New Delhi · Operating since 2002
Every managed provider says its people are its greatest asset. The claim worth testing is narrower and much easier to check: are the analysts employed here, and are there enough of them to actually cover the hours being sold?
The second half of that is arithmetic, and it is set out below. It is the same sum that tells you whether building your own operations floor makes financial sense — which is why it is on this page rather than hidden in a proposal.
The arithmetic
Why round-the-clock cover costs about five people per seat
A week has 168 hours. An engineer works about forty of them. Everything else follows from those two numbers.
The soft number is the cover factor. 168 and 40 are facts; the multiplier for leave, training, sickness and attrition is an assumption, and a generous employer’s is higher than a thin one’s. It is flagged here rather than buried because it is the figure a provider would quietly shrink to make a rota look adequate on paper.
Structure
The tiers, and which one gets quietly outsourced
Three analyst tiers, two functions, and one of the four below is where shortcuts are least visible from the outside.
L1 · Monitoring and triage
Works the queue, applies the runbook, decides what is noise and what goes up. The tier most often outsourced by providers who describe themselves as in-house, and the tier where a shortcut is least visible from outside.
L2 · Investigation
Takes what L1 escalates and establishes what actually happened — scope, entry, what else the attacker touched. This is where an incident is either understood or merely closed.
L3 · Specialists and engineering
Forensics, malware analysis, detection engineering and hunting. Cannot be kept sharp by a single estate, which is precisely why the shared model exists.
NOC · Network operations
Link state, capacity, device health and configuration. Separate people from the SOC, with separate measures, because under pressure a combined team has one set of targets and the targets decide the answer.
Leadership
Who you deal with
The commercial and delivery leadership. The engineers above sit behind them.
Sanjay Seth
Founder and CEO
Founded the company in 2002 and still takes escalations. The address on every page of this site reaches him directly.
Dinesh Jain
Chief Financial Officer
Commercial structure and contracting, including the multi-year terms that managed services are bought on.
Israfil Ansari
Director, Cyber Security
Owns the security practice — detection, response and the standards the SOC operates to.
Vikas Mishra
Director, Sales
Enterprise accounts, largely infrastructure and firewall estates.
Jahnavi Seth
Director, Sales
Commercial terms and scoping, including saying when a smaller engagement is the right one.
Deepak Gupta
Director, Services
Delivery across managed engagements — the transition from signature to steady state.
Sunny Nagrath
Head, Government and GeM
Public-sector engagements and GeM procurement, which runs to its own rules and timelines.
Credentials
What the team holds, and what the company holds
Held by individuals
CISSP CISM CEH CompTIA Security+
Fortinet NSE Cisco Dell
Vendor-neutral credentials show someone understands the discipline; vendor certifications show they can operate a specific product. Both are useful and they are not interchangeable, though they are routinely quoted as if they were.
Held by the company
ISO/IEC 27001:2022, with a certified scope covering our NOC and SOC operations in New Delhi.
This is the one that matters more, because individuals leave and a certification of how the operation runs does not leave with them. When comparing providers, ask whether the certified scope reaches the operations floor or stops at a registered office — the difference is substantial and almost never advertised.
Commitments
Four things worth holding us to
Employed here, not subcontracted
Subcontracting analyst tiers is common in this market and rarely volunteered until it surfaces during an incident. Ask any provider — including us — who employs the person who would answer at 3 a.m., and whether that answer changes at night or at weekends.
Separate NOC and SOC rotas
The two functions have different people and different measures. A single team wearing both hats has one set of targets, and when a signal is ambiguous the targets decide which explanation gets tested. See about us for why that distinction is the whole argument.
Someone is allowed to say “stay down”
A named analyst can hold a system offline while scope is established, and is not measured on uptime. Without that authority the decision defaults to whoever is shouting loudest, which is everybody.
Certifications that are individual, not corporate
The credentials below are held by people, and people leave. That is why the ISO/IEC 27001:2022 certification matters more than any individual certificate — it covers how the operation runs regardless of who is on shift this week.
Questions we get asked
Our team, answered
Are your analysts employed by you, or subcontracted?
Employed here. It is worth asking every provider directly and specifically about nights and weekends, because subcontracting the out-of-hours tier while describing the service as in-house is common and is almost never volunteered. The question that gets a straight answer is: who employs the person who would pick up at 3 a.m., and does that change at the weekend?
How many people are in the NOC and SOC?
More than fifty engineers across both functions. The diagram on this page shows why that is roughly the floor rather than a boast: covering one seat around the clock takes about five people once leave, training and attrition cover are included, and six seats — three tiers across two functions — is about thirty before a single specialist is hired.
What certifications does the team hold?
Vendor-neutral credentials including CISSP, CISM, CEH, CompTIA Security+, alongside vendor certifications including Fortinet NSE, Cisco, Dell. The distinction matters: a vendor certificate proves someone can operate a product, and a vendor-neutral one proves they understand the discipline. Buyers routinely conflate the two.
Does the company hold a certification, or just the individuals?
Both, and the company one matters more. Individuals hold their own credentials and individuals leave. P J Networks holds ISO/IEC 27001:2022, and the certified scope covers the NOC and SOC operations in New Delhi rather than stopping at the head office — a distinction worth checking with any provider, because it is rarely advertised and frequently narrow.
Who would we actually deal with day to day?
A named delivery contact from the services side, with the security practice behind them. Escalation paths are agreed in writing at the start of an engagement rather than discovered during an incident, and they name people rather than queues.
Are the analysts based in India?
Yes, the operations floor is in New Delhi, and the analysts are not US-based. Providers are sometimes vague about this and it is the kind of thing that collapses in due diligence rather than in the sales cycle, so we state it rather than leave it to be inferred.
What happens when someone leaves?
Runbooks, detection content and escalation paths are written down and owned by the company, not carried in an individual’s head. That is the practical reason process documentation matters more than any single hire, and it is what the ISO certification is largely about.
Can we meet the team before signing?
Yes, and we would encourage it for anything beyond a small engagement. Ask to speak to the people who would actually run your account rather than only the commercial team — the difference between those two conversations is informative in itself.
Next step
Ask to speak to the people who would run your account
Not only the commercial team. The difference between those two conversations tells you more about a provider than any capability document, and we are happy to arrange the second one before anything is signed.
Related
Also part of the firewall lifecycle: virtual CISO services.



