THE ANOMAL SOC

What a Swiss Managed SOC
should be.

An inside look at how we operate, not a product pitch. Automation handles the routine triage work, Agentic AI analyses the context during investigation, and our analysts decide. For you, that means protection around the clock, from Switzerland.

78%
cases auto-resolved
0
cold starts for analysts
24/7
Operated from Switzerland
Why ANOMAL · Six positions

We don't just
forward alerts.
We are your SOC.

Legacy MSSP vs. ANOMAL
Coverage
Legacy MSSP

Only Critical and High cases get looked at. Low and Medium are out of scope.

ANOMAL

We work every case from Low to Critical, 24/7.

Direct line
Legacy MSSP

Email ticket via a service manager, reply in a few hours. The provider stays outside.

ANOMAL

Teams, Slack or your channel, directly with the analyst on the case. Response within minutes. We work as part of your team, not as an external ticket desk.

Licenses & tools
Legacy MSSP

The MSSP locks you into its stack. Rip and replace or nothing.

ANOMAL

Buy licences through us or we operate inside your own SIEM, EDR, XDR. Your choice, no vendor lock-in.

Baseline & silence
Legacy MSSP

Ten “Can you check this?” requests a day. Alert fatigue lands on the customer.

ANOMAL

A clean baselining phase. After that you only hear from us when something matters. No noise pushed to you.

Pricing
Legacy MSSP

Surcharges per alert and per investigation, plus a fresh quote for every incident.

ANOMAL

Flat fee per year. Response and containment inside your mandate are included. An incident response engagement for a major incident is billed separately, and the Halcyon add-on covers ransomware financially.

Documentation
Legacy MSSP

One line in the ticket, case closed. No auditable trail.

ANOMAL

Every case is documented in full detail. You see everything, and your knowledge of your own environment grows every day.

Bottom line

Same regulator. Same attack surface. Different operating model.

Legacy vs. ANOMAL

The tiered SOC is a
2010 org chart.

Legacy MSSPs still bill you for L1 analysts who move alerts through queues and L2 analysts who triage them again. We replace that routine work with Hyper Automation: deterministic where possible, Agentic AI where judgement is needed. That leaves our analysts free for the decisions that matter.

Legacy tiered SOC
L1 → L2 → L3
cold starts
ANOMAL Operating Model
Human-led · Tier-less
zero cold start
Triage depth
Basic dedup · L1 tags & escalates
Triage depth
Δ 12× more context
Full context · TI, risk, geo, MITRE stage
Investigation time
Analyst starts from scratch
Investigation time
Δ Minutes, not hours
Deterministic playbooks and AI reasoning, no wait time
Handoffs per case
L1 → L2 → L3 · 3 handoffs per case
Handoffs per case
Δ 3 → 0
No tiers · no handoffs
Analyst load
Analysts triage 50+ alerts per shift
Analyst load
Δ Signal, not queue
Analysts make decisions instead of sifting noise
Auto-close rate
8% auto-closed · rest queued
Auto-close rate
Δ Higher auto-close share
78% auto-closed within mandate · full audit trail
Bottom line

Same tools, same regulator, a different result. Switch providers, keep your tools.

Discuss switching providers
Operating Model · Who does what

Who does
what?

Every alert goes through the same five stages: triage, investigation, scoring, response and improvement. Each stage has a clear division of labour. Deterministic playbooks handle everything that must run the same way every time. Agentic AI steps in where judgement is needed. Our analysts make the decisions. Every step is logged and traceable.

Layer
Automation
Our analysts
Enrich
Triage

Dedupe, correlate, normalise across every source. Enrichment via our Threat Intelligence.

Agentic AI steps in only where reasoning is needed, for example the triage summary.

No human here. Raw alerts never reach analysts.

Reason
Investigation

Playbooks fetch the evidence the agents need, deterministic and auditable.

Agentic AI analyses the enriched evidence. Every step is recorded as a reasoning trace.

No analyst yet. The case reaches an analyst only after scoring.

Decide
Scoring

Risk signals for user, device and environment feed the score deterministically.

Scoring based on your past cases and your environment (RAG). Agentic AI proposes a verdict.

No analyst here either. Agentic AI derives which customer mandate applies from the verdict.

Act
Response

Actions execute deterministically inside your approved mandate, low-impact and reversible first (revoke before isolate).

Agents draft the action set. Nothing runs outside the mandate.

The analyst is accountable for every decision and acts as the final guardrail.

Learn
Improvement

Baselines, playbooks and detections tuned per tenant.

RAG index and reasoning updated from every closed case.

Analyst decisions are the benchmark the system learns from. That is how noise disappears at the source.

Human layer

Our analysts.
Always reachable.

Every SOC talks about AI. Regulators, boards and CISOs still ask the same question: who decides, who is accountable, who picks up the phone. Our answer: a Swiss team, based in the Zurich region, operating 24/7. Agentic AI does the work. Our analysts make the decisions.

What our analysts do
  • Decide on scored cases with full context
  • Approve contain actions on high-impact assets
  • Own quarterly business reviews and detection strategy
  • Escalate to the customer CISO on critical cases, 24/7
What they don't
  • Triage alert queues by hand
  • Copy-paste between SIEM, EDR, ticketing
  • Start from zero on every case
  • Wait for L2 to pick up an escalation
ANOVIEW

Your SOC, live in the customer portal.

Cases, SLAs, MITRE coverage and reporting in real time. Every decision traceable, at any time.

Explore the ANOVIEW demo
Delivery Models

Three ways.
One operating model.

Not everyone needs the same thing. We deliver the operating model in the mode that fits your organisation and maturity. Switching modes is possible as your setup evolves.

Model 01Flagship

Fully Managed SOC

We run everything.

Complete SOC operation on our platform. Detection, response, tuning, reporting, compliance. You get the outcomes, we carry the ops load.

  • Full operation on the ANOMAL platform
  • 24/7 detection & response included
  • Multi-week onboarding phase
  • One contact, one contract, one price
Ideal for teams without a dedicated SOC or with a legacy MSSP.
Model 02

Co-Managed SOC

We operate on your platform.

You already have SIEM, EDR, SOAR. We take over operations where you are. Content engineering, detection, response, all in your environment.

  • Operation on your SIEM/XDR/SOAR
  • Analysts work in your console
  • Playbooks and runbooks stay with you
  • Knowledge transfer included, no vendor lock-in
For organisations that have already invested in their own tools.
Model 03

Hybrid 24/7

Daytime you. Nights and weekends us.

Your team works business hours, we cover nights, weekends and holidays. Clean handovers, shared case context, no double work.

  • Off-hours coverage: nights, weekends and public holidays
  • Shared case queue with clear handoffs
  • Escalation matrix per shift
  • Reduces analyst burnout and the risk of losing staff
Ideal for teams with their own SOC but without 24/7 capacity.

Not sure which model fits? A 30-minute chat is usually enough to figure it out. No slide decks, we show ANOVIEW live.

SLA & Coverage

What you can
expect from us.

Typical service parameters for a new tenant. Concrete SLAs are defined in your mandate, adjusted to your regulatory footprint and business criticality. No small print: what the flat fee includes is set out in your mandate.

  • Coverage24/7 / 365 · Swiss-operated
  • Response · CriticalContractual < 60 min · typical < 15 min
  • Response · HighTypical <30 min
  • Response · Medium / LowSame business day
  • OnboardingMulti-week onboarding phase to first live coverage
  • ReportingLive in ANOVIEW · monthly SOC report · quarterly business review
  • IR bridge line24/7 encrypted channel for SEV-1

Discuss SLAs and onboarding for your environment.

Data sources, response times and flat fee for your setup, directly with our team.

Complementary services: Penetration testing, vulnerability management, hardening and consulting.

View security services
Compliance
ISO 27001Swiss data residencyEU data residency
Two ways to work with us

Your SOC, delivered as a service.
Or build your own, with us.

30 min intro · live ANOVIEW · real cases, no slides

Read next

Go deeper on the topics that matter.

All topics
Guide

SOC as a Service in Switzerland: The Complete Guide

SOC as a Service is an externally operated Security Operations Center that monitors your environment around the clock, detects attacks and triggers the response. According to Mandiant M-Trends 2026, attackers went undetected for a median of 14 days in 2025. With a SOC that detects and assesses around the clock, typical detection time becomes much shorter.

SOC topics
Article

What is a SOC? Definition, tasks and structure

A Security Operations Center (SOC) is a team of people, processes and technology. It monitors an organisation's IT and OT environment around the clock, detects attacks and coordinates the response. A SOC is not a piece of software; it is an operating unit.

SOC topics
Article

SOC for manufacturing: monitoring IT and OT together

During an incident, manufacturers lose production, not data. A SOC for manufacturing monitors the IT network and OT environment (PLC, HMI, legacy systems). It stops ransomware before the production line goes down. The core risk is not encryption; it is downtime.

SOC topics
Article

SOC, SIEM, EDR, XDR, MDR: the terms explained

SOC is the function; SIEM, EDR and XDR are tools; MDR is a service. The label matters less than whether response happens and in whose mandate. At ANOMAL, SOC as a Service covers detection and response and is often called MDR; a managed SIEM is part of the SOC with analysts and response in the mandate. Customers keep their existing tools.

SOC topics
Article

What is MDR? Managed Detection and Response explained

Managed Detection and Response (MDR) is the common name for a service that detects attacks, investigates them and responds, including isolating compromised systems. MDR is neither a tool nor a platform, but a contract with defined response duties. At ANOMAL, this service is part of SOC as a Service.

SOC topics
Article

What is XDR? Extended Detection and Response explained

Extended Detection and Response (XDR) is a detection platform that correlates telemetry from endpoint, identity, email, cloud and network in one data model. XDR replaces many functions of a classic SIEM, but it does not replace a team. Only combined with a SOC or MDR does it turn into security.

SOC topics
FAQ

Frequently asked questions about the ANOMAL SOC

How is the SOCaaS priced and what is in scope of the flat fee?+

One flat fee per year, based on the number of endpoints, with no per-alert billing. In scope: ingest and normalisation across SIEM, EDR, NDR, XDR, IDR, 24/7 case work, tuning, response actions inside your approved mandate, quarterly threat-intelligence reviews and audit-ready evidence. Out of scope: platform licence fees of your existing detection tools, an incident response engagement for a major incident, which is billed separately, and the optional Halcyon add-on. You receive the quote for your mandate after the detection-source inventory.

What does the onboarding look like week by week?+

Week 1: detection-source inventory across SIEM, EDR, NDR, XDR, IDR, plus mandate-scope workshop with your CISO / IT-lead. Weeks 2-3: ingestion, normalisation and detection-rule tuning against the ANOMAL Operating Model. Week 4: shadow-run, ANOMAL analysts work cases in parallel with your current provider. Weeks 5-8: staged go-live and first monthly report. Total 5-8 weeks depending on source complexity, everything driven from the Zurich region.

Where is telemetry stored, who has access, and what evidence do I get?+

Storage: Switzerland by default, ISO 27001 certified Swiss data-centres; EU residency on request. No telemetry leaves the CH/EU perimeter, contractually. Access: named analysts of ours only, four-eyes on every response action inside your approved mandate. Evidence: DPA aligned to revDSG (nDSG / nLPD) and EU GDPR, FINMA Circ. 2023/1 and DORA / NIS2 evidence packs on demand, immutable case log per tenant, quarterly independent access reviews.

Do you only handle Critical and High alerts?+

No. We work every case from Low to Critical, 24/7. Many attacks start with inconspicuous Low and Medium signals that classic MSSPs ignore. Hyper Automation prepares every case, benign and duplicate cases are closed inside your mandate with an audit trail, and everything else is reviewed by one of our analysts.

Which detection sources and tools can be connected?+

All common ones: EDR (CrowdStrike, Microsoft Defender), NDR (Exeon), SIEM (Elastic, Splunk, Sentinel), XDR, cloud (AWS, Azure, GCP), email and identity (Okta, Entra), plus custom log sources. You keep your existing licences, there is no vendor lock-in. We handle ingest, normalisation and operations.

What happens during a real incident and how fast do you respond?+

For a Critical case we contractually guarantee a response within 60 minutes, around the clock. In practice we typically respond in under 15 minutes. Response actions run inside your approved mandate and start with the least invasive, reversible measure. In parallel we notify your contacts directly via Teams or Slack. Concrete SLAs are defined in your mandate.

How does Halcyon add protection against ransomware?+

Halcyon is an optional anti-ransomware add-on: an engine on every endpoint, encryption key capture for recovery and stopping data exfiltration during a live attack, plus Halcyon's Ransomware Warranty. ANOMAL operates Halcyon inside its own SOC, so prevention and response come from one operator.

What is the contract term for the SOCaaS?+

The minimum term is 12 months. That leaves enough time for onboarding, baselining and tuning so the SOC is matched to your environment. The flat fee per year stays predictable throughout.

Can we keep our internal security team (co-managed)?+

Yes. Besides fully managed we offer co-managed and hybrid. Your team keeps access to all cases and decisions, while ANOMAL covers nights, weekends and the triage load. Responsibilities and escalation paths are defined together in the mandate.