Standing Up 24/7 SOC Coverage for an APAC MSSP Under MAS TRM and OJK
Standing up a new SOC operating model is straightforward; standing one up that already satisfies two regulators' expectations on day one is a different project.
What we were solving
Regional MSSP expanding coverage across Singapore and Indonesia, needing to satisfy MAS TRM (Singapore) and OJK POJK 11 (Indonesia) requirements from launch.
- MAS TRM and OJK POJK 11 have overlapping but distinct expectations for incident response timelines, evidence retention, and escalation - building for one and patching for the other later would mean rework.
- 24/7 coverage across two time zones needed a staffing and handover model that didn't lose context between shifts.
- The MSSP's clients expected audit-ready evidence from their very first incident, not after a maturity ramp-up period.
What we built
- Mapped MAS TRM and OJK requirements against each other up front to build one playbook set satisfying both, rather than a Singapore playbook and a separate Indonesia patch.
- Designed shift handover around a shared incident timeline view so context survived the change of analyst, not just the change of ticket status.
- Built evidence capture into the response workflow itself - timestamps, actions, and approvals logged as the incident happened, not reconstructed afterward for a report.
Key results
- 24/7 coverage live within one quarter of engagement start
- One playbook set satisfying both MAS TRM and OJK from day one
- First regulator review passed with zero rework on existing evidence
- Shift handovers preserved incident context across time zones
What it was built on
Representative tools and patterns — exact vendors vary per client environment.
Operations
Compliance
Platform
What we'd tell the next team
- Map overlapping regulatory frameworks against each other before building anything - a playbook built for one and patched for the other later means redoing real work.
- Evidence captured live during response is dramatically more defensible than evidence reconstructed for a report afterward.
- Shared incident timelines matter more than shift handover documents - context lives in the timeline, not the notes about it.
Questions this engagement anticipated
Why map MAS TRM and OJK together instead of building separately?
The two frameworks overlap significantly but differ in specifics like incident timelines and evidence retention - building one playbook set against both from the start avoided the rework that comes from patching a single-market design later.
How is evidence handled differently here than in a typical SOC?
Evidence is captured as part of the live response workflow - timestamps, actions, and approvals logged in real time - rather than reconstructed from memory and tickets after the fact for an audit.
This is one of several case studies on siem & soc modernization.
See the rest of the cluster →Compare your situation to this case.
Bring your constraints - environment, timeline, and budget. We scope before we quote.