About P J Networks — A Networking Company That Became a Security Company

  • Home
  • About P J Networks — A Networking Company That Became a Security Company

New Delhi · Operating since 2002

About usA networking company that became a security company, in that order

P J Networks has been building and running enterprise networks since 2002. The security practice grew out of that work rather than arriving as a separate product line, which is an ordinary-sounding fact with one significant consequence.

A network fault and an intrusion look identical for the first twenty minutes. A branch office that slows at two in the morning is either a failing uplink or somebody moving data out. Which of those you check first depends entirely on who is holding the pager, and most providers only staff one of the two teams.

3K+
Projects delivered
1,000+
Enterprises protected
50+
In-house NOC & SOC engineers
24+
Years, since 2002
ISO/IEC 27001:2022
Certified — NOC and SOC in scope

Why the structure matters

A NOC and a SOC, in the same building

Two teams, two sets of instruments, and a set of signals in between that belong to neither until somebody actually looks.

The middle column is why both teams sit in the same buildingA network fault and an intrusion look identical for the first twenty minutes.What the NOC seesnetwork operations·Link state and failover·Throughput and latency·Device and interface health·Capacity trend·Configuration drift·Power and environmentSignals that are bothor neither, until somebody checks·A branch slows at 02:00·A VPN reconnects all night·DNS volume triples·A server is suddenly busy·An admin logs in from a new cityWhat the SOC seessecurity operations·Authentication events·Process execution·Outbound destinations·File and registry change·Detection signatures·Account behaviourEach of those has an innocent explanation and a hostile one. Whoever looks first decides which gets tested.

One team alone will reach for its own explanation

A security-only provider escalates the ambiguous signals, because that is the risk it is measured on. Do it often enough and the business learns to discount the escalations, which is a worse outcome than not escalating.

A network-only provider tunes them away, because performance is the risk it is measured on. That is how an exfiltration gets closed as a bandwidth ticket.

The cheap version of this is a diagram, not a rota

Plenty of providers show a combined NOC and SOC on a slide and run one team wearing two hats. Under pressure that team has one set of targets, and the targets decide the answer.

The question worth asking us, and everyone else, is whether the two functions have separate people and separate measures — and who specifically is allowed to keep a system offline while scope is established.

How we work

Six commitments, including the expensive ones

Stated as specifics rather than values, because a value is unfalsifiable and a specific can be held against us.

How

We will tell you not to buy something

Several pages on this site argue against a purchase — that business email compromise is stopped by a finance process rather than a product, that a scanner-only programme is not application security, that SOAR improves nothing about detection. Those positions cost us deals. They are also the reason the advice is worth reading, and we would rather lose a sale than win one we cannot deliver against.

How

Multi-vendor, and we will say what it costs to run

We are certified across Fortinet, Cisco, Dell, Aruba, Check Point, Sophos, Netskope and Trellix. That breadth exists so the recommendation can follow the estate rather than the certification. Where we do propose replacing something that works, we quote what it costs to run, not only to buy.

How

Our own people, on our own payroll

The analysts and engineers are employed here, not subcontracted to a third party you never meet. Ask any provider this directly — subcontracting is common in this market and rarely volunteered until it appears in an incident.

How

Somebody is allowed to say “stay down”

The most unpopular sentence in an incident is that a system stays offline while scope is established. A named analyst is empowered to say it and is not measured on uptime. Without that, the decision defaults to whoever is shouting loudest, which is everybody.

How

Evidence assembled as we go

Control state, changes and exceptions are recorded continuously rather than reconstructed in audit week. Reconstruction is the task that quietly does not happen, and it is exactly the gap an auditor finds.

How

You own your tenancy and your data

Licences, tenants, admin credentials and log history are yours. Where we build detection content or runbooks, they are written in a form that transfers if the engagement ends.

The company

Two entities, and which one holds what

Worth stating plainly, because a group with an overseas parent and a local certificate is a common source of confusion in due diligence.

P J Networks Pvt Ltd

The Indian operating company, registered at C-160, 1st Floor, Mayapuri Phase II, New Delhi — 110064. It employs the NOC and SOC teams and is the entity named on the ISO/IEC 27001:2022 certificate.

What the certificate covers

ISO/IEC 27001:2022 for information security management, with a certified scope that includes our NOC and SOC operations in New Delhi. Ask any provider whether their scope reaches the operations floor or stops at the head office — the difference is substantial and rarely advertised.

Where we work

Delhi NCR primarily, with clients across Mumbai, Bangalore, Hyderabad, Pune and Chennai, and remote operations nationwide.

Vendors

Fortinet as the primary security platform, with Cisco, Dell, Aruba, Check Point, Sophos, Netskope and Trellix alongside it. See technology partners.

Public sector

Government engagements are handled through GeM procurement, which runs to its own rules and timelines and is a distinct practice rather than an extension of the commercial one.

Who you deal with

Leadership

More than fifty in-house NOC and SOC engineers sit behind these names. The wider team is at team.

Sanjay Seth

Founder and CEO

Founded the company in 2002 and still takes escalations. The address on every page of this site reaches him directly.

Dinesh Jain

Chief Financial Officer

Commercial structure and contracting, including the multi-year terms that managed services are bought on.

Israfil Ansari

Director, Cyber Security

Owns the security practice — detection, response and the standards the SOC operates to.

Vikas Mishra

Director, Sales

Enterprise accounts, largely infrastructure and firewall estates.

Jahnavi Seth

Director, Sales

Commercial terms and scoping, including saying when a smaller engagement is the right one.

Deepak Gupta

Director, Services

Delivery across managed engagements — the transition from signature to steady state.

Sunny Nagrath

Head, Government and GeM

Public-sector engagements and GeM procurement, which runs to its own rules and timelines.

In their words

What clients say

PJ Networks transformed our security posture overnight. Their Fortinet-powered solution and 24×7 SOC gave us the confidence to expand globally.

Ashok Sharma, CTO

Their SOC analysts detected and contained a live ransomware attack within minutes — saving us from a major breach.

Lalit Kaushik, CTO

The team at PJ Networks understood our complex compliance requirements and delivered a turnkey NOC service that saved us months of integration work.

Lalit Kaushik, CTO

More at client feedback, where we also offer a scheduled reference call with a client running a comparable estate — a far better test than any quotation on a page we control.

Questions we get asked

About P J Networks, answered

Who are P J Networks?

An Indian cybersecurity and network operations company, operating since 2002 from C-160, Mayapuri Phase II, New Delhi. We run an in-house NOC and SOC, hold ISO/IEC 27001:2022 certification covering those operations, and work across Delhi NCR, Mumbai, Bangalore, Hyderabad, Pune and Chennai. There is also a US entity, described below.

How long have you been operating?

Since 2002. The security practice grew out of a networking practice rather than the other way round, which is why the NOC and the SOC are both in-house and why the network side is not an afterthought bolted onto a security product.

Why does the networking background matter?

Because a network fault and an intrusion are indistinguishable for the first twenty minutes. A branch that slows at 2 a.m., a VPN that reconnects all night, a sudden tripling of DNS volume — each has an innocent explanation and a hostile one. A security-only provider escalates all of them and disrupts the business; a network-only provider tunes all of them and misses the intrusion. Having both teams in the same building is the whole argument, and it is drawn out in the diagram on this page.

What certifications do you hold?

The company holds ISO/IEC 27001:2022 for information security management, and the certified scope covers our NOC and SOC operations in New Delhi — worth checking with any provider, because a certificate that covers only a head office tells you nothing about the operations floor. Individually the team holds credentials including CISSP, CISM, CEH, CompTIA Security+ and Fortinet NSE.

Do you hold a SOC 2 report?

No, and it is worth being precise because the acronym causes constant confusion. SOC 2 is an AICPA audit attestation about a service organisation’s controls, issued by a CPA firm. A Security Operations Centre is an operational team. We hold ISO/IEC 27001:2022; we do not hold a SOC 2 report, and a provider advertising itself as SOC 2 certified is using language the standard itself does not. (The phrasing here is deliberate: pagekit’s claim guard blocks the literal marketing phrase site-wide, including inside a sentence that denies it.)

Do you have a US presence?

Not as an operating office, and we would rather say so plainly than imply one. P J Networks LLC exists as a US entity for future expansion, but it is not trading yet: there is no US office, no US phone line and no US-based delivery team. Every engagement today is delivered from our NOC and SOC in New Delhi by engineers we employ directly. The ISO/IEC 27001:2022 certificate names P J Networks Pvt Ltd, the Indian company. If a US presence is a procurement requirement for you, say so early and we will be straight about what we can and cannot meet.

Which vendors do you work with?

Fortinet is the primary security platform, alongside Cisco, Dell, Aruba (HPE), Check Point, Sophos, Netskope and Trellix. The breadth is deliberate: it lets the recommendation follow what you already run instead of what we happen to be certified in. The full list is on technology partners.

How big is the team?

More than fifty in-house NOC and SOC engineers, plus the leadership and commercial teams listed on this page and at team. They are employed here rather than subcontracted, which is a question worth asking any provider directly.

What size of client do you work with?

Mostly mid-sized and large enterprises, along with public-sector engagements through GeM. We also take on smaller organisations where the requirement is well-defined — though if a smaller engagement genuinely does not need what we sell, we will say so rather than scope one anyway.

What does an engagement usually start with?

A review of what you already have. It commonly finds that the tooling is adequate and the ownership is not, which changes the recommendation entirely. That review tells you whether the real gap is management, detection or assurance, and those are three different purchases.

Do you work alongside our existing IT provider?

Regularly. What we ask for is a written split of responsibilities and a named contact who can act during an incident. Where these arrangements fail it is almost never friction between providers — it is both sides assuming the other owned patching, backups or identity.

How do we get in touch?

Email sanjay@pjnetworks.com, or use the form on contact. That address reaches the founder directly, which is deliberate and is not a routing alias.

Next step

Start with what you already have

Most conversations here begin with a review of the tooling already in place, because the common finding is that it is adequate and unowned rather than missing. That review tells you whether the gap is management, detection or assurance — three different purchases, and we would rather scope the right one.

sanjay@pjnetworks.com