Skip to content
Macksofy Technologies
IAM · PAM · SSO · Zero Trust Architecture

Identity Security & Zero Trust in India & UAE.

End-to-end identity security: IAM topology review, privileged-access (PAM) tightening, SSO / OIDC / SAML hardening, conditional-access design and a phased Zero Trust roadmap mapped to NIST SP 800-207 and India's CERT-In + DPDP authentication expectations.

800-207
NIST aligned
90 days
quick-wins backlog
8–12 wk
assessment + roadmap
Tier-0
where we start
In short

What is Zero Trust identity security?

Zero Trust identity security replaces implicit network trust with continuous verification — strong authentication, least-privilege access, and segmentation so a stolen credential can't roam freely. Macksofy assesses and builds IAM, PAM, and Zero Trust architectures aligned to the RBI IT-Governance mandate for banks and enterprises across India.

The starting position

Nobody designed this. It accreted.

On-prem AD still authoritative, Entra syncing part of the estate, a federation layer in front of SaaS, and privileged access split across vaults that different teams own. The attack paths live in the seams between them.

  • Phishing-resistant MFA on tier-0 and admin populations
  • Cut blast radius — kill standing privilege, enforce JIT/JEA
  • Pass RBI / SEBI / DPDP authentication evidence asks on first pass
  • Reduce identity-related audit findings to near-zero within one cycle
  • Cost-rationalise overlapping IAM/PAM tooling
Hybrid identity estate · where the seams are
On-prem Active Directory
Still authoritative for tier-0

Delegation, ACLs and service accounts accumulated over a decade

Entra ID
Syncs a partial estate

The sync boundary is where on-prem admin becomes cloud admin

SaaS federation
Okta or Ping in front of the app estate

Stale OAuth grants and app-to-app scopes nobody reviews

PAM vaults
Often more than one, owned separately

Dormant safes and standing admin that no single team can see whole

Paths the attack-path map goes looking for
On-prem admincloud Global Admin

Privilege inherited across the directory-sync boundary

Phished usertier-0 service account

Kerberoastable SPN with a password older than the policy that governs it

Public appadmin app

A shared OAuth client trusted by both

IT workstationOT realm

Engineering laptops domain-joined to the corporate forest

Hybrid is the norm in India, not an edge case. The assessment enumerates every identity provider, directory, federation and break-glass account before it maps a single path.

The roadmap

A Zero Trust plan that survives the change board.

Zero Trust programmes fail on sequencing, not on architecture. The first ninety days have to close real paths without needing a budget cycle — everything else follows from having proved that.

Zero Trust roadmap · by pillar
NIST SP 800-207 · CISA ZTMM
Traditional
Initial
Advanced
Optimal
Identity
First 90 days

Phishing-resistant MFA on tier-0 and every admin population

Twelve-month target

Passwordless as default, continuous risk-based re-authentication

Devices
First 90 days

Compliance signal enforced in conditional access for admin sessions

Twelve-month target

Device posture as a first-class input to every access decision

Networks
First 90 days

Tier-0 isolated, break-glass paths documented and alerted

Twelve-month target

Microsegmentation across east-west, ZTNA replacing flat VPN

Applications & workloads
First 90 days

Stale OAuth grants revoked, shared clients split by trust level

Twelve-month target

Per-app authorisation with workload identity, no long-lived secrets

Data
First 90 days

Crown-jewel stores identified and standing access removed

Twelve-month target

Classification-driven access with JIT elevation and full session record

Sequencing recommendation, not a maturity score. Where your estate actually sits on each pillar is the output of the assessment — and the 90-day column is deliberately the part that survives a change-advisory board.

Methodology

Inventory, then paths, then architecture.

In that order — a target-state diagram drawn before the inventory is a diagram of somebody else’s network.

Phase 1
Identity inventory
  • Enumerate every IdP, directory, federation and break-glass account
  • Crowdsource shadow-IAM via SaaS SSO logs + finance procurement data
  • Tier-0 / Tier-1 / Tier-2 classification of human + service identities
  • Privileged-account census — domain, cloud, app and DB admins
Phase 2
Attack-path mapping
  • BloodHound + Azure AD attack-path enumeration
  • Kerberoasting, AS-REP, ACL-abuse and constrained-delegation review
  • Cloud lateral movement — IAM trust policies, role chaining, secrets
  • SaaS-to-SaaS OAuth scope abuse and stale grants
Phase 3
Zero Trust architecture
  • Trust-boundary diagram aligned to NIST 800-207 + CISA ZTMM
  • Conditional access policy design (Entra ID / Okta / Ping)
  • Phishing-resistant MFA rollout plan — FIDO2 / passkeys / certificate-based
  • Microsegmentation design for east-west traffic
Phase 4
PAM tightening
  • Vault rationalisation across CyberArk / Delinea / HashiCorp Vault
  • JIT / JEA workflows; break-glass with dual-control + alerting
  • Service-account rotation, password-less wherever possible
  • Privileged session recording + UEBA alerting
Phase 5
Roadmap & evidence
  • 90-day quick wins backlog + 12-month maturity plan
  • RBI / SEBI / DPDP authentication-evidence pack
  • Quarterly red-team identity validation (optional retainer)
  • Board-level metrics: standing-privilege count, MFA coverage, JIT %
Three ways in

You do not have to buy the whole programme.

4–6 weeks
PAM tightening only

Vault rationalisation, standing-privilege removal, JIT and break-glass with dual control. The fastest way to cut blast radius.

8–12 weeks
Assessment + Zero Trust roadmap

Full identity inventory, attack-path map and a staged target-state architecture. Sized against roughly a 5,000-identity estate.

Retainer
Multi-year execution

Architecture advisory through a phased rollout, with optional quarterly red-team validation of the identity boundary.

Regulator mapping

Every finding lands against a control.

RBI Cyber Security Framework

Authentication and privileged-access controls mapped finding by finding, in the language the inspection uses.

SEBI CSCRF

Identity controls for market intermediaries, with the governance sign-off trail the framework expects.

DPDP reasonable security

Access control mapped to the reasonable-security-practices obligation, including processors and vendor identities.

ISO 27001:2022

A.5.15 access control, A.5.16 identity management, A.5.17 authentication information and A.8.5 secure authentication.

Engagement snapshots

Three estates, three kinds of seam.

Listed Bank

Scope · Tier-0 path mapping + PAM consolidation

Finding · Kerberoastable tier-0 service account + dormant CyberArk safes with 100+ unused admins

Standing privilege cut 78% in 60 days; clean RBI inspection

Risk severity · Critical
LMHC
B2B SaaS

Scope · Zero Trust architecture for SOC 2 + EU customers

Finding · Public-app to admin-app lateral path via shared OAuth client

Split-tenant identity model shipped pre-Series-C diligence

Risk severity · High
LMHC
Pharma manufacturer

Scope · IT-OT identity boundary for IEC 62443

Finding · OT engineering laptops domain-joined to IT AD; flat trust

Dedicated OT realm + jump-host model; USFDA-PAI ready

Risk severity · High
LMHC
Vendor-neutral

We assess first and sell nothing.

CyberArk, Delinea, HashiCorp Vault, SailPoint and Saviynt are all in the delivery toolkit and none of them pay us. The architecture comes before the shortlist, which is the only order that produces an honest shortlist.

Tools we operate
BloodHound CE / EnterprisePingCastleROADreconMicrosoft Entra ID / Azure ADOktaPing IdentityCyberArkDelinea Secret ServerHashiCorp VaultSailpointSaviynt
Indicative pricing · INR

Transparent tiers. No surprises at quote time.

Indicative price ranges based on typical Indian engagements. Final fixed-price quote within 72 hours of the discovery call.

Free 30-day retest · CERT-In format reports
Tier 01

Build

₹4L–₹8L
Initial setup · single SOC tier
  • Tooling (Wazuh / ELK / Splunk) implementation
  • Baseline detection rules
  • Runbook authoring
Request a fixed-price quote
Tier 02

Operate

₹10L–₹20L
L1 + L2 with retainer
  • Everything in Build
  • 24×7 monitoring across business hours
  • Monthly threat-hunt + posture reviews
Request a fixed-price quote
Tier 03

Resilience

Starts at ₹24L
Full 24×7 SOC + threat intel
  • Everything in Operate
  • L3 threat hunters + IR retainer
  • Annual table-top + DR drill
Request a fixed-price quote

Note · Indicative pricing in INR. Setup + 12-month operate is the most-asked combination. Custom blends available.

What clients say · Trusted India + UAE

Rated 4.9 ★ from 612 client reviews.

CERT-In Empanelled
Govt of India · MeitY
EC-Council ATC
Authorized Training
ISO 27001 Certified
Info Security Mgmt
We've worked with three Big 4 firms before Macksofy. None found what their team did in our payments stack. The most actionable report we've received in a decade.
AK
Aisha Khan
Information Security Manager · Listed Fintech · BKC, Mumbai
The CHFI training Macksofy delivered for our cyber cell raised investigation quality measurably. Practical, India-context-aware, and respectful of our operational realities.
RK
R. Karandikar
Cyber Cell · Maharashtra Police · Mumbai
Came in with zero security background. 5 weeks later I was running Burp Suite and Metasploit confidently. Cleared CEH on the first attempt.
VI
Vivek Iyer
DevSecOps Lead · Healthcare SaaS · Hyderabad
FAQ

Questions before the inventory starts.

Both — we start with assessment + architecture (no tool bias), then optionally help implement. Macksofy is vendor-neutral; CyberArk, Delinea, HashiCorp Vault, Sailpoint and Saviynt are all in our delivery toolkit.
Delivery footprint

Where Macksofy delivers Identity & ZT.

On-site engagements across India's BFSI, fintech, government and SaaS metros plus the UAE. Senior consultants fly from Mumbai BKC for kickoff, key reviews and exit briefings; remote weeks run through the rest of the engagement.

References & standards

Macksofy delivers this work to the following standards and regulator requirements. Definitions and controls are sourced from the issuing bodies below.

Talk to us

Get a fixed-price proposal in 48 hours.

Tell us about your security need — pentest, audit, training or a wider engagement. A senior consultant will reply within a few business hours.

CERT-In Empanelled
Information Security Auditor · India
  • CERT-In Empanelled
  • EC-Council ATC · CompTIA Authorized
  • 20,000+ professionals trained
  • India + UAE engagements