Skip to content
Macksofy Technologies
24×7 · CERT-In Empanelled · India Data-Residency

Managed Security Services in India & UAE.

Outsource the heavy lifting of day-to-day security operations to a CERT-In empanelled team. Managed SOC, managed EDR/XDR, managed vulnerability operations, managed identity hygiene and incident response — all under one SLA, one ticketing pane and one quarterly board report.

24×7
monitoring cover
15 min
tier-1 triage SLA
30–60d
onboarding to cover
12 mo
minimum engagement
In short

What are managed security services (MSSP)?

Managed security services outsource the day-to-day operation of your security controls — monitoring, detection, response, patching, and reporting — to a specialist provider. Macksofy runs MSSP engagements on your SIEM and endpoint stack, with SLAs and regulator-ready reporting for BFSI, fintech, and SaaS across India and the UAE.

What makes this different

An MSSP you can walk away from.

The usual MSSP trade is cheaper operations in exchange for a capability you can never take back in-house. We do not structure it that way, and the four points below are why.

You keep the SIEM

It runs in your tenancy, on your data, with detection content you own. Ending the contract does not end the capability — that is the difference between outsourcing and renting.

India data residency

For CERT-In, RBI and SEBI-regulated clients the full stack runs in-country, with data-localisation evidence produced on request.

Coverage in 30–60 days

Onboarding, not an 18-month hiring cycle. The baseline period exists so the MTTD and MTTR improvement is measured rather than asserted.

Reporting auditors accept

Monthly operations report and a quarterly business review, in the format CERT-In, RBI, SEBI, ISO 27001 and SOC 2 reviewers take as-is.

The team you are buying

Four tiers, one accountable provider.

Most mid-market teams run two to four engineers against a couple of hundred assets across cloud, on-prem and SaaS. This is the pod that sits behind them.

  • Predictable monthly cost vs. fully-loaded ₹3–5 Cr/yr for a 24×7 in-house SOC
  • Coverage maturity in 30–60 days instead of 12–18 months of hiring
  • Single accountable provider for SOC, EDR, IR, vuln-ops and reporting
  • Quarterly board pack auditors and regulators accept as-is (CERT-In · RBI · SEBI · ISO 27001)
The pod · 24×7 across four tiers
Bar width = volume reaching that tier
Tier 1Triage
15 min
  • Alert triage against the agreed runbook
  • Enrichment, dedup and false-positive suppression
  • Escalation with context attached, not a ticket number
Tier 2Investigation
30 min
  • Scoping: one host or a foothold?
  • Timeline reconstruction across endpoint, identity and cloud logs
  • Containment recommendation against pre-approved playbooks
Tier 3Detection engineering & hunting
Continuous
  • Use-case backlog worked by risk, not by vendor roadmap
  • Threat hunts aligned to your sector's actors
  • Noise tuning measured against the false-positive ratio
IR on-callIncident command
Retained hours
  • DFIR hours rolled into the contract, not quoted mid-incident
  • Forensic preservation and chain of custody where litigation is likely
  • Regulator notification support

Tier-1 and Tier-2 response times are contracted SLAs. Tier-3 and hunting run continuously against an agreed backlog rather than a clock.

Fully managed or co-managed

Keep what your team is genuinely better at.

Your engineers know which server matters at quarter-end. We know what a Cobalt Strike beacon looks like at 3 a.m. Co-managed splits on that line, and pricing scales with the split.

Responsibility split · fully managed vs co-managed
Function Fully managed Co-managed
SIEM, data and detection content ownershipYouYou
Business context and asset criticalityJointYou
Tier-1 alert triageMacksofyYou
Tier-2 investigationMacksofyMacksofy
Tier-3 detection engineeringMacksofyMacksofy
Threat huntingMacksofyMacksofy
24×7 out-of-hours coverMacksofyMacksofy
Vulnerability operationsMacksofyJoint
Containment executionJointYou
Incident command (High / Critical)MacksofyJoint
Board and regulator reportingJointJoint

No lock-in, by design · the SIEM runs in your tenancy and the rules, dashboards, historical logs and runbooks are yours. If the engagement ends, the capability stays.

How onboarding runs

Baseline first, so the improvement is measurable.

Phase 1
Onboarding & baseline
  • Asset and identity inventory · crown-jewel tagging
  • Risk baseline + control coverage gap analysis
  • SIEM / EDR / IDS / cloud-log connector mapping
  • Runbook + escalation matrix sign-off
Phase 2
Detection engineering
  • MITRE ATT&CK coverage map (current → target)
  • Use-case backlog prioritised by risk + business impact
  • Custom detection rules · noise tuning · KPI baselining (MTTD / MTTR / false-positive ratio)
Phase 3
24×7 operations
  • Tier-1 triage SLA 15 minutes · Tier-2 investigation SLA 30 minutes
  • Threat hunting cycles aligned to MITRE TTPs and your industry threat actors
  • Managed vulnerability operations: prioritisation, exception tracking, remediation chasing
  • Identity hygiene watch (stale accounts, MFA exceptions, privileged access drift)
Phase 4
Incident response on-call
  • DFIR retainer hours rolled into the MSS contract
  • Containment + eradication playbooks pre-approved with your IT team
  • Forensic preservation + chain-of-custody if litigation likely
Phase 5
Reporting & governance
  • Monthly operations report (MTTD, MTTR, top-10 risks, control gaps)
  • Quarterly business review with security leadership + finance
  • Annual program maturity assessment (NIST CSF / ISO 27001 alignment)
  • Evidence pack ready for CERT-In, RBI, SEBI, SOC 2 and ISO 27001 audits
Engagement snapshots

What the run state actually caught.

Listed NBFC (Mumbai)

Scope · 24×7 MSS across AWS + on-prem AD, 1,800 endpoints

Result · Detected and contained a ransomware-precursor (Cobalt Strike beacon) inside 22 minutes of initial access — domain compromise avoided

Critical — regulator notification not required; full forensic timeline delivered in 48 hours

Risk severity · Critical
LMHC
Fintech Lending Platform (Bengaluru)

Scope · Managed SOC + managed EDR + DFIR retainer

Result · MTTD reduced from 6.8 hours to 18 minutes over 90-day baseline period

Material — measurable risk reduction reported to board + SEBI System Audit

Risk severity · High
LMHC
Stack

Open-source where it wins. Your licences where you have them.

Wazuh and ELK carry a lot of mid-market estates well. Where you have already bought Splunk, Sentinel, QRadar, CrowdStrike or SentinelOne, we operate inside those rather than migrating you for our own convenience.

SOAR playbooks are built per client, not shipped as a template.
Tools we operate
Wazuh + ELK (open-source)Splunk · Microsoft Sentinel · IBM QRadar (client-licensed)CrowdStrike Falcon · SentinelOne · Microsoft Defender XDRTenable · Qualys · Rapid7 InsightVMTheHive + CortexMISP · OpenCTICustom SOAR playbooks
Predictable monthly retainer

Outsourced security operations, priced like a utility.

MSS pricing scales with monitored asset count, log volume and required SLA. 12-month minimum, billed monthly. Share your environment size and we’ll send a tier-based proposal within 5 working days.

What's included

What the retainer covers

  • 24×7 monitoring + Tier-1 to Tier-3 triage and investigation
  • Managed EDR / XDR + managed vulnerability operations
  • Incident response retainer hours (included)
  • Monthly operations report + quarterly business review
  • MITRE ATT&CK coverage map kept current
  • Annual program maturity assessment
  • Audit-ready evidence pack for CERT-In · RBI · SEBI · ISO 27001 · SOC 2
Industries

Sectors we operate in

Banking & Financial ServicesFintech & PaymentsHealthcare & HealthTechInsurance & InsurTechSaaS & Product CompaniesGovernment & PSUManufacturing & EnergyTelecom
What clients say · Trusted India + UAE

Empanelled by CERT-In. Accredited by EC-Council.

CERT-In Empanelled
Govt of India · MeitY
EC-Council ATC
Authorized Training
ISO 27001 Certified
Info Security Mgmt
CompTIA Authorized Partner
Training Delivery
We've worked with three Big 4 firms before Macksofy. None found what their team did in our payments stack. The most actionable report we've received in a decade.
LF
Information Security Manager
Listed Fintech · BKC, Mumbai
The CHFI training Macksofy delivered for our cyber cell raised investigation quality measurably. Practical, India-context-aware, and respectful of our operational realities.
MP
Cyber Cell
Maharashtra Police · Mumbai
Came in with zero security background. 5 weeks later I was running Burp Suite and Metasploit confidently. Cleared CEH on the first attempt.
HS
DevSecOps Lead
Healthcare SaaS · Hyderabad
FAQ

The questions procurement asks.

You own the SIEM, the data, and the detection content — always. We deploy, tune and operate it under your tenancy. If the engagement ends, you keep everything: rules, dashboards, historical logs, runbooks. No lock-in.
Inside your environment by default (your AWS / Azure / GCP tenant or on-prem datacenter). India data-residency available on demand. For regulated clients (RBI, SEBI, CERT-In), we run the full stack in-country and produce data-localisation evidence on request.
12 months. Onboarding takes 30–60 days; we want a clean baseline period to demonstrate measurable MTTD / MTTR improvement. 24- and 36-month engagements unlock discounted rates and rolled-in DFIR hours.
Yes. Co-managed SOC is common — your in-house team owns Tier-1 + business context, we own Tier-2/3 + detection engineering + 24×7 cover. Pricing scales with split.
The SOC build engagement is a one-time setup; MSS is the run-state operation. Many clients buy the build first, then transition into MSS for the operate phase. The contracts integrate cleanly.
Delivery footprint

Where Macksofy delivers MSSP.

On-site engagements across India's BFSI, fintech, government and SaaS metros plus the UAE. Senior consultants fly from Mumbai BKC for kickoff, key reviews and exit briefings; remote weeks run through the rest of the engagement.

References & standards

Macksofy delivers this work to the following standards and regulator requirements. Definitions and controls are sourced from the issuing bodies below.

Talk to us

Get a fixed-price proposal in 48 hours.

Tell us about your security need — pentest, audit, training or a wider engagement. A senior consultant will reply within a few business hours.

CERT-In Empanelled
Information Security Auditor · India
  • CERT-In Empanelled
  • EC-Council ATC · CompTIA Authorized
  • Thousands of professionals trained
  • India + UAE engagements