



Your FortiGate firewall logged 2.4 million events last month. Your endpoint agents flagged 18,000 anomalies. Your cloud workloads triggered 900 alerts. And your security team investigated fewer than 200 of them.
This is not a staffing problem. It is a visibility problem — and it is the single biggest gap between Indian enterprises that detect breaches in hours and those that discover them months later in a media headline.
Security Information and Event Management (SIEM) was supposed to solve this. But poorly tuned SIEM deployments often make the problem worse: more alerts, more noise, more burnout. The difference lies in how you deploy it, what you correlate, and who is watching at 2 AM when the attack actually happens.
This guide explains how Indian enterprise CISOs can use FortiSIEM — and a 24/7 managed SOC — to finally close that visibility gap.
A 2025 industry survey of mid-to-large Indian enterprises found that the average organisation runs security tools from seven different vendors, generating logs in incompatible formats across on-premises data centres, AWS, Azure, and branch offices connected via SD-WAN. The result is a fragmented picture where no single analyst — or team — can stitch together an attack chain in real time.
The consequences are severe:
The answer is not more tools. It is smarter correlation through a purpose-built SIEM — and the human expertise to act on what it surfaces.
FortiSIEM is Fortinet’s enterprise SIEM platform, and it goes considerably further than log aggregation. Here is what matters for Indian enterprise deployments:
FortiSIEM automatically discovers and inventories every device on your network — servers, endpoints, IoT sensors, firewalls, switches, and cloud instances. It correlates identity (who), device (what), location (where), and behaviour (how) into a single context layer. When an alert fires, analysts immediately see the full asset profile: is this a finance workstation? A production server? A contractor’s laptop on guest Wi-Fi?
FortiSIEM ingests logs from over 700 device and application types — including FortiGate, FortiMail, Windows Active Directory, Linux syslog, AWS CloudTrail, Azure Monitor, Oracle databases, and SAP systems. It normalises all of them into a common schema, making cross-source correlation possible without custom parsers for every vendor.
For Indian enterprises running hybrid environments — a legacy data centre in Mumbai, cloud workloads in AWS Mumbai Region, and 40 branch offices — this heterogeneous ingestion is not a nice-to-have. It is essential.
Signature-based detection catches known malware. Behaviour-based detection catches attackers using legitimate tools (a technique called Living Off the Land, or LotL). FortiSIEM’s User and Entity Behaviour Analytics (UEBA) builds baselines for every user and device, then flags deviations:
Each of these behaviours alone might be innocent. FortiSIEM’s correlation rules chain them together — and when three anomalies from the same user appear within an hour, the system escalates automatically.
FortiSIEM connects to FortiGuard Threat Intelligence, Fortinet’s global threat research arm, which processes over 100 billion security events daily. Indicators of compromise (IOCs) — malicious IPs, domains, file hashes, URLs — are pushed to your FortiSIEM in real time and matched against your traffic logs. If an attacker’s command-and-control server has been flagged by FortiGuard in Tokyo, your Mumbai SIEM knows about it within minutes.
When FortiSIEM triggers a high-confidence alert, it automatically reconstructs the incident timeline: which asset was the initial entry point, what lateral movement occurred, which credentials were used, what data was accessed or exfiltrated. This is the capability that makes CERT-In’s 6-hour reporting window achievable — because your analysts are not spending the first four hours assembling log fragments by hand.
Since April 2022, CERT-In requires covered entities to report cybersecurity incidents within six hours of detection. The regulation is explicit: it covers ransomware, data breaches, unauthorised access, and targeted attacks. Failure to report carries penalties and — more damagingly — invites regulatory scrutiny of your entire security posture.
The challenge is that “within six hours of detection” assumes you can detect the incident with enough specificity to write a coherent report. Without a SIEM, most organisations spend those six hours still trying to understand what happened.
With FortiSIEM, the workflow changes fundamentally:
This is not a theoretical workflow. It requires three things working together: FortiSIEM’s correlation, a 24/7 SOC with trained analysts, and pre-defined playbooks for common incident types. The organisations that cannot meet the 6-hour window typically lack one or more of these.
India’s Digital Personal Data Protection Act (2023) requires data fiduciaries to implement “reasonable security safeguards” to prevent personal data breaches. The Act does not define a prescriptive technical standard — but regulators and courts will assess reasonableness against industry benchmarks. A SIEM is now part of that benchmark.
Specifically, your FortiSIEM deployment should be able to demonstrate:
Every access to systems storing personal data — customer databases, HR systems, CRM platforms — must be logged, and anomalous access must trigger alerts. FortiSIEM’s database activity monitoring and user behaviour analytics provide this capability, generating an audit trail that is admissible as evidence of due diligence.
FortiSIEM can monitor for large data transfers, unusual export activity, and bulk downloads from databases or file shares. When an employee downloads 50,000 customer records at 11 PM on a Friday, that event fires an alert — and the log is preserved in tamper-evident storage.
Logs must be retained for a defined period (typically 12 months under CERT-In guidelines, longer for regulated sectors). FortiSIEM provides encrypted, compressed log storage with integrity verification — so you can demonstrate to a DPDP adjudicating officer that logs have not been altered after the fact.
If a personal data breach occurs, you must notify the Data Protection Board and affected data principals. FortiSIEM’s automatic incident report generation provides the forensic foundation for that notification — timeline, scope, root cause, and affected data categories.
A poorly configured SIEM is worse than no SIEM — it creates false confidence while burying real threats under thousands of false positives. Here are the mistakes we see most often in Indian enterprise deployments:
Connecting every log source on day one is tempting. In practice, it overwhelms analysts and inflates licensing costs. Start with the highest-risk sources: domain controllers, FortiGate firewall logs, email gateway (FortiMail), VPN/ZTNA access logs, and your most sensitive application servers. Add sources in phases as your team develops the capacity to investigate them.
FortiSIEM ships with hundreds of out-of-the-box correlation rules. Many of them will generate false positives in your specific environment. A rule that flags “user login outside business hours” makes sense for a 9-to-5 finance company — it is useless for a 24/7 manufacturing plant. Spend the first 30 days tuning rules to your environment before going live with alerting.
FortiSIEM’s deepest value comes from tight integration with FortiGate NGFW. When FortiSIEM identifies a threat, it can push a block policy directly to FortiGate — isolating a compromised host in seconds rather than minutes. If your SIEM and your firewall are not integrated for automated response, you are leaving the most powerful capability on the table.
An alert that reaches a screen but triggers no defined response process is just expensive noise. Every alert tier should have a documented playbook: who gets paged, what the first three investigation steps are, when escalation occurs, and how containment is initiated. Without playbooks, your SOC analysts make inconsistent decisions under pressure — and attack dwell time increases.
Attackers do not respect business hours. The most sophisticated intrusions begin on Friday evenings and holiday weekends precisely because they know security teams are understaffed. A SIEM without 24/7 eyes-on-glass is a monitoring gap attackers actively exploit.
For most Indian enterprises — those with security teams of 5 to 50 people — the realistic answer is not to build a 24/7 in-house SOC. The economics do not work: three shifts of analysts, continuous training, attrition management, and tool licensing adds up to ₹3–5 crore annually before you factor in management overhead.
The alternative is a managed SIEM-as-a-service model: your FortiSIEM instance (on-premises or cloud-hosted) feeds alerts to a managed SOC that provides 24/7 analyst coverage, threat hunting, and incident response. You retain full access to your logs and dashboards. You own your data. But you do not have to staff a night shift.
This architecture delivers:
For a mid-sized Indian enterprise (500–5,000 employees, hybrid environment), here is a realistic deployment timeline:
FortiSIEM’s latest releases incorporate machine learning models for anomaly detection that go beyond static thresholds. Rather than flagging “more than 50 failed logins in 5 minutes” (a rule sophisticated attackers deliberately avoid triggering), ML models learn the pattern of legitimate failed-login bursts in your environment and alert on deviations from that learned pattern.
This matters because modern attackers — particularly nation-state actors and ransomware groups targeting Indian enterprises — deliberately operate below rule thresholds. They perform slow reconnaissance over days, not hours. They use valid credentials obtained via phishing. They move laterally using built-in Windows tools like PowerShell and WMI. Traditional correlation rules miss all of this. Behaviour-based ML models do not.
The caveat: ML models require data to learn from. A FortiSIEM instance deployed for fewer than 30 days does not have enough baseline data to make accurate ML detections. This is why the 90-day roadmap above front-loads the baseline collection period before enabling advanced detection rules.
PJ Networks has deployed and manages FortiSIEM environments across Indian enterprises in banking, manufacturing, healthcare, and professional services. Our managed SIEM service combines FortiSIEM’s platform with our 24/7 NOC/SOC operations, FortiGate-integrated response, and India-specific compliance reporting for DPDP and CERT-In.
We offer a no-obligation SIEM readiness assessment — a structured review of your current log coverage, alert fatigue levels, and compliance posture — that produces a gap analysis and a costed deployment roadmap. Whether you are starting your SIEM journey or looking to get more value from an existing deployment, the conversation starts with understanding where your visibility gaps actually are.
Reach out to the PJ Networks team to schedule your assessment. Your logs already contain the evidence of what is happening on your network. The question is whether anyone is reading them.