Pillar Guide

SOC as a Service in Switzerland: The Complete Guide

SOC as a Service is an externally operated Security Operations Center that monitors your environment around the clock, detects attacks and triggers the response. According to Mandiant M-Trends 2026, attackers went undetected for a median of 14 days in 2025. With a SOC that detects and assesses around the clock, typical detection time becomes much shorter.

All

What is SOC as a Service?

SOC as a Service is the outsourced operation of detection and response by a specialist provider. The same service promise is often called MDR; at ANOMAL it is part of SOC as a Service. The provider brings 24/7 analysts, processes and a detection engineering team, while you keep your existing tools, data sovereignty and control of the mandate.

  • 24/7 monitoring of every security-relevant data source
  • Triage, investigation and prioritisation of every alert
  • Response and containment within the agreed mandate
  • Continuous detection engineering rather than static rules

How a modern SOC works

A modern SOC has moved beyond the classic Tier 1 / Tier 2 / Tier 3 model. Deterministic automation handles routine work, agentic AI correlates context, and our analysts make the decisions. This reduces noise, shortens response times and gives analysts context from the start.

What does SOC as a Service cost?

Cost logic

Costs follow log volume, endpoint count, cloud footprint and how much active response is included. International MDR providers publish around USD 10 to 30 per endpoint per month in public price overviews (as of 2026). Swiss providers hardly publish prices; offers differ sharply by scope.

An in-house 24/7 SOC: 8,760 hours per round-the-clock seat and roughly 1,700 productive hours per full-time role add up to at least 5 to 6 full-time roles, plus management, platform, licences and training. Insert your own payroll rates. Economically, running your own SOC only pays off with a large environment and a dedicated team.

Who benefits from SOC as a Service?

SOC as a Service benefits any organisation that cannot afford to miss an incident for weeks. That covers SMEs from around 50 employees, financial services firms under FINMA, and manufacturers running OT environments.

How to choose a provider

  • Data sovereignty and analyst location
  • Response times per severity in the SLA, with contractual and typical values shown separately
  • Clarity on whether and under which mandate the provider responds, and what counts separately as incident response
  • Transparent pricing: no hidden log overage costs
  • Fit with FINMA, ISG, revFADP (revised Federal Act on Data Protection), ISO 27001 and DORA; data held in Switzerland or the EU, existing tools and a parallel run when switching

Compliance: FINMA, ISG, revFADP

Since April 2025, the Swiss ISG (Art. 74b) requires operators of critical infrastructure to report reportable incidents to the National Cyber Security Centre (NCSC) within 24 hours. Switzerland's revised Data Protection Act is also called nDSG in German and nLPD in French. It additionally requires notification to the FDPIC as soon as possible if affected individuals' personality rights face a high risk. The law sets no rigid 72-hour deadline for notifying the FDPIC. The 72-hour requirement comes from DORA and from the FINMA reporting duty under Guidance 05/2020 and 03/2024 (full report following the initial notification). Organisations need reliable detection to submit any of these notifications reliably.

Legal basis and sources

  • FINMA Guidance 05/2020 on reporting cyber attacks (Art. 29 para. 2 FINMASA): finma.ch
  • FINMA Guidance 03/2024 refining the reporting duty: finma.ch
  • FINMA Circular 2023/1 «Operational risks and resilience»: finma.ch
  • FINMASA (SR 956.1): Fedlex
  • ISG reporting duty at the National Cyber Security Centre (NCSC) including routing: bacs.admin.ch
  • Reporting data security breaches to the FDPIC: edoeb.admin.ch
  • ISG (SR 128), Art. 74a-74f: Fedlex

For your industry

For SMEs

Small IT teams immediately gain 24/7 coverage without hiring analysts.

Read more: SOC for SMEs in Switzerland: what is realistic, what it costs, what makes sense
For financial services

FINMA expects explicit detection capability and documented MTTD/MTTR; reporting of material cyber attacks follows from Art. 29 para. 2 FINMASA (Guidance 05/2020, refined by Guidance 03/2024). A managed SOC covers both.

Read more: SOC & FINMA: What a Swiss financial institution needs to satisfy the supervisor
For manufacturing

Production downtime is the most expensive scenario. We monitor IT and OT and stop ransomware before the line halts.

Read more: SOC for manufacturing: monitoring IT and OT together
Continue reading in this cluster
What is a SOC? Definition, tasks and structure
A Security Operations Center (SOC) is a team of people, processes and technology. It monitors an organisation's IT and OT environment around the clock, detects attacks and coordinates the response. A SOC is not a piece of software; it is an operating unit.
SOC, SIEM, EDR, XDR, MDR: the terms explained
SOC is the function; SIEM, EDR and XDR are tools; MDR is a service. The label matters less than whether response happens and in whose mandate. At ANOMAL, SOC as a Service covers detection and response and is often called MDR; a managed SIEM is part of the SOC with analysts and response in the mandate. Customers keep their existing tools.
What a SOC costs: cost drivers, pricing models, in-house or service
SOC costs arise from the response scope first, not the platform licence. What counts are endpoint and identity counts, log sources and data volume, the response scope you choose, onboarding and licences. Swiss providers rarely publish prices; offers differ widely by scope. Your own calculation starts by holding the cost drivers against your organisation.
Managed vs in-house SOC: which model pays off in Switzerland, and when
An in-house 24/7 SOC needs 8,760 hours of cover per seat; at roughly 1,700 productive hours per full-time role, that means at least 5 to 6 roles, plus platform and training. Economically, running your own SOC only pays off with a large environment and a dedicated team, when regulation, data sovereignty or OT proximity demand it.
SOC for SMEs in Switzerland: what is realistic, what it costs, what makes sense
For Swiss SMEs between 50 and 500 endpoints, managed SOC is almost always the right answer. An in-house SOC rarely pays off at that size: one 24/7 seat covers 8,760 hours, which requires at least 5 to 6 full-time roles and a capable platform. Managed SOC delivers 24/7 detection, documented response and regulatory evidence for revFADP (revised Federal Act on Data Protection), ISG and customer contracts.
SOC & FINMA: What a Swiss financial institution needs to satisfy the supervisor
FINMA requires supervised institutions to document detection and response capabilities and demonstrate operational resilience. Institutions must report material cyber incidents within 24 hours of assessment. FINMA Circular 2023/1 Operational Risks and Resilience is the authoritative reference. It has been in force since 1 Jan 2024 and replaced Circular 2008/21. A SOC delivers 24/7 detection, a ticket and evidence trail and audit-ready evidence. Institutions need all three to meet the requirements reliably.
SOC for manufacturing: monitoring IT and OT together
During an incident, manufacturers lose production, not data. A SOC for manufacturing monitors the IT network and OT environment (PLC, HMI, legacy systems). It stops ransomware before the production line goes down. The core risk is not encryption; it is downtime.
SOC & ISG: The 24-hour cyber-incident reporting duty in Switzerland
Since 1 April 2025, the Swiss Information Security Act (ISG, SR 128, Art. 74a-74f) imposes a cyberattack reporting duty on critical infrastructure operators. Operators must report cyberattacks to the National Cyber Security Centre (NCSC) within 24 hours of detection. Operators need 24/7 detection and documented response processes to meet this deadline reliably. A SOC delivers these two building blocks.
Comparing SOC providers: the neutral selection checklist
Comparing SOC providers works via verifiable criteria, not logos: data scope, response authority inside the customer tenant, evidence artefacts, response times and contract wording. This page lists the questions used to line offers up side by side. Deliberately without vendor names, so the checklist holds up even when ANOMAL is not on the shortlist.

Frequently asked questions

What does SOC as a Service cost in Switzerland?

Costs follow log volume, endpoints and response scope; Swiss providers hardly publish prices. ANOMAL offers an annual flat fee based on endpoint count, with all severities from low to critical handled.

What is the difference between SOC and MDR?

A SOC monitors and alerts. MDR (Managed Detection and Response) monitors, alerts and actively responds, including containment. The two can be combined.

Who benefits from a managed SOC?

A managed SOC benefits any organisation that needs 24/7 monitoring without running an internal SOC team. In Switzerland, these are typically companies with 50 or more employees.

Do our data stay in Switzerland?

With ANOMAL, your data stay in Switzerland. We conduct analysis and store data in Switzerland. International providers do not always offer this. Check explicitly before signing.

How fast is a managed SOC operational?

A modern onboarding takes 5 to 8 weeks (discovery, log ingestion, rule tuning, playbook handover, steady-state review). In week one the SOC already delivers first detections from a baseline use-case set.