Cybersecurity
SOC as a Service in India: A Guide for Firms
Affix Center · · 6 min read

Most Indian companies now run firewalls, antivirus and cloud services that produce thousands of security alerts and log entries every day. The problem is that nobody watches them in real time. Alerts pile up in consoles, and an intrusion is often found weeks later by a customer, a bank or an auditor. SOC as a service in India has grown because very few mid-sized firms can staff a 24x7 security team on their own.
A Security Operations Centre (SOC) is the team, process and tooling that monitors your systems around the clock, investigates suspicious activity and helps you respond. With SOC as a service, a provider runs this for you from its own facility. This guide explains what a managed SOC includes, how it links to Indian compliance duties, how to evaluate providers and how to prepare your organisation.
What SOC as a Service Actually Includes
Offerings vary, but a complete service usually covers these parts:
- Log collection: Gathering logs from firewalls, servers, Active Directory, endpoints, email, cloud platforms and key applications.
- SIEM platform: A Security Information and Event Management tool that stores logs and correlates events to spot attacks.
- 24x7 monitoring: Analysts who review alerts in shifts, including nights, weekends and holidays.
- Triage and investigation: Separating real threats from false positives and working out what happened.
- Incident response support: Clear guidance or hands-on action to contain an attack, such as isolating a laptop or disabling an account.
- Threat intelligence: Feeds and rules updated for new attack methods.
- Reporting: Daily or weekly summaries, monthly reviews and evidence for audits.
Some providers also include endpoint detection and response (EDR) tools, vulnerability scanning and dark web monitoring. Ask for a written list of what is and is not covered.
Why Indian Organisations Are Moving to a Managed SOC
Regulatory pressure
The CERT-In directions issued in April 2022 require covered entities to report specified cyber incidents within six hours of noticing them, and to keep ICT system logs for 180 days within India. You cannot report what you have not detected, and you cannot produce logs you never collected. A SOC helps with both.
Sector regulators add their own expectations. For example, SEBI's Cybersecurity and Cyber Resilience Framework (CSCRF), issued in August 2024, expects regulated entities to have security operations centre capability, whether their own, shared or through a third party. Banks, NBFCs and insurers have similar requirements from their regulators. The Digital Personal Data Protection Act, 2023 has also been passed, with detailed rules awaited, which adds focus on protecting personal data from breaches.
Cost and talent
Running an in-house SOC means buying a SIEM, hiring at least five to eight analysts to cover shifts, training them and retaining them in a competitive market. For most mid-sized firms in Mumbai or Pune, this is hard to justify. A managed SOC spreads the cost of tools and people across many clients.
Speed
A provider with an existing platform and playbooks can usually start monitoring your key systems within weeks, not the months needed to build a team.
Fully Managed, Co-Managed or In-House?
There are three common models. In a fully managed SOC, the provider owns the tools and people, and your team receives alerts and reports. In a co-managed SOC, your staff work with the provider, often handling day-shift investigation while the provider covers nights and weekends. An in-house SOC gives the most control but needs the most investment. Many firms start fully managed, then move to co-managed as their own security skills grow. Choose the model based on your risk, budget and how much internal expertise you can realistically keep.
How to Evaluate SOC as a Service Providers in India
Use this checklist when you compare proposals:
- Data location: Where will your logs be stored and processed? Confirm that storage meets CERT-In and any sector rules on keeping data in India.
- Coverage: Which log sources are included in the base price? Cloud workloads, Microsoft 365 or Google Workspace, and OT systems are sometimes extra.
- Response times: What are the committed times to acknowledge, investigate and escalate critical alerts? Get these in the contract, not just the brochure.
- Response scope: Will the provider only notify you, or can it take approved containment actions?
- Analyst depth: Ask about tiered analysts, escalation paths and who you can call at 2 am.
- Tuning: How will they reduce false positives during the first months?
- Reporting and audits: Can they provide the reports your auditors, board or regulator ask for?
- Exit terms: If you leave, will you get your logs, rules and incident history back in a usable format?
Pricing is often based on the number of devices, users or log volume per day. The cost depends on the log sources, retention period, response scope and whether tools such as EDR are bundled. Ask each provider to price the same scope so you can compare fairly.
Preparing Your Organisation Before Onboarding
A SOC is only as good as the data it receives and the decisions your team makes. Before onboarding, do the following:
- Build an asset list: Servers, network devices, cloud accounts, critical applications and their owners.
- Enable logging: Make sure firewalls, domain controllers, VPNs and key applications actually generate and send logs.
- Sync clocks: Point all systems to a reliable time source so events can be matched correctly.
- Define escalation contacts: Named people, phone numbers and backups for each type of incident.
- Agree on playbooks: What should happen for ransomware, phishing, a compromised account or data leakage?
- Clarify reporting duties: Decide who informs CERT-In, regulators, customers and insurers, and within what time.
Your internal IT team stays involved. A SOC detects and advises, but patching, account changes and system restores are usually done by IT. Our IT operations services can take on these follow-up actions if your team is small.
Common Pitfalls With Managed SOC Services
- Monitoring only the perimeter. Many attacks start with a stolen password or a phishing email, so identity, email and endpoint logs matter as much as firewall logs.
- Ignoring the monthly review. Use it to close repeat issues, not just to read charts.
- Too many alerts, too little action. Agree which alerts need a call and which can wait for a ticket.
- No testing. Run a tabletop exercise with the provider at least once a year to check that escalation works.
Frequently Asked Questions
What is SOC as a service?
It is a managed service where an external provider monitors your IT systems 24x7, investigates security alerts and helps you respond to incidents, using its own team and tools.
Is a managed SOC suitable for small and mid-sized companies?
Yes. It is often the most practical option for firms that cannot hire and retain a round-the-clock security team. Scope can start with critical systems and grow.
Does a SOC help with CERT-In compliance?
It helps. Log collection supports the 180-day retention requirement, and fast detection supports the six-hour reporting window. Your organisation still owns the duty to report.
What is the difference between a SOC and a NOC?
A NOC (Network Operations Centre) watches uptime and performance. A SOC watches for security threats and attacks. Some providers offer both, but the skills and tools differ.
How Affix Center Can Help
Affix Center helps organisations in Mumbai and across India plan and set up security monitoring that fits their size and risk. Our cybersecurity team can assess your readiness, define log sources and playbooks, and support SOC as a service arrangements, including follow-up remediation.
To discuss round-the-clock monitoring for your systems, get in touch with us.