



Attackers no longer need to find a vulnerability to breach your network. In 2026, the fastest path into an Indian enterprise is through a legitimate identity. Once an adversary has valid credentials — stolen via phishing, purchased on the dark web, or extracted through malware — they move through your environment as a trusted user. No exploit. No alarm. No obvious footprint.
This shift has spawned an entirely new security discipline: Identity Threat Detection and Response (ITDR). ITDR is the practice of continuously monitoring identity infrastructure — Active Directory, Azure AD/Entra ID, privileged accounts, service accounts, and SSO systems — to detect anomalous behaviour that signals a compromised identity. It then automates the containment response before damage spreads.
For Indian enterprise IT leaders and CISOs, ITDR is no longer optional. The combination of India’s expanding digital attack surface, the Digital Personal Data Protection (DPDP) Act’s breach notification obligations, and CERT-In’s 6-hour incident reporting directive makes rapid identity threat detection a regulatory imperative, not just a best practice.
The identity layer — everything that governs authentication and authorisation — has become the primary battlefield for modern threat actors. Several converging factors make Indian enterprises particularly exposed:
India’s cybersecurity regulatory landscape adds urgency to ITDR deployment. Two frameworks stand out:
CERT-In’s April 2022 direction requires covered entities — which includes virtually every enterprise operating digital infrastructure in India — to report cybersecurity incidents within six hours of detection. For identity-based breaches, the clock starts the moment you know an account has been compromised. Without automated detection, many organisations cannot reliably determine when detection occurred, creating both compliance risk and legal exposure. ITDR provides a timestamped detection event that anchors your incident timeline.
The DPDP Act obligates Data Fiduciaries to implement “reasonable security safeguards” to prevent personal data breaches. A compromised privileged account with access to customer databases, employee records, or financial data constitutes a potential personal data breach. ITDR — by detecting and containing identity compromise before data exfiltration occurs — is a concrete technical safeguard that helps evidence compliance with the Act’s security obligations. Note: ITDR supports compliance with the DPDP Act; it does not by itself make an organisation fully compliant.
Understanding the attack lifecycle helps frame the ITDR detection points:
Traditional security controls — firewalls, EDR, DLP — are largely blind to steps 2 through 4 because the attacker is using legitimate credentials and legitimate tools. ITDR is specifically designed to detect the behavioural anomalies in these middle stages.
An effective ITDR programme for Indian enterprises should deliver the following:
Real-time monitoring of Active Directory changes — new privileged account creation, changes to sensitive group membership, modifications to domain controller replication settings, and alterations to ACLs on high-value objects. Changes that happen outside change-management windows should trigger immediate alerts.
Baseline normal login behaviour (time, location, device, source IP) for each user. Flag deviations: a finance manager logging in at 2 AM from an unfamiliar IP, a service account suddenly performing interactive logins, or a single account authenticating to dozens of servers in rapid succession (indicative of lateral movement).
Privileged accounts — domain admins, server admins, application service accounts — should have tightly defined usage patterns. Any deviation, such as a domain admin account suddenly accessing HR file shares, should trigger an investigation workflow.
Graph-based analysis of AD relationships to map potential attack paths from any compromised account to your most sensitive assets (crown jewels). This helps SOC teams understand blast radius and prioritise containment actions.
When a compromised identity is confirmed, manual response is too slow to meet CERT-In’s 6-hour window. Automated response actions — disabling the account, forcing a password reset, revoking active sessions, pushing a block rule to the firewall — compress response time from hours to minutes.
Implementing ITDR at scale requires a platform that can ingest identity telemetry alongside network, endpoint, and application data, correlate it intelligently, and drive automated response. At PJ Networks, we deploy and operate PrahiX Ora — a unified SecOps platform built by PrahiX Tech Pvt Ltd — for enterprise clients requiring this level of capability. Here is how Ora’s four pillars directly support an ITDR programme:
PrahiX Ora’s SIEM ingests logs from domain controllers, Azure AD sign-in logs, VPN gateways, PAM platforms, and endpoint agents into a unified pipeline. Correlation rules mapped to the MITRE ATT&CK framework — particularly the Credential Access, Lateral Movement, and Persistence tactics — surface attack chains that individual log sources miss. Ora’s graph-based attack storyline reconstruction connects the initial phishing email, the AD reconnaissance queries, and the lateral movement events into a single coherent narrative, giving your SOC analysts the full context rather than isolated alerts.
For Indian enterprises, Ora’s tiered retention (hot, cold, and archive storage) is directly relevant to CERT-In’s direction on maintaining logs for 180 days within India. Logs stay in-country, retentions are configurable per source, and the archive tier keeps costs manageable for high-volume environments.
Identity threats do not exist in a vacuum — they ride on the network. Ora’s Network Management System provides unified observability across your FortiGate firewalls, managed switches, wireless APs, and WAN/SD-WAN links. LLDP/CDP topology discovery keeps the network map current; network path tracing helps analysts validate whether an anomalous authentication originated from an expected network segment. For multi-vendor estates — a reality for most Indian enterprises where NOC visibility is fragmented across separate tools — Ora’s ML-based anomaly detection can flag unusual east-west traffic patterns that correlate with lateral movement even when the traffic looks legitimate at the application layer.
For manufacturing, retail, and multi-site enterprises, identity-based attacks sometimes have a physical dimension — an insider using a compromised badge alongside a compromised digital credential, or a contractor physically accessing a server room at an unusual hour. Ora’s video surveillance (VMS) module manages ONVIF/Hikvision/Dahua cameras with video analytics, allowing physical access events to be correlated with digital identity events in the same operations console. When a privileged account logs into a data centre server at 3 AM, Ora can surface the corresponding physical access video clip — a capability that is increasingly relevant for enterprises operating under DPDP Act obligations around physical data security.
The critical bottleneck in ITDR is response speed. Ora’s SOAR module delivers playbook automation with pre-built connectors and automated response actions — including pushing dynamic blocklists to FortiGate NGFWs in real time. When Ora’s SIEM correlates a Golden Ticket attack pattern, the SOAR playbook can automatically: disable the compromised account in Active Directory, force a Kerberos ticket revocation, isolate the affected host at the network layer via FortiGate, and generate a draft CERT-In incident report with the required fields pre-populated from the detection event. This is what makes the 6-hour reporting window realistic — manual processes cannot achieve it consistently, but automation can. The same automation creates the audit trail that evidences your response capability under the DPDP Act.
Use this checklist to assess your organisation’s ITDR posture:
PJ Networks has been securing Indian enterprises across BFSI, manufacturing, healthcare, and logistics sectors for over two decades. Our ITDR service combines FortiGate NGFW and FortiMail to reduce the attack surface, a 24/7 NOC/SOC for continuous monitoring, ZTNA to replace legacy VPN with identity-aware access, and the PrahiX Ora platform for SIEM-powered identity analytics and SOAR-driven automated response.
Whether you are building ITDR from scratch, consolidating fragmented identity monitoring tools, or preparing to meet CERT-In and DPDP Act obligations, our team can assess your current posture and design a programme that fits your environment and budget.
Concerned about credential-based threats in your environment? Speak with a PJ Networks security advisor to assess your ITDR readiness and understand how PrahiX Ora can centralise your identity and network telemetry under a single operations view. Contact us at pjnetworks.com/contact.