FAQ — Buying, Contracts and Engagement Questions About Managed Security

  • Home
  • FAQ — Buying, Contracts and Engagement Questions About Managed Security
FAQ — Buying, Contracts and Engagement Questions About Managed Security
FAQ — Buying, Contracts and Engagement Questions About Managed Security
FAQ — Buying, Contracts and Engagement Questions About Managed Security
FAQ — Buying, Contracts and Engagement Questions About Managed Security

Frequently asked · Operating since 2002

FAQThe questions that span every service, and where the rest are answered

Technical questions about a particular service are answered in depth on that service’s own page, and repeating them here would only produce a longer version of a worse answer.

What this page covers is everything that belongs to no single service: how engagements start, what is in a contract, who is on shift at 3 a.m., what happens if you leave. The routing grid below points to the rest.

3K+
Projects delivered
1,000+
Enterprises protected
50+
In-house NOC & SOC engineers
24+
Years, since 2002
ISO/IEC 27001:2022
Certified — NOC and SOC in scope

Start here

Where your question is actually answered

Each of these pages carries its own detailed FAQ. If your question is about one service, that page will answer it better than this one can.

Which service do I need?

Three questions — is it working, is someone in it, would it hold — and everything sits under one of them.

All services

Is my IT provider already covering this?

The difference between an MSP and an MSSP, and the case for not buying a second management layer.

Managed security services

What does it cost, and how is it metered?

Billing units by service, published vendor list prices, and the decisions that move a quote most.

Pricing models

How does 24×7 monitoring actually work?

The service model, the contract terms that matter, and an eight-point RFP checklist.

Managed SOC services

What about firewalls and the network?

Appliance sizing, subscription cost over the term, and rule-base decay.

Firewall services

Do we need a test, or monitoring?

What VAPT actually buys, and how to tell a manual test from a scanner export.

VAPT

Who are you, and what is certified?

The company, both legal entities, and exactly what the ISO/IEC 27001:2022 scope covers.

About us

Can we speak to a client?

Client feedback, and the offer of a scheduled reference call with a comparable estate.

Client feedback

Buying, contracts and working together

The cross-cutting questions

Several of these are worth asking every provider you are considering, not only us. Where that is the case, it says so.

How does an engagement usually start?

With a review of what you already have. The common finding is that the tooling is adequate and unowned rather than missing, which changes the recommendation entirely — and tells you whether the real gap is management, detection or assurance. Those are three different purchases, and we would rather scope the right one than sell all three.

What happens in the first thirty days?

Discovery and audit, then transfer of ownership for whatever we are taking on, then tooling and baseline, then the runbook and escalation path in writing, then go-live and a review. The part worth insisting on with any provider is that escalation paths name people rather than queues, and that they are agreed before go-live rather than discovered during the first incident.

What contract length do you work on?

Managed services are normally annual or multi-year, because the cost of onboarding is real and a one-month agreement prices that risk into the rate. Assessments and projects are one-off. What matters more than the length is whether the agreement can change shape without renegotiation — requirements move, and a contract that cannot move with them becomes the reason to change provider rather than the reason to stay.

Can we start small?

Yes, and we often recommend it. A single site, one function, or a controls review before any managed service is a reasonable way to test whether the working relationship suits you — and a much cheaper way to discover a mismatch than a three-year agreement.

What are your support hours?

That depends on what you buy, and it is worth being exact rather than reassuring. Business-hours administration, 24×7 monitoring, and 24×7 response are three separate things that are routinely sold as one. Ask us — and everyone else — what happens at 7 p.m. on a Friday, and whether the answer is an analyst investigating or a queue somebody reviews on Monday.

Will you work alongside our existing IT provider?

Regularly, and it is a common arrangement. We ask for a written split of responsibilities and a named contact on their side who can act during an incident. Where these fail it is almost never friction between providers — it is both sides assuming the other owned patching, backups or identity. Settle those three in writing first.

Who owns the licences, tenants and data?

You do. Licences, cloud tenants, admin credentials and log history stay yours, and where we build detection content or runbooks they are written in a form that transfers. Controls administered inside a provider’s own tenancy with no exportable configuration are a lock-in you will discover at renewal rather than at signature.

What happens if we leave?

You receive configurations, rule bases, documentation and log history in an agreed format. Ask for the exit terms before signing rather than after — the willingness to put them in writing at the start tells you most of what you need to know, and the answer is far harder to obtain once you are a customer.

What does year two cost?

Ask this of every provider, including us. Threat hunting, extended retention and vulnerability management are frequently included in year one and become line items afterwards. This is the single most common cause of a relationship souring at the first anniversary, and it is entirely avoidable by asking for the renewal schedule up front.

Are your analysts employed by you?

Yes. Subcontracting analyst tiers — particularly the out-of-hours tier — is common in this market and rarely volunteered. The question that gets a straight answer from anyone is: who employs the person who would pick up at 3 a.m., and does that change at weekends?

Do you work outside India?

Yes. We have delivered for clients outside India, including in the Gulf, with the operations floor in New Delhi throughout. There is no overseas office — P J Networks LLC is a US entity registered for future expansion, not a trading one — and we say so plainly rather than leaving it to be inferred. Provider location is the kind of detail that surfaces in due diligence rather than in a sales conversation, so for Middle East buyers we put it on the page instead: how we serve the Middle East from India.

Do you only sell Fortinet?

No. Fortinet is the primary security platform and we are certified across Cisco, Dell, Aruba, Check Point, Sophos, Netskope and Trellix as well. The breadth exists so a recommendation can follow your estate rather than our certifications. Where we suggest replacing something that works, we quote what it costs to run over the term, not only to buy.

What if something goes wrong during an engagement?

Engagements do go wrong — a migration overruns, a change causes an outage, a detection misses. What distinguishes providers is whether the first report of it reaches you from them or from you. We would rather make an uncomfortable call early than manage a discovery later.

Do you have written case studies?

Not in the form the term usually implies, and it would be easy to imply otherwise. What we offer instead is a scheduled conversation with a client running a comparable estate, which answers what a case study is written to answer and permits follow-up questions a document cannot. Ask on client feedback.

How do we contact you?

Email sanjay@pjnetworks.com, or use the form on contact. That address reaches the founder directly and is not a routing alias.

Next step

Ask us something that is not on this page

If a question here was not answered, or was answered in a way that sounds like marketing, say so directly. The questions that are awkward to answer are usually the ones worth asking, and a provider unwilling to answer them in writing before a contract will not become more forthcoming afterwards.

sanjay@pjnetworks.com