Godwit AI Labs Talk to us

HomeServices › Cybersecurity

Cybersecurity and compliance that survives an incident

Companies are overwhelmingly breached through identity, email or an unpatched laptop, not through a missing policy document. We fix what attackers use, in the order that reduces risk fastest, and we tell you which compliance clock is really ticking.

ONE PHISHED ACCOUNT illustrative Mailbox Laptop Identity File server Domain admin Flat estate — four hops to domain admin Mailbox Laptop Identity File server Domain admin Segmented — stopped at the second hop
The same phish, twice · the only difference is segmentation
Fee
Posture review, fixed fee + GST · 2 weeks
Runs for
2 weeks
Covers
Identity, endpoint, cloud, network
VAPT
CERT-In empanelled partner
01

Where breaches start

Talk to us about this

Almost none of the incidents we get called about begin with a clever exploit. They begin with a password that worked from anywhere, an inbox rule nobody noticed, or a laptop two months behind on patches. That is where the money goes first, so it is where we go first.

  • Identity. MFA that covers every account rather than most of them, conditional access, admin rights that are borrowed instead of held, and a leaver process that removes access on the day they leave.
  • Email. SPF, DKIM and DMARC set to reject rather than to monitor forever, plus the banking-change and invoice checks that stop a convincing mail costing you money. Business email compromise is still the most expensive thing that happens to mid-market companies in India.
  • Endpoints. Endpoint detection somebody reads, disk encryption, and a patch window that exists on a calendar rather than in an intention.

None of this is exciting and all of it is cheap relative to what it prevents. If the budget only stretches to one of the three, we will tell you which one.

6 hoursthe CERT-In window to report an incident, in force since 2022, not 2027
180 daysof logs CERT-In expects you to be able to produce on request
13 May 2027when DPDP notice, consent and breach reporting bite
02

Ransomware, and the recovery nobody tested

Talk to us about this

A backup is not a control until someone has restored from it under time pressure. The question is not whether you have backups (nearly everyone does), but whether a copy exists that an attacker could not reach, and how long a full restore takes.

  • One copy offline or immutable, so encrypting the network does not encrypt the recovery.
  • A restore rehearsed against a real system, with the elapsed time written down.
  • A recovery order agreed in advance: identity first, then the two systems the business cannot trade without.

We would rather spend the first week proving a restore than installing anything.

03

VAPT, through a CERT-In empanelled partner

Talk to us about this

A one-time vulnerability assessment and penetration test on an application or an external estate (web, mobile or API) delivered through a CERT-In empanelled partner, because that is what the customer questionnaire, the bank and the auditor will ask for. An unempanelled tester's report is often technically fine and still fails the paperwork it was commissioned to satisfy.

  • Scoped against what you expose, with the rules of engagement and the test window agreed in writing first.
  • Findings rated by exploitability rather than by scanner severity, so the list is ordered by what somebody could really do.
  • A retest after remediation, so what you hand over is a closed report rather than an open one.
  • We do the fixing as a separate, separately quoted piece, or your team does, and we stay out of it.

The empanelment is the partner's, and we will name them before you commit. We are not going to imply a certification we do not hold.

04

A SOC, onboarded and then run

Talk to us about this

Most SOC disappointments are onboarding failures rather than technology failures. The platform gets bought, half the estate never ships logs to it, the use cases are the vendor's defaults, and the alerts go to a mailbox nobody owns. Twelve months later there is a licence renewal and no detection.

  • Onboarding: log sources enumerated against the estate, so coverage is a known number rather than an assumption; parsing and retention set against the 180 days CERT-In expects; detection content written for your environment.
  • Running it: triage, escalation and an incident process with a named decision-maker, tuned so an alert means something. Cover hours are scoped to what you need rather than sold as 24×7 by default.
  • Proof it works: we test detections by generating the activity, rather than waiting for a real incident to find out.

We will still tell you when a SOC is the wrong next purchase. If identity, backups and patching are not done, monitoring an unhardened estate mostly buys you a more detailed account of how you were breached.

05

Noticing, and the six-hour clock

Talk to us about this

The CERT-In Directions have been in force since 2022, and they are far more immediate than any 2027 deadline: six hours to report a reportable incident, and 180 days of logs you must be able to produce. Most companies we meet would not notice the incident inside six days, let alone six hours, and could not produce the logs at all.

  • Logging that reaches somewhere central, retained long enough to satisfy the directive and to answer questions afterwards.
  • A small number of alerts that mean something, rather than a console nobody opens.
  • An incident plan naming who decides, who reports, and what gets isolated first, on one page, not in a binder.
  • SOC monitoring through our partner network where the risk genuinely warrants it. For a lot of mid-market companies it does not yet, and we will say so.
06

Hardening what you already run

Talk to us about this

A good deal of security quietly lives inside the cloud and network work on the rest of this site. Where the estate is already documented, most of this is inspection rather than a project.

  • Cloud configuration: public buckets and databases, over-broad IAM, unencrypted volumes, security groups open to the world, and no logging in the account that matters.
  • Network segmentation, so a compromised laptop cannot reach the finance server or the switch management address.
  • Vulnerability management with an owner, a cadence, and a definition of what gets fixed in days rather than someday.
  • Remote access that does not rest on a flat VPN and a shared credential.
07

The risk you inherited from someone else

Talk to us about this

Your payroll provider, your CRM, the agency with a login to your marketing platform, the vendor whose engineer keeps a standing remote session. Under DPDP a processor's failure is still your notification to make.

  • A list of who holds your data and what they can reach, usually longer than expected.
  • The security clauses worth having in the contract, and which ones are theatre.
  • Access reviews for third-party accounts on the same cadence as your own.
08

Compliance, in the order it will hit you

Talk to us about this

Three clocks run at different speeds, and most proposals mention only the slowest.

  • CERT-In: already live. Six-hour reporting and 180-day log retention apply to you today. This is the obligation companies are most often unknowingly in breach of.
  • ISO 27001 and SOC 2: when a customer asks. Usually triggered by an enterprise deal or a funding round. We make the controls and the evidence real, then work alongside your auditor.
  • DPDP: 13 May 2027. Notice, consent, data-principal rights, grievance redressal and breach reporting. Consent-manager registration provisions are already switched on, and the government has indicated the timeline could be pulled in rather than pushed out. It starts with a data map, because you cannot write a notice about data you cannot find.

Sector rules sit on top of these: RBI, SEBI and IRDAI each carry their own expectations, and PCI-DSS applies if you touch card data. We will tell you which you are genuinely in scope for, which is usually fewer than a vendor deck suggests.

DELIVERABLES

What you walk away with

Yours to keep, and to hand to anyone else, including a provider that isn't us.

Talk to us about this
A scored posture review

Against a practical control set, ranked by the risk you carry, not by how alarming each item sounds.

A risk register with owners

Every finding against a person and a date, so it can be tracked rather than admired.

Budget vs. decision

The remediation split into what needs money and what just needs someone to decide.

A data map, where DPDP applies

Systems, exports and third parties: the inventory the DPDP Rules assume you already have.

QUESTIONS

Asked before you ask

The ones that come up on nearly every first call.

Talk to us about this
Where should we start if the budget is small?

Identity, then backups you have tested, then patching. That order holds for almost every estate of this size, and none of the three needs a new product to begin. Monitoring comes after, not before. There is little point watching an environment nobody has hardened.

Is the posture review the same thing as a VAPT?

No. They answer different questions, and we sell both. A VAPT tells you what is exploitable today; a posture review tells you what will keep being exploitable, and who owns fixing it. If you need the VAPT for a customer questionnaire or an audit, we run it through a CERT-In empanelled partner. If you have had one already, bring the report. It shortens the review rather than duplicating it.

Are you CERT-In empanelled yourselves?

No. The VAPT is delivered through a CERT-In empanelled partner, and we will name them before you commit to anything. We scope the test, manage the engagement, and do the remediation work afterwards if you want us to, but the empanelment on the certificate is theirs, and we are not going to blur that.

Does every company need a SOC?

No, and we would rather say so before selling you one. A 24×7 SOC is a real ongoing cost, and for many mid-market companies the money is better spent on identity, backups and patching first. Where a SOC is genuinely warranted, usually by a customer contract or a regulator, we do the onboarding properly and run it, with cover hours scoped to what you need rather than 24×7 by default.

Are you a law firm?

No, and this is not legal advice. We handle the technical and operational side: the data map, the controls, the detection, the evidence. Where a genuine legal interpretation is needed you want counsel, and we will say so rather than guess.

Can you certify us for ISO 27001 or SOC 2?

No. Certification comes from an accredited auditor, and anyone offering you both the readiness work and the certificate is selling you a conflict of interest. We build the controls and the evidence so that the audit is short.

What if we are breached before we are ready?

Then the priority is containment, evidence and notification, in that order, and the CERT-In clock is six hours, so it matters that someone can decide quickly. If you are in the middle of something now, call rather than fill in the form.

Not sure this is the one you need?

Tell us the symptom, not the service, and we'll say which of these applies, or that none of them do. A reply within one working day, from someone technical.

Talk to us