SOC as a Service (SOCaaS) in India — 24×7 Managed SOC

  • Home
  • SOC as a Service (SOCaaS) in India — 24×7 Managed SOC

Delhi NCR · Operating since 2002

SOC as a ServiceA full security operations centre — analysts, platform and a 24×7 roster — rented instead of built

SOC as a Service (SOCaaS) is a security operations centre delivered as a subscription. You get the L1, L2 and L3 analysts, the SIEM, the threat intelligence and the round-the-clock roster for a monthly fee, and what arrives at your desk is an investigated incident rather than a queue of raw alerts.

This page explains the model honestly: what it includes, how it differs from MDR and from a traditional MSSP, what the delivery variants actually mean, what it costs against the in-house alternative, and which questions separate a real provider from a reseller with a dashboard. If you already know you want a provider and are comparing vendors, our SOC services page covers our own SLA and tiering.

3K+
Projects delivered
1,000+
Enterprises protected
50+
In-house NOC & SOC experts
24+
Years, since 2002
ISO/IEC 27001:2022
Certified — SOC in scope

The definition

What SOC as a Service actually means

SOCaaS stands for Security Operations Centre as a Service. The acronym follows SaaS and IaaS: the capability is consumed rather than owned, and it sits inside the wider Security as a Service model alongside the identity, email, endpoint and network layers. In Indian tenders you will also see it written SOC-as-a-Service, and the phrases “managed SOC” and “outsourced SOC” are used to mean the same thing.

A security operations centre is the team and tooling that watches your estate continuously, decides which of the day’s events are actually an attack, and does something about the ones that are. Built in-house it is three tiers of analyst, a SIEM, threat intelligence feeds and a roster that covers nights, weekends and public holidays. Bought as a service, it is the same function on somebody else’s payroll, shared across many customers — which is precisely why the rare skills become affordable.

The economics are the whole argument. A reverse engineer or forensics specialist cannot be kept busy, sharp or interested by a single mid-sized estate, but can be across thirty. That is not a sales line; it is the reason the model exists.

A word on the acronym. If you arrived here searching for “SOC compliance”, “SOC 1” or “SOC 2”, you may want something else entirely. Those refer to AICPA Service Organization Control reports — audit attestations issued by a CPA firm about a service organisation’s controls. A Security Operations Centre is an operational team that detects and responds to attacks. The two are connected only in that good monitoring produces the evidence that makes such an audit survivable. If you need the report, you need an auditor; if you need someone watching at 3 a.m., read on.

The comparison everyone asks for

SOCaaS vs MDR vs MSSP vs in-house vs co-managed

These five labels overlap, and vendors blur them on purpose. Here is the distinction we would give a client across a table, including the limitation of each — the column most comparison charts leave out.

Scroll the table sideways →

Model What you actually buy Who owns the tooling Response included? Typical buyer The honest limitation
SOC as a ServiceSOCaaS A complete security operations function — L1/L2/L3 analysts, SIEM, threat intelligence and a 24×7 roster — rented rather than built. The provider Detection and investigation always; containment depends on the contract — read it. Mid-market and enterprise with no SOC, or one that only works in office hours. Breadth means the provider must learn your estate. Expect a real onboarding period, not a switch-flip.
Managed Detection & ResponseMDR Detection and active response, usually anchored on endpoint telemetry, with the provider empowered to contain. The provider, and usually their chosen stack Yes — response is the product. Organisations whose main risk is endpoint and identity compromise. Narrower telemetry. Strong on endpoints, weaker on network, OT and the long tail of application logs.
Managed Security Service ProviderMSSP Operation of security devices — firewalls, gateways, VPN — often with monitoring bundled alongside. You typically own the licences Varies widely. Frequently alerting only. Estates with a lot of security hardware to keep healthy and patched. “Monitoring” in an MSSP contract can mean device uptime, not threat detection. Ask which one you are buying.
In-house SOC Your own analysts, your own SIEM, your own playbooks and your own roster. You Yes, and entirely on you. Large regulated institutions with the headcount to sustain three tiers. The binding constraint is people, not tooling. L3 skills are hard to hire, hard to keep busy and harder to retain.
Co-managed SOC You keep the platform and daytime team; the provider adds nights, weekends and the specialist tiers. Shared — usually your SIEM, their analysts Split by an agreed escalation matrix. Teams with a working day-shift SOC and no realistic path to 24×7. Only works if the handover is written down. Ambiguous ownership at 3 a.m. is how incidents get dropped.

If you take one thing from this table, make it the response column. The single most common disappointment in this market is an organisation that believed it had bought containment and had in fact bought notification. It is a contractual question, not a technical one, and it is answerable in one sentence before you sign.

Delivery models

Choosing between fully managed, co-managed, hybrid and virtual

These four labels describe who does what, not four different products — so the honest way to choose is to start from what your team already covers, not from a brochure. Find your row.

Scroll the table sideways →

Your starting point The model that fits Who does what The catch
No SOC today, and no appetite to build one Fully managedmost common We supply the platform, the analysts and the 24×7 roster. What reaches you is an investigated incident with a named escalation path, never a queue of raw alerts. Onboarding is real work — we have to learn your estate before detections are trustworthy. Distrust any provider who calls it a switch-flip.
A working SIEM and a competent day shift, but no realistic path to nights and weekends Co-managed You keep the console, the licence and the day team; we take nights, weekends, public holidays and the specialist L3 work. It only works if the escalation matrix is written down before go-live. Ambiguous ownership at 3 a.m. is how incidents get dropped.
A strong internal team with deep context on the crown-jewel applications Hybrid Your team holds the systems only they understand; we hold the perimeter, the branch estate and the cloud. Splitting by estate needs disciplined handovers wherever the two halves interact — an attacker does not respect your org chart.
Comfortable outsourcing, but asking “where physically is this SOC?” Virtual SOC The same tiers and tooling, with the desks in our Delhi NCR facility instead of a room on your premises. The phrase describes geography, not scope. Confirm the tiering and roster are unchanged before accepting the label.

These are staffing arrangements, and each is quoted against your estate rather than off a rate card. The commercial half of the decision — the pricing units that actually appear on Indian quotes, and the RFP questions that expose a thin offering — is covered in depth on our managed SOC services page.

Coverage

What a SOCaaS engagement actually monitors

Detection quality is decided by what you feed the platform. An estate monitored only at the firewall will miss the identity attacks that now start most breaches, which is why coverage breadth matters more than detection cleverness.

Network & perimeter

Firewalls, IPS, VPN concentrators, routers and switches — Fortinet, Cisco, Palo Alto, Sophos and the rest of a real mixed estate.

Endpoints & servers

EDR telemetry, Windows and Linux event logs, privileged account use and lateral movement between segments.

Cloud & SaaS

AWS CloudTrail, Azure and Microsoft 365 sign-in and audit logs, GCP, and the identity provider that ties them together.

Identity

Directory changes, MFA fatigue and push-bombing patterns, impossible-travel sign-ins and privilege escalation.

Applications & data

Web application firewalls, database audit trails, file integrity and the data-exfiltration paths that matter to DPDP.

Email

The channel most incidents still start in — phishing, business email compromise and malicious attachments.

Our platform work sits behind this: managed SIEM for collection and correlation, SOAR for the repeatable response steps, network monitoring where availability and security overlap, NOC as a service where we run that watch for you, and PrahiX Ora — built by PrahiX — where a customer wants the whole stack from one place. Estates with industrial systems are covered under OT security.

India, specifically

What Indian regulators require of an outsourced SOC

This is where most global SOCaaS material stops being useful. Indian obligations are specific, they name the SOC directly, and several of them explicitly contemplate outsourcing.

SEBI — CSCRF

The Cyber Security and Cyber Resilience Framework, issued 20 August 2024, mandates a SOC for almost every regulated entity and then lets you choose the model: your own or your group’s SOC, the Market SOC operated by the exchanges and depositories, or any third-party managed SOC. Small-size and self-certification entities are directed onto the Market SOC. On ISO 27001, the position moved: the June 2025 FAQ requires third parties to be certified for the services outsourced to them, but a technical clarification of 28 August 2025 made certification recommended rather than mandatory for Qualified REs. It stays mandatory for market infrastructure institutions.

RBI — C-SOC

The Cyber Security Framework requires a Cyber Security Operation Centre under the CISO, and Annex-2 sets out the L1, L2 and L3 tier structure directly. The same annex candidly lists why banks struggle to run one: specialist skills, hiring difficulty, expensive training, compensation design and retention.

CERT-In — the six-hour clock

Specified incidents must be reported within six hours of being noticed, and security logs retained for a rolling 180 days within Indian jurisdiction. The trigger is noticing, not confirming — which makes the deadline a detection problem before it is a paperwork problem. We map every Indian deadline in the six-hour clock.

Sector obligations layer on top of these: IRDAI for insurers, the Telecommunications (Telecom Cyber Security) Rules 2024 for telecom, and the DPDP Act 2023 for personal data across all of them. Our compliance services page maps the reporting and retention requirements to their instruments.

Money

What SOC as a Service costs, and the number to compare it against

Almost nobody in this market publishes a price, ourselves included, because the figure genuinely depends on log volume, monitored asset count and whether you are buying monitoring alone or monitoring with response. What we can do is publish the other side of the equation honestly, so you can do the arithmetic yourself before anyone quotes you.

Why in-house only pays at scaleShapes follow the staffing arithmetic. The crossing point is not a fixed number.Estate size —→Annual cost —→OutsourcedBuilt in-housecrossover~30 people beforea single specialistThe in-house line starts high because a 24×7 rota costs the same floor whether you are 200 people or 2,000.

The shapes come from the staffing arithmetic rather than a price list. Where exactly the lines cross depends on salaries and estate complexity, so treat the crossing as a region rather than a number.

What 24×7 actually costs to staff

Start with the arithmetic rather than the sales pitch. Covering a single seat continuously is 8,760 console-hours a year. An analyst on a 45-hour week, after annual leave, public holidays, casual and sick leave and a modest allowance for training, delivers roughly 1,900 productive hours. That is about 4.6 people to keep one chair occupied around the clock — so you hire five or six to survive one resignation. Two concurrent seats, the realistic minimum for genuine triage rather than alarm-watching, lands near ten or eleven people before a single specialist is hired.

ONE SEAT, COVERED CONTINUOUSLY8,760 hours a year365 × 24WHAT ONE ANALYST ACTUALLY DELIVERS2,340 h gross1,900 hProductive324 h leave & holidays · 117 h training8,760÷1,900=4.6full-time equivalentsto keep one chair occupied — hire 5–6 to survive one resignationArithmetic on a 45-hour week with 36 days of leave and public holidays. Adjust to your own terms and the shape barely moves.

Scroll the table sideways →

Role Median annual CTC Typical range Sample size
SOC analyst (L1) ₹5.5 L ₹3.8 L – ₹7.9 L 11,858
SOC analyst 2 ₹10.0 L ₹5.0 L – ₹15.3 L 1,100
Senior SOC analyst ₹10.2 L ₹5.7 L – ₹17.0 L 679
Threat intelligence analyst ₹10.6 L ₹4.3 L – ₹22.0 L 124
Malware analyst ₹8.5 L ₹3.2 L – ₹15.4 L 157
Incident response analyst ₹8.3 L ₹3.0 L – ₹16.0 L 239
Security operations manager ₹22.3 L ₹5.5 L – ₹38.0 L 258

Indian market medians from AmbitionBox role pages, reviewed July 2026, shown with sample sizes so you can see which rows are solid. We have left out roles where the sample was too thin to stand behind. A credible minimum three-tier roster — eight L1, four L2, two L3, a detection engineer and a manager — comes to roughly ₹1.4 crore in base salary, before recruitment, facilities, backfill and training loading.

Then the platform on top

SIEM licensing is the second line and it scales with data, not headcount. As a public reference point, Microsoft Sentinel in the Central India region lists at ₹568.25 per GB for analytics-tier ingestion, with Log Analytics ingestion charged separately at ₹303.95 per GB and retention beyond the free period at ₹13.22 per GB per month. A hundred-gigabyte-a-day commitment tier lists at ₹39,117 per day.

Add threat-intelligence subscriptions, which almost no vendor prices publicly, and the twelve to eighteen months it typically takes before detections are trustworthy rather than merely noisy.

The retention problem, in numbers

The figure that should worry a CISO is not salary but tenure. Across 11,858 Indian SOC analyst records, the population peaks at three to four years of experience and then collapses by roughly 91 per cent by the five-to-six-year band. Median pay for the role has been effectively flat in nominal terms across 2024, 2025 and 2026 — a real-terms cut against inflation, in a job people leave by year five.

Read that as a tenure distribution rather than a measured attrition rate — it mixes people leaving the profession with people promoted out of the title. We are not going to publish an attrition percentage, because we could not source one we would stand behind. The operational point stands regardless: almost nobody is still an L1 analyst at year six, and your roster has to absorb that.

Where the crossover sits

Below roughly fifteen to twenty monitored servers, outsourcing wins on cost alone and it is not close — you cannot buy 4.6 full-time equivalents of coverage for less than the floor above. As the estate grows the two converge, and the decision stops being about price at all. It becomes whether you can actually sustain the night shift, whether your one SIEM engineer is a single point of failure, and what happens to your detection coverage the week they resign. At genuine scale the honest answer is often hybrid: keep detection engineering and the specialist tiers in-house, and buy the round-the-clock L1 cover.

We will scope your estate and give you a specific monthly figure with this comparison beside it, rather than a wide range designed to open a negotiation. The full breakdown of what moves an Indian SOCaaS quote — pricing units, platform components, retention and the year-two costs — is in our guide to SOC as a Service pricing in India.

Before you sign

Eight questions that separate a SOC from a dashboard

Useful in an RFP, and useful on a first call. We would rather you asked us these than found the answers out during an incident — and if a competitor answers them better than we do, that is worth knowing too. A longer set, aimed at telling providers apart rather than at testing this model, is in our guide to SOC service providers in India.

Scope

Which log sources are in the price, and what does adding one cost?

Most disputes start here. Get the included source list in the contract, with the unit price for additions.

Response

Does the SLA measure time-to-alert, or time-to-verified-incident?

An alert inside sixty seconds is meaningless if a human confirms it four hours later. Insist the clock ends at human verification.

Authority

Can the provider contain — isolate a host, disable an account — without waiting for you?

If the answer is no, you have bought monitoring. That may be the right choice, but decide it deliberately.

Tiers

Are L2 and L3 dedicated, shared, or subcontracted?

Ask where the analysts physically sit and who employs them. Subcontracting is common and rarely volunteered.

Retention

Where are logs stored, and for how long?

CERT-In requires 180 rolling days inside Indian jurisdiction. Confirm the region, not just the duration.

Certification

Does the ISO 27001 certificate cover the SOC, or only head office?

Many certificates are scoped to a corporate function and nothing more. Read the scope statement rather than the logo — and if you are a SEBI-regulated entity, note that the certification requirement is mandatory for market infrastructure institutions but was downgraded to recommended for Qualified REs in August 2025.

Exit

On termination, do you get your historical logs and detection content back, and in what format?

Ask before signing. Extraction after a relationship sours is expensive and slow.

Evidence

What does the monthly report actually contain?

Ask for a real redacted sample. “Executive dashboard” often means a pie chart of alert volumes and nothing an auditor can use.

Depth

How many alerts does one analyst actually investigate per shift?

The number nobody volunteers. A desk triaging many hundreds a shift is pattern-matching, not investigating, and the difference shows up precisely on the alert that mattered.

Transparency

Can you see the investigation, or only the verdict?

Ask whether you get the reasoning — what was checked, what was ruled out — or a closed ticket saying “benign”. If you cannot audit how a conclusion was reached, you cannot challenge it or learn from it.

Detections

Who writes detections specific to our environment, and how quickly?

Generic detection content catches generic attacks. Ask who tunes rules for your applications and business processes, what the turnaround is for a new detection, and whether that work costs extra.

Metrics

What are your mean time to detect and to respond, and how are they measured?

Most providers quote MTTD and MTTR; few define the start and stop points. A figure measured from alert generation rather than from initial compromise flatters the provider and tells you very little.

Straight answers

What people get wrong about outsourced SOCs

Myth

“SOCaaS and MDR are the same thing”

They overlap and vendors blur them deliberately. The useful distinction is breadth versus depth: MDR is built around endpoint and identity telemetry with response included, while SOCaaS is a broader operations function across network, cloud, identity and applications. If your risk is ransomware on laptops, MDR may be enough. If you have OT, branch networks or a compliance obligation across the estate, it is not.

Myth

“Outsourcing the SOC breaks compliance”

The opposite, if anything. SEBI’s CSCRF mandates a SOC for almost every regulated entity and then lets you choose the model: your own or your group’s SOC, the Market SOC operated by the exchanges and depositories, or any third-party managed SOC. Small-size and self-certification entities are directed onto the Market SOC. The RBI requires a C-SOC under the CISO but does not require you to staff it yourself. Outsourcing is a sanctioned model, not a workaround.

Fact

The reporting clock starts at “noticing”

CERT-In’s six-hour window runs from when the incident is noticed or brought to your notice — not from when you confirm it. Finding out on day nine from a customer does not buy grace; it means you have already failed and now have six hours. Reporting deadlines are a detection problem first.

Myth

“Our analysts must be in India for compliance”

The residency rule is about where the logs live, not where the analysts sit. CERT-In requires 180 days of logs within Indian jurisdiction. SEBI goes further in the other direction: its framework expressly exempts IT and cyber-security data sent to a global or international SOC from data-localisation, subject to annual IT Committee review and Board approval. Our analysts are in Delhi NCR, which helps context and response time — we are not going to tell you it is a legal requirement, because it is not.

Myth

“SOC compliance” means a security operations centre

Usually it does not. In most Indian RFPs “SOC 1”, “SOC 2” and “SOC report” refer to AICPA Service Organization Control audits — an attestation performed by a CPA firm about a service organisation’s controls. That is a different product from a security operations centre. If you need SOC 2, you need an auditor. We can give you the monitoring and evidence that makes the audit survivable.

Fact

L1, L2 and L3 are the regulator’s words

The tier model is not vendor jargon. Annex-2 of the RBI’s Cyber Security Framework describes Level 1 monitoring by trained staff round the clock, Level 2 investigation by specialists, and Level 3 work covering deep packet analysis, IOC collection, forensics and malware reverse engineering.

Myth

“A SIEM is a SOC”

A SIEM is a tool; a SOC is a function. Buying a SIEM licence gives you a system that collects and correlates logs and produces alerts — it does not give you anyone to read them at 2 a.m., decide which matter, or act. This is the single most expensive misunderstanding in the market: shelfware SIEMs bought as compliance evidence, generating alerts nobody triages. Our managed SIEM page covers running the platform; this page covers running the function.

Myth

“AI has made SOC analysts unnecessary”

AI has genuinely changed the first tier. Machine-led triage now discards a large share of routine noise and clusters related alerts, and any modern SOC that is not using it is wasting analyst hours. What it has not done is remove judgement: deciding whether unusual behaviour on a finance server at midnight is a compromise or an overworked accountant still requires context about your business. Treat “AI-driven SOC” as a claim about efficiency, not about headcount — and ask what happens after the model flags something.

P J Networks

Why buy this from us

We have been doing network and security operations in Delhi NCR since 2002, which is long enough to have run the in-house version of this argument for clients on both sides of it.

Our own analysts

Fifty-plus in-house NOC and SOC engineers in Delhi NCR. Ask us who sits in which tier and we will tell you — the same question we suggest you put to everyone else you shortlist. The specialist tier also runs hypothesis-led threat hunting across the estates we monitor.

Multi-vendor by default

Real estates are mixed. We monitor Fortinet, Cisco, Dell, Palo Alto and Sophos alongside cloud and identity telemetry — see our technology partners. Evaluating Fortinet’s own bundled offering instead? We have written an honest assessment of Fortinet SOCaaS, including where it fits and where it does not.

Audit-ready

ISO/IEC 27001:2022 certified with the SOC inside the certified scope, and retention and reporting aligned to CERT-In, RBI, SEBI and DPDP from the start rather than assembled before an audit.

P J Networks 24x7 security operations centre in Delhi NCR, where SOC as a Service engagements are monitored and escalated
Our SOC, Delhi NCR
3K+
Projects delivered
1,000+
Enterprises protected
50+
In-house NOC & SOC experts
24+
Years, since 2002
ISO/IEC 27001:2022
Certified — SOC in scope

Questions we get asked

SOC as a Service, answered

What is SOC as a Service?

SOC as a Service is a security operations centre delivered as a subscription instead of built in-house. The provider supplies the L1, L2 and L3 analysts, the SIEM platform, the threat intelligence and the 24x7x365 roster; you receive detected, investigated and escalated incidents for a predictable monthly fee. It is the same function a large bank builds internally, sized and priced for organisations that cannot justify eight to twelve analysts of their own.

What does SOCaaS stand for?

SOCaaS stands for Security Operations Centre as a Service, and is also written SOC-as-a-Service or SOC as a Service. The acronym follows the same pattern as SaaS and IaaS: the capability is consumed as a service rather than owned. In India the terms “managed SOC”, “outsourced SOC” and “SOCaaS” are used more or less interchangeably in tenders.

What is the difference between SOC as a Service and MDR?

Breadth versus depth. MDR (Managed Detection and Response) is built around endpoint and identity telemetry and includes active containment as a core part of the product. SOCaaS is a wider operations function covering network, cloud, identity, applications and email, with response scope set by contract. Many buyers need MDR’s response authority and SOCaaS’s coverage, which is why the two increasingly overlap — but if a provider will not tell you which telemetry they actually ingest, that is the question to press.

Is managed SOC the same as SOC as a Service?

In practice, yes. “Managed SOC”, “outsourced SOC” and “SOC as a Service” describe the same commercial model and are used interchangeably in the Indian market. Where a genuine difference exists it is usually co-management: some “managed SOC” contracts run on the customer’s own SIEM licence, while SOCaaS more often includes the platform. Check which one you are being quoted.

What is the difference between SOCaaS and an MSSP?

An MSSP traditionally operates security devices — keeping firewalls, gateways and VPNs configured, patched and healthy — and may add monitoring on top. SOCaaS is specifically the detection and investigation function. The trap is the word “monitoring”: in many MSSP contracts it means device availability monitoring, not threat detection. Ask explicitly whether you are buying uptime or detection.

How much does SOC as a Service cost in India?

There is no single figure, and any provider quoting one before seeing your estate is guessing. Price follows log volume, the number of monitored assets, and whether you are buying monitoring only or monitoring with response. The useful comparison is against the alternative: genuine 24x7x365 shift cover needs roughly eight to twelve analysts once leave, weekly offs and attrition are accounted for, plus SIEM licensing and threat-intelligence subscriptions, and typically twelve to eighteen months before detections are reliable. Below roughly fifteen to twenty monitored servers, outsourcing wins on cost alone; above that the deciding factors become coverage and retention rather than price. The cost drivers are broken down line by line in our SOC as a Service pricing guide for India. We will scope your estate and give you a specific monthly figure with the in-house comparison beside it.

What is a co-managed SOC?

A co-managed SOC splits the function between your team and a provider. Typically you keep the SIEM platform and the day shift, and the provider covers nights, weekends, public holidays and the specialist L3 work such as forensics and malware analysis. It suits organisations that already have a working day-shift capability but no realistic path to staffing 24×7. It only works when the escalation matrix — who owns what, at what hour, with what authority — is agreed in writing before go-live.

What is a virtual SOC?

A virtual SOC has no physical operations room on your premises. The analysts work from the provider’s facility against your telemetry, using the same tooling and tiering as an on-site SOC. The term describes where the desks are, not a reduction in the function. Ours is a staffed facility in Delhi NCR.

Can a SEBI or RBI regulated entity outsource its SOC?

Yes. SEBI’s Cyber Security and Cyber Resilience Framework mandates a SOC for almost every regulated entity and then offers three models: the entity’s own or group SOC, the Market SOC operated by the exchanges and depositories, or any third-party managed SOC. Small-size and self-certification entities are directed onto the Market SOC. The RBI requires a Cyber Security Operation Centre under the CISO but does not require you to staff it yourself. On certification, be precise about the current position rather than the headline: SEBI’s CSCRF FAQ of June 2025 states that where services are outsourced the third-party provider must itself be ISO 27001 certified for those services, with the SOC inside the certified scope — but a technical clarification issued on 28 August 2025 made ISO 27001 “encouraged and recommended (not mandatory)” for Qualified REs, leaving it mandatory for market infrastructure institutions. P J Networks is certified to ISO/IEC 27001:2022 with our SOC operations inside the certified scope, so the distinction does not affect us either way, and the scope statement is available on request.

Do our logs stay in India?

Yes. CERT-In requires security logs to be retained for a rolling 180 days within Indian jurisdiction, and we retain them accordingly by default. It is worth separating two things that are often conflated: the residency requirement is about where the data sits, not where the analysts sit. SEBI’s framework goes as far as exempting IT and cyber-security data sent to a global or international SOC from data-localisation, subject to annual IT Committee review and Board approval. Our analysts happen to be in Delhi NCR, which helps response time and context — but that is an operational advantage, not a legal obligation.

Is “SOC compliance” the same as a security operations centre?

Usually not, and the ambiguity causes real confusion in Indian tenders. SOC 1 and SOC 2 refer to AICPA Service Organization Control reports — audit attestations produced by a CPA firm about a service organisation’s controls. A Security Operations Centre is an operational team that detects and responds to attacks. If your customer is asking for a SOC 2 report you need an audit firm; if they are asking for 24×7 monitoring you need this page. The two are related only insofar as good monitoring produces evidence that makes an audit easier.

Can you monitor the SIEM we already own?

Yes, and it is a common arrangement. We operate FortiSIEM and our own PrahiX Ora platform, and we also take over monitoring on a SIEM you have already licensed. We audit the inherited rule set first, because platforms that have run without a dedicated team almost always have detections nobody has reviewed in a year and log sources that stopped reporting without anyone noticing.

How long does onboarding take?

For a typical mid-market estate, first log sources are ingested within days and meaningful detection coverage is in place within four to six weeks. The honest constraint is not integration speed but tuning: a SIEM that has just been pointed at your network produces a great deal of noise, and the value comes from the weeks of baselining that follow. Any provider promising reliable detection on day one is describing alerting, not detection.

What happens when you find something at 3 a.m.?

An L2 analyst validates the alert and opens the case, and for a P1 you get a phone call — not an email into a shared mailbox. What happens next depends on the authority you have granted us in the contract: monitoring-only means we advise and you act, while full response means we contain first and tell you immediately. We would rather agree that boundary at contract stage than debate it during an incident.

Next step

Find out what your estate would actually cost to monitor

We will scope your log sources and monitored assets, quote a specific monthly figure, and put the in-house comparison next to it. If building it yourself is the better answer for your size, we will say so.

P J Networks Pvt Ltd · C-160, Mayapuri Phase II, New Delhi 110064
+91 98183 61787 · sanjay@pjnetworks.com

Related

Related to SOC as a Service: our managed SOC services page for the cost and RFP side, how to choose between SOC service providers in India, an assessment of Fortinet SOCaaS, threat hunting, the incident response retainer — or download the SOC platform datasheet.