The MSSP your CISO actually wants
Most Indian MSSPs sell endpoint count and SIEM licence. The CISO buying it gets a monthly invoice and a quarterly executive summary deck. What they don't get is operational SOC truth: how fast did we detect things, what did we catch that we wouldn't have caught alone, what's the false-positive rate, what's our coverage map.
Bachao.AI's MSSP delivery is built around four operational SLOs and a transparency dashboard your team accesses live. Here's how it works.
The four SLOs
| SLO | Target | Measured by |
|---|---|---|
| Mean Time to Detect (MTTD) | < 4 minutes | Detection-to-page interval, all severities |
| Mean Time to Respond (MTTR) | < 22 minutes | Page-to-containment-action interval, S1+S2 |
| Detection coverage | 90% of MITRE ATT&CK techniques applicable to your stack | Bi-weekly purple team gap analysis |
| Reporting cadence | Weekly digest + monthly board pack | Calendar-locked, not on-demand |
The 24×7 staffing model
Bachao.AI runs a 24×7 SOC out of two India locations + one APAC backup site, with the following rota:
Tier 1 analyst — 24×7 coverage, triages every detection within 4 minutes. Responsible for: confirm signal, escalate or close, document in ticket.
Tier 2 analyst — 24×7 coverage, handles S2+ escalations. Responsible for: deeper investigation, lateral movement check, containment recommendation, customer notification draft.
Tier 3 / incident commander — on-call 24×7, paged for S1 events. Responsible for: incident command, customer call lead, regulatory notification, forensic preservation.
Hunt engineer — daytime IST. Responsible for: proactive hunting (not just reacting to detections), detection rule tuning, MITRE coverage gap analysis.
Dedicated lead — your account's named SOC lead, attends monthly reviews and shapes the detection strategy specific to your business.
This is not a "shared analyst across 50 customers" model. Bachao.AI staffs tier 1 + tier 2 at a ratio that allows real human investigation, not just rubber-stamp triage.
Know your vulnerabilities before attackers do
Run a free VAPT scan — takes 5 minutes, no signup required.
Book Your Free ScanOnboarding: weeks 1–6
A new MSSP engagement runs a 6-week onboarding. Most other MSSPs go live faster, but the cost is months of false positives until tuning catches up.
Week 1: discovery and connectors
- Asset inventory (workloads, identities, network segments)
- Telemetry connector setup: CloudTrail, GuardDuty, GitHub, Okta/Workspace, EDR, k8s audit logs
- Initial detection rule deployment from Bachao's India-market library (~280 rules)
- "What's a normal Tuesday at 9am?" workshops
- Critical asset designation (which 5 systems are the company crown jewels?)
- Customer notification preferences (Slack channel, email DL, SMS escalation tree)
- Run all rules in alert-only mode
- False-positive review (every single alert reviewed with you)
- Rule disable / threshold adjustment / context enrichment
- 8–12 runbooks for the most likely incidents in your stack
- Each runbook gets a tabletop walkthrough with your team
- Containment authority pre-approved for specific actions (revoke key, isolate host, disable user)
- Bachao Red Team runs 12 simulated attacks against your environment
- SOC tier 1 must detect them in production
- Gaps logged and detection rules added
- Full production paging enabled
- First weekly digest goes out
- Monthly review cadence locked in calendar
Pricing: per-workload, not per-endpoint
Most MSSPs charge per endpoint or per GB ingested. Both incentivize the wrong behaviour (under-instrument to keep cost down).
Bachao.AI charges per workload tier:
| Tier | Workloads covered | Monthly fee |
|---|---|---|
| Startup (1 prod environment) | Up to 50 critical workloads + 200 supporting | ₹3L |
| Growth (multi-env, single product) | Up to 200 critical + 800 supporting | ₹6L |
| Enterprise (multi-product, regulated) | Up to 1,000 critical + 5,000 supporting | ₹12L |
| Custom | Above 1,000 critical workloads | Quote |
There is no per-event surcharge. No "ingestion overage." No surprise invoice in month 4.
What you receive operationally
Real-time:
- Slack/Teams channel with severity-tagged detections (S1 → @here, S2 → no ping, S3+S4 → digest)
- Live SOC dashboard (auth via Okta/Workspace)
- Incident war-room channel auto-spun for S1 events
- Detection digest (PDF) summarising all S2+ events of the week
- New detections added this week
- Tuning changes proposed
- Coverage status against MITRE ATT&CK
- Board-pack security report (8 pages)
- SLO scorecard (MTTD, MTTR, coverage, FP rate)
- Detection roadmap for the next 30 days
- Threat intelligence brief (sector-specific to BFSI, SaaS, healthtech, etc.)
- Purple team exercise (separate from monthly hunts)
- Risk register update with the vCISO if engaged
- Threat landscape brief for the board
When MSSP and vCISO bundle
Most Bachao.AI MSSP customers also retain a vCISO at a lower-tier (10–15 hours/month) for governance, compliance, and customer-facing security work. The MSSP is operational, the vCISO is strategic. Bundling them means the SOC understands the regulatory context and the vCISO has direct visibility into operational reality.
How to start
The first step is a 90-minute SOC scoping workshop. We walk through your existing telemetry, current incident history, regulatory obligations, and the right tier. Quote within 5 working days. Onboarding can start within 2 weeks of contract signature.
Schedule the SOC scoping workshop →
Related: Sample MSSP Monthly Report · MSSP Case Study: NBFC MTTR
