As cyber threats intensify, mid-market enterprises need scalable security without building everything in-house. explores managed security, AI-augmented SOCs, human oversight and partner-led cyber defence.

As cyber threats become more sophisticated, mid-market enterprises face a difficult equation: they need stronger security capabilities but cannot always build and sustain the people, tools and infrastructure required to operate them. Managed security services are emerging as one way to bridge that gap. At the same time, AI is reshaping the SOC, improving detection and response while keeping human judgement central to security decisions.
In this conversation, Dipesh Kaura, Country Director, India and SAARC, Securonix and Ajay Baliram Sawant, Chairman and Managing Director, Orient Technologies, examine the business value of cybersecurity, the evolution towards AI-augmented SOCs, and how the Securonix-Orient partnership aims to extend cyber defence capabilities through a wider partner ecosystem.
CIO&Leader: Mid-market organisations often struggle to justify cybersecurity investments because they cannot be certain about the ROI, while the threat landscape continues to evolve. How should organisations look at the commercial value of cybersecurity?
Ajay Baliram Sawant: You need to defend the organisation at every level, taking into consideration both technology and the commercial aspect, including ROI. Most mid-market customers are hesitant to make major investments because they know that however much they invest, they can never be 100% secure. There is still an iota of doubt because attackers are becoming smarter.
The way technology vendors are using AI, attackers are also using AI for the wrong purposes. We need to prevent that from impacting customers because their brand equity is at stake.
There are also regulatory risks. SEBI has guidance that if somebody is attacked, including in a ransomware incident, the organisation has to inform investors within six hours. Downtime and business resilience are other risks that need to be considered when assigning commercial value to cybersecurity.
You cannot always put an exact cost on these risks. That is what insurance is about. We take life insurance considering the value of our life, and I relate insurance and security on the same platform. The value that cybersecurity brings to the table is immense until an incident happens.
Till the time you are protecting the organisation, it may appear to be an expense. But it is actually a long-term investment to protect the brand.
CIO&Leader: What changes for mid-market customers as cyberattacks become increasingly inevitable?
Dipesh Kaura: It is not about whether a customer is going to get attacked; it is about when. Everybody accepts that sooner or later there will be a situation where an organisation faces a cyberattack.
The mid-market faces two major challenges. First is hiring resources and creating an army of people to monitor a large number of devices. That is neither easy nor economically viable. If a customer has to buy five or six tools, install and operate them, it could take a year or a year and a half. During that period, the organisation continues to operate within a window of risk.
The second challenge is maintaining specialised resources when cybersecurity is not the organisation’s core business.
This is where an MSSP, or managed security services provider, can help. An MSSP can provide a cyber defence strategy and roadmap based on the customer’s existing cyber maturity, allowing the organisation to start from where it is and scale its capabilities over time.
Cyber defence involves endpoint tools, server protection, proxy, identity and access management, DPDP compliance and other technologies, all of which need to be monitored through a SOC. Orient provides both the technology and the SOC services, bringing the tools, people and operational capability together.
For a mid-market customer, this means cybersecurity does not have to become a business disabler. The customer gets access to specialised capabilities without having to build the entire function internally.
CIO&Leader: Orient is also an active service provider. As you expand the regional business, how do you reassure regional system integrators and MSSPs that Orient is there to enable them rather than compete for their end accounts?
Ajay Baliram Sawant: There are two go-to-market approaches with Securonics: partner engagement and customer engagement.
Every partner has its own set of customers, just as Orient has its own customer base. The market is large enough that most of us do not even know each other’s customers. We are also in a world where collaboration plays a very important role.
In 2011, when AWS was not yet in India, Orient, along with 15 partners who were competitors in different states, came together and formed a company called All Time IT and started our FE Cloud services. At that time, people used to ask whether cloud was real.
Fifteen partners from different states came together, and I chaired that meeting. We developed a value proposition to start our own cloud and, on 11-11-2011, started All Time IT under the FE Cloud brand. That is how we started our cloud services.
CIO&Leader: Looking 12 months to two years ahead, what specific metrics will determine the success of this partnership?
Dipesh Kaura: One of the key problems in cyber defence today is the availability of quality resources. That is where Orient’s influence comes in. As Ajay mentioned, Orient has 1,200 qualified technical people.
The immediate agenda between Securonics and Orient is to get at least the first 150 people trained over the next one to one-and-a-half years. Once those 150 people are Securonics-qualified, they become an extended team for Securonics from a technology standpoint.
The second aspect is go-to-market. Orient has its own customer base and reach, while Securonics brings its global capabilities and methodologies. Combining the two creates an opportunity to expand the technology’s reach in the Indian market.
The third challenge for any OEM in India is covering the length and breadth of the country. Hiring 50 to 100 people to establish that presence could itself take one-and-a-half to two years. Our association with Orient provides that reach immediately because Orient is already present across the country. We need to enable them from the sales, pre-sales and technology perspectives.
A significant investment has also been made by Orient in creating a state-of-the-art SOC in Mumbai. We are looking at that SOC as a centre of excellence, where customers and partners can access the required capabilities.
Ajay Baliram Sawant: We are investing heavily in three areas: building the SOC, skilling the people who operate it and establishing the right processes. Tools and people are one aspect, but if you have the right processes, everything comes together.
Dipesh Kaura: So it is essentially people, process and technology being synchronised in one direction by two organisations that have the same objective.
CIO&Leader: How does this partnership create opportunities for smaller system integrators and MSSPs?
Dipesh Kaura: The mid-market is catered to by many smaller partner communities. These partners have an opportunity, but they also have capability constraints. They have less access to tools, limited financial resources and do not have a large technology workforce.
When a brand like Orient sits behind these system integrators and smaller, or Tier-2, MSSPs, they can leverage this equation and take it to their customers.
From Orient’s perspective, it is our value-added distributor role. The transaction would be routed through Orient, so there is no commercial advantage for Orient to disrupt that deal and take it directly.
We are creating a country-level support engine where direct customers and partners entering this business can access best-of-breed capabilities. Our scale also allows partners to access technology more economically than if they were making the investments independently.
We are becoming more partner-focused and moving towards a value-focused model through the channel. The partner gets advantages in terms of cost, support, technology and reach. Most importantly, the partner community can grow its business with Orient backing it, with Securonics providing the technology.
This is about changing the dynamics of the market. This business is about collaboration and synergies.
Ajay Baliram Sawant: SOC business is not easy. The break-even happens only after 18 to 20 months, and ROI comes after three years. That is how the SOC business works.
Coming back to economies of scale, we want to make this business easier for partners. They should be more willing to work with Orient so that they do not have to reinvent the wheel.
That is the strength of the partnership between Securonics and Orient, and it can help both partners and customers.