Skip to navigation Skip to search Skip to content
Contact

Leuchter IT Cyber Security Operations Center (SOC)

The Leuchter SOC monitors, analyzes, and responds to security incidents around the clock (24/7). We detect cyber threats early on and eliminate them before they pose a risk to your business.

A security analyst at the Cyber Security Operations Center monitors IT systems on multiple screens, focusing on threat detection, data protection, and real-time security analysis in Switzerland.

Why is a
Security Operations Center (SOC)?

 

The number of cyberattacks has risen sharply worldwide in recent years. With the use of AI, these attacks are also becoming increasingly sophisticated, targeted, and difficult to detect. Ransomware, data theft, and the disruption of digital services and business processes can cause significant economic damage. Reports of hacker attacks, data breaches, and new security vulnerabilities appear almost daily.

Cyberattacks don’t adhere to business hours. That’s why it’s necessary to monitor systems and security-related events around the clock. But how can a corporate network be comprehensively protected if there are no in-house IT security experts? And how can risks be assessed if potential threats aren’t detected in time?

To address this, Leuchter IT has established its own Security Operations Center (SOC). The SOC monitors your IT environment 24/7, detects and analyzes cyber threats early on, and immediately initiates the necessary measures. This allows security incidents to be contained effectively and minimizes potential damage to your company.

What is a Security Operations Center?

A Security Operations Center, or SOC for short, is a central department within a company. It is responsible for monitoring, analyzing, and responding to security incidents.

A SOC uses technology, established procedures, and the expertise of specialists to identify and respond to threats to information security. A SOC monitors networks and systems, analyzes incidents, responds to attacks, conducts audits, and provides guidance on security measures. The SOC is crucial for protecting against cyberattacks and data loss.

A SOC is crucial for maintaining information security in companies and organizations. This is particularly important because cyberattacks and data breaches are becoming increasingly common.

Icon graphic for a Cyber Security Operations Center featuring a user, a security lock, and analysis monitors, symbolizing real-time monitoring and IT security management in Switzerland.

Why choose Leuchter for the SOC
from Leuchter?


The Leuchter IT Cyber Security Operations Center complements your IT security department. It helps you comply with legal requirements. A security report documents this. Leuchter developed this service specifically for small and medium-sized enterprises (SMEs). The goal is to provide them with optimal support in the area of cybersecurity. Services include, among others:

Infographic on the Cyber Security Operations Center, featuring the four phases—Prevent, Detect, Investigate, and Respond—with a focus on security processes and threat management in Switzerland.

Proactive Monitoring of Endpoints, Identities, and Cloud Services

Implementation of defined measures to mitigate damage

Immediate Response to Critical Security Incidents

Ongoing refinement of the detection rules

24/7 Monitoring of Security-Related Events

Continuous Analysis and Prioritization of Alarms

Regular Security Audits and Security Reports

Personalized support from experienced security analysts

What Sets Us Apart


Leuchter IT Solutions AG operates the SOC itself around the clock. Our IT security experts continuously monitor, analyze, and evaluate your IT infrastructure. By applying insights gained from detection and prevention, we improve your cybersecurity over the long term. The result: We stop and eliminate future cyber threats to your business even faster.

The Benefits of Leuchter IT's Cyber Security Operations Center

Benefit from our IT security expertise and thereby improve your IT security posture in the long term.

Round-the-clock (24/7) monitoring and operation

Coverage even at night, on weekends, and on holidays

Rapid Assessment and Handling of Security Alarms

Clear escalation and response procedures

Proactive Detection of Malware, Attacks, and Vulnerabilities

Experienced security analysts without having to build your own team

Transparent safety reporting and traceable measures

Reducing potential downtime and consequential damage through early intervention

Keeping Up with the Times
with Microsoft Azure Sentinel

Leuchter SOC uses Microsoft Sentinel, a cloud-native SIEM solution for the centralized collection and analysis of security-related data. Microsoft Sentinel supports the detection, investigation, and response to threats with powerful analytics, automation, and threat intelligence.

This enables our security analysts to detect, classify, and respond to security incidents more quickly.

Azure_Sentinel with Office Banner _1200x600

You set the rules!


The Leuchter IT Cyber Security Operations Center allows you to define rules for customers and devices. This enables you to address individual needs and processes while ensuring the highest level of security. You also have access to a standard rule set with over 300 rules.

Depending on the rule, we check them every 15 minutes or at intervals of up to once a day. We define and evaluate the rules on a customer-specific basis. Starting with the Leuchter IT Cyber Security Operations Center Silver plan, we enable advanced queries to be executed thanks to Microsoft Sentinel.

Icon for a Cyber Security Operations Center featuring process symbols, access control, and an input form to illustrate security workflows and incident handling in Switzerland.

The Foundation of Leuchter IT
Cyber Security Operations Center


Our Leuchter IT Cyber Security Operations Center is based on four pillars:

  • Prevent

  • Detect

  • Investigate

  • Respond

We use state-of-the-art technologies and processes for proactive monitoring. Algorithms immediately detect and isolate known attack scenarios. Artificial intelligence ensures that suspicious applications and activities are identified and stopped.

As soon as an alert is triggered, our cybersecurity team analyzes the situation. It immediately takes all necessary measures to protect your corporate network.

A modern office with workstations and a SOC cycle diagram illustrating a Cyber Security Operations Center, with a focus on security monitoring and incident response in Switzerland.

1. Prevention

All potential risks to your business are identified through a series of assessments and transparently listed. The residual risk is reduced by implementing structured, recurring measures, which are listed below. This is fully in line with our motto: Prevention is more effective than reaction.

  • Antivirus protection and reducing the attack surface
  • Dedicated security and product updates
  • Threat and security risk management
  • Leuchter IT Security Compliance Checker
  • Leuchter IT Cyber Security Audits
  • Protecting Active Directory Security
An icon featuring a clipboard and checklist, symbolizing preventive security measures, IT risk analyses, and awareness planning in Switzerland.

2. Detection


The service logs security events across all relevant data sources, thereby providing comprehensive transparency and visibility. Thanks to advanced attack detection—nearly in real time—security analysts can effectively analyze and prioritize alerts, centrally isolate endpoints, and gain insight into the full scope of an incident to take action to mitigate threats.

In this phase, rules tailored to the customer also take effect and block network traffic on a case-by-case basis. Suspicious domains, files, URLs, and IP addresses identified through our own analyses and those of third-party providers are blocked immediately by default.

An icon featuring servers and a magnifying glass, symbolizing the detection of cyber threats, security incidents, and system anomalies in Swiss IT infrastructures.

3. Analyze (Investigate)


As soon as an alert is triggered, the SOC manager reviews the alert using a proven and standardized process. Experienced analysts ensure sound decision-making and continuous improvement throughout the entire detection and analysis process. This includes:

  • Assessment by the SOC analyst
  • Malware analysis, including isolating malware in a sandboxed environment and understanding the functionalities and capabilities of a compiled program (reverse engineering)
  • Extraction of threat intelligence
  • Assessment by experienced IT security analysts and interdisciplinary knowledge sharing
An icon featuring a microscope and an alarm bell, symbolizing the analysis of security incidents, log data, and threat intelligence in Swiss IT environments.

4. Mitigation (Respond)


In the event of an incident, our IT security analysts immediately initiate defensive measures and isolate the malware. A coordinated approach following defined process steps enables an exceptionally rapid response. Once the incident has been successfully contained, it is handed over to the responsible recovery team. Measures include:

  • Development of complex, multi-layered incident response plans (playbooks, runbooks, etc.)
  • Multi-stage process (containment – remediation – handoff to the recovery team)
  • SOC analysts initiate defensive measures
  • Crisis management and crisis communication
  • Integrated incident response management
An icon featuring a central shield and highlighted points of attack, symbolizing the elimination of cyber threats and vulnerabilities in Swiss IT networks.

Our Packages

The measures listed above (Prevent, Detect, Investigate, Response) are implemented in all of our packages.
The packages differ only in terms of the scope of services.


Decide for yourself how much cybersecurity your business needs. Choose from our Bronze, Silver, and Gold SOC packages.

  • Cybersecurity Operations Center

    STARTER

    • Annual Audit (Light)
    • Semiannual review of defined technical security requirements
    • Service availability up to 24/7 SOC monitoring
    • 30 incidents and damage mitigation per year
  • Cybersecurity Operations Center

    BRONZE

    • Annual Audit
    • Leuchter Custom Rules Basic
    • Leuchter IT Threat Intelligence Endpoint
    • Access to Historical Data
    • Semiannual review of defined technical security requirements

    • Service availability up to 24/7 SOC monitoring

    • 30 incidents and damage mitigation per year
  • Cybersecurity Operations Center

    SILVER

    • Device Discovery
    • Custom Detection Rules
    • Historical Logs and Analytics Data
    • Leuchter Custom Rules Advanced
    • Quarterly review of defined technical security requirements
    • Continuous logging of changes in Active Directory with weekly monitoring
    • User-based behavioral analysis
    • Sandbox analysis
    • Service availability up to 24/7 SOC monitoring
    • 60 incidents and damage mitigation per year
  • Cybersecurity Operations Center

    GOLD

    • Device Discovery
    • Custom Detection Rules
    • Semiannual Audit
    • Leuchter Custom Rules Advanced
    • Monthly review of defined technical security requirements
    • Continuous logging of changes in Active Directory with daily monitoring
    • User-Based Behavioral Analysis
    • Access to Microsoft experts as needed
    • Sandbox analysis
    • Service availability up to 24/7 SOC monitoring
    • 150 incidents and damage mitigation per year

 

Do you need more information?

 

Do you have questions about the services offered by our Security Operations Center? Or would you like advice on IT security? We look forward to getting to know you.

Articles on IT Security

Knowledge is power! Especially when it comes to preventing cyberattacks. So be sure to check out our blog.