ANOMAL consulting

Zero-Trust and NIST consulting: a baseline, not a product purchase

ANOMAL evaluates Zero-Trust maturity and NIST CSF coverage through interviews, configuration checks and architecture reviews, not a product list. The output is a prioritised measure list with effort classes, architecture decisions and a board-ready summary. Segmentation, conditional access and application access are developed as a roadmap with measurable milestones. Effort and depth depend on the environment and target state and are quoted per customer.

All

Zero-Trust: baseline and target architecture

Zero-Trust defines a target model for access decisions. ANOMAL assesses the current state against a maturity model. We check how identity, device and context are verified for every access request. We identify flat network segments with implicit trust and users accessing applications directly without controlled paths. This baseline produces a roadmap with measurable milestones. Zero-Trust and SOC explains the connection to ongoing SOC operations, particularly how Zero-Trust signals feed into detection.

  • Maturity scoring across identity, devices, network, applications and data.
  • Segmentation and access-path design: which flows are possible today and which should be, per target state.
  • Device trust and conditional access strategy, aligned to the existing identity platform without requiring a new purchase.
  • Application access via controlled paths without flat network access, including handling of legacy applications without modern authentication.
  • Phased plan with measurable milestones (e.g. share of segmented zones, share of enforced conditional access rules).

Evidence-based NIST CSF assessment

The NIST Cybersecurity Framework structures the assessment across the five functions Identify, Protect, Detect, Respond and Recover. ANOMAL assesses maturity per function through questionnaires, interviews with responsible teams and spot-check configuration reviews. The resulting gap list provides prioritised measures that go beyond a score alone.

NIST functionTypical review points
IdentifyAsset inventory, crown jewels, risk register, ownership.
ProtectAccess control, hardening, awareness, patch processes.
DetectLog coverage, alerting paths, time to detection in daily operations.
RespondPlaybooks, escalation paths, reporting duties, last exercise.
RecoverBackup strategy, restore testing, post-incident communication plan.

We also map the gap list to Swiss regulatory requirements. These include revFADP (revised Federal Act on Data Protection) (nDSG / nLPD) data protection duties and the ISG reporting duty for critical infrastructure. We also cover FINMA requirements for regulated institutes and NIS2 for Swiss subsidiaries of EU groups. Details are on revFADP and SOC, ISG reporting duty, FINMA requirements and NIS2 for Swiss subsidiaries.

Deliverables of a Zero-Trust or NIST engagement

  • Assessment report with maturity per area or function and the underlying evidence base.
  • Prioritised action plan with effort classes, without fixed deadlines or costs.
  • Architecture decision records for key decisions (e.g. segmentation boundaries, conditional access policy structure).
  • Board-ready summary that presents risk, progress and next steps without technical jargon.

Effort and depth depend on the number of systems, sites and regulatory requirements and are quoted as a dedicated offer per customer. General SOC cost drivers are described on What does a SOC cost in Switzerland.

What a Zero-Trust or NIST engagement does not do

  • ANOMAL does not resell products. Recommendations remain vendor-neutral and reflect what is already in use.
  • ANOMAL does not issue a compliance certificate. A NIST assessment is not a certification and does not replace one.
  • The accredited auditor conducts certification audits (e.g. ISO 27001). ANOMAL prepares clients for the audit and does not conduct it. See ISO 27001 and SOC.

How this compares to neighbouring topics

OfferingFocusWhere it stops
Zero-Trust and NIST consultingMaturity assessment, architecture and gap analysis, roadmap.No implementation of measures itself; no certificate.
ISO 27001 certification auditFormal review against the standard text by an accredited body.Reviews without implementation; requires a prepared ISMS.
Cloud and identity hardeningConcrete implementation of configuration changes in cloud and identity platforms.Often builds on assessment recommendations; does not replace the baseline assessment.
Penetration testingActive exploitation of vulnerabilities in a defined scope at a point in time.Point-in-time technical depth, without structured maturity evaluation.

Placement in the consulting portfolio

Zero-Trust and NIST consulting is one of several consulting services at ANOMAL, see Security consulting Switzerland. Results often feed directly into running SOC detection: segmentation and conditional access rules influence which signals the SOC can even see. The full operating model is described on SOC as a Service Switzerland.

Frequently asked questions

Is Zero-Trust a project with an end date?

Zero-Trust is an ongoing target model reached in steps. ANOMAL delivers a roadmap with measurable milestones. The work has no fixed completion date.

Does ANOMAL conduct the NIST assessment as a certification?

A NIST CSF assessment establishes a baseline with a gap list. It does not provide certification. The accredited auditor remains responsible for certification audits.

Are specific products recommended or sold?

ANOMAL provides vendor-neutral consulting and does not sell products. Recommendations reflect the existing environment. We state transparently where ANOMAL operates a platform, for example Microsoft Sentinel or Elastic in the SOC context.

How does this relate to our SOC?

Segmentation and conditional access decisions determine which signals a SOC receives at all. The connection is on [Zero-Trust and SOC](/en/soc/zero-trust-and-soc).

What does a Zero-Trust or NIST assessment cost?

Effort and depth depend on the number of systems, sites and regulatory requirements. Every engagement gets a dedicated quote per customer.

Continue reading in this cluster
Zero Trust and SOC: from principle to effective detection
Zero Trust is an architecture principle, not a product category. No network, device or account is trusted implicitly, and every request is continuously authenticated and authorised. For the principle to work you need a SOC that correlates identity, device and network signals and detects violations of the defined policies. Without detection Zero Trust stays a diagram; without a Zero Trust foundation the SOC runs in circles. Frame and operating model in detail on [SOC as a Service Switzerland](/en/soc/soc-as-a-service-switzerland).
ISO 27001 and SOC: where the ISMS ends and operations begin
ISO 27001 requires a management system for information security with documented processes, risks and controls. A SOC complements the ISMS as its operational foundation. It puts controls A.5.24 to A.5.30 (incident management, continuity, readiness) and A.8.15 to A.8.16 (logging, monitoring) into practice. Without 24/7 detection, several Annex A controls remain operationally ineffective despite formal compliance.
SOC & FINMA: What a Swiss financial institution needs to satisfy the supervisor
FINMA requires supervised institutions to document detection and response capabilities and demonstrate operational resilience. Institutions must report material cyber incidents within 24 hours of assessment. FINMA Circular 2023/1 Operational Risks and Resilience is the authoritative reference. It has been in force since 1 Jan 2024 and replaced Circular 2008/21. A SOC delivers 24/7 detection, a ticket and evidence trail and audit-ready evidence. Institutions need all three to meet the requirements reliably.
SOC & ISG: The 24-hour cyber-incident reporting duty in Switzerland
Since 1 April 2025, the Swiss Information Security Act (ISG, SR 128, Art. 74a-74f) imposes a cyberattack reporting duty on critical infrastructure operators. Operators must report cyberattacks to the National Cyber Security Centre (NCSC) within 24 hours of detection. Operators need 24/7 detection and documented response processes to meet this deadline reliably. A SOC delivers these two building blocks.
What a SOC costs: cost drivers, pricing models, in-house or service
SOC costs arise from the response scope first, not the platform licence. What counts are endpoint and identity counts, log sources and data volume, the response scope you choose, onboarding and licences. Swiss providers rarely publish prices; offers differ widely by scope. Your own calculation starts by holding the cost drivers against your organisation.