What a SOC costs: cost drivers, pricing models, in-house or service

SOC costs arise from the response scope first, not the platform licence. What counts are endpoint and identity counts, log sources and data volume, the response scope you choose, onboarding and licences. Swiss providers rarely publish prices; offers differ widely by scope. Your own calculation starts by holding the cost drivers against your organisation.

All

How this compares to neighbouring topics

This page covers cost. For weighing managed SOC against in-house, read Managed SOC vs. in-house. For the fundamentals of the operating unit, see What is a SOC. As a full offering, SOC as a Service Switzerland covers platform, team and response.

What drives the price: the seven cost drivers

  • Endpoints: every monitored workstation, server and device generates volume and handling time.
  • Identities: accounts, privileges and sessions generate their own alerts and investigation effort.
  • Log sources: the more sources feed in, the wider the coverage and the higher the operating effort.
  • Data volume: ingest drives licence and infrastructure cost in many models.
  • Response scope: alerts-only costs far less than containment in the provider's mandate.
  • Onboarding: setup, use-case engineering and playbooks are one-off costs often underestimated.
  • Licences: platform, threat intel and add-on modules come on top of staff cost.

Two offers with the same endpoint count can differ in price because response scope and log sources differ. Compare scope and mandate, not only price.

Pricing models explained neutrally

ModelHow it worksAdvantageDrawback
Per endpointFixed price per monitored device and monthPredictable and easy to compareScales linearly; IoT and OT inflate the count quickly
By data volumePrice follows ingest (GB per day or EPS)Small environments pay little; fine-grained tuning possibleCosts jump when volume or sources grow
Flat feeFixed annual price matched to environment and scopeBudget certainty; response scope is includedOnly comparable when scope and mandate are defined identically

Light orientation: international MDR providers quote around USD 10 to 30 per endpoint and month in public price overviews (as of 2026). Swiss providers rarely publish prices, and offers differ widely by scope. Compare whether and in whose mandate response happens before comparing prices.

In-house: the calculation with visible assumptions

One 24/7 seat requires 8,760 hours a year. A full-time employee delivers roughly 1,700 productive hours per position. Around-the-clock with redundancy means at least 5 to 6 full-time positions, plus leadership and level-3 expertise. Insert your own salary costs: fully loaded cost per position times 5 to 6 positions, plus platform, ingest, threat intel, recruitment and training.

PositionAssumptionYour figure
Fully loaded SOC analyst cost per yearYour salary cost including social contributions… CHF
Positions for 24/7 with redundancy8,760 hours per seat divided by roughly 1,700 productive hoursat least 5 to 6
Platform, ingest, threat intelLicence model and data volume of your environment… CHF
Recruitment, turnover, trainingYour HR's own experience… CHF
Excluding overhead for space, onboarding and IT support. The comparison against a service offer starts only after this sum.

The full comparison including switching costs and control questions is under Managed SOC vs. in-house.

What justifies the cost: benefits qualitatively

  • Avoided downtime: an incident contained early keeps production, sales and support running.
  • Insurer requirements: cyber cover increasingly demands demonstrable detection and response.
  • Customer requirements: questionnaires and audits ask for 24/7 operation and response evidence.
  • Regulatory evidence: FINMA, ISG and DORA require documented incidents and deadlines.

These points cannot be pressed into a general ROI figure without knowing your own environment. The honest calculation compares annual cost with the value of the services your organisation actually needs.

How ANOMAL charges

ANOMAL works with a flat fee per year, scaled to the number of endpoints. Detection and response in the shared mandate are included, as are response and containment; larger incident response engagements are charged separately. This keeps response scope part of the price, not an add-on. Details and a quote come from the conversation; SOC as a Service Switzerland describes the scope.

Frequently asked questions

Why do Swiss providers rarely publish prices?

Because response scope, environment and mandate drive the effort. A price without defined scope is not comparable; ask for the service catalogue first, the number second.

What happens to cost as we grow?

Per-endpoint models scale linearly. EPS or GB models can jump when log volume grows. Clarify the pricing structure before signing.

Can we start with managed SOC and internalise later?

Yes, provided the contract governs data return and detection-content handover. Address a clean exit during selection to avoid later disputes.

How many staff does an in-house 24/7 SOC need?

At least 5 to 6 full-time positions: 8,760 hours per 24/7 seat divided by roughly 1,700 productive hours each, plus leadership and level-3 expertise. Insert your own salary costs into the calculation.

Does an in-house SOC still pay off?

It pays off only for a large environment and its own team, when regulation, data sovereignty or OT proximity demand it. For most other setups, service operation is more economical.

Continue reading in this cluster