Managed SOC in Delhi · Government, PSU & Ministry
24×7 SOC for central government, PSU banks, ministries and Delhi-NCR fintech — CERT-In + MeitY + RBI submission-format detection content.
How a Macksofy soc + siem engagement runs in Delhi NCR.
Delhi managed-SOC demand is dominated by central-government, PSU and ministry buyers — and the central-government SOC operating model is fundamentally different from a private-sector SOC. Tendering routes through GeM (Government e-Marketplace), the Central Public Procurement Portal (CPPP), or the Defence e-Procurement portal where applicable. The buyer asks for CERT-In empanelment, GeM seller-ID, ISO 27001:2022 + ISO 9001:2015 certificates, and Indian-passport-only senior consultant deployment for defence-adjacent scope. Macksofy operates a GeM-listed managed-SOC capability with a Delhi-resident bid-desk for active tender response within the portal's 7-21 day windows.
Central-government SOC content is the headline library. The detection-content library covers MeitY / CERT-In / NCSC office continuous-monitoring expectations for ministry citizen-portal estates — citizen-portal anomaly (Hindi + Bhashini regional-language frontend abuse, citizen-data egress, role-of-officer authorisation drift), Aadhaar AUA / KUA integration anomaly (biometric-replay, eKYC consent-flow integrity, virtual-ID handling per UIDAI Authentication Regulations 2016), DigiLocker integration anomaly (OAuth scope confusion per MeitY partner-onboarding checklist), and APIGW-of-India inter-ministry consent-and-purpose-binding layer monitoring. State-government and PSU adjacencies layer in TN-eGA, Delhi-Govt-IT, AP-state-IT and Telangana-state-IT-specific content where the engagement scope crosses state-government estates.
PSU bank SOC content is the second pillar — calibrated to the heterogeneous PSU bank IT estate (Finacle + BaNCS coexisting, legacy mainframe-RACF, 4,000-15,000 branch nodes). Content covers RBI Master Direction on IT Governance (November 2023) continuous-monitoring expectations, the Department of Financial Services circular cadence, and the CAG audit overlay that drives milestone-aligned monitoring evidence packs. PSU bank SOC engagements are typically 12-24 month retainers with milestone payments tied to CAG audit cycles. Inspection-defence support is included as a base deliverable for DFS / RBI thematic-review cycles.
Defence-adjacent SOC content adds Indian-soil-only delivery and Indian-passport-only senior consultant requirements. Macksofy maintains an Indian-soil-only delivery option (no foreign-soil data egress, no foreign-passport-holder access to engagement materials) for defence-adjacent ministry, public-sector-undertaking and adjacent department engagements. Attestation that satisfies the procuring department's information-security policy is signed by an authorised Macksofy signatory. Detection-content shipment uses Indian-soil tooling and the storage configuration is Indian-soil-only.
Delhi-NCR fintech SOC content is the third pillar — same library architecture as our Mumbai and Noida fintech SOC operations. RBI Master Direction + RBI PA-PG (for the Connaught Place / Karol Bagh / Saket fintech corridor's PA-PG licensees) + RBI Digital Lending Guidelines (for the corridor's lending fintech) detection content. Aadhaar AUA / KUA / DigiLocker / account aggregator / credit-bureau integration anomaly content is shipped per the Noida combo's coverage.
DPDP Act §16 cross-border-transfer monitoring is a base deliverable. Central-government and PSU engagements rarely have cross-border-data flows but ministry-adjacent fintech, Delhi-NCR foreign-bank GCCs (where the engagement scope is mixed) and Delhi-headquartered IT-services majors have substantial cross-border-data flows. DPDP §16 monitoring covers contractual-safeguard reference, technical-safeguard verification (encryption-in-transit + at-rest with customer-managed keys), and operational evidence (egress monitoring, consent-flow integrity, withdrawal-propagation).
Tier structure is calibrated to central-government scope. Tier-1 (24×7 SIEM triage) operates from Mumbai BKC and (for Indian-soil-only delivery scopes) from a dedicated Indian-soil-only delivery floor. Tier-2 (8×5 senior analyst) operates from Mumbai BKC with a Delhi-resident embedded senior for sustained ministry / PSU bank programmes. Tier-3 (on-call DFIR specialist) mobilises from Mumbai BKC and flies BOM → DEL (2 hours) plus Aerocity → ministry / PSU bank head-office drive (30-90 minutes depending on location). Onsite SLA inside 6 hours from escalation.
Procurement reality matters. Central-government SOC engagements close through GeM reverse auction or BoQ-based bidding with the empanelment certificate + GeM seller-ID + comparable-engagement-experience as the three levers that decide L1 outcome. PSU bank SOC closes through the GM-IT + CISO + board-IT-committee secretary with CAG-aligned milestone payments. Delhi-NCR fintech SOC closes through the CTO + AppSec lead + head of compliance in faster CTO-and-AppSec-lead signoff cycles. Engagement length is typically 12-36 months for central-government / PSU programs, 12 months for Delhi-NCR fintech.
Five phases. Delhi NCR timeline.
Every Macksofy soc + siem engagement in Delhi NCR runs through the same phased protocol — adapted to Delhi NCR-specific procurement, regulator and delivery realities.
- GeM / CPPP / Defence e-Procurement bid response with empanelment certificate, GeM seller-ID and comparable-engagement list
- Joint kickoff with procuring department's IT secretary or PSU bank GM-IT + CISO
- Indian-soil-only delivery attestation + Indian-passport-only consultant deployment where required
- Tier structure agreement with CAG-aligned milestone payments for PSU bank scope
- MeitY / CERT-In / NCSC office content + state-government adjacency content for central-government scope
- RBI Master Direction + DFS circular + CAG audit overlay content for PSU bank scope
- RBI PA-PG + Digital Lending Guidelines content for Delhi-NCR fintech scope
- Aadhaar AUA / KUA / DigiLocker / APIGW-of-India integration anomaly content shipped on Day 8-21
- Baseline tuning and false-positive suppression against actual citizen-portal / PSU bank / fintech traffic
- Runbook review with the customer's IT + (where applicable) ministry / PSU bank board-IT-committee
- Go-live cutover with paired Tier-2 senior on-site for the first 72 hours at the ministry / PSU bank head-office
- First executive summary delivered at Day 30 in CERT-In / MeitY / NCSC submission-format
- 24×7 Tier-1 triage from Mumbai BKC (and Indian-soil-only delivery floor where required)
- Tier-2 threat-hunting and complex correlation 8×5 with Delhi-resident embedded senior
- Tier-3 DFIR on-call with BOM → DEL 2-hour mobilisation + Aerocity → ministry / PSU head-office drive
- Inspection-defence support for DFS / RBI / CSITE / MeitY / NCSC thematic-review cycles
- Monthly executive summary in CERT-In / MeitY / NCSC / RBI submission-format
- Quarterly board pack with CAG audit-cycle milestone alignment (PSU bank)
- Half-yearly purple-team exercise with the Macksofy red-team bench
- Annual RBI + DFS + CAG + MeitY + NCSC evidence-pack delivery for compliance team
Which Delhi NCR verticals we deliver SOC + SIEM for.
Central government departments
Citizen-portal + Aadhaar AUA / KUA + APIGW-of-India SOC monitoring with MeitY / NCSC submission-format.
Public-sector banks
Indian Bank / IOB / Bank of Baroda / Punjab National Bank-adjacent — RBI Master Direction + DFS + CAG triple-overlay monitoring.
Defence-adjacent ministries
Indian-soil-only delivery + Indian-passport-only senior consultants for defence-adjacent ministry, PSU and department engagements.
Aadhaar ecosystem actors
AUA / KUA / Sub-AUA entities — Authentication Regulations 2016 monitoring and audit-log retention evidence.
Delhi-NCR fintech & lending
Connaught Place / Karol Bagh / Saket fintech corridor — RBI PA-PG + Digital Lending Guidelines monitoring.
State PSUs (Delhi Govt)
Delhi Government IT department + DJB / DTC-adjacent IT estates — state-portal monitoring with MeitY + state-IT format.
The Delhi NCR deliverable pack.
Every Delhi NCR soc + siem engagement closes with the pack below — regulator-ready evidence, technical detail and board-readable summaries.
- 24×7 SOC operation with documented SLA per severity tier
- Vendor-native detection content shipped into the customer's SIEM
- Central-government library — MeitY / CERT-In / NCSC office continuous-monitoring use-cases
- PSU bank library — RBI Master Direction + DFS circular + CAG audit overlay continuous-monitoring
- Aadhaar AUA / KUA / DigiLocker / APIGW-of-India integration anomaly content
- Indian-soil-only delivery attestation signed by Macksofy authorised signatory
- Monthly executive summary in CERT-In / MeitY / NCSC / RBI submission-format
- Annual RBI + DFS + CAG + MeitY + NCSC evidence-pack delivery
A Delhi NCR soc + siem case study.
24×7 managed SOC across the ministry's citizen-portal (Hindi + 8 regional-language Bhashini frontends), Aadhaar AUA / KUA layer, DigiLocker OAuth integration, APIGW-of-India inter-ministry consent layer; Indian-soil-only delivery; Splunk Enterprise Security platform; MeitY / CERT-In / NCSC office submission-format evidence cycle
Six Aadhaar AUA authentication-API rate-limit-anomaly events flagged and remediated within minutes of first detection; two DigiLocker OAuth scope-confusion campaigns blocked at API boundary; three regional-language frontend abuse campaigns mitigated via Bhashini-aware filter tuning; one APIGW-of-India inter-ministry consent-and-purpose-binding-anomaly event traced to a misconfigured downstream ministry consumer and remediated through coordination with MeitY; MeitY / NCSC office monthly evidence packs accepted on first read across the engagement year.
Rated 4.9 ★ from 612 client reviews.
“We've worked with three Big 4 firms before Macksofy. None found what their team did in our payments stack. The most actionable report we've received in a decade.”
“The CHFI training Macksofy delivered for our cyber cell raised investigation quality measurably. Practical, India-context-aware, and respectful of our operational realities.”
“Came in with zero security background. 5 weeks later I was running Burp Suite and Metasploit confidently. Cleared CEH on the first attempt.”
Questions Delhi NCR buyers ask before signing.
Other Macksofy engagements in Delhi NCR.
Same engagement, other Macksofy metros.
Get a fixed-price proposal in 48 hours.
Tell us about your security need — pentest, audit, training or a wider engagement. A senior consultant will reply within a few business hours.
- CERT-In Empanelled
- EC-Council ATC · CompTIA Authorized
- 20,000+ professionals trained
- India + UAE engagements
