How a 24/7 SOC works in practice
A 24/7 SOC runs in overlapping analyst shifts with clear tiers, playbooks and an escalation matrix up to executive level. Alerts flow from EDR, identity, cloud and network into a central SIEM or XDR. They are triaged on L1, investigated on L2/L3 and never parked outside the customer tenant. Targets for critical cases: MTTR up to 60 minutes, MTTC between 1 and 4 hours.
How this compares to neighbouring topics
This page describes ongoing 24/7 operations. SOC onboarding Switzerland covers integration, rule tuning and go-live. Co-Managed SOC explains the contractual split between internal teams and the provider. MTTD and MTTR in a SOC explains target metrics in detail. What is a SOC defines the service. The pillar page SOC as a Service Switzerland covers the full service, including operations, evidence and governance.
Shift model and handovers
A productive 24/7 SOC runs in overlapping shifts with documented handovers. Every shift starts with a briefing on open cases and ends with a structured handover so no case gets lost between two analysts.
| Element | What happens |
|---|---|
| Shift overlap | 30 to 60 minutes of overlap with a structured case handover for each open case. |
| Follow-the-sun | Providers with multiple sites route cases by time zone without losing context. |
| Out-of-hours on-call | Additional L2 and L3 on-call for critical cases at night and on weekends. |
| Case system | Every alert becomes a case with an owner, status, timeline and response actions. Teams do not use ad hoc emails. |
L1, L2 and L3 tiers and what they do
- L1 triage: receives alerts, checks context and false-positive signals, executes standard playbooks and escalates by clear criteria.
- L2 investigation: reconstructs the attack path across endpoint, identity, cloud and network, decides on response actions in the customer tenant.
- L3 advanced response and threat hunting: handles complex cases, develops detection content, runs purple-team exercises with internal teams.
- Compliance and governance: maintains evidence for revFADP (revised Federal Act on Data Protection), ISG, FINMA and cyber insurance, documents response times and decisions.
Escalation matrix up to the executive level
| Severity | L1 reaction | Escalates to | Customer notification |
|---|---|---|---|
| Low | Playbook-based response, case close | None (weekly report) | Portal / weekly report |
| Medium | L2 investigation, response after sign-off | L2 and customer IT lead | Case email plus portal |
| High | Immediate containment per playbook | L3 plus customer security lead | Call plus chat plus portal |
| Critical | Immediate isolation and session lock | L3, customer security, CIO/CISO, executive board | Call within minutes, written follow-up |
Response targets, not contractual SLAs
For critical cases the operational target for MTTR sits at up to 60 minutes and MTTC between 1 and 4 hours. Those are operational targets, not contractual SLAs. Full definitions and calculation on MTTD and MTTR in a SOC.
Response times depend on alert quality, response sign-offs and customer tenant access. Ask what a minute-level figure refers to: alert acknowledgement, the start of analysis or containment. And ask whether it is contractually committed or typically achieved.
What a customer sees in a real incident
- A call to the named customer contact within minutes, documented in the case.
- Immediate containment per pre-approved response actions (host isolation, user disable).
- A timeline with every step: when what was done by whom and with what effect.
- Post-incident review within a few working days, including feedback into detection rules.
Common misconceptions about 24/7
- 24/7 equals alert forwarding. An email bot without an analyst is not a SOC.
- External night shifts lack context. If L1 does not know the customer, it slows response.
- The customer has no documented escalation matrix. The provider calls, but no one is available or authorised to act.
Frequently asked questions
What does 24/7 mean concretely when no one calls?
In steady state the SOC continuously triages alerts, runs standard playbooks and maintains detection content. Customer-visible output shows up in the weekly report and the portal. Customers receive calls only in exceptional circumstances.
Is a 24/7 SOC possible without internal on-call?
Yes, provided response authority is delegated far enough that the provider can act without a call. In regulated environments internal on-call still makes sense so executive decisions do not wait for the next working day.
How is this different from a NOC on-call rotation?
A NOC monitors availability and performance, while a SOC monitors security signals. A NOC raises alarms for outages, and a SOC raises alarms for attack behaviour. Both use shift operations, but the playbooks and skills are fundamentally different.
Do operations continue unchanged during annual leave and public holidays?
Yes. A 24/7 SOC does not differentiate between working days and public holidays. Internal customer teams often have fewer staff available on public holidays. The provider's pre-approved response authority supports action during these periods.
How can I as a customer verify that 24/7 works?
Run tabletop exercises at inconvenient times (Friday 10 pm, Sunday morning). Review documented MTTR and MTTC metrics in the quarterly review. [MTTD and MTTR in a SOC](/en/soc/soc-mttd-mttr) provides details.
Related terms
- SOC A Security Operations Center (SOC) is the team that constantly monitors an organisation's IT for attacks and intervenes during incidents.
- SOCaaS SOC as a Service (SOCaaS) is a SOC operated by an external provider and delivered as an ongoing service.
- Runbook A runbook is a detailed operational procedure outlining the technical steps for a specific task.
- Playbook A playbook is a predefined procedure describing how a SOC responds to a specific type of security incident.
- T1 / T2 / T3 T1, T2, and T3 are the classic tiered roles for analysts within a Security Operations Center.