Architecture

Zero Trust and SOC: from principle to effective detection

Zero Trust is an architecture principle, not a product category. No network, device or account is trusted implicitly, and every request is continuously authenticated and authorised. For the principle to work you need a SOC that correlates identity, device and network signals and detects violations of the defined policies. Without detection Zero Trust stays a diagram; without a Zero Trust foundation the SOC runs in circles. Frame and operating model in detail on [SOC as a Service Switzerland](/en/soc/soc-as-a-service-switzerland).

All

Scope: Zero Trust vs SASE vs perimeter

Zero Trust is a security principle with seven tenets (see NIST SP 800-207): no implicit trust zones, least privilege, continuous verification. SASE is a delivery model for network and security functions (SWG, CASB, ZTNA, FWaaS) from the cloud. It can make Zero Trust operational without replacing it. Classical perimeter architecture trusts everything inside the network; this is obsolete with cloud, remote work and SaaS. This page treats Zero Trust as the foundation for SOC detection.

Short version

Zero Trust defines the rules. SASE delivers the technology. The SOC verifies that the rules hold in reality.

Which signals the SOC gets from a Zero Trust architecture

LayerSourceDetection example
IdentityEntra ID, Okta, Ping: sign-ins, Conditional Access, risk eventsImpossible travel, MFA bypass, unusual OAuth grants; see ITDR.
DeviceEDR, MDM: posture, compliance state, process treeAccess from a non compliant device to a sensitive app; see SOC EDR vs MDR.
NetworkZTNA broker, firewall, NDREast-west traffic that should no longer exist after segmentation; see NDR.
Application / dataSaaS audit logs, DLP, data access governanceAccess to customer data outside approved roles and times.

Why this matters especially in Switzerland

  • revFADP (revised Federal Act on Data Protection): Zero Trust puts purpose limitation and data minimisation into practice through fine-grained access control. If an incident is likely to result in a high risk to the persons concerned, the FDPIC must be notified as soon as possible. See revFADP and SOC.
  • FINMA: institutions report material cyber attacks under Art. 29 para. 2 FINMASA (Guidance 05/2020, refined by Guidance 03/2024): initial notification within 24 hours of discovery, full report within 72 hours. FINMA Circular 2023/1 expects layered controls; Zero Trust telemetry delivers evidence for supervisory questions. See SOC and FINMA.
  • ISG: operators of critical infrastructures notify cyber incidents to the National Cyber Security Centre (NCSC) within 24 hours; segmented architectures limit impact and speed up assessment. See ISG reporting duty.
  • ISO 27001: least privilege and continuous verification address controls such as A.5.15 (Access control), A.5.18 (Access rights) and A.8.2 (Privileged access rights). See ISO 27001 and SOC.

Pragmatic roadmap for the Swiss mid-market

  1. Identity as the new perimeter: mandatory MFA, Conditional Access, privileged access management. Feed ITDR into the SOC.
  2. Enforce device posture: EDR with compliance signals, ZTNA instead of legacy VPN, unmanaged devices into their own enclaves.
  3. Segment the network step by step: crown-jewel applications first, monitor east-west with NDR, close dead legacy paths.
  4. Data access by classification: sensitive data behind just-in-time access, audit logs centrally in the SIEM, maintain DLP rules.
  5. Anchor detection and response: SOC playbooks for policy violations, threat hunting against bypassed controls. See Threat hunting Switzerland.
What fails in practice

Zero Trust projects rarely fail on technology. They fail on exceptions: legacy applications that cannot do modern authentication; admin accounts that stay MFA free by exception; remote maintenance that bypasses the broker. The SOC must know and monitor those exceptions, otherwise every exception hollows out the principle.

Legal basis and sources

  • FINMA Guidance 05/2020 on reporting cyber attacks (Art. 29 para. 2 FINMASA): finma.ch
  • FINMA Guidance 03/2024 refining the reporting duty: finma.ch
  • ISG (SR 128), Art. 74a-74f: Fedlex
  • ISG reporting duty at the National Cyber Security Centre (NCSC) including routing: bacs.admin.ch
  • Reporting data security breaches to the FDPIC: edoeb.admin.ch

Frequently asked questions

Does Zero Trust necessarily require SASE or ZTNA products?

No. Zero Trust is a principle that can be implemented with different stacks. ZTNA and SASE speed up implementation, but Conditional Access, EDR, good segmentation and a SOC are equally valid building blocks.

How does Zero Trust relate to legacy OT and industrial plants?

OT systems rarely speak Zero Trust themselves. The pragmatic path is strict segmentation, broker or jump-host access, passive SOC monitoring and explicit exception lists with expiry dates.

Which metrics show progress?

Useful metrics are the share of applications behind Conditional Access and the share of devices with enforced posture. Add the number of open exceptions, time to detect policy violations (MTTD) and time to respond (MTTR). See [MTTD and MTTR](/en/soc/soc-mttd-mttr).

What is the role of the SIEM in a Zero Trust world?

The SIEM aggregates signals from identity, device, network and application, correlates policy context and delivers cases to analysts. Without that correlation the signals stay isolated. See [SIEM](/en/glossary/siem).

How long does a serious Zero Trust rollout realistically take?

A mid-sized company is typically on the road for 12 to 24 months when identity, EDR, segmentation and data classification run in parallel. Value materialises much earlier once identity and EDR are married with the SOC.

Continue reading in this cluster
SOC as a Service in Switzerland: The Complete Guide
SOC as a Service is an externally operated Security Operations Center that monitors your environment around the clock, detects attacks and triggers the response. According to Mandiant M-Trends 2026, attackers went undetected for a median of 14 days in 2025. With a SOC that detects and assesses around the clock, typical detection time becomes much shorter.
ITDR: Identity Threat Detection and Response for Switzerland
ITDR (Identity Threat Detection and Response) detects attacks on the identity itself, not just endpoints or networks. Targets are accounts, tokens, sessions, permissions and identity providers such as Entra ID or Okta. ITDR extends EDR and SIEM with signals only visible in the identity layer. These include impossible travel, consent phishing, refresh-token abuse, role abuse and attacks on federation and directory objects. For Swiss organisations running M365, Entra ID and regulated processes, ITDR today is as important as EDR was five years ago.
Attack surface management: what is visible outside your perimeter
Attack surface management (ASM) is the continuous discovery, classification and assessment of every internet-facing asset an organisation exposes. The goal is to find exposed systems, forgotten subdomains, vulnerable services and leaked credentials before attackers exploit them. ASM complements vulnerability management (known assets, deep scanning) with the outside-in view: what attackers learn about you when they start from a blank page.
ISO 27001 and SOC: where the ISMS ends and operations begin
ISO 27001 requires a management system for information security with documented processes, risks and controls. A SOC complements the ISMS as its operational foundation. It puts controls A.5.24 to A.5.30 (incident management, continuity, readiness) and A.8.15 to A.8.16 (logging, monitoring) into practice. Without 24/7 detection, several Annex A controls remain operationally ineffective despite formal compliance.
SOC, SIEM, EDR, XDR, MDR: the terms explained
SOC is the function; SIEM, EDR and XDR are tools; MDR is a service. The label matters less than whether response happens and in whose mandate. At ANOMAL, SOC as a Service covers detection and response and is often called MDR; a managed SIEM is part of the SOC with analysts and response in the mandate. Customers keep their existing tools.