A payment gateway in Central Asia, connecting merchants to card schemes and domestic transfer rails, runs its security operations on Secure60 with the platform and its data on Rackcorp infrastructure inside the country.
The gateway handles card and account-transfer traffic for merchants, which brings card-scheme security obligations, and holds personal data registered under the Law on Personal Information (No. 58 of 2008). The Law on Cybersecurity (No. 121 of 2024) then brought critical information infrastructure under state coordination.
The scheme obligations and the two laws all require security operations to be running and evidenced, and the data was expected to stay in the country. The company’s IT team was small and had no security operations function of its own.
Secure60 was deployed on Rackcorp infrastructure in-country, where Secure60 has two datacentres, so the platform and every log it holds stay within the jurisdiction. Log Management takes the gateway, network and corporate telemetry; SIEM runs the managed rule library over it, with payments-specific tuning; Governance maps the evidence to the scheme requirements and to both laws.
Secure60 runs the operation. Digital workers triage alerts around the clock and Secure60 experts handle escalation, investigation and the periodic evidence reviews, so the gateway’s IT team keeps its focus on the payments platform.
A security operations function running from day one, without the gateway recruiting analysts.
The platform’s location answers the residency question for the schemes and the regulator.
Evidence for the scheme assessment and both laws is maintained rather than assembled.
Alert handling left the IT team’s queue. First-line triage runs around the clock, and the team is called only when an escalation warrants it.