ZENTARA
The Zentara SOC — the 24/7 watch room in Jakarta, red ZENTARA display wall over the analyst stations

Security Operations · Build–Operate–Transfer

Turnkey SOC (Build-Operate-Transfer)

The engagement ends when your team can run it — not when the contract runs out.

Zentara designs the architecture, builds the infrastructure, trains your analysts, and transitions full operational control to your organization.

4–6 wks

Strategic design phase

3

Validated reference stacks

100%

Operational control transferred

Certified & audited operations

BSSN — Badan Siber dan Sandi NegaraISO/IEC 27001 CertifiedISO/IEC 42001:2023 CertifiedAICPA SOC 2 Type 2
Verify at our trust centre

The challenge

Why most internal SOC programs stall before they operate

01

No blueprint

Tools are selected before threat models are defined. Detection logic is built without knowing the actual risk surface.

02

Talent gap

Qualified Tier 2 and Tier 3 analysts are scarce. Recruitment timelines consistently exceed build program estimates.

03

Transition cliff

Integrators deploy and exit. Organizations receive documentation but no operational continuity.

04

Sovereignty constraint

Fully outsourced models require data to leave national infrastructure. For entities under POJK and BSSN, this is not a viable option.

Introducing Zentara Turnkey SOC

The engagement ends when your team can run it — not when the contract runs out.

A build-operate-transfer engagement that leaves you with a sovereign, internally operated SOC: architecture, infrastructure, trained analysts, and full operational control — transferred.

Main deliverables

  • SOC Blueprint and Target Operating Model
  • Reference architecture, deployment, and detection engineering
  • Playbook and runbook library
  • Tier 1/2/3 training curricula and tabletop exercises
  • SOC room design and facility buildout
  • Hypercare co-managed transition

Service architecture

Four phases. One handover.

Every phase ships a named output — and Phase 0 stands alone, so you can start with the blueprint before committing to the build.

Phase 04–6 weeks

Strategic Design

Define the target before selecting the tools.

A SOC maturity diagnostic maps your threat model to regulatory exposure and delivers a SOC Blueprint with a target operating model. This standalone phase is the entry point for every Turnkey SOC engagement.

Output — SOC Blueprint + Target Operating Model

Phase 13–5 months

Architecture & Build

Engineered architecture, not best-guess procurement.

Tool selection follows the blueprint using three validated reference stacks: Microsoft-centric, Elastic-based, and a Splunk/Sentinel hybrid. Deliverables include architecture documentation, deployment and integration, detection engineering, a full playbook and runbook library, and SOC room design covering facility layout, workstation configuration, and display infrastructure.

Output — Operational SOC infrastructure

Phase 22–3 months

Staffing & Enablement

Your analysts operate the platform.

We define the SOC structure, role and JD templates, support recruitment, and deliver Tier 1–3 training including tabletop and purple team exercises. Enablement starts during build, so analysts train on the actual environment they will operate in.

Output — Trained SOC team and defined operating mode

Phase 36–12 months

Operational Transition

Handover against a maturity benchmark, not a calendar date.

Our analysts shadow operations, then co-staff with your team, and step back as maturity benchmarks such as triage ratios, MTTD, and playbook adherence are met. If hiring takes longer than planned, the engagement shifts to managed SOC or staff augmentation without renegotiation — the SOC stays operational and the transition timeline adapts.

Output — Sovereign, internally operated SOC

Our commitment

The principles behind every Turnkey SOC engagement we run

Vendor-agnostic by design

We start with your risks and architecture, not a tool quota. Our reference stacks let us move fast while keeping your SOC flexible and free from long-term vendor lock-in.

Built for regulatory environments

Your SOC is mapped to financial, national, and sectoral regulations from day one — so it satisfies auditors, regulators, and boards, not just security teams.

The transition is the product

The real challenge is handover. Our hypercare and co-managed model ensures your team can run the SOC independently, with confidence.

From build to managed, seamlessly

If hiring takes longer than planned, we can extend into managed or staff augmentation so your SOC keeps running without disruption.

The reference implementation

The SOC we build is the SOC we run

Zentara's SOC in Jakarta operates 24/7 on ZX — and the facility around it was designed the way we design yours: the watch room, the workstation floor, the display infrastructure, the playbooks, the shift discipline.

The Zentara SOC — the 24/7 watch room in Jakarta

The SOC · Zentara's 24/7 watch room, Jakarta

Analysts at multi-monitor stations on the operations floor

Analysts at work · the operations floor

The operations floor mid-shift

The operations floor, mid-shift

Workstation rows — the facility buildout

Workstation rows · facility buildout

Live dashboards seen through the glass

Live dashboards, through the glass

Walk our floor before we design yours.

See the SOC in operation

Built for high-stakes industries

Where data cannot leave national infrastructure

Primary buyers are institutions where data cannot leave national infrastructure. Indonesia is the primary market — and the same sovereign-data requirements are emerging across Malaysia, Vietnam, and Thailand.

Banking & Financial Services (BFSI)

Under POJK

State-Owned Enterprises (BUMN)

Post-PDN

Energy & Utilities

Sectoral frameworks

Telecommunications

Sectoral frameworks

Large Manufacturing

Sectoral frameworks

Government Agencies

Post-PDN · BSSN

Track record

Built for BFSI under POJK, state-owned enterprises post-PDN, and government agencies working with BSSN.

FAQ

Common questions

Straight answers. If yours isn't here, ask us directly.

With Phase 0 — Strategic Design. In 4–6 weeks we run a SOC maturity diagnostic, map your threat model to regulatory exposure, and deliver a SOC Blueprint with a target operating model. It is a standalone phase, and the entry point for every Turnkey SOC engagement.

Scope a Turnkey SOC engagement

Send us your context — we'll respond with scope, method, and timeline. No generic pitch decks.