SOC onboarding in Switzerland: process, roles, realistic timeline
A clean SOC onboarding typically takes 5 to 8 weeks. It has five phases: discovery and scoping, log ingestion with EDR, rule tuning, playbook handover with go-live, and a 30-day steady-state review. Vendors promising faster onboarding usually skip rule tuning. The result: alert fatigue within weeks and a SOC that fails to make decisions when it matters.
How this compares to neighbouring topics
This page describes the operational onboarding path. See SOC cost Switzerland for pricing, Co-Managed SOC for contract models and Managed vs in-house SOC for model choice. For the basic service definition see What is a SOC.
The five onboarding phases
| Phase | Duration | Focus |
|---|---|---|
| Discovery and scoping | 1 week | Asset and log inventory, crown jewels, regulatory scope (revDSG, ISG, FINMA, DORA). |
| Log ingestion and EDR rollout | 1-2 weeks | EDR across all endpoints, cloud and identity logs, critical server and network sources. |
| Rule tuning and baseline | 1-2 weeks | Environment baseline, false-positive reduction, detection content per business context. |
| Playbook handover and go-live | 1-2 weeks | Response playbooks per alert type, escalation matrix, tabletop with internal IT and executives. |
| Steady-state transition with review | 1 week | 30-day review, KPIs, re-tuning; handover to the quarterly governance cadence. |
Cleanly run onboardings land at 5 to 8 weeks. Regulated and OT-heavy environments sit at the upper end, cloud-heavy small SMEs at the lower.
Roles the customer side must staff
- A project owner with real IT-infrastructure decision authority, not a coordinator role.
- A technical contact for identity, cloud and network with admin rights or direct access to them.
- Documented sign-off on which response actions the SOC may execute autonomously (host isolation, user disable).
- A named escalation chain up to executive level for out-of-hours cases.
What internal IT should prepare before onboarding starts
- Up-to-date asset inventory with criticality, at least for servers, identity systems and crown jewels.
- Zone-level network diagram, including OT and production zones where applicable.
- List of every privileged and service account with an owner. Without it, clean identity monitoring is impossible.
- Backup and restore evidence for the last 90 days. In a real incident these become the critical path.
Typical onboarding mistakes
- Onboarding in a few days without rule tuning. Result: alert fatigue within weeks.
- Log ingestion without prioritisation. Result: high platform cost, little detection value.
- Playbooks without internal sign-off. Result: response actions blocked by governance.
A SOC that goes live in a few days has no baseline. It either alerts on everything or on nothing. Both outcomes let real attacks disappear in the noise.
What go-live means in practice
At go-live, the SOC handles defined alert types 24/7 using approved response playbooks. The escalation matrix has passed testing, and the schedule includes a 30-day review. Until then, the SOC operates actively and tunes rules frequently. After that, steady-state operations include quarterly governance and ongoing rule maintenance.
Placement in SOC operations
See SOC as a Service Switzerland for details of ongoing operations after onboarding.
Frequently asked questions
Why does onboarding take 5 to 8 weeks and not less?
Rule tuning needs time with real environment data. A baseline covering less than two weeks of production data mainly produces noise and cannot yet support reliable detection. Vendors promising faster onboarding typically provide alerting without response.
Can we get attacked during onboarding?
Yes. That is why EDR and core log ingestion go live in phase 2, even while detection rules are still being tuned. A responsible provider documents emergency access for customers from day 1.
Which log sources are mandatory at the start?
You need EDR across all endpoints, an identity provider (Entra ID or equivalent), an email gateway, a perimeter firewall and central server systems. Everything else follows by priority. See [SOC pricing models](/en/soc/soc-cost-switzerland) for cost impact.
What if we already have an internal SOC team?
Then onboarding runs as a co-managed model with a RACI matrix instead of a full managed service. See [Co-Managed SOC](/en/soc/co-managed-soc) for the process, roles and contract structure.
What changes after 30 days?
The 30-day review checks the false-positive rate, actual response times and playbook fit. Its findings guide adjustments to rules, alert prioritisation and the escalation matrix. After that, the service moves to quarterly governance.
Related terms
- SOCaaS SOC as a Service (SOCaaS) is a SOC operated by an external provider and delivered as an ongoing service.
- Log Source A log source is any system that provides security-relevant events to a SIEM or the SOC.
- Telemetry Pipeline A telemetry pipeline collects, filters, and routes logs and events before they are analysed in the SIEM or SOC.
- Runbook A runbook is a detailed operational procedure outlining the technical steps for a specific task.