and response times.
Metrics, reporting and transition into operations
The target model needs measurable figures: detection coverage per tactic, response times per criticality class, automatically closed case rates and audit evidence density. The consulting ends with a guided transition into live operations. This covers in-house operations, an ANOMAL managed SOC or a co-managed arrangement. For regulatory evidence, ISO 27001 and SOC and FINMA requirements are relevant follow-on topics.
How this compares to neighbouring topics
| Offering | Focus | Where it stops |
|---|---|---|
| SOC consulting | Maturity, target operating model, build-vs-buy decision, escalation matrix and transition into operations. | Does not run ongoing operations itself; ends with the handover. |
| Managed SOC operations | 24/7 detection, triage and response in day-to-day operations. | Assumes an already defined target picture and mandate, otherwise the basis for priorities is missing. |
| SIEM engineering consulting | Technical implementation of use cases, parsing and rules on a concrete platform. | Does not answer how shifts, escalation or mandate should be organised. |
| Compliance audit | Checks the current state against a control framework and identifies deviations. | Limited to identifying gaps; excludes operating model design. |
Placement in SOC operations
SOC consulting provides the path to operations; SOC as a Service Switzerland describes the ongoing operations afterwards. IAM and PAM consulting complements the target model where identity and access topics shape it. Security consulting Switzerland provides an overview of all consulting services.
Frequently asked questions
How long does a SOC maturity assessment take?
Effort depends on the number of systems, locations and existing documentation. ANOMAL scopes every assessment individually and provides a dedicated quote per customer.
Does a tierless SOC make sense for every company size?
The principle scales up and down as long as automation and enrichment grow with it. For very small environments, a leaner model is often more suitable; the assessment also examines this.
Does ANOMAL still consult if we do not end up choosing ANOMAL as managed SOC?
Yes. The consulting delivers the decision basis for build, buy or co-managed, independent of who ends up operating it.
What happens to the mandate when asset criticality changes?
ANOMAL creates the escalation matrix and mandate as living documents. Reviews at agreed intervals keep response authority aligned with the current system landscape.
How does SOC consulting relate to ISO 27001 or FINMA?
A cleanly documented target operating model with escalation matrix and mandate produces directly usable audit evidence. [ISO 27001 and SOC](/en/soc/iso-27001-and-soc) and [FINMA requirements](/en/soc/soc-finma-requirements) provide details.
Related terms
- SOCaaS SOC as a Service (SOCaaS) is a SOC operated by an external provider and delivered as an ongoing service.
- Playbook A playbook is a predefined procedure describing how a SOC responds to a specific type of security incident.
- Hyper Automation Hyper Automation is the consistent, end-to-end automation of all recurring tasks in a Security Operations Center.
- MITRE ATT&CK MITRE ATT&CK is a publicly accessible knowledge base of adversarial tactics and techniques based on real-world observations.