SOC as a Service for BFSI — RBI and SEBI Aligned Security Operations

  • Home
  • SOC as a Service for BFSI — RBI and SEBI Aligned Security Operations

Banks · NBFCs · Insurers · SEBI-regulated entities

SOC as a Service for BFSISecurity operations aligned to RBI, SEBI, IRDAI and CERT-In — with the evidence to prove it

A BFSI security operations centre is not a generic monitoring contract with a compliance slide attached. RBI names the tier structure your SOC must have, SEBI names the operating models you may choose, and CERT-In sets a six-hour reporting clock that starts when an incident is noticed, not confirmed. This page covers what that changes for a regulated buyer.

For the generic model first — what the subscription includes, the variants and the cost arithmetic — our SOC as a Service page is the authority. Here we stay with the regulated version: the RBI Cyber Security Framework and its Annex-2 tiers, SEBI’s CSCRF and its three permitted SOC models, the CERT-In deadlines, and what an examiner will ask to see.

3K+
Projects delivered
1,000+
Enterprises protected
50+
In-house NOC & SOC experts
24+
Years, since 2002
ISO/IEC 27001:2022
Certified — SOC in scope
SOC as a Service for BFSI — RBI and SEBI aligned security operations in India

The regulatory map

Three regulators, three ways of saying “watch your estate”

In Indian financial services the SOC is not inferred from a principle — it is named, tiered and, in SEBI’s case, model-specified in the regulation itself.

RBI — banks and NBFCs

The Cyber Security Framework requires a Cyber Security Operation Centre (C-SOC) under the CISO, with Annex-2 spelling out the L1, L2 and L3 tiers. The same annex lists why institutions struggle: scarce skills, hiring difficulty, training cost and retention.

SEBI — market entities

The Cyber Security and Cyber Resilience Framework (CSCRF), issued 20 August 2024, mandates a SOC for almost every regulated entity and lets you choose the model: your own or group SOC, the Market SOC, or a third-party managed SOC.

IRDAI — insurers

IRDAI’s Information and Cyber Security Guidelines require continuous monitoring, a SOC capability and time-bound incident reporting. The vocabulary differs; the ask — someone watching, around the clock, with evidence — is the same.

Layered across all three: CERT-In’s six-hour reporting and 180-day in-India log retention, and the DPDP Act 2023 wherever personal data moves. Our compliance services practice maps every obligation to its instrument.

RBI’s Annex-2, read properly

The L1–L3 tier structure is the regulator’s, not ours

Annex-2 of the RBI Cyber Security Framework describes the three levels itself — which matters at inspection, because your SOC design traces to the annex, not to a brochure.

Scroll the table sideways →

Tier What Annex-2 describes What it means when outsourced
Level 1 Round-the-clock monitoring of security events by trained staff, with defined escalation. Continuous console cover with a roster that absorbs nights, weekends and leave — the hardest tier to staff in-house.
Level 2 Investigation of escalated events by specialists, correlating across sources. Experienced analysts with playbooks written for your estate — payment rails, branch networks, identity — rather than generic triage.
Level 3 Deep packet analysis, IOC collection, forensics and malware reverse engineering. The tier almost no mid-sized institution can justify on its own payroll; shared across many estates it becomes affordable — the economic case for the model.

The framework requires the function to exist under the CISO; it does not require your employees to occupy the chairs — Annex-2 itself lists why that is hard. What never transfers is accountability: your CISO remains answerable to the Board and to RBI, so a provider’s reporting quality matters more than its dashboard.

SEBI CSCRF

Three permitted SOC models — and the ISO 27001 position that moved twice in 2025

The CSCRF does not merely permit outsourcing; it enumerates it: your own or group SOC, the Market SOC operated by the market infrastructure institutions, or any third-party managed SOC. Small-size and self-certification entities are directed onto the Market SOC; everyone above that tier chooses.

On certification, be precise about the current position. SEBI’s CSCRF FAQ of June 2025 required an outsourced provider to be ISO/IEC 27001 certified for the services provided, with the SOC inside the certified scope. A technical clarification of 28 August 2025 softened this for Qualified REs to “encouraged and recommended (not mandatory)”, leaving it mandatory for market infrastructure institutions. Either way, “it was only recommended” is a weak answer when an examiner asks why you chose an uncertified provider.

Fact

A third-party SOC is a sanctioned model, not a workaround

The CSCRF lists it alongside the own-SOC and Market SOC options — you are choosing from a menu the regulator wrote.

Fact

The scope statement is the certificate

“ISO 27001 certified” is meaningless if the certificate covers only head office. Confirm the SOC is inside the scope — the FAQ expects exactly that.

CERT-In, on top of all of it

Six hours to report, 180 days of logs, in India

Sectoral obligations do not replace CERT-In’s directions; they run in parallel. Two of them shape how a BFSI SOC must be built.

The six-hour clock

Specified incidents must be reported to CERT-In within six hours of being noticed. The trigger is noticing, not confirming — finding out on day nine from a customer means the deadline was already missed. That makes reporting a detection problem first, and the strongest argument for 24×7 monitoring: an incident noticed at 02:10 by a staffed console is reportable by 08:10.

The 180-day floor

Security logs must be retained for a rolling 180 days within Indian jurisdiction; our platform retains them in India by default. The rule governs where the logs sit, not where the analysts sit — SEBI even exempts data sent to a global SOC from data-localisation, subject to annual IT Committee review and Board approval. Our analysts are in Delhi NCR for context and response time — an operational advantage, not a legal obligation.

RBI and SEBI run their own reporting timelines in parallel — we build that evidence trail into the same case record.

Telemetry

What a BFSI estate actually feeds the SIEM

Detection quality is decided upstream, by coverage. A BFSI estate has log sources a generic enterprise does not — and one system, the core banking platform, that we deliberately monitor around rather than inside.

Core banking adjacencies

We do not tap the CBS directly; we monitor what surrounds it — ATM and POS switches, fraud and reconciliation systems, net-banking middleware and the integration layer — where anomalies surface without touching the transaction engine.

Payment systems

UPI, NEFT/RTGS, card switches and SWIFT-adjacent infrastructure: time-sensitive flows where fraud versus operational error is a correlation problem.

Trading and broking

FIX order flow, OMS/EMS logs, exchange connectivity and algo infrastructure — anomalies measured in milliseconds, with fraud patterns specific to markets.

Identity and Microsoft 365

Sign-in and audit logs, MFA fatigue, impossible travel, privilege changes — where most BFSI incidents now start, and what a firewall-anchored SOC misses.

Branch and WAN networks

Firewalls, VPN concentrators and SD-WAN across dozens or hundreds of branches, where lateral movement and shadow IT actually appear.

Endpoints and email

EDR telemetry, server event logs and the phishing channel — still the most common first move against financial-sector staff.

We run this on PrahiX Ora, on FortiSIEM, or on a SIEM you already own — including inherited deployments whose rule sets nobody has reviewed in a year.

The smaller-entity question

Market SOC or private SOCaaS — how to choose

For entities above the small-size and self-certification tiers this is a genuine choice, and the honest answer is not always “private”.

Scroll the table sideways →

Dimension Market SOC Private SOCaaS
Cost Lower entry cost; priced for the long tail of small intermediaries. Higher, quoted against your log volume and asset count.
Tuning Standardised detections for a typical intermediary estate; limited appetite for your specific applications. Detections tuned to your OMS, branch estate and identity setup, with a defined turnaround for new use cases.
Escalation Shared queues; you are one subscriber among very many. A named escalation path and a phone call for a P1, with containment authority if you grant it contractually.
Inspection evidence Standard reporting; adequate for the directed tiers it was designed for. Monthly evidence packs built to answer what an examiner asks — timelines, SLA adherence, retention proof.

If the Market SOC satisfies your obligation and your estate is simple, take it and spend the difference on remediation. If you carry payment, trading or core-banking adjacencies needing tuned detection and inspection-grade evidence, a private engagement earns its cost. We will tell you which side of that line you are on — including when it is not us.

Audit and inspection

What RBI and SEBI examiners actually ask to see

The gap between “we have a SOC” and “we can show a SOC” is where regulated entities struggle. These are the artefacts examiners and statutory auditors request; our monthly reporting produces them as a by-product of operations, not a scramble before an inspection.

  • Incident MIS with timelines — counts by severity, time-to-detect and time-to-respond with defined start and stop points, and the case trail for anything reported to CERT-In or your regulator.
  • Proof of log retention — the rolling 180 days and the region it lives in, not an assertion in a slide.
  • Coverage mapping — which log sources feed the SOC, mapped to the framework, with gaps acknowledged rather than hidden.
  • Escalation and drill records — the written matrix, who was called during real incidents, and drill results.
  • Provider due diligence — the provider’s ISO scope statement, subcontracting position, and contract clauses on response authority and exit.

Ask any provider you shortlist — us included — for a redacted sample of the monthly report before signing. “Executive dashboard” too often means a pie chart of alert volumes and nothing an examiner can use.

Why PJ Networks for BFSI

ISO/IEC 27001:2022 — with the SOC inside the certified scope

After SEBI’s June 2025 FAQ, the first filter many regulated buyers apply is the provider’s certificate — specifically its scope statement. Ours reads the way the FAQ expects: P J Networks is certified to ISO/IEC 27001:2022, with the Security Operations Centre inside the certified scope. The scope statement is available on request.

Our own analysts, in Delhi NCR

Fifty-plus in-house NOC and SOC engineers, operating since 2002. Ask us who sits in which tier and who employs them — no subcontracted tiers.

Your platform or ours

PrahiX Ora, FortiSIEM, or a SIEM you already own — we audit the inherited rule set first, because unmonitored platforms decay quietly. For Mumbai-centred BFSI estates, see SOC as a Service in Mumbai.

Evidence by default

Retention, reporting and case-trail artefacts are built into operations from day one, aligned to CERT-In, RBI, SEBI and DPDP through our compliance services practice.

Straight answers

SOC as a Service for BFSI, answered

Can an NBFC outsource its SOC under RBI rules?

Yes. The RBI Cyber Security Framework requires a Cyber Security Operation Centre under the CISO, with the L1/L2/L3 tiers set out in Annex-2, but it requires the function to exist — it does not require your employees to staff it. The same annex lists the skills, hiring and retention difficulties that make in-house operation hard. Accountability never transfers: your CISO and Board remain answerable, which is why a provider’s reporting quality matters more than its tooling.

Does SEBI allow brokers to use a third-party SOC?

Yes, explicitly. The CSCRF mandates a SOC for almost every regulated entity and offers three models: your own or group SOC, the Market SOC run by the exchanges and depositories, or any third-party managed SOC. Small-size and self-certification entities are directed onto the Market SOC; Qualified REs choose freely.

Is ISO 27001 mandatory for our SOC provider?

It depends on your category. SEBI’s CSCRF FAQ of June 2025 required third-party providers to be ISO/IEC 27001 certified for the outsourced services, with the SOC inside the certified scope. A clarification of 28 August 2025 made this “encouraged and recommended (not mandatory)” for Qualified REs; it remains mandatory for market infrastructure institutions. The practical advice is unchanged: choose a certified provider with the SOC in scope. P J Networks is certified to ISO/IEC 27001:2022 with the SOC inside the certified scope.

Should we use the Market SOC or a private SOCaaS provider?

If you are a small-size or self-certification entity, the question is answered for you — the Market SOC is the directed route and is sensibly priced. Above that tier, choose the Market SOC for a simple estate with standardised detections; choose a private engagement if you run payment, trading or core-banking-adjacent systems needing tuned detection, a named escalation path and evidence that stands up in a supervisory meeting. We will tell you honestly which side of that line you are on.

Where do our logs sit, and for how long?

In India, for a rolling 180 days, as CERT-In requires. The residency rule governs where the logs live, not where the analysts sit — SEBI even exempts data sent to a global SOC from data-localisation, subject to annual IT Committee review and Board approval. Our analysts are in Delhi NCR as an operational advantage, not a legal claim.

What evidence will we have for an RBI or SEBI inspection?

A monthly pack produced as a by-product of operations: incident MIS by severity with detect and respond timelines, the case trail for anything reported to CERT-In or your sectoral regulator, proof of 180-day retention and its region, coverage mapped against the framework, and escalation and drill records. We will show you a redacted sample before you sign.

Can you monitor the SIEM we already own?

Yes, and it is common. We operate PrahiX Ora and FortiSIEM, and we also take over monitoring on a platform you already license. We audit the inherited rule set first, because unmonitored platforms almost always carry stale detections and log sources that silently stopped reporting.

What does SOC as a Service cost for a BFSI organisation?

No honest figure exists before scoping: price follows log volume, monitored asset count and whether response authority is included. The comparison that matters is the alternative — a credible in-house three-tier roster is roughly 1.4 crore rupees a year in base salary before overheads, plus SIEM licensing and a year or more of tuning. We scope your estate and quote a specific monthly figure with that comparison beside it.

Next step

Get a scoped quote your examiner will understand

We will map your log sources and monitored assets, quote a specific monthly figure, and put the in-house comparison beside it. If the Market SOC or an in-house build is the better answer, we will say so.

P J Networks Pvt Ltd · C-160, Mayapuri Phase II, New Delhi 110064
+91 98183 61787 · sanjay@pjnetworks.com