Zero-Trust and NIST consulting: a baseline, not a product purchase
ANOMAL evaluates Zero-Trust maturity and NIST CSF coverage through interviews, configuration checks and architecture reviews, not a product list. The output is a prioritised measure list with effort classes, architecture decisions and a board-ready summary. Segmentation, conditional access and application access are developed as a roadmap with measurable milestones. Effort and depth depend on the environment and target state and are quoted per customer.
Zero-Trust: baseline and target architecture
Zero-Trust defines a target model for access decisions. ANOMAL assesses the current state against a maturity model. We check how identity, device and context are verified for every access request. We identify flat network segments with implicit trust and users accessing applications directly without controlled paths. This baseline produces a roadmap with measurable milestones. Zero-Trust and SOC explains the connection to ongoing SOC operations, particularly how Zero-Trust signals feed into detection.
- Maturity scoring across identity, devices, network, applications and data.
- Segmentation and access-path design: which flows are possible today and which should be, per target state.
- Device trust and conditional access strategy, aligned to the existing identity platform without requiring a new purchase.
- Application access via controlled paths without flat network access, including handling of legacy applications without modern authentication.
- Phased plan with measurable milestones (e.g. share of segmented zones, share of enforced conditional access rules).
Evidence-based NIST CSF assessment
The NIST Cybersecurity Framework structures the assessment across the five functions Identify, Protect, Detect, Respond and Recover. ANOMAL assesses maturity per function through questionnaires, interviews with responsible teams and spot-check configuration reviews. The resulting gap list provides prioritised measures that go beyond a score alone.
| NIST function | Typical review points |
|---|---|
| Identify | Asset inventory, crown jewels, risk register, ownership. |
| Protect | Access control, hardening, awareness, patch processes. |
| Detect | Log coverage, alerting paths, time to detection in daily operations. |
| Respond | Playbooks, escalation paths, reporting duties, last exercise. |
| Recover | Backup strategy, restore testing, post-incident communication plan. |
We also map the gap list to Swiss regulatory requirements. These include revFADP (revised Federal Act on Data Protection) (nDSG / nLPD) data protection duties and the ISG reporting duty for critical infrastructure. We also cover FINMA requirements for regulated institutes and NIS2 for Swiss subsidiaries of EU groups. Details are on revFADP and SOC, ISG reporting duty, FINMA requirements and NIS2 for Swiss subsidiaries.
Deliverables of a Zero-Trust or NIST engagement
- Assessment report with maturity per area or function and the underlying evidence base.
- Prioritised action plan with effort classes, without fixed deadlines or costs.
- Architecture decision records for key decisions (e.g. segmentation boundaries, conditional access policy structure).
- Board-ready summary that presents risk, progress and next steps without technical jargon.
Effort and depth depend on the number of systems, sites and regulatory requirements and are quoted as a dedicated offer per customer. General SOC cost drivers are described on What does a SOC cost in Switzerland.
What a Zero-Trust or NIST engagement does not do
- ANOMAL does not resell products. Recommendations remain vendor-neutral and reflect what is already in use.
- ANOMAL does not issue a compliance certificate. A NIST assessment is not a certification and does not replace one.
- The accredited auditor conducts certification audits (e.g. ISO 27001). ANOMAL prepares clients for the audit and does not conduct it. See ISO 27001 and SOC.
How this compares to neighbouring topics
| Offering | Focus | Where it stops |
|---|---|---|
| Zero-Trust and NIST consulting | Maturity assessment, architecture and gap analysis, roadmap. | No implementation of measures itself; no certificate. |
| ISO 27001 certification audit | Formal review against the standard text by an accredited body. | Reviews without implementation; requires a prepared ISMS. |
| Cloud and identity hardening | Concrete implementation of configuration changes in cloud and identity platforms. | Often builds on assessment recommendations; does not replace the baseline assessment. |
| Penetration testing | Active exploitation of vulnerabilities in a defined scope at a point in time. | Point-in-time technical depth, without structured maturity evaluation. |
Placement in the consulting portfolio
Zero-Trust and NIST consulting is one of several consulting services at ANOMAL, see Security consulting Switzerland. Results often feed directly into running SOC detection: segmentation and conditional access rules influence which signals the SOC can even see. The full operating model is described on SOC as a Service Switzerland.
Frequently asked questions
Is Zero-Trust a project with an end date?
Zero-Trust is an ongoing target model reached in steps. ANOMAL delivers a roadmap with measurable milestones. The work has no fixed completion date.
Does ANOMAL conduct the NIST assessment as a certification?
A NIST CSF assessment establishes a baseline with a gap list. It does not provide certification. The accredited auditor remains responsible for certification audits.
Are specific products recommended or sold?
ANOMAL provides vendor-neutral consulting and does not sell products. Recommendations reflect the existing environment. We state transparently where ANOMAL operates a platform, for example Microsoft Sentinel or Elastic in the SOC context.
How does this relate to our SOC?
Segmentation and conditional access decisions determine which signals a SOC receives at all. The connection is on [Zero-Trust and SOC](/en/soc/zero-trust-and-soc).
What does a Zero-Trust or NIST assessment cost?
Effort and depth depend on the number of systems, sites and regulatory requirements. Every engagement gets a dedicated quote per customer.
Related terms
- ISO 27001 ISO 27001 is the international standard for information security management systems. Certification confirms that risks are managed systematically.
- NIS2 NIS2 is a European Union directive setting minimum cybersecurity requirements for important and essential entities.
- DORA The Digital Operational Resilience Act (DORA) is an EU regulation for the digital resilience of the financial sector.
- revFADP The revFADP is the revised Swiss Federal Act on Data Protection, which governs personal data processing.
- Conditional Access Conditional Access is a form of policy-based access control for user sign-ins and sessions.