Delhi NCR · Staffed around the clock
Most “24/7 monitoring” sold in India is an engineer asleep with a pager. Genuine 24/7 SOC monitoring means an analyst at a console at 3 a.m. on a Sunday, triaging your alerts in real time, with an L2 and L3 behind them — and it matters most when your own team is offline.
This page is about what the phrase should mean before you pay for it: how to tell a staffed night shift from an on-call rota, what telemetry has to be watched, which SLA number is worth arguing over, and the arithmetic of doing it yourself. The wider model is covered on our SOC as a Service page, our tiers and SLA on the SOC services page, and the platform underneath on managed SIEM services.
The definition
What genuine 24×7 monitoring actually means
Three very different arrangements are all sold under the same “24/7” label in Indian proposals. The difference decides who is looking at your estate when an attack actually happens.
Staffed night desk
Analysts on shift at the console through nights, weekends and public holidays, working the same queue and the same SLA as the day team. This is the only arrangement that is genuinely 24×7, and the most expensive to run — which is why it is the rarest.
Follow-the-sun
Coverage handed between offices in different time zones, so everyone works daytime hours. Legitimate when real — but verify the overnight office is staffed for your queue, not merely open.
On-call
Alerts page an engineer at home, who wakes up, logs in, and starts work cold. Response is measured from when they surface, not from when the alert fired. Most “24/7” claims in the Indian market are this, priced as if it were the first row.
The test is one question, asked in writing: at 3 a.m. on a public holiday, is a named analyst already watching my console, or does someone get woken up? A staffed provider answers with a roster; an on-call provider answers with an SLA measured from acknowledgement — precisely the gap you are trying to close.
Our desk is staffed: L1 on shift continuously, L2 reachable within minutes, L3 on a published escalation path. The full model is on the SOC as a Service page.
The timing problem
Why attacks land at nights, weekends and public holidays
Attackers read your calendar. Ransomware detonation is deliberately scheduled for Friday nights and long weekends because that is when detection is slowest and decision-makers are hardest to reach — the encryption runs for hours before anyone with authority is awake.
India adds its own wrinkles. The festival calendar — Diwali week, Holi, the year-end stretch — is when offices run skeleton crews and change freezes leave half-applied patches in place. And an attacker operating from another time zone experiences your 3 a.m. as their working afternoon.
The uncomfortable conclusion: a nine-to-six SOC covers the hours when you are least likely to be attacked. Two-thirds of the week sits outside office hours once nights and weekends are counted, and that two-thirds is where attackers concentrate. Monitoring that pauses at 6 p.m. is perimeter lighting that switches off at dusk.
Coverage
The telemetry that has to be watched
A night desk watching only the firewall will sleep through the identity attack that opens most breaches. These are the feeds that have to reach the console.
Network & perimeter
Firewalls, IPS, VPN concentrators and remote-access gateways — the first place lateral movement and command-and-control show up in a mixed Fortinet, Cisco or Sophos estate.
Endpoints & servers
EDR telemetry and Windows and Linux event logs — where ransomware staging, suspicious PowerShell and mass file-renaming are visible before encryption completes.
Identity
Directory changes, MFA fatigue patterns, impossible-travel sign-ins and privilege escalation. Identity is now the most common way in, and the most commonly unmonitored feed.
Cloud & SaaS
AWS CloudTrail, Azure and Microsoft 365 audit logs, GCP, and the sign-in telemetry of the identity provider that ties them together.
Phishing, business email compromise and malicious attachments — still where most incidents begin.
OT & industrial
Where plants or operational technology exist, their telemetry needs watching too — with detection content written for protocols that a generic SIEM rule set has never heard of.
Collection and correlation across these feeds is the platform problem; our managed SIEM services cover it, including on a SIEM you already own. Proactive searching across the same telemetry — the hypothesis-led work that finds what rules miss — sits under threat hunting.
The honest numbers
Alert triage is not investigation
Every SOC produces alerts; the product you are buying is the judgement applied to them. Triage is deciding an alert is probably noise and closing it. Investigation is proving it — pulling the surrounding logs, checking the host, ruling out the benign explanation. The two look identical on a dashboard and are completely different at 3 a.m.
The number no provider volunteers is alerts per analyst per shift. A desk where one analyst faces many hundreds of alerts a shift is pattern-matching at a glance — seconds per alert, not investigation. A desk sized so an analyst can open, check and document a few dozen properly is doing the work you think you are paying for. Ask for the figure, and ask what happens when the queue spikes: the honest answer involves an L2 absorbing the overflow, not a quieter threshold.
Machine triage genuinely discards routine noise and is worth having, but it does not replace the human decision on the alert that survives filtering — and that alert is the only one that matters.
The contract
The SLA definitions that matter
Most monitoring SLAs are written to be won by the provider. The metric that protects you is time-to-verified-incident — the clock from the event occurring to a human confirming it is real and telling you. Everything shorter is a consolation prize.
Time-to-alert
The SIEM fired a rule. Automated, instant and meaningless — the alert may sit unread for hours.
Time-to-acknowledge
An analyst opened the ticket. In an on-call arrangement the clock starts when someone wakes up; the gap before that is invisible.
Time-to-verified-incident
A human has investigated, confirmed or dismissed the alert with reasoning, and — if real — escalated it to you. Insist the SLA clock stops here, not earlier.
Two more definitions to pin down before signature: severity classification — what counts as P1 and who declares it, since every response-time figure is indexed to it — and the measurement start point, since mean time to detect measured from alert generation flatters the provider. Our own commitments are on the SOC services and SLA page.
India, specifically
CERT-In’s six-hour clock makes 3 a.m. detection a compliance capability
CERT-In requires specified cyber incidents to be reported within six hours of being noticed — not confirmed, not understood, noticed. For an Indian organisation, round-the-clock detection is not an operational luxury; it is what makes the statutory deadline meetable.
Run the scenario honestly. An intrusion begins at 1 a.m. on a Sunday. With a staffed desk it is noticed within the hour, verified by 3 a.m., and your six-hour window opens with nearly all of it intact. With an office-hours arrangement nobody notices until Monday at 9 a.m.; the clock has been running for over a day and you are already in breach before the first coffee. With on-call, the answer depends on whether the pager worked and how fast a cold-start investigation goes at 4 a.m.
CERT-In also requires logs retained for a rolling 180 days within Indian jurisdiction, which is how we hold them by default — a night desk without log history cannot reconstruct what happened anyway. Sector rules layer on top: SEBI’s CSCRF mandates a SOC for almost every regulated entity and permits a third-party managed one; the RBI’s framework prescribes the L1/L2/L3 tiers directly in Annex-2.
The arithmetic
What staffing your own night shift actually costs
Before comparing any provider’s quote, run the numbers on the alternative. They are structural, not negotiable, and they are why this service exists.
One console seat covered continuously is 8,760 hours a year. An analyst on a 45-hour week, after leave, public holidays, sick days and a training allowance, delivers roughly 1,900 productive hours. Dividing one by the other gives 4.6 full-time equivalents per seat — and you hire five or six to survive a single resignation. Genuine triage rather than alarm-watching wants two concurrent seats, landing near ten or eleven people before a single specialist is hired. A credible three-tier roster — eight L1, four L2, two L3, a detection engineer and a manager — comes to roughly ₹1.4 crore a year in base salary, before recruitment, facilities, backfill and the SIEM licence on top.
The retention problem makes it worse: across more than eleven thousand Indian SOC analyst records, the population peaks at three to four years of experience and thins by around 90 per cent by year six. Your night shift is a revolving door by design, and every departure takes tuned detection context with it. The full comparison is in our guide to SOC as a Service pricing in India.
Below roughly fifteen to twenty monitored servers, buying beats building on cost alone, and it is not close. Above that, the deciding factor is whether you can sustain the roster, not whether you can afford it.
Authority
Monitoring and response are separate purchases — decide containment in the contract
Finding an incident and being allowed to stop it are different things, and the boundary is contractual, not technical. The most common disappointment in this market is an organisation that believed it had bought containment and had in fact bought notification.
Three arrangements exist. Monitoring only: we investigate and advise, you act — workable only if someone on your side actually answers at 3 a.m. Pre-authorised containment: the contract grants specific rights — isolate a host, disable an account, block an indicator — exercised first and reported immediately. Escalated authority: a named decision-maker on your side, reachable within a defined window, approves each action. All three are defensible; ambiguity is not, because it resolves itself during the incident, at the worst possible moment, in favour of doing nothing.
Whichever you choose, write the escalation matrix down before go-live: who is called, in what order, with what authority, and what happens when nobody answers. Talk to us about where the boundary should sit for your estate.
Straight answers
24/7 SOC monitoring, answered
Is 24/7 monitoring the same as 24/7 response?
No. Monitoring means a staffed desk detects, investigates and escalates around the clock. Response adds the authority to act — isolating a host, disabling an account — without waiting for your approval. Both are legitimate purchases; the mistake is assuming monitoring includes response. Decide containment rights in the contract, because the default is notification only.
Is an on-call engineer the same as 24/7 monitoring?
No. On-call means alerts page someone at home, who wakes up and starts work cold — response time runs from when they surface, not from the event. Genuine 24/7 means an analyst is already at the console. The written test: at 3 a.m. on a public holiday, is a named analyst watching your queue, or does someone get woken up?
What happens when you find something at 3 a.m.?
An L1 on shift triages the alert immediately; anything that survives goes to an L2, who validates it and opens the case. For a genuine P1 you get a phone call, not an email into a shared mailbox. What happens next depends on the authority in the contract: we advise and you act, or we contain first and tell you immediately. CERT-In’s six-hour clock starts at noticing, which is why the phone call matters.
Can you monitor the SIEM we already own?
Yes — a co-managed arrangement where you keep the platform and licence while our analysts run the watch is common. We operate FortiSIEM and our own PrahiX Ora platform, and we take over monitoring on SIEMs customers have already licensed. We audit the inherited rule set first, because platforms that ran without a dedicated team almost always have unreviewed detections and log sources that silently stopped reporting.
How long are logs retained?
CERT-In requires security logs retained for a rolling 180 days within Indian jurisdiction, and we hold them accordingly by default — region included, since the requirement is about where the data sits, not just for how long. Retention beyond 180 days is available where your sector obligations or forensics policy call for it, priced as storage.
How much does 24/7 SOC monitoring cost in India?
There is no honest single figure before someone sees your estate: price follows log volume, monitored asset count and whether you buy monitoring alone or with response authority. The useful comparison is the alternative — one continuously covered seat needs about 4.6 full-time equivalents, and a credible three-tier roster is roughly ₹1.4 crore a year in base salary before platform costs. We quote a specific monthly figure against your estate.
How long does onboarding take?
First log sources are ingested within days; meaningful detection coverage typically lands within four to six weeks for a mid-market estate. The honest constraint is tuning, not integration — a newly pointed SIEM produces a great deal of noise, and the value comes from the baselining that follows. A provider promising trustworthy detection on day one is describing alerting, not detection.
Do you also monitor network availability and uptime?
Yes, but it is a different discipline. A SOC watches for threats; a NOC watches availability — link health, device uptime, circuit degradation. The two share telemetry and in our case a facility, which helps when an outage and an attack look similar at first. See our NOC as a Service page; many engagements run both.
Next step
Find out who would be watching your estate at 3 a.m.
We will scope your log sources and assets, quote a specific monthly figure, and put the in-house roster arithmetic beside it. If building your own night shift is the better answer, we will say so.
P J Networks Pvt Ltd · C-160, Mayapuri Phase II, New Delhi 110064
+91 98183 61787 · sanjay@pjnetworks.com
Related
Related to 24/7 SOC monitoring: the wider SOC as a Service model, our SOC services and SLA, managed SIEM services, threat hunting, the SOC as a Service pricing guide for India, NOC as a Service for availability monitoring — or contact us to scope your estate.



