How we designed, deployed, and operated a 24/7 Security Operations Center that cut Vertex Financial's mean time to detect threats from 9 hours to under 4 minutes — while reducing incident response cost by 52%.
3m 40s
Mean time to detect
Down from 9 hours
38 min
P1 response time
Down from 72 hours
-52%
Cost vs MSSP
Annualized savings
0
RBI audit findings
Critical issues closed
Vertex Financial Services, a mid-market NBFC with operations across India and the UAE, was operating without a dedicated security function. Their infrastructure had grown organically — 140+ cloud workloads across AWS and Azure, 800+ endpoints, six third-party SaaS integrations handling customer financial data, and zero centralized visibility.
A failed RBI audit and a near-miss ransomware incident forced the issue. Their board gave the CIO 90 days to stand up a functioning Security Operations Center or risk losing their lending license.
They had three hard constraints:
Before buying a single tool, we mapped their actual risk surface:
Based on the risk model, we selected a stack built around open standards instead of vendor lock-in:
We built a single pane of glass on top of Wazuh:
Every detection rule had three artifacts: the rule, a runbook, and a test case. Nothing shipped without all three.
We ran a hybrid "follow-the-sun" model instead of a single 24/7 local team:
We wrote 47 SOAR playbooks that handled the high-volume, low-complexity alerts automatically — phishing triage, brute force containment, suspicious login geo-blocks, malware isolation. Analyst time is reserved for the work that actually needs a human.
The SOC doubled as Vertex's compliance engine:
Within the 90-day deadline, Vertex had a fully operational SOC. Six months in, the numbers were unambiguous:
Independent penetration testing six months post-launch rated the environment as "significantly above peer benchmark" for NBFCs of comparable size.
Most SOC deployments fail because teams buy tools before they understand their own risk. We spent the first three weeks doing nothing but mapping what actually mattered to Vertex's business. Every technology choice after that was forced to justify itself against that risk model. The result was a SOC that is smaller, cheaper, and more effective than the traditional "buy the Gartner leader and hope" approach.
"Agix delivered what three larger firms told us was impossible in the timeline. More importantly, they built us a function — not a dependency. Our team now runs the SOC day-to-day with Agix as partners, not operators." — CIO, Vertex Financial Services