PrahiX

Security operations

How to evaluate SOC service providers.

Comparing SOC (security operations centre) service providers in India is hard because every proposal uses the same words — 24x7, SIEM, threat intelligence, SLA — for operations that behave very differently at 3am. The separation shows up in a handful of questions: whether the SLA covers response or only notification, what the provider is authorised to contain without waking you, where your logs physically live, who owns the tooling, and what leaving would actually take. This guide walks through those questions and ends with the full checklist.

Why provider lists don't settle it

Search for SOC providers in India and you will find ranked lists. They are useful for building a longlist and useless for choosing, because they rank marketing reach, not operational behaviour. Two providers can sit beside each other on the same list while one runs genuine detection engineering and the other forwards alerts from a tool you could have bought yourself. The only way to tell them apart is to ask questions whose answers are hard to fake — and to ask every shortlisted provider the same ones, so the answers are comparable.

Does the SLA cover response, or only notification?

This is the widest gap in the market. Many services are contractually complete once they have told you about an incident — the SLA clock stops at notification, and containment is your problem at whatever hour it lands. A response SLA keeps the clock running until something has actually been done: a host isolated, a token revoked, an address blocked. Read the SLA for the verb it commits to. If the commitment is to inform, the overnight shift you are paying for is a messenger, not an operation.

What is the provider authorised to contain?

Response authority is agreed, not assumed. A capable provider will ask you, during onboarding, which containment actions may run unattended, which need approval, and which stay advisory — per action type and per environment. Be wary of either extreme: a provider that wants no authority at all is planning to notify and step back, and one that wants blanket authority on day one has not thought about your change-control. The right answer is a documented authority matrix that starts conservative and widens as trust builds.

Where do your logs live, and who can produce them?

India's CERT-In directions require covered organisations to report listed cyber incidents within six hours of noticing them, and to enable logs across ICT systems and retain them for a rolling 180 days. When an incident report is due, the logs behind it must be producible quickly — so log custody is an operational question, not a paperwork one. Ask where your log data is stored, in which jurisdiction, how fast the provider can hand it to you or to an auditor, and what happens to it at contract end. A provider who hesitates on any of those has answered the question.

  • Which jurisdiction holds the logs, and can Indian-jurisdiction storage be committed to in writing?
  • How quickly can raw logs for a given period be exported on request?
  • Is 180-day rolling retention included in the base price, or an extra?
  • What is deleted, returned or transferred when the contract ends?

Who owns the tooling — and what happens when you leave?

In some engagements you license the SIEM and the provider operates it; in others the platform belongs to the provider and you subscribe to the outcome. Both models work, but they fail differently at exit. If the tooling is yours, you keep the detections and the history but must re-staff the operation. If it is theirs, ask before signing: which detections, dashboards, incident timelines and tuning survive a migration, and in what format? An engagement you cannot leave without starting from zero is priced with that lock-in included, whether or not it appears on the quote.

Fully managed or co-managed?

If you have no security analysts and no plans to hire, a fully managed service is the honest fit. If you have a team you want inside the loop — working investigations on the provider's platform, keeping business context and approvals in-house while the provider carries the platform and the overnight watch — you are describing a co-managed SOC, and you should evaluate providers on how well they support that model rather than whether their brochure mentions it. Ask to see the actual console access your analysts would get, not a screenshot.

Reporting cadence, and what an escalation contains

Ask for a sample escalation from a real (redacted) incident and a sample of the monthly report. A good escalation arrives with context — what fired, what was correlated, severity, what was already contained, and a recommended next action. A good monthly report shows trends, tuning decisions and false-positive rates, not a page count of alerts. Providers are proud of these artefacts when they are good; reluctance to show them is a signal in itself.

The checklist, in one place

Put every shortlisted provider through the same ten questions and score the answers side by side.

  • Does the SLA commit to response, or only to notification?
  • Which containment actions can run unattended, and how is that authority agreed?
  • Where are our logs stored, and in which jurisdiction?
  • Can 180-day rolling retention and rapid export be committed to in writing?
  • Who owns the SIEM and detections — and what leaves with us at exit?
  • Is co-managed access to the platform available for our analysts?
  • Are detections mapped to a published framework such as MITRE ATT&CK?
  • What does a real escalation look like — show one, redacted?
  • Which compliance reports come out of the box — CERT-In, RBI, SEBI CSCRF, DPDP?
  • What exactly drives the price up or down as our estate changes?

Where a platform-led provider differs

One structural difference worth understanding as you compare: some providers assemble their service from licensed tools, while others run their own platform. PrahiX sits in the second camp — SIEM correlation and SOAR response are one system rather than an integration, and network, security and camera telemetry share a single timeline. That model is not automatically better for every buyer, but it changes several checklist answers at once: there is no separate SIEM licence in the price, and the exit question becomes about exporting your data and history rather than untangling shared tooling. Whoever you evaluate, make them place themselves on this map.

Have Questions? We've Got Answers.

Three is usually enough to see the market's range without drowning the evaluation. Use published lists to build the longlist, then cut to providers who will answer the operational questions — SLA verb, containment authority, log custody — in writing before you sit through a demo.

Whether the SLA covers response or only notification. It is the fastest way to separate an operation from an alert-forwarding service, and the answer reshapes how you read everything else in the proposal, including the price.

The labels overlap and vendors use them loosely, so evaluate the behaviour rather than the category. An engagement that manages your devices and forwards alerts is an MSSP pattern whatever it is called; one that owns detection, triage and response end to end is SOC as a Service. The checklist questions work on both.

Normalise them against the same variables: data volume ingested, endpoints and users covered, retention period, whether response is included or advisory, and SLA tightness. A quote that looks cheap usually differs on one of those five — most often retention or response scope — rather than on efficiency.

The CERT-In directions require logs to be enabled and retained for a rolling 180 days and expect them to be maintained within Indian jurisdiction, with published FAQs adding qualifications for some scenarios. Regulated sectors can carry stricter expectations of their own. The practical evaluation question is whether the provider will commit in writing to the residency your obligations require — not whether their default happens to match.

Keep reading

Want our answers to these ten questions?

Put the checklist to us. Tell us what you run and we will answer every question in writing — then show you the platform doing the work on a slice of your own estate.