SOC as a Service in Switzerland: The Complete Guide
SOC as a Service is an externally operated Security Operations Center that monitors your environment around the clock, detects attacks and triggers the response. According to Mandiant M-Trends 2026, attackers went undetected for a median of 14 days in 2025. With a SOC that detects and assesses around the clock, typical detection time becomes much shorter.
What is SOC as a Service?
SOC as a Service is the outsourced operation of detection and response by a specialist provider. The same service promise is often called MDR; at ANOMAL it is part of SOC as a Service. The provider brings 24/7 analysts, processes and a detection engineering team, while you keep your existing tools, data sovereignty and control of the mandate.
- 24/7 monitoring of every security-relevant data source
- Triage, investigation and prioritisation of every alert
- Response and containment within the agreed mandate
- Continuous detection engineering rather than static rules
How a modern SOC works
A modern SOC has moved beyond the classic Tier 1 / Tier 2 / Tier 3 model. Deterministic automation handles routine work, agentic AI correlates context, and our analysts make the decisions. This reduces noise, shortens response times and gives analysts context from the start.
What does SOC as a Service cost?
Costs follow log volume, endpoint count, cloud footprint and how much active response is included. International MDR providers publish around USD 10 to 30 per endpoint per month in public price overviews (as of 2026). Swiss providers hardly publish prices; offers differ sharply by scope.
An in-house 24/7 SOC: 8,760 hours per round-the-clock seat and roughly 1,700 productive hours per full-time role add up to at least 5 to 6 full-time roles, plus management, platform, licences and training. Insert your own payroll rates. Economically, running your own SOC only pays off with a large environment and a dedicated team.
Who benefits from SOC as a Service?
SOC as a Service benefits any organisation that cannot afford to miss an incident for weeks. That covers SMEs from around 50 employees, financial services firms under FINMA, and manufacturers running OT environments.
How to choose a provider
- Data sovereignty and analyst location
- Response times per severity in the SLA, with contractual and typical values shown separately
- Clarity on whether and under which mandate the provider responds, and what counts separately as incident response
- Transparent pricing: no hidden log overage costs
- Fit with FINMA, ISG, revFADP (revised Federal Act on Data Protection), ISO 27001 and DORA; data held in Switzerland or the EU, existing tools and a parallel run when switching
Compliance: FINMA, ISG, revFADP
Since April 2025, the Swiss ISG (Art. 74b) requires operators of critical infrastructure to report reportable incidents to the National Cyber Security Centre (NCSC) within 24 hours. Switzerland's revised Data Protection Act is also called nDSG in German and nLPD in French. It additionally requires notification to the FDPIC as soon as possible if affected individuals' personality rights face a high risk. The law sets no rigid 72-hour deadline for notifying the FDPIC. The 72-hour requirement comes from DORA and from the FINMA reporting duty under Guidance 05/2020 and 03/2024 (full report following the initial notification). Organisations need reliable detection to submit any of these notifications reliably.
Legal basis and sources
- FINMA Guidance 05/2020 on reporting cyber attacks (Art. 29 para. 2 FINMASA): finma.ch
- FINMA Guidance 03/2024 refining the reporting duty: finma.ch
- FINMA Circular 2023/1 «Operational risks and resilience»: finma.ch
- FINMASA (SR 956.1): Fedlex
- ISG reporting duty at the National Cyber Security Centre (NCSC) including routing: bacs.admin.ch
- Reporting data security breaches to the FDPIC: edoeb.admin.ch
- ISG (SR 128), Art. 74a-74f: Fedlex
For your industry
Small IT teams immediately gain 24/7 coverage without hiring analysts.
Read more: SOC for SMEs in Switzerland: what is realistic, what it costs, what makes senseFINMA expects explicit detection capability and documented MTTD/MTTR; reporting of material cyber attacks follows from Art. 29 para. 2 FINMASA (Guidance 05/2020, refined by Guidance 03/2024). A managed SOC covers both.
Read more: SOC & FINMA: What a Swiss financial institution needs to satisfy the supervisorProduction downtime is the most expensive scenario. We monitor IT and OT and stop ransomware before the line halts.
Read more: SOC for manufacturing: monitoring IT and OT togetherFrequently asked questions
What does SOC as a Service cost in Switzerland?
Costs follow log volume, endpoints and response scope; Swiss providers hardly publish prices. ANOMAL offers an annual flat fee based on endpoint count, with all severities from low to critical handled.
What is the difference between SOC and MDR?
A SOC monitors and alerts. MDR (Managed Detection and Response) monitors, alerts and actively responds, including containment. The two can be combined.
Who benefits from a managed SOC?
A managed SOC benefits any organisation that needs 24/7 monitoring without running an internal SOC team. In Switzerland, these are typically companies with 50 or more employees.
Do our data stay in Switzerland?
With ANOMAL, your data stay in Switzerland. We conduct analysis and store data in Switzerland. International providers do not always offer this. Check explicitly before signing.
How fast is a managed SOC operational?
A modern onboarding takes 5 to 8 weeks (discovery, log ingestion, rule tuning, playbook handover, steady-state review). In week one the SOC already delivers first detections from a baseline use-case set.
Related terms
- SOCaaS SOC as a Service (SOCaaS) is a SOC operated by an external provider and delivered as an ongoing service.
- SOC A Security Operations Center (SOC) is the team that constantly monitors an organisation's IT for attacks and intervenes during incidents.
- MDR Managed Detection and Response (MDR) is a service that detects threats and actively contains them.
- MSSP A Managed Security Service Provider (MSSP) operates specific security services for its clients, such as firewalls or monitoring.
- Tier-less SOC A Tier-less SOC is a model that operates without the traditional T1, T2, and T3 analyst hierarchy.
- Hyper Automation Hyper Automation is the consistent, end-to-end automation of all recurring tasks in a Security Operations Center.