Strategy & Governance

Managed Security

Cyber Defense

Governance, Risk & Compliance

Operations & People

Talk to us

Managed Security

A managed SOC where every alert has an action beside it.

Managed SOC services in India are frequently a shared dashboard and a monthly PDF. The measure that matters is different and much simpler: when something bad happens at 3am on a Sunday, does a human being look at it, decide, and tell you, or does it wait in a queue until Monday?

A security operations centre is people, process and tooling in that order. The platform collects and correlates; the detection content decides what is worth waking someone for; the analysts decide what it means and what to do. Buying the platform alone gets you a very expensive log archive, which is the most common outcome we are asked to fix.

We run monitoring against your environment with detection tuned to it, triage by analysts who can tell a scheduled job from a threat, and a defined escalation path into incident response when something is real. Coverage extends to cloud, identity and endpoint, because that is where intrusions now begin.

Why you need it

01 / 06

Why organisations outsource the SOC.

01

Round-the-clock coverage needs more people than you think.

Genuine 24/7 monitoring with holidays, illness and attrition covered takes eight to twelve analysts. Building that is a multi-crore annual commitment before a single tool is licensed, and attackers deliberately operate outside your working hours.

02

A SIEM without detection engineering is a log archive.

Out-of-the-box rules generate volume, not signal. Detection has to be written for your environment, tuned against your normal behaviour and maintained as that behaviour changes. It is a continuous engineering job, not an installation.

03

Alert fatigue is a security control failure.

A team that receives four hundred alerts a day stops reading them, and the one that mattered arrives in the same queue as the rest. Triage quality, how much reaches you and how much is resolved before it does, is the real product.

04

Detection is what your evidence pack is missing.

ISO 27001:2022, SOC 2 and sector regulators all expect monitoring, logging and demonstrable response. Retained logs, dated alerts and documented handling are the evidence, and they only exist if someone was collecting them.

Instrument

02 / 06

A shift, compressed.

A simulated analyst feed. Every signal carries the action beside it, because a detection nobody acts on is just a log line.

What we deliver

03 / 06

What the service includes.

01

Threat detection and monitoring

Continuous collection and correlation across endpoints, servers, network, cloud, identity providers and SaaS applications, with detection content mapped to MITRE ATT&CK and tuned against your environment rather than shipped as defaults.

02

Analyst-led triage

Every alert that fires is assessed by a person against a documented playbook. Most are closed as benign with the reason recorded; what reaches you is what needs a decision, with the investigation already done and the recommended action attached.

03

Incident response integration

Confirmed incidents move on a defined path: containment actions taken within the authority you have granted us, escalation to your named contacts, and handover into full incident response with the timeline and evidence already assembled.

04

Detection engineering

New rules written for the threats relevant to your sector and the systems you actually run, tested before deployment, and reviewed continuously as your estate changes. Coverage gaps are reported honestly rather than hidden behind an availability figure.

05

Vulnerability management

Scheduled scanning across the monitored estate, with findings correlated against exploitation activity and against what our monitoring shows is exposed, so remediation is prioritised by real risk rather than by CVSS ordering.

06

Compliance reporting

Log retention to your regulatory requirement, evidence packs for ISO 27001:2022, SOC 2 and sector-specific audits, documented incident handling records, and reporting written to be handed to an assessor without rework.

How we run it

04 / 06

From onboarding to steady state.

  1. 01

    Initial assessment

    Your estate, your existing tooling, your log sources and your obligations. We establish what can be monitored today, what is missing, and what the realistic coverage will be, stated plainly, including the parts we cannot see.

    Weeks 1-2
  2. 02

    Deployment and integration

    Log sources connected, collectors and agents deployed, cloud and identity telemetry integrated, retention configured to your requirement. Where you already own a SIEM or endpoint platform, we work with it rather than replacing it.

    Weeks 2-5
  3. 03

    Baseline and tuning

    Learning what normal looks like in your environment, tuning out the noise, and writing detection for the things that actually matter to you. This phase is the difference between a SOC that works and one that is muted within a quarter.

    Weeks 5-8
  4. 04

    Continuous monitoring

    Analysts watching the feed, investigating what fires, closing what is benign with a recorded reason, and escalating what is not. Threat hunting runs alongside, looking for what no rule caught.

    Ongoing, 24/7
  5. 05

    Incident handling

    Playbook-driven response within the authority you have delegated (isolation, account disablement, session revocation) followed by escalation to your contacts with the investigation already documented.

    On detection
  6. 06

    Ongoing review

    Monthly reporting on what was seen, escalated and closed; quarterly review of detection coverage, log source health, false-positive rates and the gaps worth closing next. Coverage is treated as something that decays and needs maintenance.

    Monthly and quarterly

Key benefits

05 / 06

What changes after.

Somebody is watching at 3am

With the authority and the playbook to contain an intrusion immediately rather than to note it for the morning, which is most of the value in the service.

The queue is trustworthy again

Analyst triage means what reaches your team is what needs a decision, with the investigation attached. Alerts that get read are worth more than alerts that are comprehensive.

Monitoring evidence assembles itself

Retained logs, dated alerts, documented handling and monthly reporting are produced as a by-product of the service and go straight into an audit file.

Tools we use

06 / 06

Named, and used on your engagement.

No “latest tech tools”. These are the ones your report will cite, alongside the manual work that a tool cannot do for you.

SIEM and analytics

  • Microsoft Sentinel
  • Elastic Security
  • Wazuh
  • Splunk

Endpoint and identity

  • Microsoft Defender for Endpoint
  • CrowdStrike Falcon
  • osquery
  • Entra ID sign-in analytics

Network and detection content

  • Suricata
  • Zeek
  • Sigma
  • YARA
  • MITRE ATT&CK

Case management and automation

  • TheHive
  • MISP
  • Shuffle
  • Velociraptor

Vulnerability management

  • Nessus
  • OpenVAS
  • Trivy
  • Nuclei

Why Aphelion

Shared

Four things you can check.

01

The work is done by people with names.

Darshap Nayak, formerly of KPMG, holds a master’s degree in cybersecurity and more than seven years in security operations. Jaimin Somani brings fifteen-plus years of academic and hands-on VAPT. Hemang Desai is an ICT network specialist from Australia. You will meet them, not a logo.

Meet the team
02

Evidence, not adjectives.

Every finding arrives with the reproduction steps, the affected asset and the fix, ranked by what it actually reaches in your environment, not by a CVSS number copied from a scanner. You get the report and the raw output, not a summary of a summary.

See how we test
03

Two offices, one practice.

Ahmedabad and Sharjah, working the same methodology on the same tooling. Indian data-residency requirements and UAE delivery are both ordinary here, and the AphelioNYX AD Pen-Test module runs entirely inside your perimeter when regulation says it must.

The platform
04

What we will not do.

Invent a statistic to make a slide land. Publish your name as a client without written permission. Print an award badge nobody awarded. Founded in 2024. We say so, and we attribute experience to the people who have it.

Ask us anything

100+ organizations secured

Across the globe, and across eight industries. We name a client only with their written permission.

  • Finance & Banking
  • Healthcare
  • Retail & E-commerce
  • Technology
  • SaaS
  • Hospitality
  • Manufacturing
  • Pharmaceuticals

AphelioNYX is SOC 2, ISO and GDPR compliant; attestations are available on request under NDA. We would rather hand you the report than print a badge.

Questions

FAQ

What clients ask about a managed SOC.

Do we have to replace the security tools we already own?
No, and we would usually advise against it. Most estates already have an endpoint platform, a cloud-native SIEM allowance, or identity telemetry that is barely being used. We integrate with what you own, tell you where the coverage gaps genuinely are, and recommend additional tooling only where a gap cannot be closed otherwise.
Is this a real 24/7 service, or an on-call rota?
It is worth asking every provider this in exactly those words, including us. Monitoring runs continuously with analyst coverage across shifts, and your contract specifies the response time by severity. Ask any provider what happens to a critical alert at 03:00 on a public holiday, and ask to see the last quarter's response times against target rather than the marketing figure.
Can you contain a threat, or only tell us about it?
Both, and you set the boundary. Many clients delegate specific containment actions (isolating an endpoint, disabling an account, revoking sessions, blocking an address) so that we act in the minutes that matter rather than waiting for someone to answer a phone. Anything outside that delegated set is escalated for your decision. The authority is written into the engagement, not improvised during an incident.
How long until we are actually protected?
Basic monitoring on core log sources typically runs within four to six weeks. Genuinely useful detection (tuned, low-noise, aware of what is normal in your environment) takes eight to twelve. Any provider promising full coverage in a fortnight is describing an installation, not a functioning SOC, and you will be muting its alerts by the second month.
What happens to our logs, and who can see them?
Retention is configured to your regulatory and contractual requirement and specified in the contract, along with data residency where that matters to you. Access is role-based and audited, analysts see only the clients they are assigned to, and the data remains yours, including on exit, where an agreed export is part of the offboarding process.

Forty-five minutes. Your environment, not a slide deck.

A personalised walkthrough and a free readiness assessment against the frameworks you are actually being asked for. Pick a time that suits you, or write to us. We reply within one business day.