What a SOC costs: cost drivers, pricing models, in-house or service
SOC costs arise from the response scope first, not the platform licence. What counts are endpoint and identity counts, log sources and data volume, the response scope you choose, onboarding and licences. Swiss providers rarely publish prices; offers differ widely by scope. Your own calculation starts by holding the cost drivers against your organisation.
How this compares to neighbouring topics
This page covers cost. For weighing managed SOC against in-house, read Managed SOC vs. in-house. For the fundamentals of the operating unit, see What is a SOC. As a full offering, SOC as a Service Switzerland covers platform, team and response.
What drives the price: the seven cost drivers
- Endpoints: every monitored workstation, server and device generates volume and handling time.
- Identities: accounts, privileges and sessions generate their own alerts and investigation effort.
- Log sources: the more sources feed in, the wider the coverage and the higher the operating effort.
- Data volume: ingest drives licence and infrastructure cost in many models.
- Response scope: alerts-only costs far less than containment in the provider's mandate.
- Onboarding: setup, use-case engineering and playbooks are one-off costs often underestimated.
- Licences: platform, threat intel and add-on modules come on top of staff cost.
Two offers with the same endpoint count can differ in price because response scope and log sources differ. Compare scope and mandate, not only price.
Pricing models explained neutrally
| Model | How it works | Advantage | Drawback |
|---|---|---|---|
| Per endpoint | Fixed price per monitored device and month | Predictable and easy to compare | Scales linearly; IoT and OT inflate the count quickly |
| By data volume | Price follows ingest (GB per day or EPS) | Small environments pay little; fine-grained tuning possible | Costs jump when volume or sources grow |
| Flat fee | Fixed annual price matched to environment and scope | Budget certainty; response scope is included | Only comparable when scope and mandate are defined identically |
Light orientation: international MDR providers quote around USD 10 to 30 per endpoint and month in public price overviews (as of 2026). Swiss providers rarely publish prices, and offers differ widely by scope. Compare whether and in whose mandate response happens before comparing prices.
In-house: the calculation with visible assumptions
One 24/7 seat requires 8,760 hours a year. A full-time employee delivers roughly 1,700 productive hours per position. Around-the-clock with redundancy means at least 5 to 6 full-time positions, plus leadership and level-3 expertise. Insert your own salary costs: fully loaded cost per position times 5 to 6 positions, plus platform, ingest, threat intel, recruitment and training.
| Position | Assumption | Your figure |
|---|---|---|
| Fully loaded SOC analyst cost per year | Your salary cost including social contributions | … CHF |
| Positions for 24/7 with redundancy | 8,760 hours per seat divided by roughly 1,700 productive hours | at least 5 to 6 |
| Platform, ingest, threat intel | Licence model and data volume of your environment | … CHF |
| Recruitment, turnover, training | Your HR's own experience | … CHF |
The full comparison including switching costs and control questions is under Managed SOC vs. in-house.
What justifies the cost: benefits qualitatively
- Avoided downtime: an incident contained early keeps production, sales and support running.
- Insurer requirements: cyber cover increasingly demands demonstrable detection and response.
- Customer requirements: questionnaires and audits ask for 24/7 operation and response evidence.
- Regulatory evidence: FINMA, ISG and DORA require documented incidents and deadlines.
These points cannot be pressed into a general ROI figure without knowing your own environment. The honest calculation compares annual cost with the value of the services your organisation actually needs.
How ANOMAL charges
ANOMAL works with a flat fee per year, scaled to the number of endpoints. Detection and response in the shared mandate are included, as are response and containment; larger incident response engagements are charged separately. This keeps response scope part of the price, not an add-on. Details and a quote come from the conversation; SOC as a Service Switzerland describes the scope.
Placement in SOC operations
The SOC as a Service Switzerland page describes the services behind the cost.
Frequently asked questions
Why do Swiss providers rarely publish prices?
Because response scope, environment and mandate drive the effort. A price without defined scope is not comparable; ask for the service catalogue first, the number second.
What happens to cost as we grow?
Per-endpoint models scale linearly. EPS or GB models can jump when log volume grows. Clarify the pricing structure before signing.
Can we start with managed SOC and internalise later?
Yes, provided the contract governs data return and detection-content handover. Address a clean exit during selection to avoid later disputes.
How many staff does an in-house 24/7 SOC need?
At least 5 to 6 full-time positions: 8,760 hours per 24/7 seat divided by roughly 1,700 productive hours each, plus leadership and level-3 expertise. Insert your own salary costs into the calculation.
Does an in-house SOC still pay off?
It pays off only for a large environment and its own team, when regulation, data sovereignty or OT proximity demand it. For most other setups, service operation is more economical.
Related terms
- SOCaaS SOC as a Service (SOCaaS) is a SOC operated by an external provider and delivered as an ongoing service.
- SOC A Security Operations Center (SOC) is the team that constantly monitors an organisation's IT for attacks and intervenes during incidents.
- MSSP A Managed Security Service Provider (MSSP) operates specific security services for its clients, such as firewalls or monitoring.
- MDR Managed Detection and Response (MDR) is a service that detects threats and actively contains them.