SOC for SMEs in Switzerland: what is realistic, what it costs, what makes sense

For Swiss SMEs between 50 and 500 endpoints, managed SOC is almost always the right answer. An in-house SOC rarely pays off at that size: one 24/7 seat covers 8,760 hours, which requires at least 5 to 6 full-time roles and a capable platform. Managed SOC delivers 24/7 detection, documented response and regulatory evidence for revFADP (revised Federal Act on Data Protection), ISG and customer contracts.

All

How this compares to neighbouring topics

This page takes the Swiss SME perspective. For raw prices, see SOC cost Switzerland. For pricing models in detail, see SOC pricing models. For the full economics, see SOC ROI. For what a SOC does, see What is a SOC.

Why SMEs can no longer wait on the SOC question

  • Attacks hit SMEs structurally harder: smaller IT teams, less redundancy, longer recovery times.
  • Customer contracts from large buyers increasingly demand 24/7 detection as a supplier criterion.
  • revFADP (revised Federal Act on Data Protection) (since 1 Sept 2023) and ISG (since 1 April 2025) require documented security processes and timely notification. Without a SOC, SMEs cannot adequately demonstrate these processes.
  • Cyber insurers increasingly set 24/7 detection as a coverage prerequisite. Without proof, premiums rise or cover lapses.

What an SME-fit SOC setup contains

  • 24/7 detection on endpoints, identity (Entra ID), cloud (Microsoft 365, Azure, AWS) and the most important on-prem footprint.
  • Response rights: the SOC may isolate hosts, end sessions and disable accounts, not just issue alerts.
  • A named service manager and monthly reporting with MTTD, MTTR, top findings and recommendations.
  • Onboarding with a clear definition of in-scope, out-of-scope, playbooks and escalation chains.
  • The SOC must demonstrate 24/7 staffing. Insurers and regulated customers require human analysts in the loop, ruling out AI-only setups.
What is often missing

SME offerings often lack response rights, a service manager and documented playbooks. Without those three, it is alert forwarding, not managed SOC.

What drives cost for SMEs

  • Number of endpoints and servers
  • Number of identities and privileged accounts
  • Connected data sources and data volume
  • Response scope within the agreed mandate
  • Onboarding effort and existing licences

International MDR providers publish around USD 10 to 30 per endpoint per month in public price overviews (as of 2026). Swiss providers hardly publish prices; offers differ sharply by scope. ANOMAL charges SOC as a Service as an annual flat fee based on endpoint count.

Onboarding: how long does it realistically take?

A cleanly run SME onboarding follows the same five-phase pattern as larger environments and typically takes 5 to 8 weeks. SMEs land at the lower end of the range because fewer log sources and simpler network zones shorten the baseline.

PhaseDurationFocus
Discovery and scoping1 weekAsset and log inventory, crown jewels, regulatory scope (revDSG, ISG, FINMA, DORA).
Log ingestion and EDR rollout1-2 weeksEDR across all endpoints, cloud and identity logs, critical server and network sources.
Rule tuning and baseline1-2 weeksEnvironment baseline, false-positive reduction, detection content per business context.
Playbook handover and go-live1-2 weeksResponse playbooks per alert type, escalation matrix, tabletop with internal IT and executives.
Steady-state transition with review1 week30-day review, KPIs, re-tuning; handover to the quarterly governance cadence.

Providers that promise onboarding in 'a few days' typically skip rule tuning. This leads to high false-positive rates and alert fatigue for internal IT. See SOC Onboarding Switzerland for detailed steps, roles and typical pitfalls.

Typical mistakes SMEs make when choosing

  • SMEs sometimes compare offers on price alone. Offers are only comparable once it is clear whether and under which mandate the provider responds around the clock.
  • SMEs sometimes accept AI as a substitute for staff. Insurers, regulated customers and serious buyers require human analysts in the loop.
  • SMEs sometimes underestimate onboarding. Poor log integration and tuning create blind spots or alert floods.
  • SMEs sometimes forget response rights in the contract. Without isolation rights, the SOC remains an observer.

Frequently asked questions

From what size is a SOC worth it for an SME?

Economically, managed SOC is usually the clear choice for small and mid-sized environments. Regulatory or contractual requirements can make it necessary beyond that, once a customer or insurer demands 24/7 detection.

Can we start with a managed SIEM and add a SOC later?

You can do this, but it usually takes longer and costs more because teams build playbooks, rules and reporting twice. For the structural difference, see [MDR vs. Managed SIEM](/en/soc/soc-siem-edr-xdr-mdr-terms).

We only have 60 endpoints. Is that too small?

No. For cloud-heavy setups the scope stays manageable, and costs follow endpoints, identities and data sources. At that size, the value often comes from customer contracts and insurance terms.

Can a SOC monitor only Microsoft 365?

Yes, a pure cloud scope is possible and often the right entry point for SMEs. Endpoint, network and identity events should follow in the second expansion phase at the latest.

How does an SME SOC differ from an enterprise SOC?

An SME SOC provides the same capabilities as an enterprise SOC, with differences in depth. SMEs need the same building blocks: 24/7 detection, response and reporting. They need fewer custom use cases, clearer playbooks and a service manager who does not overwhelm the internal IT team.