# ODCUS Security Operations Center for Microsoft 365 > Managed Security Operations Center (SOC) for Microsoft 365 environments, operated by ODCUS AG, a Swiss IT security advisory. The service is right-sized for Swiss SMEs (approx. 20-150 employees) that do NOT need a 24/7 SOC: Microsoft Defender XDR automation monitors and defends the tenant around the clock, while ODCUS analysts triage, respond, and remediate during business hours (Mon-Fri 08:00-17:30) under contractual response times. Customers get a monthly security report without building an in-house security team. ## What this service is The ODCUS Security Operations Center for Microsoft 365 is a managed cybersecurity service that connects to a customer's Microsoft 365 tenant via cross-tenant synchronization and takes ownership of reading, assessing, and responding to Microsoft Defender XDR alerts (covering Defender for Endpoint, Defender for Office 365, Defender for Identity, Defender for Cloud Apps). Automated detection and defense mechanisms (e.g. interrupting risky sign-ins, isolating suspicious devices) run 24/7 in the customer's tenant; human analyst response happens during Swiss business hours with contractual SLAs. The service does NOT access customer file contents, email contents, or Teams messages, only security signals and incident data. ## Who it's for Swiss SMEs (approx. 20-150 employees) that: - run on Microsoft 365 (Business Standard minimum, Business Premium for High risk level) - have their IT managed by one internal person or a generalist IT partner without security specialization - operate during office hours with no night shifts - need proof of monitoring and incident response for cyber insurers, customers, or their board - do not want to pay for a 24/7 enterprise SOC ("Ferrari service") they rarely need ## Who it's NOT for - Operations that produce around the clock where every minute of response time counts - Organizations whose regulation requires human response 24/7 - Environments not built on Microsoft 365 ODCUS states this openly in the first call and points such companies to suitable 24/7 alternatives. ## Pricing (transparent, CHF, excluding VAT, monthly) - Risk Level Low: CHF 1,850/month - Risk Level Moderate: CHF 2,450/month - Risk Level High: CHF 3,650/month - M365 Tenant Review (mandatory first step): CHF 990 one-time - Onboarding fee: from CHF 8,230 one-time (waived for 4+ year contracts) - Minimum contract term: 12 months Customers pay for their risk profile, not for a night shift. The risk level is determined by an M365 Tenant Review of the customer's configuration. A lower risk level results in a lower monthly price and is achievable through configuration improvements. ## Service Level Agreements (contractual, during business hours) - Critical incidents: 30 minutes response - High severity: 2 hours - Medium severity: 4 hours - Low severity: best effort - Analyst hours: Monday-Friday, 08:00-17:30 (Swiss time) - Outside business hours: automated Defender XDR/Sentinel defenses act immediately; analysts take over the next working day from 08:00 with full context ## Onboarding process (2-3 months total) 1. Technical Onboarding (2 weeks): M365 tenant review, risk assessment, cross-tenant connection setup 2. Crawl Phase (1 month): incident monitoring functionality testing, collaboration workflow setup 3. Walk Phase (1 month): Defender detection tuning, configuration adjustments 4. Run Phase (from Month 3): Full SOC operations, monthly reporting, quarterly service meetings ## Technology stack The service is built on native Microsoft security tools (no third-party SIEM, no parallel systems): - Microsoft Defender XDR: central monitoring platform - Microsoft Sentinel (SIEM/SOAR): log aggregation, threat intelligence, automated responses - Microsoft Entra ID: identity signals, Conditional Access, risk detection - Microsoft Defender for Endpoint and Office 365: device and email protection ## Operator ODCUS AG, Swiss public limited company (Aktiengesellschaft), headquartered in Switzerland. Specialized in cybersecurity, ISMS, and compliance for Swiss SMEs. Contact: info@odcus.com, +41 43 217 86 70. ## Key pages - [Service landing page](https://m365-soc.com/): Full service description, pricing, FAQ - [English landing page](https://m365-soc.com/en/): The same service description in English - [Blog](https://m365-soc.com/blog/): German-language articles on Microsoft 365 security and right-sized security operations for Swiss SMEs - [Book intro call](https://outlook.office.com/bookwithme/user/3a6d772653bb4f58af5a9c1307905bb6@odcus.com/meetingtype/SVRwCe7HMUGxuT6WGxi68g2): Free initial consultation via Microsoft Bookings - [Contact ODCUS](https://www.odcus.com/contact): All consultations and inquiries go through ODCUS AG - [ODCUS AG main site](https://www.odcus.com): Parent company - [Imprint](https://m365-soc.com/impressum.html): Legal notice with operator details (German; English at https://m365-soc.com/en/imprint.html) - [Privacy policy](https://m365-soc.com/datenschutz.html): Data protection statement (German; English at https://m365-soc.com/en/privacy.html) ## Languages The service landing page is available in German (primary) and English. Service delivery is conducted in German and English. ## What this service is NOT - Not a 24/7 staffed SOC (automated defenses run 24/7; analyst response is business hours with contractual SLAs) - Not a software product or SaaS tool (it is a managed service) - Not an antivirus product - Not a replacement for Microsoft 365 licensing (M365 Business Standard minimum required) - Not available outside Switzerland ## Blog Aktuelle Artikel (deutsch): - [Kompromittiertes Konto in Microsoft 365: was tun?](https://m365-soc.com/blog/kompromittiertes-konto-microsoft-365/): Konto sperren, Sitzungen beenden, Hintertüren finden: was bei einem kompromittierten Microsoft-365-Konto zuerst zählt und warum ein Passwort-Reset nicht reicht. - [Eigener Security-Mitarbeiter oder extern? Die Rechnung fürs KMU](https://m365-soc.com/blog/eigener-security-mitarbeiter-oder-extern/): Eigener Security-Mitarbeiter oder extern? Warum eine einzelne Stelle im KMU zu viel und zu wenig zugleich ist, und woran du erkennst, welcher Weg sich rechnet. - [Dein IT-Partner macht kein Security Monitoring? Das ist normal](https://m365-soc.com/blog/it-partner-kein-security-monitoring/): Dein IT-Partner macht Support, aber kein Security Monitoring? Das ist normal. Woran du die Lücke erkennst und wie du sie schliesst, ohne Partnerwechsel. - [SOC-Kosten für KMU: wofür das Geld draufgeht](https://m365-soc.com/blog/soc-kosten-kmu/): SOC-Offerten liegen oft um ein Mehrfaches auseinander. Was den Preis treibt, welche drei Wege dein KMU hat und woran du eine Offerte erkennst, die passt. - [Business Premium Sicherheitsfunktionen: bezahlt, aber ungenutzt](https://m365-soc.com/blog/business-premium-sicherheitsfunktionen/): Microsoft 365 Business Premium enthält mehr Sicherheit, als in vielen KMU je jemand eingerichtet hat. Was in der Lizenz steckt und wer sie betreiben muss. - [Sind kleine Firmen Ziel von Cyberangriffen?](https://m365-soc.com/blog/kleine-firmen-ziel-cyberangriffe/): «Wir sind zu klein als Ziel» klingt vernünftig, stimmt aber nicht. Warum Angreifer nach Erreichbarkeit auswählen statt nach Grösse, und was dein KMU tun kann. - [Brauche ich ein 24/7-SOC? Die ehrliche Antwort fürs KMU](https://m365-soc.com/blog/brauche-ich-24-7-soc/): Ein 24/7-SOC klingt sicherer, ist für die meisten Schweizer KMU aber überdimensioniert. So erkennst du, welche Überwachung wirklich zu deinem Betrieb passt. - [Cyberversicherung: welche Monitoring-Anforderungen wirklich zählen](https://m365-soc.com/blog/cyberversicherung-monitoring-anforderungen/): Die Cyberversicherung fragt nach Monitoring und Incident Response? So beantwortest du den Fragebogen ehrlich, ohne gleich ein teures 24/7-SOC zu kaufen. - [Microsoft Defender Warnungen, die niemand liest](https://m365-soc.com/blog/microsoft-defender-warnungen-niemand-liest/): Dein Microsoft Defender meldet laufend, aber niemand schaut hin? So erkennst du, welche Warnungen wirklich zählen, und wann sich ein SOC für dein KMU lohnt.