Home › Services › Cybersecurity
Cybersecurity and compliance that survives an incident
Companies are overwhelmingly breached through identity, email or an unpatched laptop, not through a missing policy document. We fix what attackers use, in the order that reduces risk fastest, and we tell you which compliance clock is really ticking.
- Fee
- Posture review, fixed fee + GST · 2 weeks
- Runs for
- 2 weeks
- Covers
- Identity, endpoint, cloud, network
- VAPT
- CERT-In empanelled partner
Almost none of the incidents we get called about begin with a clever exploit. They begin with a password that worked from anywhere, an inbox rule nobody noticed, or a laptop two months behind on patches. That is where the money goes first, so it is where we go first.
- Identity. MFA that covers every account rather than most of them, conditional access, admin rights that are borrowed instead of held, and a leaver process that removes access on the day they leave.
- Email. SPF, DKIM and DMARC set to reject rather than to monitor forever, plus the banking-change and invoice checks that stop a convincing mail costing you money. Business email compromise is still the most expensive thing that happens to mid-market companies in India.
- Endpoints. Endpoint detection somebody reads, disk encryption, and a patch window that exists on a calendar rather than in an intention.
None of this is exciting and all of it is cheap relative to what it prevents. If the budget only stretches to one of the three, we will tell you which one.
A backup is not a control until someone has restored from it under time pressure. The question is not whether you have backups (nearly everyone does), but whether a copy exists that an attacker could not reach, and how long a full restore takes.
- One copy offline or immutable, so encrypting the network does not encrypt the recovery.
- A restore rehearsed against a real system, with the elapsed time written down.
- A recovery order agreed in advance: identity first, then the two systems the business cannot trade without.
We would rather spend the first week proving a restore than installing anything.
A one-time vulnerability assessment and penetration test on an application or an external estate (web, mobile or API) delivered through a CERT-In empanelled partner, because that is what the customer questionnaire, the bank and the auditor will ask for. An unempanelled tester's report is often technically fine and still fails the paperwork it was commissioned to satisfy.
- Scoped against what you expose, with the rules of engagement and the test window agreed in writing first.
- Findings rated by exploitability rather than by scanner severity, so the list is ordered by what somebody could really do.
- A retest after remediation, so what you hand over is a closed report rather than an open one.
- We do the fixing as a separate, separately quoted piece, or your team does, and we stay out of it.
The empanelment is the partner's, and we will name them before you commit. We are not going to imply a certification we do not hold.
Most SOC disappointments are onboarding failures rather than technology failures. The platform gets bought, half the estate never ships logs to it, the use cases are the vendor's defaults, and the alerts go to a mailbox nobody owns. Twelve months later there is a licence renewal and no detection.
- Onboarding: log sources enumerated against the estate, so coverage is a known number rather than an assumption; parsing and retention set against the 180 days CERT-In expects; detection content written for your environment.
- Running it: triage, escalation and an incident process with a named decision-maker, tuned so an alert means something. Cover hours are scoped to what you need rather than sold as 24×7 by default.
- Proof it works: we test detections by generating the activity, rather than waiting for a real incident to find out.
We will still tell you when a SOC is the wrong next purchase. If identity, backups and patching are not done, monitoring an unhardened estate mostly buys you a more detailed account of how you were breached.
The CERT-In Directions have been in force since 2022, and they are far more immediate than any 2027 deadline: six hours to report a reportable incident, and 180 days of logs you must be able to produce. Most companies we meet would not notice the incident inside six days, let alone six hours, and could not produce the logs at all.
- Logging that reaches somewhere central, retained long enough to satisfy the directive and to answer questions afterwards.
- A small number of alerts that mean something, rather than a console nobody opens.
- An incident plan naming who decides, who reports, and what gets isolated first, on one page, not in a binder.
- SOC monitoring through our partner network where the risk genuinely warrants it. For a lot of mid-market companies it does not yet, and we will say so.
A good deal of security quietly lives inside the cloud and network work on the rest of this site. Where the estate is already documented, most of this is inspection rather than a project.
- Cloud configuration: public buckets and databases, over-broad IAM, unencrypted volumes, security groups open to the world, and no logging in the account that matters.
- Network segmentation, so a compromised laptop cannot reach the finance server or the switch management address.
- Vulnerability management with an owner, a cadence, and a definition of what gets fixed in days rather than someday.
- Remote access that does not rest on a flat VPN and a shared credential.
Your payroll provider, your CRM, the agency with a login to your marketing platform, the vendor whose engineer keeps a standing remote session. Under DPDP a processor's failure is still your notification to make.
- A list of who holds your data and what they can reach, usually longer than expected.
- The security clauses worth having in the contract, and which ones are theatre.
- Access reviews for third-party accounts on the same cadence as your own.
Three clocks run at different speeds, and most proposals mention only the slowest.
- CERT-In: already live. Six-hour reporting and 180-day log retention apply to you today. This is the obligation companies are most often unknowingly in breach of.
- ISO 27001 and SOC 2: when a customer asks. Usually triggered by an enterprise deal or a funding round. We make the controls and the evidence real, then work alongside your auditor.
- DPDP: 13 May 2027. Notice, consent, data-principal rights, grievance redressal and breach reporting. Consent-manager registration provisions are already switched on, and the government has indicated the timeline could be pulled in rather than pushed out. It starts with a data map, because you cannot write a notice about data you cannot find.
Sector rules sit on top of these: RBI, SEBI and IRDAI each carry their own expectations, and PCI-DSS applies if you touch card data. We will tell you which you are genuinely in scope for, which is usually fewer than a vendor deck suggests.
What you walk away with
Yours to keep, and to hand to anyone else, including a provider that isn't us.
Talk to us about thisAgainst a practical control set, ranked by the risk you carry, not by how alarming each item sounds.
Every finding against a person and a date, so it can be tracked rather than admired.
The remediation split into what needs money and what just needs someone to decide.
Systems, exports and third parties: the inventory the DPDP Rules assume you already have.
Asked before you ask
The ones that come up on nearly every first call.
Talk to us about thisWhere should we start if the budget is small?
Identity, then backups you have tested, then patching. That order holds for almost every estate of this size, and none of the three needs a new product to begin. Monitoring comes after, not before. There is little point watching an environment nobody has hardened.
Is the posture review the same thing as a VAPT?
No. They answer different questions, and we sell both. A VAPT tells you what is exploitable today; a posture review tells you what will keep being exploitable, and who owns fixing it. If you need the VAPT for a customer questionnaire or an audit, we run it through a CERT-In empanelled partner. If you have had one already, bring the report. It shortens the review rather than duplicating it.
Are you CERT-In empanelled yourselves?
No. The VAPT is delivered through a CERT-In empanelled partner, and we will name them before you commit to anything. We scope the test, manage the engagement, and do the remediation work afterwards if you want us to, but the empanelment on the certificate is theirs, and we are not going to blur that.
Does every company need a SOC?
No, and we would rather say so before selling you one. A 24×7 SOC is a real ongoing cost, and for many mid-market companies the money is better spent on identity, backups and patching first. Where a SOC is genuinely warranted, usually by a customer contract or a regulator, we do the onboarding properly and run it, with cover hours scoped to what you need rather than 24×7 by default.
Are you a law firm?
No, and this is not legal advice. We handle the technical and operational side: the data map, the controls, the detection, the evidence. Where a genuine legal interpretation is needed you want counsel, and we will say so rather than guess.
Can you certify us for ISO 27001 or SOC 2?
No. Certification comes from an accredited auditor, and anyone offering you both the readiness work and the certificate is selling you a conflict of interest. We build the controls and the evidence so that the audit is short.
What if we are breached before we are ready?
Then the priority is containment, evidence and notification, in that order, and the CERT-In clock is six hours, so it matters that someone can decide quickly. If you are in the middle of something now, call rather than fill in the form.
Not sure this is the one you need?
Tell us the symptom, not the service, and we'll say which of these applies, or that none of them do. A reply within one working day, from someone technical.
The rest of what we do
Most engagements start with one of these and grow into another.