Identity Security & Zero Trust
End-to-end identity security: IAM topology review, privileged-access (PAM) tightening, SSO / OIDC / SAML hardening, conditional-access design and a phased Zero Trust roadmap mapped to NIST SP 800-207 and India's CERT-In + DPDP authentication expectations.
- Quote SLA48 hours
- Typical engagement5–15 working days
- RetestFree within 30 days
- Reporting formatCERT-In + ISO + SOC 2 ready
- Team100% in-house · OSCP / OSWE / OSEP
What is Zero Trust identity security?
Zero Trust identity security replaces implicit network trust with continuous verification — strong authentication, least-privilege access, and segmentation so a stolen credential can't roam freely. Macksofy assesses and builds IAM, PAM, and Zero Trust architectures aligned to the RBI IT-Governance mandate for banks and enterprises across India.
A Identity & ZT engagement, in plain language.
Most Indian enterprises run a sprawl of identity systems — on-prem Active Directory still authoritative, Entra ID syncing a partial estate, Okta or Azure AD federating SaaS, three separate PAM tools owned by three different teams, and ~40% of admin accounts shared. Macksofy enumerates every authentication boundary, maps lateral-movement paths from a phished user to crown jewels, and ships a 90-day plan that closes the worst paths first — phishing-resistant MFA on tier-0, JIT for break-glass, RBAC consolidation, and a measured Zero Trust rollout that survives contact with the change-advisory-board.
- Phishing-resistant MFA on tier-0 and admin populations
- Cut blast radius — kill standing privilege, enforce JIT/JEA
- Pass RBI / SEBI / DPDP authentication evidence asks on first pass
- Reduce identity-related audit findings to near-zero within one cycle
- Cost-rationalise overlapping IAM/PAM tooling
Phased delivery — every step documented.
Interactive walkthrough of how we run a Identity & ZT engagement — tap a phase to expand its activities.
1 · Identity inventory
- 01Enumerate every IdP, directory, federation and break-glass account
- 02Crowdsource shadow-IAM via SaaS SSO logs + finance procurement data
- 03Tier-0 / Tier-1 / Tier-2 classification of human + service identities
- 04Privileged-account census — domain, cloud, app and DB admins
Industry-standard + custom.
We use the same tooling top BFSI red teams operate — combined with Macksofy in-house extensions and proprietary scripts where commercial tools fall short.
Sectors we operate in
What you get
- Identity inventory + tiering memo
- Attack-path map with prioritised closure backlog
- Zero Trust target-state architecture diagram + 12-month roadmap
- PAM tightening plan with vault-by-vault remediation tasks
- Phishing-resistant MFA rollout playbook for tier-0
- Regulator-mapped authentication evidence pack
Anonymized engagement snapshots.
Scope · Tier-0 path mapping + PAM consolidation
Finding: Kerberoastable tier-0 service account + dormant CyberArk safes with 100+ unused admins
Standing privilege cut 78% in 60 days; clean RBI inspection
Scope · Zero Trust architecture for SOC 2 + EU customers
Finding: Public-app to admin-app lateral path via shared OAuth client
Split-tenant identity model shipped pre-Series-C diligence
Scope · IT-OT identity boundary for IEC 62443
Finding: OT engineering laptops domain-joined to IT AD; flat trust
Dedicated OT realm + jump-host model; USFDA-PAI ready
Transparent tiers. No surprises at quote time.
Indicative price ranges based on typical Indian engagements. Final fixed-price quote within 72 hours of the discovery call.
Build
- Tooling (Wazuh / ELK / Splunk) implementation
- Baseline detection rules
- Runbook authoring
Operate
- Everything in Build
- 24×7 monitoring across business hours
- Monthly threat-hunt + posture reviews
Resilience
- Everything in Operate
- L3 threat hunters + IR retainer
- Annual table-top + DR drill
Note · Indicative pricing in INR. Setup + 12-month operate is the most-asked combination. Custom blends available.
Rated 4.9 ★ from 612 client reviews.
“We've worked with three Big 4 firms before Macksofy. None found what their team did in our payments stack. The most actionable report we've received in a decade.”
“The CHFI training Macksofy delivered for our cyber cell raised investigation quality measurably. Practical, India-context-aware, and respectful of our operational realities.”
“Came in with zero security background. 5 weeks later I was running Burp Suite and Metasploit confidently. Cleared CEH on the first attempt.”
Things people ask before signing.
Often paired with this engagement.
Digital Forensics & Incident Response (DFIR)
When the worst happens, every minute matters.
Learn moreMalware Analysis & Reverse Engineering
Decode what hit you. Detect the next variant.
Learn moreNetwork Security Architecture & Segmentation
Stop east-west blast radius before the next ransomware does.
Learn moreWhere Macksofy delivers Identity & ZT.
On-site engagements across India's BFSI, fintech, government and SaaS metros plus the UAE. Senior consultants fly from Mumbai BKC for kickoff, key reviews and exit briefings; remote weeks run through the rest of the engagement.
Macksofy delivers this work to the following standards and regulator requirements. Definitions and controls are sourced from the issuing bodies below.
Get a fixed-price proposal in 48 hours.
Tell us about your security need — pentest, audit, training or a wider engagement. A senior consultant will reply within a few business hours.
- CERT-In Empanelled
- EC-Council ATC · CompTIA Authorized
- 20,000+ professionals trained
- India + UAE engagements
