For Middle East buyers · Operating since 2002
We are an Indian managed security provider. We have delivered work for clients outside India, including in the Gulf, and the operations floor has been in New Delhi throughout. There is no regional office, no regional entity and no regional staff.
Most pages aimed at this market imply a local presence they do not have, which leaves a Gulf buyer to discover the delivery model during due diligence instead of during evaluation. This page states it first, then answers the questions that follow from it: who you contract with, where your data goes, what the time difference does, and what an offshore provider genuinely cannot do for you.
The arrangement
What you would actually be buying
A remote-delivered security operations capability, staffed from one floor, contracted through one Indian company. That is the whole model, and its limits are as important as its strengths.
What sits where
The SOC and the NOC are both in New Delhi, in-house, staffed around the clock by engineers on our own payroll. There is no overflow arrangement that hands your alerts to a third party overnight — which is worth checking with anyone you evaluate, because it is common and it is rarely volunteered.
You would contract with P J Networks Pvt Ltd, operating since 2002 and the entity named on our ISO/IEC 27001:2022 certificate. No intermediate entity, no regional subsidiary, nothing to trace through.
Why we lead with this
Because the alternative is worse. A regional page that implies a Dubai desk buys a slightly warmer first call and then fails the first serious procurement question, and a buyer who finds out late is right to wonder what else was arranged for effect.
The honest version is also the more useful one. An offshore delivery model is a genuinely good fit for some organisations and a genuinely poor fit for others, and which one you are is decidable in a single conversation if nobody is being coy about the facts.
The clock
What the time difference actually does
Less than people expect, and in the useful direction. New Delhi runs ahead of every Gulf capital, so your working day begins after ours does — the overlap is complete rather than partial.
Scroll the table sideways →
| Country | Cities | Offset | Delhi is ahead by | Your 09:00–18:00 | Is our |
|---|---|---|---|---|---|
| United Arab Emirates | Dubai, Abu Dhabi | UTC+4 | 1h 30m | 09:00–18:00 | 10:30–19:30 |
| Oman | Muscat | UTC+4 | 1h 30m | 09:00–18:00 | 10:30–19:30 |
| Saudi Arabia | Riyadh, Jeddah, Dammam | UTC+3 | 2h 30m | 09:00–18:00 | 11:30–20:30 |
| Qatar | Doha | UTC+3 | 2h 30m | 09:00–18:00 | 11:30–20:30 |
| Bahrain | Manama | UTC+3 | 2h 30m | 09:00–18:00 | 11:30–20:30 |
| Kuwait | Kuwait City | UTC+3 | 2h 30m | 09:00–18:00 | 11:30–20:30 |
Where it genuinely helps
Scheduled work — change windows, patching, reviews, reporting — lands inside our normal day rather than requiring anyone to be awake at an unusual hour. An engineer working a planned change at a sensible local time makes fewer mistakes than one doing it at 04:00, which is a real operational argument and not a scheduling convenience.
Where it is irrelevant
Incidents. The floor is staffed around the clock, so the time an alert fires does not determine who sees it. Time zones only matter at providers whose night shift is thinner than their day shift — so the question worth asking any of us is not “where are you” but “how many people are on the floor at 03:00 on a Friday, and do they work for you”.
Straight answers
What an offshore provider cannot do for you
Six facts about this arrangement, including the ones that lose deals. A provider who only lists strengths has told you nothing you can use to decide.
No Gulf office, and no Gulf entity
There is no Dubai desk and no Riyadh presence. You would contract with P J Networks Pvt Ltd, the Indian company, and every engineer on your account sits in New Delhi. If a local contracting entity is a hard procurement requirement, we do not meet it and would rather you learn that from this page than from week three.
No on-site incident response in the region
When an incident needs hands on a device in your building, that is your team or a local partner, coordinated by us. Anyone promising you a four-hour on-site SLA in the Gulf from an Indian delivery centre is describing something they cannot do.
Your data is processed in India
Monitoring means telemetry — logs, alerts, flow data, sometimes packet captures — leaving your estate and arriving on ours. Ours is in India. That is a material fact for anyone with a data residency requirement, and it belongs on page one of the evaluation rather than in an appendix.
The certificate is ours, not yours
We hold ISO/IEC 27001:2022 with the SOC in scope. That says our operations were assessed. It says nothing about your environment, and a provider who lets those two blur in a procurement conversation is telling you something about how they will behave later.
Coverage is genuinely 24/7, not follow-the-sun marketing
The operations floor is staffed around the clock by people we employ directly. There is no overflow arrangement to a third party at night, which is the arrangement most buyers discover only during an incident.
No claim about your regulator’s requirements
This page names frameworks and stops there. What any of them requires of you turns on how your entity is classified, and that is a question for your own advisers and the instrument itself, not for a vendor page.
Compliance
Frameworks buyers in the region ask us about
Named, with what we do about each. Deliberately not explained — what any of these requires of your organisation depends on how your entity is classified, and a vendor page is the wrong place to learn it.
Scroll the table sideways →
| Framework | Who it concerns | What it is | What we do about it |
|---|---|---|---|
| UAE Personal Data Protection LawFederal Decree-Law No. 45 of 2021 | United Arab Emirates | The federal personal data protection law, in force since 2 January 2022. | We map what we collect, where it goes and who can see it, then hand you that record to take to your own advisers. |
| DIFC and ADGM data protection regimes | Entities in those financial free zones | The free zones operate their own data protection regimes, separate from the federal law. | If you sit in a free zone, tell us at the outset — which regime you answer to changes the questions worth asking us. |
| NCA Essential Cybersecurity Controls | Saudi Arabia | The control set issued by the National Cybersecurity Authority. | We map our monitoring and reporting to the control references your assessor uses, so evidence arrives in their vocabulary. |
| Saudi Central Bank Cyber Security Framework | Saudi financial institutions | The framework issued by the Saudi Central Bank for its regulated entities. | Same approach: your control references, our evidence, one mapping maintained rather than a translation exercise each audit. |
| ISO/IEC 27001:2022 | Recognised across the region | An information security management system standard, and the one certificate we hold ourselves. | Our certificate covers our own operations with the SOC in scope. It is not a certificate for your environment, and we will not let it be read as one. |
Before you sign
Seven questions for any offshore security provider
Use them on us as readily as on anyone else. Question seven is the one that separates a provider who has thought about your problem from one who has thought about their pipeline.
Where do the people on my account physically sit?
Not the head office. The individual analysts. Providers with genuinely distributed teams answer this instantly; providers with a subcontract arrangement go vague.
Which legal entity signs, and where is it registered?
If the entity on the contract is not the entity doing the work, ask why, and ask which one carries the liability.
Where does my telemetry physically reside, and for how long?
Country, and retention period. Then ask what happens to it at the end of the contract.
Who answers at 03:00 on a Friday?
Ask for the name of the employer, not the name of the service. Weekend and public-holiday coverage differs between your calendar and ours, and that gap is where handovers fail.
Show me a real report from another client, redacted.
A sample generated for the pitch tells you nothing. A redacted real one shows you what a normal month actually looks like.
What is in scope of your own certification?
Read the scope statement, not the logo. A certificate scoped to a head office says nothing about the delivery centre that would run your account.
What will you not do?
The most useful answer in any evaluation. A provider whose capability has no edges has not thought about yours.
Working with us
How we would run your account
The same way we run every account, which is the point — there is no separate international tier, because there is only one operations floor.
People we employ
Every analyst and engineer on your account is on our payroll in New Delhi. No subcontracted night shift, and you can ask who is on the floor at any hour.
One entity, one contract
P J Networks Pvt Ltd signs, delivers and carries the liability. Nothing to trace through a chain of regional subsidiaries.
Your control references
Reporting mapped to the framework your assessor uses, so evidence arrives in their vocabulary instead of needing translation at audit.
Named escalation
You get people, not a queue address — including who to call when the answer you have is not good enough.
Told early, not discovered late
Where the model does not fit — on-site response, in-region data, local contracting — we say so in the first conversation.
Twenty-four years of it
Enterprise networks since 2002 and security operations alongside them. The NOC and the SOC are the same building and frequently the same incident.
Questions we get asked
Working with an Indian provider, answered
Do you have an office in the UAE or Saudi Arabia?
No. There is no Gulf office, no Gulf entity and no Gulf-based staff, and we would rather state that plainly than let a regional page imply otherwise. Work we have delivered for clients outside India, including in the Gulf, has been run from the operations floor in New Delhi throughout. If a local presence is a procurement requirement for you, say so at the first conversation and we will tell you honestly whether it is worth continuing.
Which entity would we be contracting with?
P J Networks Pvt Ltd, the Indian company, operating since 2002. It is also the entity named on our ISO/IEC 27001:2022 certificate. There is a separate US entity, P J Networks LLC, registered for future expansion and not trading — it is not the counterparty for anything and it has no bearing on Gulf work.
Where would our log data be stored?
In India, on infrastructure we operate. We would rather lead with that than have it emerge during a security review. If your obligations or your own customers require telemetry to remain in-region, tell us at the outset: it is a genuine constraint on this delivery model, not a detail to negotiate later, and it may mean we are the wrong provider for you.
How does the time difference affect response?
For scheduled work it helps more than it hurts. New Delhi is 1 hour 30 minutes ahead of the UAE and 2 hours 30 minutes ahead of Saudi Arabia, and neither side observes daylight saving, so the gap never shifts. A Gulf working day sits entirely inside a Delhi working day. For incidents the question is irrelevant anyway, because the floor is staffed around the clock — time zones matter to providers whose overnight cover is thinner than their daytime cover, which is the thing actually worth asking about.
Can you help us meet our regulator’s requirements?
We can map our monitoring, alerting and reporting to the control references your assessor works from, so evidence arrives in the vocabulary they expect rather than needing translation at audit. What your regulator requires of you specifically is a question for your own advisers and for the instrument itself — we name frameworks on this page and deliberately do not restate what any of them demands, because applicability turns on how your entity is classified.
Do you have Gulf client references?
Nothing we can show you on a public page. We have delivered for clients outside India including in the Gulf, but no client has consented to being written about here, and we are not going to publish an anonymised story vague enough to be unfalsifiable. Ask during an evaluation and we will tell you what we can, with the client’s agreement or not at all.
Is an offshore SOC actually cheaper?
Usually, and that is the honest reason most of these conversations start. It is also the wrong question to decide on. The one that matters is whether the coverage is real at 03:00, whether the people are employed or subcontracted, and whether the provider will tell you what they cannot do. A cheap SOC that pages a rota nobody staffs is not a saving.
What happens if we need someone physically on site?
You or a local partner provide the hands, and we coordinate. We are explicit about this because it is the most common gap in an offshore arrangement and the one most likely to be glossed over in a pitch. It is workable when it is planned for, and it goes badly when it is discovered mid-incident.
Do you work in Arabic?
Our reporting, tooling and analyst communication are in English. If Arabic-language reporting is a requirement, raise it early — we would rather tell you where the limits are than let it surface after a contract is signed.
Next step
Start by telling us the constraint
If telemetry has to stay in-region, if a local contracting entity is mandatory, or if you need on-site response inside a fixed window, say so first. Those are the three things that decide whether this model fits, and we would rather establish it in one conversation than three. If it does not fit, we will tell you.



