Delhi NCR · SOC at Mayapuri, New Delhi
SOC as a Service in Delhi NCR should mean more than a provider with a Delhi pin code on its brochure. Ours is a staffed operations floor in Mayapuri, New Delhi: the analysts, the shift leads and the onboarding engineers who come to your premises in Delhi, Gurgaon or Noida all work from the same address.
This page covers what buying SOC as a Service from a Delhi NCR provider actually changes: the facility you can audit in person, on-site onboarding across the NCR, a roster that never hands you off to another timezone, and CERT-In reporting handled from the same jurisdiction as your logs. The full delivery model is on our main SOC as a Service page; tiers and escalation commitments are on our SOC services and SLA page; and if you are shortlisting, see our notes on being a cyber security company in Delhi NCR and on comparing SOC service providers in India.

The facility
Come and audit the desks before you sign
Almost no provider in this market will let you do this, and we think that tells you something. Our SOC sits at C-160, Mayapuri Phase II, New Delhi — and a prospective client can book a working visit, not a demo suite.
On a visit you can watch a live queue being triaged, meet the shift lead who would take your escalation call, and check the roster on the wall against what the proposal claims. An afternoon at the facility answers questions that a hundred-page RFP response cannot.
It also settles the questions providers dodge on calls. Where do the analysts sit? Mayapuri. Who employs them? We do. Is the ISO/IEC 27001:2022 certificate scoped to the SOC or to head office? The SOC is inside the certified scope, and the scope statement is available on request. Put the same questions to every provider you shortlist; the answers — or the hesitation — will do the shortlisting for you.
On the ground
On-site onboarding and reviews, across the NCR
Detection quality is decided in the first weeks, and the first weeks go better in person. Our engineers run the log-source workshop at your premises, sit with your network team at the firewall and directory, and leave with a source list that reflects your estate, not a template.
Delhi
Head-office estates, government and PSU offices, and the Okhla and Bawana industrial units. Onboarding workshops, tabletop exercises and quarterly reviews on-site; the SOC itself is minutes away in Mayapuri.
Gurgaon
BFSI back offices, GCCs and SaaS-heavy estates along Cyber City and Golf Course Road. Identity and Microsoft 365 telemetry dominate here; the log-source workshop focuses on sign-in audit trails and conditional access before firewalls.
Noida & Greater Noida
Manufacturing, media and data-centre-heavy estates in Sectors 62–63 and along the Expressway. These often include OT-adjacent segments needing careful separation of plant telemetry from IT logs.
Faridabad
Manufacturing and engineering units on the industrial belt. On-site onboarding covers the mixed estates typical here — older Windows servers, flat networks and ERP systems never designed with logging in mind.
Ghaziabad
Warehousing, logistics and manufacturing along NH-9 and Sahibabad. Same terms as the rest of the NCR: on-site onboarding, operations from Mayapuri, quarterly reviews in person.
Everywhere else in India
The SOC operates remotely for estates outside the NCR with the same roster and SLA. What the NCR gets extra is proximity — workshops, reviews and incident coordination on-site.
Quarterly reviews are held at your office by default for NCR clients, with the analyst who works your estate in the room — not an account manager reading a deck.
What we watch here
The NCR estate mix, and what each feeds the SIEM
Delhi NCR is not one kind of estate. What a PSU office sends the SIEM has little in common with what a Manesar plant or a Gurgaon back office sends — and detection content that ignores that fills the queue with noise that hides the alert that mattered.
Government & PSU offices
Hardened perimeters, strict change control, and audit obligations that make log integrity non-negotiable. These estates feed firewall, directory and endpoint telemetry, with the emphasis on defensible evidence: who changed what, when, and whether the log chain survives an audit. CERT-In timelines apply in full, and the paperwork discipline matters as much as the detection.
Manufacturing on the industrial belt
Okhla, Faridabad, Manesar, Noida and Ghaziabad plants bring legacy Windows, flat networks and OT-adjacent segments. What they feed the SIEM is sparse but high-signal: engineering workstations, ERP servers and the jump hosts between office and plant. Detection here is about lateral movement, not volume.
BFSI back offices
Gurgaon and Noida host operations centres for banks, insurers and NBFCs, many under RBI or IRDAI expectations through their principals. Identity telemetry dominates — sign-in patterns, privileged account use, MFA fatigue — alongside strict data-handling terms, and contractual response times are often tighter than our standard SLA.
Healthcare
Hospitals and diagnostic chains run estates where availability is a patient-safety issue, not an IT metric. Telemetry centres on imaging and lab systems, endpoint fleets and the billing data that makes healthcare a ransomware target. DPDP obligations around health data shape retention design and escalation.
The roster
The same IST desk answers at 3 a.m.
Many SOC contracts in India are delivered follow-the-sun: watched from Delhi by day, handed to another timezone at night. It is efficient for the provider, and it is where incidents get dropped — context dies at every handoff.
Our roster is staffed around the clock from Mayapuri, on IST, by our own engineers. The night shift sits in the same room as the day shift and joins the same handover meeting. When a P1 fires at 3 a.m., the person who calls you is an L2 analyst who knows your estate, your escalation matrix and your named contacts — not a duty officer reading your runbook for the first time.
The economics are worth stating plainly, because they are why most providers avoid this. One continuously covered seat is 8,760 console-hours a year; one analyst delivers roughly 1,900 productive hours; so one chair costs about 4.6 full-time equivalents, and a credible three-tier roster runs to around ₹1.4 crore a year in base salary before overheads. That is the floor for building this yourself in Delhi — and why you should ask every bidder where their night shift sits.
For incidents that outrun monitoring, the SOC escalates directly into our local incident response bench — the same building, the same timezone. Clients who want guaranteed response capacity hold an incident response retainer, so the forensic team is already contracted and briefed before the night it is needed.
Same jurisdiction
CERT-In reporting and retention, from inside the jurisdiction
CERT-In requires specified incidents to be reported within six hours of being noticed, and security logs retained for a rolling 180 days within Indian jurisdiction. The clock starts at noticing, not confirming — which makes compliance a detection problem before it is a paperwork problem.
Because the SOC, the logs and the response team all sit in New Delhi, none of this crosses a border. Logs are retained in India by default, satisfying the 180-day requirement without exceptions, and when a reportable incident occurs the report goes to CERT-In from the same jurisdiction that holds the evidence — no cross-border evidence transfer, no timezone arithmetic on a deadline measured in hours.
For DPDP Act 2023 purposes this simplifies the processor conversation: the logs never leave India and the people reading them work for an Indian company under Indian law. Sector rules — SEBI CSCRF, RBI’s Cyber Security Framework, IRDAI — layer on top, carried into the same SLA rather than a separate arrangement.
The subscription
What the monthly fee actually includes
This page is about the Delhi NCR specifics, so this section is deliberately brief: the model, tiering and honest limitations are covered in full on our SOC as a Service explainer, which this page defers to. In outline, the subscription includes:
- L1 triage, L2 investigation and L3 specialist work — forensics, malware analysis and detection engineering — on a 24x7x365 roster from Mayapuri.
- The SIEM platform — our own PrahiX Ora, FortiSIEM, or a SIEM you already own — with collection, correlation and 180-day in-India log retention.
- Threat intelligence feeds and detection content tuned to your estate during onboarding and maintained thereafter.
- A written escalation matrix with named contacts, agreed before go-live, and P1 escalation by phone call rather than email.
- CERT-In incident reporting support within the six-hour window, and quarterly service reviews at your office for NCR clients.
What it does not include by default is containment authority — isolating hosts or disabling accounts on your behalf. That is a contractual choice, agreed in writing before go-live rather than debated during an incident. If you are weighing providers, our guide to choosing between SOC service providers in India lists the RFP questions that expose a thin offering.
Getting started
Onboarding timeline for an NCR estate
For a typical mid-market NCR estate — head office, a few branches, firewalls, servers and Microsoft 365 — this is what the first eight weeks look like.
Scroll the table sideways →
| When | What happens | Where | What we need from you |
|---|---|---|---|
| Week 1 | Log-source workshop: we map your estate, agree the monitored asset list, and identify the crown-jewel systems. Escalation matrix drafted. | Your premises | Network and application owners in the room; read access to firewall and directory inventories. |
| Weeks 2–3 | Collectors deployed, first log sources ingested, connectivity and log integrity verified end to end. | Remote from Mayapuri, with on-site days as needed | A nominated engineer with change-window access. |
| Weeks 4–6 | Baselining and tuning — the noisy phase: suppressing false positives, writing estate-specific detections, calibrating thresholds against your normal traffic. | Remote | Occasional confirmation that flagged behaviour is expected business activity. |
| Weeks 7–8 | Escalation matrix signed, a live escalation drill conducted, reporting cadence agreed. Meaningful detection coverage in place. | Review at your office or ours | Sign-off from whoever owns the incident decision. |
The honest constraint is tuning, not integration speed. Any provider promising reliable detection on day one is describing alerting, not detection.
Straight answers
SOC as a Service in Delhi NCR, answered
Can we visit your SOC before signing?
Yes, and we encourage it. Our SOC is a staffed operations floor at C-160, Mayapuri Phase II, New Delhi, and prospective clients can book a working visit during a live shift: watch real triage, meet the shift lead who would take your escalation calls, check the roster against the proposal. Visits run during live operations rather than staged demos, so you see the queue as it is.
Do you do on-site onboarding in Gurgaon and Noida?
Yes. The log-source workshop, collector deployment support and quarterly reviews are all done at your premises across Delhi, Gurgaon, Noida and Greater Noida by our own engineers. Gurgaon estates typically centre on identity and Microsoft 365 telemetry; Noida and Greater Noida more often include manufacturing and OT-adjacent segments. The workshop is tailored accordingly, not run from a template.
Are our logs stored in India?
Yes. CERT-In requires security logs to be retained for a rolling 180 days within Indian jurisdiction, and we retain them in India by default — the platform, the storage and the analysts all sit in New Delhi. For DPDP Act 2023 purposes this means your logs never leave the jurisdiction, simplifying the processor terms.
Do you cover Faridabad and Ghaziabad?
Yes, on the same terms as the rest of the NCR. On-site onboarding and quarterly reviews are done at your premises in Faridabad and Ghaziabad, with 24×7 operations from our Mayapuri SOC. These estates are typically manufacturing, warehousing and logistics, so onboarding pays particular attention to legacy servers, flat networks and ERP systems with limited native logging.
What does SOC as a Service cost for a Delhi NCR mid-market company?
Any figure quoted before scoping your estate is a guess. Price follows log volume, monitored asset count and whether you are buying monitoring alone or monitoring with response authority. The honest comparison is against the alternative: a credible in-house 24×7 roster in Delhi needs roughly 4.6 full-time equivalents per continuously covered seat and runs to around Rs 1.4 crore a year in base salary before overheads, plus SIEM licensing. We scope your estate and quote a specific monthly figure with that comparison beside it.
Do you work with government and PSU estates?
Yes. We monitor government and PSU offices in Delhi, and we understand what distinguishes them: strict change control, audit-driven log integrity and CERT-In reporting obligations in full. Onboarding emphasises defensible evidence chains and formal documentation, and audit visits can be arranged at Mayapuri.
How fast can onboarding start?
The log-source workshop can usually be scheduled within a week of signing, and first log sources are typically ingested within days of that. Meaningful detection coverage takes four to six weeks, because the value comes from baselining and tuning rather than integration speed. For NCR estates the workshop and on-site deployment days happen at your premises.
Who do we call at 3 a.m.?
You do not call anyone — we call you. For a P1, an L2 analyst validates the alert and phones your named contact directly, not a shared mailbox. The analyst on the phone works from Mayapuri on the same IST roster as the day shift, knows your estate, and can bring in the incident response bench in the same building if the contract includes it. The escalation matrix — who gets called, in what order — is agreed in writing before go-live.
Next step
See the SOC before you buy it
Book a working visit to the Mayapuri facility, watch a live shift, and then let us scope your estate for a specific monthly figure. If building your own SOC is the better answer at your size, we will say so.
P J Networks Pvt Ltd · C-160, Mayapuri Phase II, New Delhi 110064
+91 98183 61787 · sanjay@pjnetworks.com
Related
Related to SOC as a Service in Delhi NCR: the full SOC as a Service model explainer, our SOC services and SLA, how to compare SOC service providers in India, our profile as a cyber security company in Delhi NCR, the incident response retainer for guaranteed response capacity, or talk to us directly. We also deliver SOC as a Service in Pune, Chennai and Hyderabad.



