Skip to content

Standing Up 24/7 SOC Coverage for an APAC MSSP Under MAS TRM and OJK

Standing up a new SOC operating model is straightforward; standing one up that already satisfies two regulators' expectations on day one is a different project.

24/7 coverage live within one quarter
One playbook set satisfying both MAS TRM and OJK
Zero rework at the first regulator review
01 — The problem

What we were solving

Regional MSSP expanding coverage across Singapore and Indonesia, needing to satisfy MAS TRM (Singapore) and OJK POJK 11 (Indonesia) requirements from launch.

  • MAS TRM and OJK POJK 11 have overlapping but distinct expectations for incident response timelines, evidence retention, and escalation - building for one and patching for the other later would mean rework.
  • 24/7 coverage across two time zones needed a staffing and handover model that didn't lose context between shifts.
  • The MSSP's clients expected audit-ready evidence from their very first incident, not after a maturity ramp-up period.
02 — The approach

What we built

  1. Mapped MAS TRM and OJK requirements against each other up front to build one playbook set satisfying both, rather than a Singapore playbook and a separate Indonesia patch.
  2. Designed shift handover around a shared incident timeline view so context survived the change of analyst, not just the change of ticket status.
  3. Built evidence capture into the response workflow itself - timestamps, actions, and approvals logged as the incident happened, not reconstructed afterward for a report.
05 — Outcomes

Key results

  • 24/7 coverage live within one quarter of engagement start
  • One playbook set satisfying both MAS TRM and OJK from day one
  • First regulator review passed with zero rework on existing evidence
  • Shift handovers preserved incident context across time zones
06 — Stack

What it was built on

Representative tools and patterns — exact vendors vary per client environment.

Operations

24/7 shift coverage modelCross-timezone handover workflowShared incident timeline

Compliance

MAS TRM-aligned playbooksOJK POJK 11-aligned playbooksIn-workflow evidence capture

Platform

SIEM/XDR correlationTicketing integrationClient-facing reporting
07 — Learnings

What we'd tell the next team

  • Map overlapping regulatory frameworks against each other before building anything - a playbook built for one and patched for the other later means redoing real work.
  • Evidence captured live during response is dramatically more defensible than evidence reconstructed for a report afterward.
  • Shared incident timelines matter more than shift handover documents - context lives in the timeline, not the notes about it.
FAQ

Questions this engagement anticipated

Why map MAS TRM and OJK together instead of building separately?

The two frameworks overlap significantly but differ in specifics like incident timelines and evidence retention - building one playbook set against both from the start avoided the rework that comes from patching a single-market design later.

How is evidence handled differently here than in a typical SOC?

Evidence is captured as part of the live response workflow - timestamps, actions, and approvals logged in real time - rather than reconstructed from memory and tickets after the fact for an audit.

This is one of several case studies on siem & soc modernization.

See the rest of the cluster →

Compare your situation to this case.

Bring your constraints - environment, timeline, and budget. We scope before we quote.

Get started

Leave your email - we'll reach out.

Share your work email and we'll follow up with a tailored note on security, AI, or data programmes - usually within one business day.

No spam. We only use your email to respond to this request.

Explore services →