How a 24/7 SOC works in practice

A 24/7 SOC runs in overlapping analyst shifts with clear tiers, playbooks and an escalation matrix up to executive level. Alerts flow from EDR, identity, cloud and network into a central SIEM or XDR. They are triaged on L1, investigated on L2/L3 and never parked outside the customer tenant. Targets for critical cases: MTTR up to 60 minutes, MTTC between 1 and 4 hours.

All

How this compares to neighbouring topics

This page describes ongoing 24/7 operations. SOC onboarding Switzerland covers integration, rule tuning and go-live. Co-Managed SOC explains the contractual split between internal teams and the provider. MTTD and MTTR in a SOC explains target metrics in detail. What is a SOC defines the service. The pillar page SOC as a Service Switzerland covers the full service, including operations, evidence and governance.

Shift model and handovers

A productive 24/7 SOC runs in overlapping shifts with documented handovers. Every shift starts with a briefing on open cases and ends with a structured handover so no case gets lost between two analysts.

ElementWhat happens
Shift overlap30 to 60 minutes of overlap with a structured case handover for each open case.
Follow-the-sunProviders with multiple sites route cases by time zone without losing context.
Out-of-hours on-callAdditional L2 and L3 on-call for critical cases at night and on weekends.
Case systemEvery alert becomes a case with an owner, status, timeline and response actions. Teams do not use ad hoc emails.

L1, L2 and L3 tiers and what they do

  • L1 triage: receives alerts, checks context and false-positive signals, executes standard playbooks and escalates by clear criteria.
  • L2 investigation: reconstructs the attack path across endpoint, identity, cloud and network, decides on response actions in the customer tenant.
  • L3 advanced response and threat hunting: handles complex cases, develops detection content, runs purple-team exercises with internal teams.
  • Compliance and governance: maintains evidence for revFADP (revised Federal Act on Data Protection), ISG, FINMA and cyber insurance, documents response times and decisions.

Escalation matrix up to the executive level

SeverityL1 reactionEscalates toCustomer notification
LowPlaybook-based response, case closeNone (weekly report)Portal / weekly report
MediumL2 investigation, response after sign-offL2 and customer IT leadCase email plus portal
HighImmediate containment per playbookL3 plus customer security leadCall plus chat plus portal
CriticalImmediate isolation and session lockL3, customer security, CIO/CISO, executive boardCall within minutes, written follow-up

Response targets, not contractual SLAs

For critical cases the operational target for MTTR sits at up to 60 minutes and MTTC between 1 and 4 hours. Those are operational targets, not contractual SLAs. Full definitions and calculation on MTTD and MTTR in a SOC.

Why this landing page has no binding SLAs

Response times depend on alert quality, response sign-offs and customer tenant access. Ask what a minute-level figure refers to: alert acknowledgement, the start of analysis or containment. And ask whether it is contractually committed or typically achieved.

What a customer sees in a real incident

  • A call to the named customer contact within minutes, documented in the case.
  • Immediate containment per pre-approved response actions (host isolation, user disable).
  • A timeline with every step: when what was done by whom and with what effect.
  • Post-incident review within a few working days, including feedback into detection rules.

Common misconceptions about 24/7

  • 24/7 equals alert forwarding. An email bot without an analyst is not a SOC.
  • External night shifts lack context. If L1 does not know the customer, it slows response.
  • The customer has no documented escalation matrix. The provider calls, but no one is available or authorised to act.

Frequently asked questions

What does 24/7 mean concretely when no one calls?

In steady state the SOC continuously triages alerts, runs standard playbooks and maintains detection content. Customer-visible output shows up in the weekly report and the portal. Customers receive calls only in exceptional circumstances.

Is a 24/7 SOC possible without internal on-call?

Yes, provided response authority is delegated far enough that the provider can act without a call. In regulated environments internal on-call still makes sense so executive decisions do not wait for the next working day.

How is this different from a NOC on-call rotation?

A NOC monitors availability and performance, while a SOC monitors security signals. A NOC raises alarms for outages, and a SOC raises alarms for attack behaviour. Both use shift operations, but the playbooks and skills are fundamentally different.

Do operations continue unchanged during annual leave and public holidays?

Yes. A 24/7 SOC does not differentiate between working days and public holidays. Internal customer teams often have fewer staff available on public holidays. The provider's pre-approved response authority supports action during these periods.

How can I as a customer verify that 24/7 works?

Run tabletop exercises at inconvenient times (Friday 10 pm, Sunday morning). Review documented MTTR and MTTC metrics in the quarterly review. [MTTD and MTTR in a SOC](/en/soc/soc-mttd-mttr) provides details.

Continue reading in this cluster
SOC onboarding in Switzerland: process, roles, realistic timeline
A clean SOC onboarding typically takes 5 to 8 weeks. It has five phases: discovery and scoping, log ingestion with EDR, rule tuning, playbook handover with go-live, and a 30-day steady-state review. Vendors promising faster onboarding usually skip rule tuning. The result: alert fatigue within weeks and a SOC that fails to make decisions when it matters.
Co-Managed SOC: contract model and responsibility matrix, not a black box
Co-managed SOC is a contract model where the internal security team and an external SOC provider share the same tenant. They split responsibility per alert type and function in a RACI matrix. Hybrid splits responsibility by time: the internal team covers daytime, and the provider covers off-hours. Co-managed splits responsibility by function within the same tenant, 24/7. It fits organisations that want to keep their existing security team and extend it with 24/7 capability.
MTTD and MTTR: the two SOC KPIs that count
Mean Time to Detect (MTTD) measures how fast a SOC spots an attack. Mean Time to Respond or Contain (MTTR, MTTC) measures how fast it is stopped. Together they are the only credible evidence that a SOC is working, not just running.
What is a SOC? Definition, tasks and structure
A Security Operations Center (SOC) is a team of people, processes and technology. It monitors an organisation's IT and OT environment around the clock, detects attacks and coordinates the response. A SOC is not a piece of software; it is an operating unit.