SOC onboarding in Switzerland: process, roles, realistic timeline

A clean SOC onboarding typically takes 5 to 8 weeks. It has five phases: discovery and scoping, log ingestion with EDR, rule tuning, playbook handover with go-live, and a 30-day steady-state review. Vendors promising faster onboarding usually skip rule tuning. The result: alert fatigue within weeks and a SOC that fails to make decisions when it matters.

All

How this compares to neighbouring topics

This page describes the operational onboarding path. See SOC cost Switzerland for pricing, Co-Managed SOC for contract models and Managed vs in-house SOC for model choice. For the basic service definition see What is a SOC.

The five onboarding phases

PhaseDurationFocus
Discovery and scoping1 weekAsset and log inventory, crown jewels, regulatory scope (revDSG, ISG, FINMA, DORA).
Log ingestion and EDR rollout1-2 weeksEDR across all endpoints, cloud and identity logs, critical server and network sources.
Rule tuning and baseline1-2 weeksEnvironment baseline, false-positive reduction, detection content per business context.
Playbook handover and go-live1-2 weeksResponse playbooks per alert type, escalation matrix, tabletop with internal IT and executives.
Steady-state transition with review1 week30-day review, KPIs, re-tuning; handover to the quarterly governance cadence.
Total duration

Cleanly run onboardings land at 5 to 8 weeks. Regulated and OT-heavy environments sit at the upper end, cloud-heavy small SMEs at the lower.

Roles the customer side must staff

  • A project owner with real IT-infrastructure decision authority, not a coordinator role.
  • A technical contact for identity, cloud and network with admin rights or direct access to them.
  • Documented sign-off on which response actions the SOC may execute autonomously (host isolation, user disable).
  • A named escalation chain up to executive level for out-of-hours cases.

What internal IT should prepare before onboarding starts

  • Up-to-date asset inventory with criticality, at least for servers, identity systems and crown jewels.
  • Zone-level network diagram, including OT and production zones where applicable.
  • List of every privileged and service account with an owner. Without it, clean identity monitoring is impossible.
  • Backup and restore evidence for the last 90 days. In a real incident these become the critical path.

Typical onboarding mistakes

  • Onboarding in a few days without rule tuning. Result: alert fatigue within weeks.
  • Log ingestion without prioritisation. Result: high platform cost, little detection value.
  • Playbooks without internal sign-off. Result: response actions blocked by governance.
Fast onboarding is not a quality signal

A SOC that goes live in a few days has no baseline. It either alerts on everything or on nothing. Both outcomes let real attacks disappear in the noise.

What go-live means in practice

At go-live, the SOC handles defined alert types 24/7 using approved response playbooks. The escalation matrix has passed testing, and the schedule includes a 30-day review. Until then, the SOC operates actively and tunes rules frequently. After that, steady-state operations include quarterly governance and ongoing rule maintenance.

Frequently asked questions

Why does onboarding take 5 to 8 weeks and not less?

Rule tuning needs time with real environment data. A baseline covering less than two weeks of production data mainly produces noise and cannot yet support reliable detection. Vendors promising faster onboarding typically provide alerting without response.

Can we get attacked during onboarding?

Yes. That is why EDR and core log ingestion go live in phase 2, even while detection rules are still being tuned. A responsible provider documents emergency access for customers from day 1.

Which log sources are mandatory at the start?

You need EDR across all endpoints, an identity provider (Entra ID or equivalent), an email gateway, a perimeter firewall and central server systems. Everything else follows by priority. See [SOC pricing models](/en/soc/soc-cost-switzerland) for cost impact.

What if we already have an internal SOC team?

Then onboarding runs as a co-managed model with a RACI matrix instead of a full managed service. See [Co-Managed SOC](/en/soc/co-managed-soc) for the process, roles and contract structure.

What changes after 30 days?

The 30-day review checks the false-positive rate, actual response times and playbook fit. Its findings guide adjustments to rules, alert prioritisation and the escalation matrix. After that, the service moves to quarterly governance.

Continue reading in this cluster
SOC as a Service in Switzerland: The Complete Guide
SOC as a Service is an externally operated Security Operations Center that monitors your environment around the clock, detects attacks and triggers the response. According to Mandiant M-Trends 2026, attackers went undetected for a median of 14 days in 2025. With a SOC that detects and assesses around the clock, typical detection time becomes much shorter.
Managed vs in-house SOC: which model pays off in Switzerland, and when
An in-house 24/7 SOC needs 8,760 hours of cover per seat; at roughly 1,700 productive hours per full-time role, that means at least 5 to 6 roles, plus platform and training. Economically, running your own SOC only pays off with a large environment and a dedicated team, when regulation, data sovereignty or OT proximity demand it.
What a SOC costs: cost drivers, pricing models, in-house or service
SOC costs arise from the response scope first, not the platform licence. What counts are endpoint and identity counts, log sources and data volume, the response scope you choose, onboarding and licences. Swiss providers rarely publish prices; offers differ widely by scope. Your own calculation starts by holding the cost drivers against your organisation.
SOC for SMEs in Switzerland: what is realistic, what it costs, what makes sense
For Swiss SMEs between 50 and 500 endpoints, managed SOC is almost always the right answer. An in-house SOC rarely pays off at that size: one 24/7 seat covers 8,760 hours, which requires at least 5 to 6 full-time roles and a capable platform. Managed SOC delivers 24/7 detection, documented response and regulatory evidence for revFADP (revised Federal Act on Data Protection), ISG and customer contracts.
What is a SOC? Definition, tasks and structure
A Security Operations Center (SOC) is a team of people, processes and technology. It monitors an organisation's IT and OT environment around the clock, detects attacks and coordinates the response. A SOC is not a piece of software; it is an operating unit.