SOC as a Service Switzerland, Buyer's Guide 2026
Introduction
Building an in-house 24x7 Security Operations Center with three shifts, a threat intelligence team and a Tier-1 SIEM licence typically costs a Swiss mid-market organisation between CHF 1.8m and CHF 3.5m per year. SOC as a Service – more often marketed as Managed Detection and Response (MDR) – shifts that spend into an OpEx model and makes round-the-clock monitoring realistic well below 500 employees. The regulatory bar has risen in parallel: FINMA Circular 2023/1 on operational risks and resilience demands explicit detection capabilities, the Federal Office for Cyber Security (BACS / NCSC) requires reporting of critical cyber incidents within 24 hours from April 2025 (Art. 74b ISG), and Art. 24 of the Federal Act on Data Protection (DSG) ties the 72-hour breach-notification clock to the controller's awareness – without detection, there is no awareness.
What this 2026 buyer's guide covers:
- When MDR/SOC-aaS genuinely beats an in-house SOC or a stand-alone SIEM operation
- The ten selection criteria that decide Swiss RFPs
- Integration scope: EDR, identity, cloud, OT – and where the limits sit
- Swiss data residency, professional secrecy and processor obligations under Art. 9 DSG
- SLA structures, MTTD/MTTR benchmarks and realistic 2026 price bands
When MDR pays off
The economic break-even for SOC as a Service in 2026 sits markedly lower than three years ago. From roughly 80 productive endpoints onwards, or for any environment with several productive SaaS applications, the economics tip toward a managed model. Three drivers dominate:
- Talent shortage: Swiss cyber-security demand exceeds supply by a factor of 4-6. A fully staffed 24x7 shift needs at least 8 FTE Tier-1/2 analysts plus 2 FTE threat hunters – with average recruitment times of 6-11 months per role.
- Tooling inflation: Tier-1 SIEM licences (Splunk, Sentinel, QRadar) start around CHF 150,000 per year at production scale, with SOAR, TIP, NDR and EDR layered on top.
- Regulatory pressure: FINMA Circular 2023/1, NIS2 for Swiss subsidiaries in the EU, DORA for financial entities and the Art. 74b ISG notification obligation all force measurable detection capability.
A high-quality MDR engagement for a Swiss SME with 250 endpoints, M365 E5, Azure IaaS and two critical business applications runs in 2026 between CHF 95,000 and CHF 185,000 per year including EDR licence and 24x7 triage. That is 30-40% of the cost of an in-house build at materially higher detection maturity. Rule of thumb: if you do not have ten dedicated cyber FTE or a specific confidentiality obligation that mandates an in-house SOC, MDR is the rational economic path.
Service scope and limits
The label SOC as a Service hides a wide range of delivery depths. A serious RFP separates at least four service tiers, each spelled out explicitly:
- Monitoring & alerting: log ingest, SIEM correlation, Tier-1 triage, hand-off to the customer. Pure observation.
- Managed detection: Tier-2 analysis, threat hunting, curated use cases, suppression tuning, monthly detection-engineering reviews.
- Managed response: active containment via EDR (host isolation, process kill, account disable) on behalf of the customer, documented in runbooks.
- Incident response: forensics, reverse engineering, threat-actor negotiation, regulator coordination. Usually contracted separately as a retainer.
Pay close attention to the boundary definitions. Who is liable if the MDR provider isolates a production-critical host? What escalation paths apply on Sundays and public holidays? What happens during a mass-phishing event with 5,000 tickets in 30 minutes – is it throttled or scaled? Contracts vary heavily in how they treat false-positive rates. An MDR that quietly suppresses 95% of alerts to protect its margins delivers a dangerous illusion of security. Insist on transparent reporting that breaks out suppression rates, investigated alerts and MITRE ATT&CK coverage.
The ten selection criteria
Across 30+ SOC-aaS selection projects in Switzerland the following ten criteria have proven decision-relevant. A weakness in any one of them typically forces a provider switch within 12 months:
- MITRE ATT&CK coverage against your real tech stack, not generic claims. Demand detections per technique.
- MTTD and MTTR SLAs with bonus/malus terms, not just ticket-response times.
- Detection engineering capability: who writes new use cases, how quickly, against which intel feeds?
- Data residency: where do telemetry and backups live? Which sub-processors sit outside Switzerland or the EU/EEA?
- Professional-secrecy fitness (Art. 321 SCC, Art. 47 BankA): pseudonymisation, encryption, strict need-to-know.
- Cloud and identity depth: Azure AD/Entra, M365, AWS CloudTrail, Okta, GCP – plus SaaS-specific telemetry.
- Threat intelligence: proprietary sources, sector sharing (e.g. FS-ISAC, BACS closed groups), industry relevance.
- Reporting quality: monthly executive summary, quarterly maturity reviews with concrete hardening recommendations.
- Onboarding discipline: a structured 60-90 day plan with use-case workshops, not just connector deployment.
- Exit clauses: data return, use-case IP, transition assistance. 24-36 month terms are standard but must remain cleanly terminable.
Data residency and professional secrecy
The Swiss data-residency question requires more nuance in 2026 than vendor marketing usually admits. Telemetry from M365 or any SaaS platform leaves Switzerland at the vendor's perimeter, long before it reaches your SIEM. The meaningful distinctions are: where are correlated alerts, investigation notes and forensic artefacts stored, and who has access? For mandates bound by Swiss professional secrecy – law firms, trustees, banks, medical practices – the answer is consistently: primary processing in Switzerland, sub-processors only in the EU/EEA, dedicated tenancy or robust client separation, encryption with customer-held keys, and four-eyes controls for privileged operations.
From a data-protection standpoint the MDR provider remains a processor under Art. 9 DSG and Art. 28 GDPR. You need a data-processing agreement with concrete TOM annexes, a complete sub-processor list with veto rights, and a defensible transfer basis (Standard Contractual Clauses plus a Transfer Impact Assessment for third countries). Transfers to the US require either the EU-US Data Privacy Framework at GDPR level or the Swiss-U.S. DPF for Swiss-law transfers – not every US-based MDR provider satisfies both. Cross-check ISO/IEC 27001:2022 controls Annex A.5.7 (threat intelligence), A.5.23 (information security for cloud services) and A.5.30 (ICT readiness for business continuity) explicitly along these interfaces.
Integration scope and telemetry
An MDR is only as strong as its telemetry. In 2026 Swiss SME environments the following minimum data feed is required for meaningful detection:
- Endpoint Detection & Response on all endpoints and servers – ideally the MDR vendor's EDR, otherwise an open integration (CrowdStrike, Defender for Endpoint, SentinelOne).
- Identity telemetry: Entra ID sign-in logs, audit logs, risk detections; Active Directory event forwarding for 4624/4625/4672/4768/4769; conditional-access failures.
- M365/Google Workspace: Unified Audit Log, Exchange mail trace, OneDrive/SharePoint activity, Defender for Cloud Apps.
- Cloud platforms: Azure Activity, Defender for Cloud, AWS CloudTrail & GuardDuty, GCP Audit Logs.
- Network: firewall logs (Palo Alto/Fortinet/Check Point), DNS, ideally an NDR sensor for lateral movement.
- OT/IoT, where present: Claroty/Nozomi data, segmented monitoring.
Commonly missing: SaaS-specific logs (Salesforce, Workday, Abacus, Bexio), printer and MFP telemetry, and build/repository data (GitHub Audit Log, GitLab, Jenkins). Precisely these sources surface insider threats and software supply-chain attacks. Clarify three points per source: format (JSON, syslog, API pull), latency (near-real-time vs 15-minute batch) and completeness (sampled vs full fidelity). Gap-free audit trails are the prerequisite for any court-admissible forensic investigation.
SLAs, KPIs and 2026 price bands
Meaningful MDR SLAs cover at least three dimensions, each with concrete bonus/malus mechanics:
- MTTD (Mean Time to Detect) – median over 90 days, split by severity. Industry median for credible providers in 2026: 8 minutes for high/critical, 25 minutes for medium.
- MTTA (Mean Time to Acknowledge) – time until Tier-1 picks up the alert. Realistic: under 10 minutes for critical, under 30 minutes for high.
- MTTR (Mean Time to Respond) – time to first containment action (host isolation, account block). Top quartile in 2026: under 30 minutes for critical including customer approval via an out-of-band channel.
Additionally relevant: reporting SLAs (monthly report within X working days), SIEM tenant availability (99.9% is industry standard), and incident-communication SLAs (first contact within 15 minutes for critical).
2026 price bands for Swiss engagements, fully loaded including EDR licences and 24x7 triage: roughly CHF 95,000-145,000 for 100-250 endpoints and one cloud tenant, CHF 180,000-280,000 for 500-800 endpoints with multi-cloud, CHF 350,000-600,000 for mid-market with an OT component. Be wary of offers materially below market: you are buying either Tier-1-only monitoring without threat hunting, an offshore location with questionable data sovereignty, or an onboarding without use-case engineering. A good RFP therefore mandates Swiss reference customers and a sample report from a real (anonymised) incident.
How SIDD supports you
SIDD guides Swiss mid-market organisations and FINMA-supervised institutions through the full SOC-as-a-Service selection process: from maturity baselining through technical and commercial RFPs, vendor short-listing and proof-of-concept architecture, all the way to contract negotiation and onboarding governance. We validate detection coverage via our own adversary simulation, confirm data-protection compliance under Art. 9 DSG including the Transfer Impact Assessment, and produce a defensible three-year total cost of ownership. Our approach is vendor-neutral – we operate with 12+ MDR providers across Switzerland, the EU and the UK and know their operational strengths and weaknesses from real engagements. On request our team also runs ongoing oversight of your MDR through an external CISO mandate or accompanies a parallel ISO 27001 implementation in which the SOC becomes a central Annex A building block. We complement this with penetration testing to measure detection quality in production. Speak with us via our contact form or request a quote for a SOC-aaS selection mandate.
