Detection, investigation and response — around the clock
P J Networks is a SOC services provider in India delivering 24×7 threat detection, investigation and response for enterprises that cannot absorb downtime or a breach. We have run production security operations for Indian businesses since 2002, supporting customers across more than 50 locations nationwide.
Our SOC as a Service model gives you an enterprise-grade security operations centre without building one — an outsourced SOC with 24×7 SOC monitoring run from Delhi: no analyst hiring, no SIEM licensing, no 24×7 roster to staff. You get the outcome — threats caught, investigated and contained — on a predictable monthly fee.

Representative SOC console — severity queue, live event stream and 24-hour volume
Our SLA, by incident severity
Most Indian security providers describe response as “rapid” or “round-the-clock” without publishing a number. These are ours, by severity tier, so you can hold us to them.
Active compromise, ransomware detonation, or confirmed data exfiltration. Customer notified within 30 minutes of detection. Containment begins immediately. Status updates hourly until the incident is closed.
Confirmed intrusion attempt, privilege escalation, or malware on a production system. Customer notified within 60 minutes. Investigation opens the same hour. Status updates every two hours.
Suspicious activity requiring analyst review, policy violation, or an isolated non-production detection. Customer notified within four hours. Status updates every four hours during business hours.
Informational detections, tuning requests and routine service requests. Acknowledged within twelve hours and handled within the agreed maintenance window.
CERT-In reporting. Indian organisations are required to report specified cyber incidents to CERT-In within six hours of noticing them. Our P1 and P2 timelines are set so that the evidence you need for that filing exists well inside the window. See our compliance services.
P1 critical incident — detection to CERT-In-format report
P1 critical incident — detection to CERT-In-format report
Why Indian enterprises choose managed SOC services
Building an in-house SOC means recruiting eight to twelve certified analysts to cover round-the-clock shifts, licensing and tuning a SIEM platform, and absorbing twelve to eighteen months of ramp-up before the first reliable detection. For most Indian enterprises that maths never works.
What our SOC services include
24x7x365 threat monitoring
Continuous monitoring across endpoints, servers, network devices, firewalls and cloud workloads. Our analysts work in shifts so there is never an unwatched hour, including national holidays.
Log collection, correlation and retention
Centralised ingestion with correlation rules tuned to your environment rather than generic vendor templates. We operate FortiSIEM and PrahiX ORA. See our SIEM services.
Automated response
Playbook-driven automation contains routine threats in seconds instead of waiting on a human queue, keeping analyst attention on incidents that need judgement. See our SOAR services.
Managed detection and response
Beyond alerting. We investigate, validate and actively respond, so you receive confirmed incidents with actions already taken rather than a backlog. See our MDR, EDR and XDR services.
Proactive threat hunting
Analyst-led hunts for adversary behaviour that automated rules miss — living-off-the-land techniques, lateral movement, credential abuse and dormant persistence. Detection engineering is mapped to MITRE ATT&CK.
Incident response and forensics
Defined escalation paths and containment procedures. When something real happens you have a named team already familiar with your environment, not a consultant learning it under pressure.
SOC services for regulated Indian industries
Banks, NBFCs and fintech
The RBI cyber security framework requires continuous surveillance and defined incident reporting timelines, and SEBI’s CSCRF places comparable obligations on market participants. Our SOC is built to produce the evidence these audits demand, not just the alerts.
Manufacturing and OT
Converged IT and OT monitoring for plants where a security incident halts production. See our OT and ICS security services.
Healthcare and pharmaceuticals
Patient data protection under the DPDP Act 2023, with detection tuned for the clinical systems and connected medical devices these environments run.
IT, ITES and SaaS
Multi-tenant cloud monitoring across AWS, Azure and GCP. See our cloud security services.
24x7x365 — never an unwatched hour
Our analysts work in shifts so detection never pauses, including national holidays.
How we get you monitored
- Discovery — we map your estate: assets, log sources, crown-jewel systems and compliance obligations.
- Deployment — collectors and agents deployed, log sources connected.
- Tuning — correlation rules tuned to your baseline so false positives do not drown real signal.
- Go live — 24×7 monitoring begins with agreed escalation paths and the SLA tiers above in force.
- Continuous improvement — monthly reviews, rule refinement and threat landscape updates.
Two decades of Indian security operations
- Operating since 2002 — more than two decades securing Indian enterprises.
- 50+ locations served across India.
- Fortinet MSSP Partner with NSE-certified engineers, plus Cisco, Dell, Netskope and Trellix alliances.
- PrahiX Implementation Partner — platform expertise at implementation depth, not reseller familiarity.
- India-based operations — CERT-In requires your security logs to be retained for 180 days within Indian jurisdiction, and ours are. Our analysts are in Delhi too, which helps response time and context — though to be precise, that part is an operational advantage rather than a legal requirement.
- NOC and SOC under one roof — network and security operations from a single provider, so nothing falls between two vendors. See our NOC services.
L1, L2 and L3 — the tier model the RBI actually specifies
Buyers evaluating an outsourced SOC often ask what the analyst tiers mean, as though it were vendor jargon. It is not. The Reserve Bank of India set the structure out itself, in Annex-2 of its Cyber Security Framework (RBI/2015-16/418), under the heading “Setting up and Operationalising Cyber Security Operation Centre (C-SOC)”.
L1 — round-the-clock monitoring
The RBI describes “Level 1 monitoring by adequately trained staff working round the clock”. In practice: watching the queue, validating alerts, discarding noise and escalating what is real. This is the tier that makes 24×7 expensive, because it needs bodies on a roster, not just skill.
L2 — investigation and containment
“Highly trained staff in specific areas”. These analysts correlate across sources, decide whether something is an incident, and take containment decisions. On our SLA it is an L2 analyst who validates a P1 and opens the case inside fifteen minutes.
L3 — hunting and forensics
The RBI is specific here too: “deep packet analysis, collection of IOC, forensic knowledge… malware reverse engineering”. This is the tier almost nobody staffs in-house, because you cannot keep a reverse engineer busy or interested on a single estate.
When you buy a managed SOC you are buying all three tiers on a shared roster. That is the actual economics of it: the rare skills are affordable because they are spread across many customers, not because anyone is cutting corners.
The RBI itself lists why banks struggle to run their own SOC
This is worth quoting because it is unusual: the same annex that mandates the C-SOC also enumerates why institutions find it hard to operate one. The RBI names specialised skill-set requirements, difficulty finding experienced staff, training that is expensive and time-consuming, the problem of designing suitable compensation, and difficulty retaining staff once trained. It goes as far as asking whether each bank needs to set one up independently or whether a consortium approach should be considered.
We are not going to pretend that is an endorsement of us specifically. But it is a regulator, in writing, describing exactly the problem a managed SOC exists to solve — and it is a more credible framing of the build-versus-buy question than anything a vendor could write.
Market SOC, managed SOC and the CSCRF
SEBI’s Cyber Security and Cyber Resilience Framework, issued 20 August 2024, requires security monitoring through a SOC — and explicitly permits that SOC to be a third party’s. Regulated entities may use a Market SOC (M-SOC), a third-party managed SOC, or in the case of smaller entities a group or global SOC. Outsourcing is a sanctioned model, not a workaround.
Your provider’s ISO 27001 scope
The CSCRF requires that where the SOC is outsourced, the provider holds ISO 27001 covering those services. Many providers hold a certificate scoped to a corporate function and nothing else. Ask for the certificate and read the scope statement.
ISO/IEC 27001:2022, SOC in scope
P J Networks is certified to ISO/IEC 27001:2022 with our Security Operations Centre operations inside the certified scope. The certificate is available on request, scope statement included.
What the auditor will ask for
Monitoring coverage, log retention, incident records and reporting timelines. We produce these as a matter of course rather than assembling them the week before an audit. See our compliance services.
The six-hour clock, and why detection decides whether you meet it
CERT-In requires specified incidents to be reported within six hours of noticing them, and security logs to be retained for 180 days within Indian jurisdiction. SEBI, IRDAI and the Department of Telecommunications have each adopted the same six-hour window for their sectors.
The trap is in the word “noticing”. The clock does not start when you confirm a breach; it starts the moment the organisation becomes aware something is wrong. An organisation that finds out on day nine from a customer has not been given nine days of grace — it has simply failed the obligation and now has six hours. Which is why reporting deadlines are, in practice, a detection problem. We map every deadline to its instrument in our guide to cyber incident reporting in India.
What managed SOC services cost in India, honestly
Nobody publishes a number, and we are not going to pretend a single figure exists either — pricing follows log volume, monitored assets, and whether you want monitoring only or full response. What we can do is be straight about the shape of the decision.
An in-house SOC costs you eight to twelve analysts for genuine 24×7 shift cover, a SIEM licence, threat-intelligence subscriptions, and twelve to eighteen months before the first reliable detection. A managed SOC replaces the headcount and the licence with a predictable monthly figure, and starts detecting in days. Below roughly fifteen to twenty monitored servers the outsourced option almost always wins on cost alone; above that the argument shifts from price to coverage, escalation and staff attrition — the things that actually break in-house SOCs.
We will scope your estate and give you a specific monthly figure with the in-house comparison alongside it, rather than a range designed to start a negotiation.
Frequently asked questions
What is SOC as a service (SOCaaS)?
SOC as a service is a security operations centre delivered as a subscription rather than built in-house. The provider supplies the analysts, the SIEM platform, the threat intelligence and the 24×7 roster; you get monitored, investigated and contained incidents on a monthly fee. It is the same function a bank builds internally, sized and priced for organisations that cannot justify eight to twelve analysts of their own.
Can a SEBI or RBI regulated entity outsource its SOC?
Yes, and SEBI says so explicitly. The CSCRF permits a Market SOC (M-SOC), a third-party managed SOC, and for smaller regulated entities a group or global SOC. The RBI’s framework requires a C-SOC under the CISO and does not prohibit the function being operated by a partner. The requirement that catches people out is SEBI’s: where the SOC is outsourced, the provider must hold ISO 27001 covering those services. We are ISO/IEC 27001:2022 certified with our SOC inside the certified scope.
What is the difference between L1, L2 and L3 SOC analysts?
L1 monitors round the clock, validates alerts and escalates what is real. L2 investigates, correlates across sources and makes containment decisions. L3 does the deep work — packet analysis, indicator collection, forensics and malware reverse engineering. This is not vendor jargon: the tiers are described in Annex-2 of the RBI’s Cyber Security Framework. The reason most organisations struggle in-house is L3, which is expensive to hire and impossible to keep busy on one estate.
How much do managed SOC services cost in India?
It depends on log volume, the number of monitored assets and whether you need monitoring only or full response with containment. What we will tell you is that below roughly fifteen to twenty monitored servers, outsourcing beats hiring on cost alone; above that, the deciding factors become 24×7 coverage and staff retention rather than price. We scope your estate and quote a specific monthly figure with the in-house comparison next to it.
Do our logs stay in India?
Yes. CERT-In requires security logs to be retained for a rolling 180 days within Indian jurisdiction, and we retain them accordingly, in India, by default. Worth separating from a claim you will hear elsewhere: the residency requirement is about where the data sits, not where the analysts sit. SEBI explicitly permits a group or global SOC. Our analysts happen to be in Delhi, which helps response time and context — but we will not tell you it is a legal requirement.
Can you monitor the SIEM we already own?
Yes, and it is a common arrangement. We operate FortiSIEM and PrahiX Ora, and we also take over monitoring on a SIEM you already licensed. We audit the existing rule set first, because inherited platforms almost always have detections nobody has reviewed in a year and whole log sources that stopped reporting without anyone noticing.
What is a SOC service provider?
A SOC service provider operates a security operations centre on your behalf, supplying the analysts, SIEM platform, threat intelligence and 24×7 processes needed to detect and respond to cyber threats, delivered as a managed service.
How much do SOC services cost in India?
Pricing depends on log volume, the number of monitored assets, and whether you need SIEM monitoring only or full MDR with active response. It is consistently well below in-house cost, which requires eight to twelve analysts plus platform licensing before any detection happens. Contact us for a scoped quote.
What is the difference between SOC as a Service and MDR?
SOC as a Service delivers a complete security operations function including compliance reporting and log management. MDR focuses specifically on detecting and responding to threats across endpoints and networks. Most organisations need both, and we deliver them together.
Do you provide SOC services outside Delhi?
Yes. Our SOC delivers remotely across India and we support customers at more than 50 locations nationwide, including Mumbai, Bangalore, Hyderabad, Chennai and Pune.
Does your SOC help with CERT-In compliance?
Yes. CERT-In directions carry specific obligations including 180-day log retention and a six-hour incident reporting window. Our SOC is configured to meet both.
Can you work alongside our existing IT team?
Yes. Most clients run a co-managed model where we handle 24×7 monitoring and escalate confirmed incidents to their internal team.
Built on the platforms your estate already runs
Fortinet MSSP Partner with NSE-certified engineers, plus Cisco, Dell, Netskope and Trellix. See our technology partners.






Stop watching alerts. Start catching threats.
Speak to our team about a scoped assessment of your environment.



