SOC as a Service in Mumbai — 24×7 Managed Security Operations

  • Home
  • SOC as a Service in Mumbai — 24×7 Managed Security Operations

Mumbai · BFSI · SEBI & RBI regulated estates

SOC as a Service in Mumbai24×7 managed security operations for Mumbai’s brokers, banks, AMCs and NBFCs

Mumbai holds the densest concentration of regulated financial entities in the country, and both principal regulators now expect a security operations centre by name. This page is about buying that capability as a subscription — monitored from our Delhi NCR SOC, logs retained in India, scoped monthly quote.

The model itself is covered on our SOC as a Service page, which this page defers to for the generic term. What follows is the Mumbai-specific part: the choice SEBI’s CSCRF puts in front of brokers and AMCs, the RBI’s Annex-2 tier expectation for banks and NBFCs, and how remote delivery to a Mumbai estate works. For the underlying obligations, see our SEBI CSCRF compliance services and RBI cyber security compliance pages.

3K+
Projects delivered
1,000+
Enterprises protected
50+
In-house NOC & SOC experts
24+
Years, since 2002
ISO/IEC 27001:2022
Certified — SOC in scope
SOC as a Service in Mumbai — managed SOC for BFSI and enterprise by P J Networks

Why here

CSCRF bites hardest in Mumbai

SEBI’s Cyber Security and Cyber Resilience Framework, issued on 20 August 2024, mandates a SOC for almost every regulated entity — and the bulk of that population sits in Mumbai, where the exchanges, depositories and the regulator itself are.

The framework names the security operations centre as a required control and gives regulated entities three ways to satisfy it: their own or group SOC, the Market SOC operated by the exchanges and depositories, or any third-party managed SOC. Small-size and self-certification entities are directed onto the Market SOC; every other category — in Mumbai, most of the BFSI mid-market — has a genuine choice.

The reason a Mumbai broker or AMC rarely builds its own SOC is arithmetic, not appetite: a credible three-tier roster is roughly ₹1.4 crore a year in base salary before overheads — which is why two of CSCRF’s three sanctioned models are outsourced.

The choice CSCRF gives you

Market SOC or a private managed SOC — how to decide

Both are legitimate routes; the honest answer depends on your estate. The Market SOC is regulator-blessed and low-friction; a private SOCaaS engagement is broader and tuned to your systems.

Scroll the table sideways →

Question Market SOC (exchanges & depositories) Third-party managed SOC
Who it is designed for Small-size and self-certification entities needing a compliant baseline at low friction. Qualified REs with mixed estates — trading systems, M365, cloud, branches — needing detection tuned to their environment.
Telemetry breadth Standardised feeds from member-facing systems; wider estate coverage can be limited. Whatever your estate produces — firewalls, EDR, identity, cloud audit logs, application telemetry.
Response authority Primarily detection and advisory; containment stays with you. Set by contract — monitoring-only or authorised containment without waiting.
Cost shape Subsidised and simple; attractive if your obligation is the baseline. Quoted against your estate; more than the Market SOC, far less than in-house.
The honest limitation A shared utility optimises for the average member. If your risk profile is not average, coverage will show it. Onboarding is real work — the provider must learn your estate before detections are trustworthy.

Small-size entities directed onto the Market SOC should take it — it exists for them. Qualified REs should decide on telemetry breadth and on what happens after an alert fires.

The other regulator

RBI-regulated Mumbai: the C-SOC and Annex-2 tier expectation

A large share of India’s banks, systemically important NBFCs and payment operators are headquartered in Mumbai, and the RBI’s Cyber Security Framework requires each to run a Cyber Security Operation Centre under the CISO. It does not require them to staff it themselves.

Annex-2 of the framework describes the tier structure directly: Level 1 monitoring by trained staff round the clock, Level 2 investigation by specialists, and Level 3 work covering deep packet analysis, IOC collection, forensics and malware reverse engineering. The same annex candidly lists why institutions struggle to run this in-house — scarce specialist skills, difficult hiring, expensive training, poor retention. That is the regulator describing the case for outsourcing.

What an examiner looks for is evidence that the tiers operate: alert-to-case records, escalation logs, shift coverage and reporting that reaches the CISO and the board-level IT committee. A managed SOC that cannot produce that evidence is monitoring, not a C-SOC. Our RBI compliance page maps the full framework.

Scope

What the subscription includes

The full delivery model is on our SOC as a Service page. In summary, a Mumbai engagement covers the following.

L1, L2 and L3 analysts

Triage, investigation and the specialist tier — forensics, malware analysis, threat hunting — on a 24×7 roster from our Delhi NCR facility.

The platform

Our PrahiX Ora SIEM/SOAR, FortiSIEM, or the SIEM you already license. You are not forced onto a new stack.

Threat intelligence

Feeds tuned to the threats that target Indian BFSI — phishing kits, mule-account infrastructure, exchange-facing attack patterns.

CERT-In reporting support

Detection-to-notification workflows built around the six-hour window, so the clock is met from evidence rather than improvisation.

Audit-ready reporting

Monthly reporting mapped to CSCRF and RBI expectations — incidents, response times, coverage — in a form an examiner can use.

Quarterly service reviews

In person in Mumbai: detection coverage, tuning backlog, SLA performance and the next quarter’s roadmap.

The commercial half — pricing units and RFP questions — is on our managed SOC services page.

Your estate

The telemetry a Mumbai estate actually produces

Detection quality is decided by what you feed the platform, and Mumbai’s BFSI estates have a particular shape. These are the sources we expect to onboard.

Trading and market-facing systems

Order management systems, FIX gateways, exchange connectivity and dealer terminals. A manipulated order path is a security incident, not an IT fault.

Core banking and NBFC platforms

The adjacencies around core banking and loan systems: middleware, payment interfaces, collection channels. The core is the vendor’s problem; the seams around it are yours.

Microsoft 365 and identity

Sign-in and audit logs, directory changes, MFA fatigue patterns, privilege escalation. Most Mumbai BFSI incidents now start here — a mailbox rule, not a firewall breach.

Cloud

AWS (most Mumbai workloads sit in ap-south-1), Azure, GCP and SaaS audit trails, onboarded alongside rather than instead of on-premises sources.

Network and perimeter

Firewalls, VPN concentrators and branch connectivity — Fortinet, Cisco, Palo Alto and the rest of a mixed estate, including branches outside head office.

Endpoints

EDR across dealing-room desktops, branch machines and servers, with privileged-use monitoring on accounts that touch settlement.

Delivery

How remote delivery to Mumbai actually works

We are honest about geography: the SOC is a staffed facility in Delhi NCR, not an office in Nariman Point. For monitoring, that distance is irrelevant — an alert fires in the same second whether the analyst is in BKC or Mayapuri. What matters is jurisdiction, and your logs never leave India.

Onboarding is structured and remote. Log sources ship over VPN or lightweight agents; first feeds are ingested within days, and tuned detection coverage is in place within four to six weeks — the honest constraint is baselining, not connectivity.

The relationship is not remote-only. Service reviews happen in person in Mumbai every quarter, and during onboarding we agree the escalation matrix — who calls whom, with what authority — with your IT and compliance teams before go-live, because ambiguous ownership at 3 a.m. is how incidents get dropped.

Myth

“We need the SOC physically in Mumbai”

Monitoring is latency-tolerant and location-independent; no regulation requires the analysts to share your PIN code. What CERT-In requires is 180 rolling days of logs within Indian jurisdiction — a data-location rule, not an analyst-location rule.

Fact

Jurisdiction of logs is the part that matters

Logs from your estate are stored in India by default, satisfying CERT-In’s retention rule and keeping you clear of cross-border questions under the DPDP Act. SEBI even exempts data sent to a global SOC from localisation — we keep it in India anyway, because it removes a question rather than answering one.

The reporting clock

CERT-In’s six hours, and where Mumbai firms get caught

Specified incidents must be reported to CERT-In within six hours of being noticed. The trigger is noticing, not confirming — which makes the deadline a detection problem before it is a paperwork problem.

The failure mode we see in BFSI estates is not a missing incident response plan; it is discovering the incident on day nine from a customer or an exchange circular, at which point you have already failed the clock. A SOC that watches continuously changes the starting position: the incident is noticed by your own monitoring and the report assembled from evidence rather than reconstructed under pressure.

Retention is the quieter obligation. Logs must be kept for a rolling 180 days inside Indian jurisdiction, and that retention is what makes the six-hour report, the CSCRF audit trail and any subsequent forensics possible. The mapping of these obligations is on our SEBI CSCRF compliance services page.

Money

What it costs against building in Mumbai salary conditions

Nobody credible quotes a figure before seeing your estate; price follows log volume, asset count and whether response is included. What we can publish is the other side of the equation.

One continuously staffed seat is 8,760 console-hours a year; one analyst delivers roughly 1,900 productive hours after leave and training; so continuous cover needs about 4.6 full-time equivalents per seat, and two concurrent seats — the realistic minimum for genuine triage — is ten or eleven people before a single specialist. A credible three-tier roster runs to roughly ₹1.4 crore a year in base salary, and Mumbai is the most expensive market in the country in which to hire it: you compete with banks, exchanges and global capability centres for the same analysts.

For a BFSI mid-cap — a mid-size broker, an AMC, an NBFC with a few thousand endpoints — the subscription wins on cost alone, and it is not close. The detailed arithmetic is in our guide to SOC as a Service pricing in India. We will scope your estate and quote a specific monthly figure with the in-house comparison beside it.

Straight answers

SOC as a Service in Mumbai, answered

Can a SEBI-regulated entity in Mumbai use a third-party SOC instead of building its own?

Yes. CSCRF mandates a SOC for almost every regulated entity and then offers three models: your own or group SOC, the Market SOC operated by the exchanges and depositories, or any third-party managed SOC. Small-size and self-certification entities are directed onto the Market SOC; Qualified REs may choose a third-party provider. SEBI’s clarification of 28 August 2025 made ISO 27001 recommended rather than mandatory for Qualified REs (it stays mandatory for market infrastructure institutions). P J Networks is certified to ISO/IEC 27001:2022 with SOC operations in the certified scope either way.

How do we choose between the Market SOC and a private SOCaaS provider?

Start with your category: small-size and self-certification entities are directed onto the Market SOC, and for them it is the sensible route. Qualified REs should decide on telemetry breadth and response. The Market SOC is optimised for the average member; a private provider monitors your full estate and can hold contractual authority to contain incidents rather than only advise. Ask both what happens after an alert fires.

Do you cover RBI’s C-SOC requirements for banks and NBFCs?

Yes. The RBI Cyber Security Framework requires a Cyber Security Operation Centre under the CISO, with Annex-2 describing the L1, L2 and L3 tiers directly. It requires the function to exist and operate; it does not require your own employees to staff it. Our service is built around the Annex-2 tiers, with the escalation matrix, shift coverage and audit-ready reporting an examiner expects.

Are our logs stored in India?

Yes. CERT-In requires security logs retained for a rolling 180 days within Indian jurisdiction, and logs from your estate are stored in India by default. Two things are often conflated here: the residency rule concerns where the data sits, not where the analysts sit. SEBI even exempts data sent to a global SOC from localisation; we keep logs in India regardless, because it removes a compliance question rather than answering one.

Do you have an office in Mumbai?

No, and we would rather say so plainly. The SOC is a staffed facility in Delhi NCR; delivery to Mumbai is remote — telemetry ships over encrypted channels and onboarding needs no hardware visit for most sources. What is not remote is the relationship: quarterly service reviews are in person in Mumbai, and we agree the escalation matrix with your team before go-live. Distance does not change detection speed; jurisdiction of logs is what matters, and your logs stay in India.

What does SOC as a Service cost for a Mumbai broking firm or NBFC?

There is no honest single figure before your estate is scoped. Price follows log volume, monitored asset count and whether response is included. The comparison is the alternative: 24×7 cover needs about 4.6 full-time equivalents per seat, and a credible three-tier roster is around ₹1.4 crore a year in base salary — in Mumbai, the most expensive hiring market in the country for security analysts. We will scope your estate and quote a specific monthly figure with the in-house comparison beside it.

How long does onboarding take for a Mumbai estate?

First log sources are typically ingested within days, and meaningful detection coverage is in place within four to six weeks. The constraint is tuning, not connectivity: a SIEM freshly pointed at a trading estate or core banking adjacency produces a great deal of noise, and the value comes from the baselining that follows. Anyone promising reliable detection on day one is describing alerting, not detection.

Can you monitor the SIEM we already run?

Yes — a common arrangement for firms that licensed a SIEM for CSCRF or RBI evidence and found nobody watching it. We operate FortiSIEM and our own PrahiX Ora platform, and we take over monitoring on customer-owned SIEMs. We audit the inherited rule set first, because platforms run without a dedicated team almost always have stale detections and log sources that stopped reporting unnoticed.

Next step

Scope your Mumbai estate in one call

Tell us your regulated category, log sources and monitored asset count, and we will quote a specific monthly figure with the in-house comparison beside it. If the Market SOC or building in-house is the better answer, we will say so.

P J Networks Pvt Ltd · C-160, Mayapuri Phase II, New Delhi 110064
+91 98183 61787 · sanjay@pjnetworks.com

Related

Related to SOC as a Service in Mumbai: the full SOC as a Service model, our managed SOC services, SEBI CSCRF compliance services, RBI compliance for banks and NBFCs, SOC as a Service for BFSI, the guide to SOC as a Service pricing in India, our SOC services and SLA — or talk to us directly. We also deliver SOC as a Service in Pune, Chennai and Hyderabad.